From sle-container-updates at lists.suse.com Tue Sep 1 07:09:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 09:09:12 +0200 (CEST) Subject: SUSE-IU-2026:6626-1: Security update of suse/sle-micro/base-5.5 Message-ID: <20260901070912.75C9FFDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6626-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.310 , suse/sle-micro/base-5.5:latest Image Release : 5.8.310 Severity : important Type : security References : 1260446 1274774 1274788 1274795 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3877-1 Released: Mon Aug 31 11:12:27 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). Changes for openssl-1_1: - August 2026 release (bsc#1274774) The following package changes have been done: - libopenssl1_1-1.1.1l-150500.17.63.1 updated - openssl-1_1-1.1.1l-150500.17.63.1 updated From sle-container-updates at lists.suse.com Tue Sep 1 07:12:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 09:12:37 +0200 (CEST) Subject: SUSE-IU-2026:6627-1: Security update of suse/sle-micro/kvm-5.5 Message-ID: <20260901071237.CBC8DFDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/kvm-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6627-1 Image Tags : suse/sle-micro/kvm-5.5:2.0.4 , suse/sle-micro/kvm-5.5:2.0.4-3.5.597 , suse/sle-micro/kvm-5.5:latest Image Release : 3.5.597 Severity : important Type : security References : 1260446 1274774 1274788 1274795 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container suse/sle-micro/kvm-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3877-1 Released: Mon Aug 31 11:12:27 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). Changes for openssl-1_1: - August 2026 release (bsc#1274774) The following package changes have been done: - libopenssl1_1-1.1.1l-150500.17.63.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.310 updated From sle-container-updates at lists.suse.com Tue Sep 1 07:17:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 09:17:15 +0200 (CEST) Subject: SUSE-IU-2026:6628-1: Security update of suse/sle-micro/rt-5.5 Message-ID: <20260901071715.9A973FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6628-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.704 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.704 Severity : important Type : security References : 1260446 1274774 1274788 1274795 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3877-1 Released: Mon Aug 31 11:12:27 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). Changes for openssl-1_1: - August 2026 release (bsc#1274774) The following package changes have been done: - libopenssl1_1-1.1.1l-150500.17.63.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.98 updated From sle-container-updates at lists.suse.com Tue Sep 1 07:20:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 09:20:40 +0200 (CEST) Subject: SUSE-IU-2026:6629-1: Security update of suse/sle-micro/5.5 Message-ID: <20260901072040.05B7DFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6629-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.98 , suse/sle-micro/5.5:latest Image Release : 5.8.98 Severity : important Type : security References : 1260446 1274774 1274788 1274795 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3877-1 Released: Mon Aug 31 11:12:27 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). Changes for openssl-1_1: - August 2026 release (bsc#1274774) The following package changes have been done: - libopenssl1_1-1.1.1l-150500.17.63.1 updated - openssl-1_1-1.1.1l-150500.17.63.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.310 updated From sle-container-updates at lists.suse.com Tue Sep 1 07:27:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 09:27:47 +0200 (CEST) Subject: SUSE-CU-2026:9402-1: Security update of private-registry/harbor-trivy-adapter Message-ID: <20260901072747.15052FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9402-1 Container Tags : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.50 , private-registry/harbor-trivy-adapter:latest Container Release : 1.50 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - system-user-harbor-2.13.5-150700.1.25 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Tue Sep 1 07:30:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 09:30:31 +0200 (CEST) Subject: SUSE-CU-2026:9405-1: Security update of suse/sle-micro/5.5/toolbox Message-ID: <20260901073031.41027FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9405-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.186 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.186 Severity : important Type : security References : 1260446 1274774 1274788 1274795 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3877-1 Released: Mon Aug 31 11:12:27 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). Changes for openssl-1_1: - August 2026 release (bsc#1274774) The following package changes have been done: - libopenssl1_1-hmac-1.1.1l-150500.17.63.1 updated - libopenssl1_1-1.1.1l-150500.17.63.1 updated - openssl-1_1-1.1.1l-150500.17.63.1 updated From sle-container-updates at lists.suse.com Tue Sep 1 07:33:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 09:33:27 +0200 (CEST) Subject: SUSE-IU-2026:6630-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260901073327.0FA2CFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6630-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.236 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.236 Severity : moderate Type : security References : 1221712 1274856 1274857 1274858 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 871 Released: Mon Aug 31 21:29:34 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1221712,1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: Security issues fixed: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). Non security issue fixed: - GCC 14: cpio package fails (bsc#1221712). The following package changes have been done: - cpio-2.15-2.1 updated - SL-Micro-release-6.0-25.127 updated - container:SL-Micro-base-container-2.1.3-7.200 updated From sle-container-updates at lists.suse.com Tue Sep 1 07:36:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 09:36:13 +0200 (CEST) Subject: SUSE-IU-2026:6631-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260901073613.17DC7FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6631-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.200 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.200 Severity : moderate Type : security References : 1221712 1274856 1274857 1274858 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 871 Released: Mon Aug 31 21:29:34 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1221712,1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: Security issues fixed: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). Non security issue fixed: - GCC 14: cpio package fails (bsc#1221712). The following package changes have been done: - cpio-2.15-2.1 updated - SL-Micro-release-6.0-25.127 updated - container:suse-toolbox-image-1.0.0-9.156 updated From sle-container-updates at lists.suse.com Tue Sep 1 07:38:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 09:38:55 +0200 (CEST) Subject: SUSE-IU-2026:6632-1: Security update of suse/sl-micro/6.0/kvm-os-container Message-ID: <20260901073855.3E7BFFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6632-1 Image Tags : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.211 , suse/sl-micro/6.0/kvm-os-container:latest Image Release : 6.211 Severity : moderate Type : security References : 1221712 1274856 1274857 1274858 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 871 Released: Mon Aug 31 21:29:34 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1221712,1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: Security issues fixed: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). Non security issue fixed: - GCC 14: cpio package fails (bsc#1221712). The following package changes have been done: - cpio-2.15-2.1 updated - SL-Micro-release-6.0-25.127 updated - container:SL-Micro-base-container-2.1.3-7.200 updated From sle-container-updates at lists.suse.com Tue Sep 1 07:42:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 09:42:00 +0200 (CEST) Subject: SUSE-IU-2026:6633-1: Security update of suse/sl-micro/6.0/rt-os-container Message-ID: <20260901074200.66105FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6633-1 Image Tags : suse/sl-micro/6.0/rt-os-container:2.1.3 , suse/sl-micro/6.0/rt-os-container:2.1.3-7.229 , suse/sl-micro/6.0/rt-os-container:latest Image Release : 7.229 Severity : moderate Type : security References : 1221712 1274856 1274857 1274858 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 871 Released: Mon Aug 31 21:29:34 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1221712,1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: Security issues fixed: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). Non security issue fixed: - GCC 14: cpio package fails (bsc#1221712). The following package changes have been done: - cpio-2.15-2.1 updated - SL-Micro-release-6.0-25.127 updated - container:SL-Micro-container-2.1.3-6.236 updated From sle-container-updates at lists.suse.com Tue Sep 1 07:56:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 09:56:24 +0200 (CEST) Subject: SUSE-IU-2026:6634-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260901075624.C4A30FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6634-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.109 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.109 Severity : moderate Type : security References : 1258307 1261256 1271500 1273197 1273200 CVE-2026-2604 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 844 Released: Mon Jun 1 15:18:04 2026 Summary: Security update for evolution-data-server Type: security Severity: moderate References: 1258307,CVE-2026-2604 This update for evolution-data-server fixes the following issues: - CVE-2026-2604: Canonicalize path before local cache file removal. (bsc#1258307) ----------------------------------------------------------------- Advisory ID: 1534 Released: Sun Aug 30 15:09:44 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. ----------------------------------------------------------------- Advisory ID: 1533 Released: Sun Aug 30 15:11:40 2026 Summary: Recommended update for nfs-utils Type: recommended Severity: moderate References: 1273197 This update for nfs-utils fixes the following issues: - nfs-client: make the rpcctl util executable (bsc#1273197) ----------------------------------------------------------------- Advisory ID: 1540 Released: Sun Aug 30 16:33:19 2026 Summary: Recommended update for ethtool Type: recommended Severity: moderate References: 1261256,1271500 This update for ethtool fixes the following issues: - backport Rx CQE coalescing support (bsc#1261256): * sync UAPI header copies with SL-16.1 * netlink: settings: add netlink support for RX CQE Coalescing params - backport post-6.14 upstream fixes (bsc#1271500): * Fix index calculation in RTTPT2C register dump loop * Fix incorrect LSB field used for wavelength tolerance * ethtool: Add --disable-netlink to help output * ethtool.spec: Add AppStream metainfo file to %files section * netlink: add NULL check for get_string() in features.c * sfpid: + Fix JSON output of SFP diagnostics + Fix 10G Base-ER module detection + Fix redundant print of Active Cu cmplnce. - misc: Fix AppStream metainfo XML ----------------------------------------------------------------- Advisory ID: 1542 Released: Sun Aug 30 16:35:57 2026 Summary: Recommended update for setools Type: recommended Severity: moderate References: 1273200 This update for setools fixes the following issues: - Move sedta and seinfoflow to setools-console-analyses and exlude its build for SLE16 as python-networkx won't be available there (bsc#1273200). The following package changes have been done: - ethtool-6.14-160000.3.1 updated - libnfsidmap1-1.0-160000.4.1 updated - timezone-2026c-160000.1.1 updated - python313-setools-4.5.1-160000.3.1 updated - nfs-client-2.8.2-160000.4.1 updated From sle-container-updates at lists.suse.com Tue Sep 1 07:56:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 09:56:29 +0200 (CEST) Subject: SUSE-IU-2026:6637-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260901075629.448ADFDCF@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6637-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.114 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.114 Severity : moderate Type : security References : 1263078 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1562 Released: Mon Aug 31 07:56:37 2026 Summary: Security update for libgpg-error Type: security Severity: moderate References: 1263078 This update for libgpg-error fixes the following issue: - Out-of-bounds read in `_gpgrt_vfnameconcat` of `stringutils.c` when the `GPGRT_FCONCAT_SYSCONF` flag is used (bsc#1263078). The following package changes have been done: - libgpg-error0-1.58-160000.2.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-0af67dd7b9ab5ee1b4854a4e80aedb763362636c923e0f1259df28a55fa44966-0 updated From sle-container-updates at lists.suse.com Tue Sep 1 07:56:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 09:56:33 +0200 (CEST) Subject: SUSE-IU-2026:6639-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260901075633.5AF51FEC9@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6639-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.116 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.116 Severity : critical Type : security References : 1262698 1262701 1266262 1266263 1271649 1272772 1272773 1272774 1274867 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1570 Released: Mon Aug 31 17:42:15 2026 Summary: Security update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen Type: security Severity: critical References: 1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1274867,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16408,CVE-2026-16409,CVE-2026-1641 0,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990 This update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.1.0 ESR. * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935 Privilege escalation in the DOM: Networking component * CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937 Use-after-free in the JavaScript: GC component * CVE-2026-74938 Mitigation bypass in the JavaScript: GC component * CVE-2026-74939 Privilege escalation in the DOM: Navigation component * CVE-2026-74940 Use-after-free in the Graphics: Text component * CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942 Privilege escalation in the Remote Settings Client component * CVE-2026-74943 Use-after-free in the Graphics: ImageLib component * CVE-2026-74944 Use-after-free in the DOM: Core & HTML component * CVE-2026-74945 Information disclosure in the Graphics: Text component * CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948 Information disclosure in the Graphics component * CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950 Privilege escalation in the Downloads API component * CVE-2026-74953 Privilege escalation in the Networking: Cookies component * CVE-2026-74954 Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955 Privilege escalation in the Request Handling component * CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957 Mitigation bypass in the Safe Browsing component * CVE-2026-74958 Information disclosure in the WebRTC component * CVE-2026-74959 Mitigation bypass in the Storage: Cache API component * CVE-2026-74960 Site isolation issue in the WebExtensions component * CVE-2026-74961 Side-channel in the Web Audio component * CVE-2026-74962 Site isolation issue in the Networking: Cookies component * CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964 Integer overflow in the Graphics component * CVE-2026-74965 Privilege escalation in the Shell Integration component * CVE-2026-74966 Information disclosure in the Form Autofill component * CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968 Site isolation issue in the Graphics: WebRender component * CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970 Site isolation issue in the Graphics component * CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973 Race condition, use-after-free in the Graphics component * CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977 Integer overflow in the Graphics component * CVE-2026-74978 Clickjacking issue in the Widget component * CVE-2026-74979 Mitigation bypass in the Add-ons Manager component * CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982 Denial-of-service in the Widget component * CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984 Race condition in the JavaScript Engine component * CVE-2026-74985 Privilege escalation in the Enterprise Policies component * CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988 Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. - MFSA 2026-68 (bsc#1271649): * CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364 Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365 Privilege escalation in the DOM: Workers component * CVE-2026-16366 Privilege escalation in the DOM: Navigation component * CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354 Information disclosure in the Graphics: ImageLib component * CVE-2026-16367 Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357 Incorrect boundary conditions in the Graphics component * CVE-2026-16370 Mitigation bypass in the DOM: Networking component * CVE-2026-16371 Privilege escalation in the DOM: Navigation component * CVE-2026-16372 Privilege escalation in the DOM: Content Processes component * CVE-2026-16373 Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374 Information disclosure in the Framework component in DevTools * CVE-2026-16375 Site isolation issue in the Networking: HTTP component * CVE-2026-16376 Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377 Mitigation bypass in the PDF Viewer component * CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379 Privilege escalation in the DOM: Content Processes component * CVE-2026-16358 Site isolation issue in the Graphics: WebRender component * CVE-2026-16380 Mitigation bypass in the Networking component * CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383 Mitigation bypass in the DOM: Networking component * CVE-2026-16384 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387 Site isolation issue in the Networking component * CVE-2026-16388 Sandbox escape in the DOM: Networking component * CVE-2026-16389 Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390 Mitigation bypass in the Enterprise Policies component * CVE-2026-16391 Information disclosure in the Storage: IndexedDB component * CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393 Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394 Mitigation bypass in the DOM: Security component * CVE-2026-16395 Integer overflow in the Audio/Video component * CVE-2026-16396 Privilege escalation in WebExtensions * CVE-2026-16397 Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398 Site isolation issue in the Graphics component * CVE-2026-16399 Site isolation issue in the DOM: Navigation component * CVE-2026-16400 Information disclosure in the DOM: Security component * CVE-2026-16401 Privilege escalation in the Data Loss Prevention component * CVE-2026-16402 Integer overflow in the Graphics: ImageLib component * CVE-2026-16403 Spoofing issue in the Address Bar component * CVE-2026-16404 Spoofing issue in Firefox for Android * CVE-2026-16405 Information disclosure in the Networking: WebSockets component * CVE-2026-16406 Mitigation bypass in the Networking component * CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408 Integer overflow in the Audio/Video: Playback component * CVE-2026-16409 Invalid pointer in the Security: PSM component * CVE-2026-16410 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411 Memory safety bugs fixed in Firefox 153 * CVE-2026-16412 Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360 Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 Changes in mozilla-nss: - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Update fuzz/config/tstclnt_arguments.py. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - update to NSS 3.113 * Fix alias for mac workers on try. * Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in rust-cbindgen: - Update to version v0.29.4+git0: * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * Explicitly request serde's std features to avoid issues with newer toml versions. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * tests: Fix symbol file and tests. * tests: Run rustfmt. The following package changes have been done: - libfreebl3-3.125-160000.1.1 updated - mozilla-nspr-4.39-160000.1.1 updated - mozilla-nss-certs-3.125-160000.1.1 updated - mozilla-nss-3.125-160000.1.1 updated - libsoftokn3-3.125-160000.1.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-0fcc1a04934c8b5ee748591f8d0ead8740478355672f2a0ab21a7858365c3cd2-0 updated From sle-container-updates at lists.suse.com Tue Sep 1 08:06:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 10:06:06 +0200 (CEST) Subject: SUSE-IU-2026:6651-1: Recommended update of suse/sl-micro/6.2/base-os-container Message-ID: <20260901080606.0A0E4FDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6651-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.58 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.58 Severity : moderate Type : recommended References : 1271602 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1538 Released: Sun Aug 30 16:33:19 2026 Summary: Recommended update for update-bootloader Type: recommended Severity: moderate References: 1271602 This update for update-bootloader fixes the following issues: - update to version 1.28: * fix test suite * add test case * adjust two tests * updated test results * fix command line parser (bsc#1271602) * fix and reenable ksh tests: ksh uses alts now * update ksh test results The following package changes have been done: - update-bootloader-1.28-160000.1.1 updated From sle-container-updates at lists.suse.com Tue Sep 1 08:06:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 10:06:08 +0200 (CEST) Subject: SUSE-IU-2026:6652-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260901080608.3D7BDFDD4@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6652-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.59 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.59 Severity : moderate Type : security References : 1263078 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1562 Released: Mon Aug 31 07:56:37 2026 Summary: Security update for libgpg-error Type: security Severity: moderate References: 1263078 This update for libgpg-error fixes the following issue: - Out-of-bounds read in `_gpgrt_vfnameconcat` of `stringutils.c` when the `GPGRT_FCONCAT_SYSCONF` flag is used (bsc#1263078). The following package changes have been done: - libgpg-error0-1.58-160000.2.1 updated From sle-container-updates at lists.suse.com Tue Sep 1 08:06:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 10:06:09 +0200 (CEST) Subject: SUSE-IU-2026:6653-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260901080609.D5DCDFEDB@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6653-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.60 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.60 Severity : critical Type : security References : 1262698 1262701 1266262 1266263 1271649 1272772 1272773 1272774 1274867 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1570 Released: Mon Aug 31 17:42:15 2026 Summary: Security update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen Type: security Severity: critical References: 1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1274867,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16408,CVE-2026-16409,CVE-2026-1641 0,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990 This update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.1.0 ESR. * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935 Privilege escalation in the DOM: Networking component * CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937 Use-after-free in the JavaScript: GC component * CVE-2026-74938 Mitigation bypass in the JavaScript: GC component * CVE-2026-74939 Privilege escalation in the DOM: Navigation component * CVE-2026-74940 Use-after-free in the Graphics: Text component * CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942 Privilege escalation in the Remote Settings Client component * CVE-2026-74943 Use-after-free in the Graphics: ImageLib component * CVE-2026-74944 Use-after-free in the DOM: Core & HTML component * CVE-2026-74945 Information disclosure in the Graphics: Text component * CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948 Information disclosure in the Graphics component * CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950 Privilege escalation in the Downloads API component * CVE-2026-74953 Privilege escalation in the Networking: Cookies component * CVE-2026-74954 Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955 Privilege escalation in the Request Handling component * CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957 Mitigation bypass in the Safe Browsing component * CVE-2026-74958 Information disclosure in the WebRTC component * CVE-2026-74959 Mitigation bypass in the Storage: Cache API component * CVE-2026-74960 Site isolation issue in the WebExtensions component * CVE-2026-74961 Side-channel in the Web Audio component * CVE-2026-74962 Site isolation issue in the Networking: Cookies component * CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964 Integer overflow in the Graphics component * CVE-2026-74965 Privilege escalation in the Shell Integration component * CVE-2026-74966 Information disclosure in the Form Autofill component * CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968 Site isolation issue in the Graphics: WebRender component * CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970 Site isolation issue in the Graphics component * CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973 Race condition, use-after-free in the Graphics component * CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977 Integer overflow in the Graphics component * CVE-2026-74978 Clickjacking issue in the Widget component * CVE-2026-74979 Mitigation bypass in the Add-ons Manager component * CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982 Denial-of-service in the Widget component * CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984 Race condition in the JavaScript Engine component * CVE-2026-74985 Privilege escalation in the Enterprise Policies component * CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988 Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. - MFSA 2026-68 (bsc#1271649): * CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364 Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365 Privilege escalation in the DOM: Workers component * CVE-2026-16366 Privilege escalation in the DOM: Navigation component * CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354 Information disclosure in the Graphics: ImageLib component * CVE-2026-16367 Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357 Incorrect boundary conditions in the Graphics component * CVE-2026-16370 Mitigation bypass in the DOM: Networking component * CVE-2026-16371 Privilege escalation in the DOM: Navigation component * CVE-2026-16372 Privilege escalation in the DOM: Content Processes component * CVE-2026-16373 Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374 Information disclosure in the Framework component in DevTools * CVE-2026-16375 Site isolation issue in the Networking: HTTP component * CVE-2026-16376 Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377 Mitigation bypass in the PDF Viewer component * CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379 Privilege escalation in the DOM: Content Processes component * CVE-2026-16358 Site isolation issue in the Graphics: WebRender component * CVE-2026-16380 Mitigation bypass in the Networking component * CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383 Mitigation bypass in the DOM: Networking component * CVE-2026-16384 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387 Site isolation issue in the Networking component * CVE-2026-16388 Sandbox escape in the DOM: Networking component * CVE-2026-16389 Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390 Mitigation bypass in the Enterprise Policies component * CVE-2026-16391 Information disclosure in the Storage: IndexedDB component * CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393 Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394 Mitigation bypass in the DOM: Security component * CVE-2026-16395 Integer overflow in the Audio/Video component * CVE-2026-16396 Privilege escalation in WebExtensions * CVE-2026-16397 Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398 Site isolation issue in the Graphics component * CVE-2026-16399 Site isolation issue in the DOM: Navigation component * CVE-2026-16400 Information disclosure in the DOM: Security component * CVE-2026-16401 Privilege escalation in the Data Loss Prevention component * CVE-2026-16402 Integer overflow in the Graphics: ImageLib component * CVE-2026-16403 Spoofing issue in the Address Bar component * CVE-2026-16404 Spoofing issue in Firefox for Android * CVE-2026-16405 Information disclosure in the Networking: WebSockets component * CVE-2026-16406 Mitigation bypass in the Networking component * CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408 Integer overflow in the Audio/Video: Playback component * CVE-2026-16409 Invalid pointer in the Security: PSM component * CVE-2026-16410 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411 Memory safety bugs fixed in Firefox 153 * CVE-2026-16412 Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360 Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 Changes in mozilla-nss: - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Update fuzz/config/tstclnt_arguments.py. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - update to NSS 3.113 * Fix alias for mac workers on try. * Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in rust-cbindgen: - Update to version v0.29.4+git0: * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * Explicitly request serde's std features to avoid issues with newer toml versions. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * tests: Fix symbol file and tests. * tests: Run rustfmt. The following package changes have been done: - libfreebl3-3.125-160000.1.1 updated - mozilla-nspr-4.39-160000.1.1 updated - mozilla-nss-certs-3.125-160000.1.1 updated - mozilla-nss-3.125-160000.1.1 updated - libsoftokn3-3.125-160000.1.1 updated From sle-container-updates at lists.suse.com Tue Sep 1 08:15:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 10:15:43 +0200 (CEST) Subject: SUSE-IU-2026:6662-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260901081543.2B740FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6662-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.100 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.100 Severity : moderate Type : security References : 1263078 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1562 Released: Mon Aug 31 07:56:37 2026 Summary: Security update for libgpg-error Type: security Severity: moderate References: 1263078 This update for libgpg-error fixes the following issue: - Out-of-bounds read in `_gpgrt_vfnameconcat` of `stringutils.c` when the `GPGRT_FCONCAT_SYSCONF` flag is used (bsc#1263078). The following package changes have been done: - libgpg-error0-1.58-160000.2.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-0af67dd7b9ab5ee1b4854a4e80aedb763362636c923e0f1259df28a55fa44966-0 updated From sle-container-updates at lists.suse.com Tue Sep 1 08:15:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 10:15:45 +0200 (CEST) Subject: SUSE-IU-2026:6664-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260901081545.2E3EBFDCF@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6664-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.102 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.102 Severity : critical Type : security References : 1262698 1262701 1266262 1266263 1271649 1272772 1272773 1272774 1274867 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1570 Released: Mon Aug 31 17:42:15 2026 Summary: Security update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen Type: security Severity: critical References: 1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1274867,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16408,CVE-2026-16409,CVE-2026-1641 0,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990 This update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.1.0 ESR. * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935 Privilege escalation in the DOM: Networking component * CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937 Use-after-free in the JavaScript: GC component * CVE-2026-74938 Mitigation bypass in the JavaScript: GC component * CVE-2026-74939 Privilege escalation in the DOM: Navigation component * CVE-2026-74940 Use-after-free in the Graphics: Text component * CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942 Privilege escalation in the Remote Settings Client component * CVE-2026-74943 Use-after-free in the Graphics: ImageLib component * CVE-2026-74944 Use-after-free in the DOM: Core & HTML component * CVE-2026-74945 Information disclosure in the Graphics: Text component * CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948 Information disclosure in the Graphics component * CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950 Privilege escalation in the Downloads API component * CVE-2026-74953 Privilege escalation in the Networking: Cookies component * CVE-2026-74954 Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955 Privilege escalation in the Request Handling component * CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957 Mitigation bypass in the Safe Browsing component * CVE-2026-74958 Information disclosure in the WebRTC component * CVE-2026-74959 Mitigation bypass in the Storage: Cache API component * CVE-2026-74960 Site isolation issue in the WebExtensions component * CVE-2026-74961 Side-channel in the Web Audio component * CVE-2026-74962 Site isolation issue in the Networking: Cookies component * CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964 Integer overflow in the Graphics component * CVE-2026-74965 Privilege escalation in the Shell Integration component * CVE-2026-74966 Information disclosure in the Form Autofill component * CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968 Site isolation issue in the Graphics: WebRender component * CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970 Site isolation issue in the Graphics component * CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973 Race condition, use-after-free in the Graphics component * CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977 Integer overflow in the Graphics component * CVE-2026-74978 Clickjacking issue in the Widget component * CVE-2026-74979 Mitigation bypass in the Add-ons Manager component * CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982 Denial-of-service in the Widget component * CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984 Race condition in the JavaScript Engine component * CVE-2026-74985 Privilege escalation in the Enterprise Policies component * CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988 Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. - MFSA 2026-68 (bsc#1271649): * CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364 Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365 Privilege escalation in the DOM: Workers component * CVE-2026-16366 Privilege escalation in the DOM: Navigation component * CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354 Information disclosure in the Graphics: ImageLib component * CVE-2026-16367 Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357 Incorrect boundary conditions in the Graphics component * CVE-2026-16370 Mitigation bypass in the DOM: Networking component * CVE-2026-16371 Privilege escalation in the DOM: Navigation component * CVE-2026-16372 Privilege escalation in the DOM: Content Processes component * CVE-2026-16373 Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374 Information disclosure in the Framework component in DevTools * CVE-2026-16375 Site isolation issue in the Networking: HTTP component * CVE-2026-16376 Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377 Mitigation bypass in the PDF Viewer component * CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379 Privilege escalation in the DOM: Content Processes component * CVE-2026-16358 Site isolation issue in the Graphics: WebRender component * CVE-2026-16380 Mitigation bypass in the Networking component * CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383 Mitigation bypass in the DOM: Networking component * CVE-2026-16384 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387 Site isolation issue in the Networking component * CVE-2026-16388 Sandbox escape in the DOM: Networking component * CVE-2026-16389 Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390 Mitigation bypass in the Enterprise Policies component * CVE-2026-16391 Information disclosure in the Storage: IndexedDB component * CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393 Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394 Mitigation bypass in the DOM: Security component * CVE-2026-16395 Integer overflow in the Audio/Video component * CVE-2026-16396 Privilege escalation in WebExtensions * CVE-2026-16397 Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398 Site isolation issue in the Graphics component * CVE-2026-16399 Site isolation issue in the DOM: Navigation component * CVE-2026-16400 Information disclosure in the DOM: Security component * CVE-2026-16401 Privilege escalation in the Data Loss Prevention component * CVE-2026-16402 Integer overflow in the Graphics: ImageLib component * CVE-2026-16403 Spoofing issue in the Address Bar component * CVE-2026-16404 Spoofing issue in Firefox for Android * CVE-2026-16405 Information disclosure in the Networking: WebSockets component * CVE-2026-16406 Mitigation bypass in the Networking component * CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408 Integer overflow in the Audio/Video: Playback component * CVE-2026-16409 Invalid pointer in the Security: PSM component * CVE-2026-16410 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411 Memory safety bugs fixed in Firefox 153 * CVE-2026-16412 Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360 Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 Changes in mozilla-nss: - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Update fuzz/config/tstclnt_arguments.py. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - update to NSS 3.113 * Fix alias for mac workers on try. * Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in rust-cbindgen: - Update to version v0.29.4+git0: * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * Explicitly request serde's std features to avoid issues with newer toml versions. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * tests: Fix symbol file and tests. * tests: Run rustfmt. The following package changes have been done: - libfreebl3-3.125-160000.1.1 updated - mozilla-nspr-4.39-160000.1.1 updated - mozilla-nss-certs-3.125-160000.1.1 updated - mozilla-nss-3.125-160000.1.1 updated - libsoftokn3-3.125-160000.1.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-0fcc1a04934c8b5ee748591f8d0ead8740478355672f2a0ab21a7858365c3cd2-0 updated From sle-container-updates at lists.suse.com Tue Sep 1 08:25:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 10:25:09 +0200 (CEST) Subject: SUSE-IU-2026:6677-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260901082509.0CA37FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6677-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.131 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.131 Severity : moderate Type : security References : 1263078 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1562 Released: Mon Aug 31 07:56:37 2026 Summary: Security update for libgpg-error Type: security Severity: moderate References: 1263078 This update for libgpg-error fixes the following issue: - Out-of-bounds read in `_gpgrt_vfnameconcat` of `stringutils.c` when the `GPGRT_FCONCAT_SYSCONF` flag is used (bsc#1263078). The following package changes have been done: - libgpg-error0-1.58-160000.2.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-9ec66dd98edc7c448d9b51920ff8422e3e443e63b8c86481451680d1ff302e80-0 updated From sle-container-updates at lists.suse.com Tue Sep 1 08:25:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 10:25:13 +0200 (CEST) Subject: SUSE-IU-2026:6679-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260901082513.BFEE0FDCF@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6679-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.133 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.133 Severity : critical Type : security References : 1262698 1262701 1266262 1266263 1271649 1272772 1272773 1272774 1274867 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1570 Released: Mon Aug 31 17:42:15 2026 Summary: Security update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen Type: security Severity: critical References: 1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1274867,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16408,CVE-2026-16409,CVE-2026-1641 0,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990 This update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.1.0 ESR. * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935 Privilege escalation in the DOM: Networking component * CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937 Use-after-free in the JavaScript: GC component * CVE-2026-74938 Mitigation bypass in the JavaScript: GC component * CVE-2026-74939 Privilege escalation in the DOM: Navigation component * CVE-2026-74940 Use-after-free in the Graphics: Text component * CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942 Privilege escalation in the Remote Settings Client component * CVE-2026-74943 Use-after-free in the Graphics: ImageLib component * CVE-2026-74944 Use-after-free in the DOM: Core & HTML component * CVE-2026-74945 Information disclosure in the Graphics: Text component * CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948 Information disclosure in the Graphics component * CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950 Privilege escalation in the Downloads API component * CVE-2026-74953 Privilege escalation in the Networking: Cookies component * CVE-2026-74954 Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955 Privilege escalation in the Request Handling component * CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957 Mitigation bypass in the Safe Browsing component * CVE-2026-74958 Information disclosure in the WebRTC component * CVE-2026-74959 Mitigation bypass in the Storage: Cache API component * CVE-2026-74960 Site isolation issue in the WebExtensions component * CVE-2026-74961 Side-channel in the Web Audio component * CVE-2026-74962 Site isolation issue in the Networking: Cookies component * CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964 Integer overflow in the Graphics component * CVE-2026-74965 Privilege escalation in the Shell Integration component * CVE-2026-74966 Information disclosure in the Form Autofill component * CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968 Site isolation issue in the Graphics: WebRender component * CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970 Site isolation issue in the Graphics component * CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973 Race condition, use-after-free in the Graphics component * CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977 Integer overflow in the Graphics component * CVE-2026-74978 Clickjacking issue in the Widget component * CVE-2026-74979 Mitigation bypass in the Add-ons Manager component * CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982 Denial-of-service in the Widget component * CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984 Race condition in the JavaScript Engine component * CVE-2026-74985 Privilege escalation in the Enterprise Policies component * CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988 Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. - MFSA 2026-68 (bsc#1271649): * CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364 Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365 Privilege escalation in the DOM: Workers component * CVE-2026-16366 Privilege escalation in the DOM: Navigation component * CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354 Information disclosure in the Graphics: ImageLib component * CVE-2026-16367 Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357 Incorrect boundary conditions in the Graphics component * CVE-2026-16370 Mitigation bypass in the DOM: Networking component * CVE-2026-16371 Privilege escalation in the DOM: Navigation component * CVE-2026-16372 Privilege escalation in the DOM: Content Processes component * CVE-2026-16373 Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374 Information disclosure in the Framework component in DevTools * CVE-2026-16375 Site isolation issue in the Networking: HTTP component * CVE-2026-16376 Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377 Mitigation bypass in the PDF Viewer component * CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379 Privilege escalation in the DOM: Content Processes component * CVE-2026-16358 Site isolation issue in the Graphics: WebRender component * CVE-2026-16380 Mitigation bypass in the Networking component * CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383 Mitigation bypass in the DOM: Networking component * CVE-2026-16384 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387 Site isolation issue in the Networking component * CVE-2026-16388 Sandbox escape in the DOM: Networking component * CVE-2026-16389 Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390 Mitigation bypass in the Enterprise Policies component * CVE-2026-16391 Information disclosure in the Storage: IndexedDB component * CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393 Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394 Mitigation bypass in the DOM: Security component * CVE-2026-16395 Integer overflow in the Audio/Video component * CVE-2026-16396 Privilege escalation in WebExtensions * CVE-2026-16397 Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398 Site isolation issue in the Graphics component * CVE-2026-16399 Site isolation issue in the DOM: Navigation component * CVE-2026-16400 Information disclosure in the DOM: Security component * CVE-2026-16401 Privilege escalation in the Data Loss Prevention component * CVE-2026-16402 Integer overflow in the Graphics: ImageLib component * CVE-2026-16403 Spoofing issue in the Address Bar component * CVE-2026-16404 Spoofing issue in Firefox for Android * CVE-2026-16405 Information disclosure in the Networking: WebSockets component * CVE-2026-16406 Mitigation bypass in the Networking component * CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408 Integer overflow in the Audio/Video: Playback component * CVE-2026-16409 Invalid pointer in the Security: PSM component * CVE-2026-16410 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411 Memory safety bugs fixed in Firefox 153 * CVE-2026-16412 Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360 Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 Changes in mozilla-nss: - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Update fuzz/config/tstclnt_arguments.py. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - update to NSS 3.113 * Fix alias for mac workers on try. * Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in rust-cbindgen: - Update to version v0.29.4+git0: * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * Explicitly request serde's std features to avoid issues with newer toml versions. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * tests: Fix symbol file and tests. * tests: Run rustfmt. The following package changes have been done: - libfreebl3-3.125-160000.1.1 updated - mozilla-nspr-4.39-160000.1.1 updated - mozilla-nss-certs-3.125-160000.1.1 updated - mozilla-nss-3.125-160000.1.1 updated - libsoftokn3-3.125-160000.1.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-93c64f77ca8ecd0bc8d3b3c465e2b39f43959a077ae04713035f9ce2952065e0-0 updated From sle-container-updates at lists.suse.com Tue Sep 1 08:37:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 1 Sep 2026 10:37:44 +0200 (CEST) Subject: SUSE-CU-2026:9410-1: Security update of suse/ltss/sle15.5/sle15 Message-ID: <20260901083744.88179FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.5/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9410-1 Container Tags : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.67 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.67 , suse/ltss/sle15.5/sle15:latest Container Release : 8.67 Severity : important Type : security References : 1260446 1260446 1274774 1274774 1274788 1274788 1274790 1274795 1274795 1274797 1275837 CVE-2026-54874 CVE-2026-54874 CVE-2026-63072 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3876-1 Released: Mon Aug 31 11:11:58 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1260446,1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). - CVE-2026-63074: CMP Indefinite Cache Growth of ExtraCerts (bsc#1274797). - CVE-2026-63076: Invalid Pointer Dereference in CMP Server via Crafted protectionAlg (bsc#1274790). - CVE-2026-75803: AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() (bsc#1275837). Changes for openssl-3: - August 2026 release (bsc#1274774). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3877-1 Released: Mon Aug 31 11:12:27 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). Changes for openssl-1_1: - August 2026 release (bsc#1274774) The following package changes have been done: - libopenssl1_1-hmac-1.1.1l-150500.17.63.1 updated - libopenssl1_1-1.1.1l-150500.17.63.1 updated - libopenssl3-3.0.8-150500.5.75.1 updated - openssl-1_1-1.1.1l-150500.17.63.1 updated - openssl-3-3.0.8-150500.5.75.1 updated From sle-container-updates at lists.suse.com Wed Sep 2 07:09:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 09:09:29 +0200 (CEST) Subject: SUSE-IU-2026:6692-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260902070929.7C7F5FDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6692-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.237 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.237 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 872 Released: Tue Sep 1 09:06:07 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-4.1 updated - SL-Micro-release-6.0-25.128 updated - container:SL-Micro-base-container-2.1.3-7.201 updated From sle-container-updates at lists.suse.com Wed Sep 2 07:11:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 09:11:57 +0200 (CEST) Subject: SUSE-IU-2026:6694-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260902071157.BC149FDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6694-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.201 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.201 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 872 Released: Tue Sep 1 09:06:07 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-4.1 updated - SL-Micro-release-6.0-25.128 updated - container:suse-toolbox-image-1.0.0-9.158 updated From sle-container-updates at lists.suse.com Wed Sep 2 07:14:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 09:14:36 +0200 (CEST) Subject: SUSE-IU-2026:6696-1: Security update of suse/sl-micro/6.0/kvm-os-container Message-ID: <20260902071436.BBC0CFDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6696-1 Image Tags : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.212 , suse/sl-micro/6.0/kvm-os-container:latest Image Release : 6.212 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 872 Released: Tue Sep 1 09:06:07 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-4.1 updated - SL-Micro-release-6.0-25.128 updated - container:SL-Micro-base-container-2.1.3-7.201 updated From sle-container-updates at lists.suse.com Wed Sep 2 07:17:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 09:17:22 +0200 (CEST) Subject: SUSE-IU-2026:6698-1: Security update of suse/sl-micro/6.0/rt-os-container Message-ID: <20260902071722.AC5EFFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6698-1 Image Tags : suse/sl-micro/6.0/rt-os-container:2.1.3 , suse/sl-micro/6.0/rt-os-container:2.1.3-7.230 , suse/sl-micro/6.0/rt-os-container:latest Image Release : 7.230 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 872 Released: Tue Sep 1 09:06:07 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-4.1 updated - SL-Micro-release-6.0-25.128 updated - container:SL-Micro-container-2.1.3-6.237 updated From sle-container-updates at lists.suse.com Wed Sep 2 07:27:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 09:27:49 +0200 (CEST) Subject: SUSE-CU-2026:9419-1: Security update of suse/sl-micro/6.0/toolbox Message-ID: <20260902072749.7B708FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9419-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.158 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.158 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 872 Released: Tue Sep 1 09:06:07 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - SL-Micro-release-6.0-25.128 updated - libbz2-1-1.0.8-4.1 updated - skelcd-EULA-SL-Micro-2024.01.19-8.127 updated From sle-container-updates at lists.suse.com Wed Sep 2 07:29:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 09:29:43 +0200 (CEST) Subject: SUSE-IU-2026:6700-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260902072943.A09B9FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6700-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.161 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.161 Severity : low Type : security References : 1263819 1266786 CVE-2026-40253 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 697 Released: Tue Sep 1 08:55:06 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1263819,1266786,CVE-2026-40253,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-slfo.1.1_2.1 updated - SL-Micro-release-6.1-slfo.1.12.70 updated - container:SL-Micro-base-container-2.2.1-5.177 updated From sle-container-updates at lists.suse.com Wed Sep 2 07:31:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 09:31:55 +0200 (CEST) Subject: SUSE-IU-2026:6702-1: Security update of suse/sl-micro/6.1/base-os-container Message-ID: <20260902073155.7598EFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6702-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.177 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.177 Severity : low Type : security References : 1263819 1266786 CVE-2026-40253 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 697 Released: Tue Sep 1 08:55:06 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1263819,1266786,CVE-2026-40253,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-slfo.1.1_2.1 updated - SL-Micro-release-6.1-slfo.1.12.70 updated - container:suse-toolbox-image-1.0.0-5.96 updated From sle-container-updates at lists.suse.com Wed Sep 2 07:34:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 09:34:10 +0200 (CEST) Subject: SUSE-IU-2026:6704-1: Security update of suse/sl-micro/6.1/kvm-os-container Message-ID: <20260902073410.359EEFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6704-1 Image Tags : suse/sl-micro/6.1/kvm-os-container:2.2.1 , suse/sl-micro/6.1/kvm-os-container:2.2.1-5.181 , suse/sl-micro/6.1/kvm-os-container:latest Image Release : 5.181 Severity : low Type : security References : 1263819 1266786 CVE-2026-40253 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 697 Released: Tue Sep 1 08:55:06 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1263819,1266786,CVE-2026-40253,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-slfo.1.1_2.1 updated - SL-Micro-release-6.1-slfo.1.12.70 updated - container:SL-Micro-base-container-2.2.1-5.177 updated From sle-container-updates at lists.suse.com Wed Sep 2 07:36:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 09:36:54 +0200 (CEST) Subject: SUSE-IU-2026:6706-1: Security update of suse/sl-micro/6.1/rt-os-container Message-ID: <20260902073654.12072FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6706-1 Image Tags : suse/sl-micro/6.1/rt-os-container:2.2.1 , suse/sl-micro/6.1/rt-os-container:2.2.1-5.174 , suse/sl-micro/6.1/rt-os-container:latest Image Release : 5.174 Severity : low Type : security References : 1263819 1266786 CVE-2026-40253 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sl-micro/6.1/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 697 Released: Tue Sep 1 08:55:06 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1263819,1266786,CVE-2026-40253,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-slfo.1.1_2.1 updated - SL-Micro-release-6.1-slfo.1.12.70 updated - container:SL-Micro-container-2.2.1-7.161 updated From sle-container-updates at lists.suse.com Wed Sep 2 08:04:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 10:04:03 +0200 (CEST) Subject: SUSE-CU-2026:9410-1: Security update of suse/ltss/sle15.5/sle15 Message-ID: <20260902080403.882B5FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.5/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9410-1 Container Tags : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.67 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.67 , suse/ltss/sle15.5/sle15:latest Container Release : 8.67 Severity : important Type : security References : 1260446 1260446 1274774 1274774 1274788 1274788 1274790 1274795 1274795 1274797 1275837 CVE-2026-54874 CVE-2026-54874 CVE-2026-63072 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3876-1 Released: Mon Aug 31 11:11:58 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1260446,1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). - CVE-2026-63074: CMP Indefinite Cache Growth of ExtraCerts (bsc#1274797). - CVE-2026-63076: Invalid Pointer Dereference in CMP Server via Crafted protectionAlg (bsc#1274790). - CVE-2026-75803: AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher() (bsc#1275837). Changes for openssl-3: - August 2026 release (bsc#1274774). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3877-1 Released: Mon Aug 31 11:12:27 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). Changes for openssl-1_1: - August 2026 release (bsc#1274774) The following package changes have been done: - libopenssl1_1-hmac-1.1.1l-150500.17.63.1 updated - libopenssl1_1-1.1.1l-150500.17.63.1 updated - libopenssl3-3.0.8-150500.5.75.1 updated - openssl-1_1-1.1.1l-150500.17.63.1 updated - openssl-3-3.0.8-150500.5.75.1 updated From sle-container-updates at lists.suse.com Wed Sep 2 08:04:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 10:04:56 +0200 (CEST) Subject: SUSE-CU-2026:9429-1: Security update of suse/ltss/sle15.6/bci-base-fips Message-ID: <20260902080456.9A6D1FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9429-1 Container Tags : suse/ltss/sle15.6/bci-base-fips:15.6 , suse/ltss/sle15.6/bci-base-fips:15.6-35.94 , suse/ltss/sle15.6/bci-base-fips:latest Container Release : 35.94 Severity : important Type : security References : 1274774 1274788 1274790 1274795 1274797 1275837 CVE-2026-54874 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/ltss/sle15.6/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3866-1 Released: Fri Aug 28 19:29:09 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release . - CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797). - CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.1.4-150600.5.64.1 updated - container:sles15-ltss-image-15.6.0-5.86 updated From sle-container-updates at lists.suse.com Wed Sep 2 08:07:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 10:07:30 +0200 (CEST) Subject: SUSE-CU-2026:9430-1: Security update of suse/ltss/sle15.6/sle15 Message-ID: <20260902080730.58442FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9430-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.86 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.86 , suse/ltss/sle15.6/sle15:latest Container Release : 5.86 Severity : important Type : security References : 1274774 1274788 1274790 1274795 1274797 1275837 CVE-2026-54874 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3866-1 Released: Fri Aug 28 19:29:09 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release . - CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797). - CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl-3-fips-provider-3.1.4-150600.5.64.1 updated - libopenssl3-3.1.4-150600.5.64.1 updated - openssl-3-3.1.4-150600.5.64.1 updated From sle-container-updates at lists.suse.com Wed Sep 2 08:08:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 10:08:36 +0200 (CEST) Subject: SUSE-CU-2026:9431-1: Security update of suse/kea Message-ID: <20260902080836.6AE4BFCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/kea ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9431-1 Container Tags : suse/kea:2.6 , suse/kea:2.6-79.15 Container Release : 79.15 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/kea was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Wed Sep 2 08:10:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 10:10:21 +0200 (CEST) Subject: SUSE-CU-2026:9432-1: Security update of suse/kiosk/firefox-esr Message-ID: <20260902081021.658C5FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9432-1 Container Tags : suse/kiosk/firefox-esr:140.14 , suse/kiosk/firefox-esr:140.14-75.18 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.18 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Wed Sep 2 08:11:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 10:11:02 +0200 (CEST) Subject: SUSE-CU-2026:9433-1: Security update of suse/kubectl Message-ID: <20260902081102.EDF37FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/kubectl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9433-1 Container Tags : suse/kubectl:1.33 , suse/kubectl:1.33.11 , suse/kubectl:1.33.11-2.70.12 , suse/kubectl:oldstable Container Release : 70.12 Severity : moderate Type : security References : 1271660 1272402 1276510 1276514 CVE-2026-41178 CVE-2026-50151 CVE-2026-63308 ----------------------------------------------------------------- The container suse/kubectl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3882-1 Released: Mon Aug 31 16:29:31 2026 Summary: Security update for helm Type: security Severity: moderate References: 1271660,1272402,1276510,1276514,CVE-2026-41178,CVE-2026-50151,CVE-2026-63308 This update for helm fixes the following issues: - CVE-2026-41178: `go.opentelemetry.io/otel/baggage`,`go.opentelemetry.io/otel/propagation`: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276510). - CVE-2026-63308: processing zero-length byte slices in template chart files can trigger an index out-of-range panic (bsc#1272402). - gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1276514). Changes for helm: - Bump vendor to address various security issues: * golang.org/x/mod at v0.40.0 * oras.land/oras-go/v2 at v2.6.2 * google.golang.org/grpc at v1.82.1 * go.opentelemetry.io/otel at v1.44.0 The following package changes have been done: - helm-3.21.3-150000.1.93.1 updated From sle-container-updates at lists.suse.com Wed Sep 2 08:11:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 10:11:36 +0200 (CEST) Subject: SUSE-CU-2026:9434-1: Security update of suse/kubectl Message-ID: <20260902081136.B050BFCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/kubectl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9434-1 Container Tags : suse/kubectl:1.35 , suse/kubectl:1.35.4 , suse/kubectl:1.35.4-1.70.12 , suse/kubectl:latest , suse/kubectl:stable Container Release : 70.12 Severity : moderate Type : security References : 1271660 1272402 1276510 1276514 CVE-2026-41178 CVE-2026-50151 CVE-2026-63308 ----------------------------------------------------------------- The container suse/kubectl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3882-1 Released: Mon Aug 31 16:29:31 2026 Summary: Security update for helm Type: security Severity: moderate References: 1271660,1272402,1276510,1276514,CVE-2026-41178,CVE-2026-50151,CVE-2026-63308 This update for helm fixes the following issues: - CVE-2026-41178: `go.opentelemetry.io/otel/baggage`,`go.opentelemetry.io/otel/propagation`: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276510). - CVE-2026-63308: processing zero-length byte slices in template chart files can trigger an index out-of-range panic (bsc#1272402). - gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1276514). Changes for helm: - Bump vendor to address various security issues: * golang.org/x/mod at v0.40.0 * oras.land/oras-go/v2 at v2.6.2 * google.golang.org/grpc at v1.82.1 * go.opentelemetry.io/otel at v1.44.0 The following package changes have been done: - helm-3.21.3-150000.1.93.1 updated From sle-container-updates at lists.suse.com Wed Sep 2 08:12:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 10:12:16 +0200 (CEST) Subject: SUSE-CU-2026:9435-1: Security update of bci/bci-micro-fips Message-ID: <20260902081216.0DF38FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9435-1 Container Tags : bci/bci-micro-fips:15.7 , bci/bci-micro-fips:15.7-27.1 , bci/bci-micro-fips:latest Container Release : 27.1 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/bci-micro-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:bci-bci-base-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Wed Sep 2 08:17:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 10:17:12 +0200 (CEST) Subject: SUSE-CU-2026:9439-1: Security update of suse/postgres Message-ID: <20260902081712.3A0D9FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9439-1 Container Tags : suse/postgres:16-contrib , suse/postgres:16.14 , suse/postgres:16.14-contrib , suse/postgres:16.14-contrib-93.17 Container Release : 93.17 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Wed Sep 2 08:17:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 10:17:44 +0200 (CEST) Subject: SUSE-CU-2026:9440-1: Security update of suse/postgres Message-ID: <20260902081744.78AEBFCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9440-1 Container Tags : suse/postgres:16 , suse/postgres:16.14 , suse/postgres:16.14 , suse/postgres:16.14-93.17 Container Release : 93.17 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Wed Sep 2 08:18:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 10:18:50 +0200 (CEST) Subject: SUSE-CU-2026:9441-1: Security update of suse/postgres Message-ID: <20260902081850.2DC8BFCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9441-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.10 , suse/postgres:17.10-contrib , suse/postgres:17.10-contrib-83.17 Container Release : 83.17 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:15:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:15:03 +0200 (CEST) Subject: SUSE-CU-2026:9443-1: Security update of suse/sle-micro/5.3/toolbox Message-ID: <20260903071503.4868AFDCF@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9443-1 Container Tags : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.275 , suse/sle-micro/5.3/toolbox:latest Container Release : 6.11.275 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3921-1 Released: Wed Sep 2 09:32:20 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue: - CVE-2026-41989: crafted ECDH ciphertext can lead denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-hmac-1.9.4-150400.6.14.1 updated - libgcrypt20-1.9.4-150400.6.14.1 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:19:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:19:39 +0200 (CEST) Subject: SUSE-CU-2026:9444-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260903071939.6627FFCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9444-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.177 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.177 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3921-1 Released: Wed Sep 2 09:32:20 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue: - CVE-2026-41989: crafted ECDH ciphertext can lead denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.9.4-150400.6.14.1 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:22:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:22:21 +0200 (CEST) Subject: SUSE-CU-2026:9445-1: Security update of suse/sle-micro/5.4/toolbox Message-ID: <20260903072221.A886EFCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9445-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.276 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.276 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3921-1 Released: Wed Sep 2 09:32:20 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue: - CVE-2026-41989: crafted ECDH ciphertext can lead denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-hmac-1.9.4-150400.6.14.1 updated - libgcrypt20-1.9.4-150400.6.14.1 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:25:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:25:15 +0200 (CEST) Subject: SUSE-IU-2026:6708-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260903072515.083E3FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6708-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.239 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.239 Severity : important Type : security References : 1268322 1273580 CVE-2026-16445 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 876 Released: Wed Sep 2 11:30:06 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). - CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: - Update to version 059+suse.615.g018c5a4: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset * fix(network-manager): ensure safe content of /tmp/dhclient.'$ifname'.dhcpopts The following package changes have been done: - dracut-059+suse.615.g018c5a4-1.1 updated - container:SL-Micro-base-container-2.1.3-7.203 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:27:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:27:54 +0200 (CEST) Subject: SUSE-IU-2026:6709-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260903072754.5D3CEFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6709-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.203 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.203 Severity : important Type : security References : 1268322 1273580 CVE-2026-16445 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 876 Released: Wed Sep 2 11:30:06 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). - CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: - Update to version 059+suse.615.g018c5a4: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset * fix(network-manager): ensure safe content of /tmp/dhclient.'$ifname'.dhcpopts The following package changes have been done: - dracut-059+suse.615.g018c5a4-1.1 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:30:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:30:30 +0200 (CEST) Subject: SUSE-IU-2026:6710-1: Security update of suse/sl-micro/6.0/kvm-os-container Message-ID: <20260903073030.DBD4AFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6710-1 Image Tags : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.214 , suse/sl-micro/6.0/kvm-os-container:latest Image Release : 6.214 Severity : important Type : security References : 1268322 1273580 CVE-2026-16445 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 876 Released: Wed Sep 2 11:30:06 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). - CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: - Update to version 059+suse.615.g018c5a4: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset * fix(network-manager): ensure safe content of /tmp/dhclient.'$ifname'.dhcpopts The following package changes have been done: - dracut-059+suse.615.g018c5a4-1.1 updated - container:SL-Micro-base-container-2.1.3-7.203 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:33:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:33:47 +0200 (CEST) Subject: SUSE-IU-2026:6711-1: Security update of suse/sl-micro/6.0/rt-os-container Message-ID: <20260903073347.568A1FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6711-1 Image Tags : suse/sl-micro/6.0/rt-os-container:2.1.3 , suse/sl-micro/6.0/rt-os-container:2.1.3-7.232 , suse/sl-micro/6.0/rt-os-container:latest Image Release : 7.232 Severity : important Type : security References : 1268322 1273580 CVE-2026-16445 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 876 Released: Wed Sep 2 11:30:06 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). - CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: - Update to version 059+suse.615.g018c5a4: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset * fix(network-manager): ensure safe content of /tmp/dhclient.'$ifname'.dhcpopts The following package changes have been done: - dracut-059+suse.615.g018c5a4-1.1 updated - container:SL-Micro-container-2.1.3-6.239 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:35:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:35:19 +0200 (CEST) Subject: SUSE-CU-2026:9446-1: Security update of suse/sl-micro/6.0/baremetal-iso-image Message-ID: <20260903073519.98654FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/baremetal-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9446-1 Container Tags : suse/sl-micro/6.0/baremetal-iso-image:2.1.4 , suse/sl-micro/6.0/baremetal-iso-image:2.1.4-6.230 , suse/sl-micro/6.0/baremetal-iso-image:latest Container Release : 6.230 Severity : moderate Type : security References : 1217586 1271544 1271545 1271547 1271548 CVE-2023-42366 CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 875 Released: Wed Sep 2 11:40:31 2026 Summary: Security update for busybox Type: security Severity: moderate References: 1217586,1271544,1271545,1271547,1271548,CVE-2023-42366,CVE-2026-38752,CVE-2026-38753,CVE-2026-38754,CVE-2026-38755 This update for busybox fixes the following issues: - CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586). - CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544). - CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545). - CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547). - CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548). The following package changes have been done: - busybox-1.36.1-5.1 updated - container:SL-Micro-container-2.1.3-6.239 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:37:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:37:40 +0200 (CEST) Subject: SUSE-CU-2026:9447-1: Security update of suse/sl-micro/6.0/base-iso-image Message-ID: <20260903073740.CAAA9FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/base-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9447-1 Container Tags : suse/sl-micro/6.0/base-iso-image:2.1.4 , suse/sl-micro/6.0/base-iso-image:2.1.4-5.230 , suse/sl-micro/6.0/base-iso-image:latest Container Release : 5.230 Severity : moderate Type : security References : 1217586 1271544 1271545 1271547 1271548 CVE-2023-42366 CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 875 Released: Wed Sep 2 11:40:31 2026 Summary: Security update for busybox Type: security Severity: moderate References: 1217586,1271544,1271545,1271547,1271548,CVE-2023-42366,CVE-2026-38752,CVE-2026-38753,CVE-2026-38754,CVE-2026-38755 This update for busybox fixes the following issues: - CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586). - CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544). - CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545). - CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547). - CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548). The following package changes have been done: - busybox-1.36.1-5.1 updated - container:SL-Micro-base-container-2.1.3-7.203 updated - container:SL-Micro-container-2.1.3-6.239 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:40:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:40:05 +0200 (CEST) Subject: SUSE-CU-2026:9448-1: Security update of suse/sl-micro/6.0/kvm-iso-image Message-ID: <20260903074005.9B3BEFCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/kvm-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9448-1 Container Tags : suse/sl-micro/6.0/kvm-iso-image:2.1.4 , suse/sl-micro/6.0/kvm-iso-image:2.1.4-6.243 , suse/sl-micro/6.0/kvm-iso-image:latest Container Release : 6.243 Severity : moderate Type : security References : 1217586 1271544 1271545 1271547 1271548 CVE-2023-42366 CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 875 Released: Wed Sep 2 11:40:31 2026 Summary: Security update for busybox Type: security Severity: moderate References: 1217586,1271544,1271545,1271547,1271548,CVE-2023-42366,CVE-2026-38752,CVE-2026-38753,CVE-2026-38754,CVE-2026-38755 This update for busybox fixes the following issues: - CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586). - CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544). - CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545). - CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547). - CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548). The following package changes have been done: - busybox-1.36.1-5.1 updated - container:SL-Micro-kvm-container-2.1.3-6.214 updated - container:SL-Micro-container-2.1.3-6.239 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:41:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:41:41 +0200 (CEST) Subject: SUSE-CU-2026:9449-1: Security update of suse/sl-micro/6.0/rt-iso-image Message-ID: <20260903074141.D5991FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/rt-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9449-1 Container Tags : suse/sl-micro/6.0/rt-iso-image:2.1.4 , suse/sl-micro/6.0/rt-iso-image:2.1.4-6.226 , suse/sl-micro/6.0/rt-iso-image:latest Container Release : 6.226 Severity : moderate Type : security References : 1217586 1271544 1271545 1271547 1271548 CVE-2023-42366 CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 875 Released: Wed Sep 2 11:40:31 2026 Summary: Security update for busybox Type: security Severity: moderate References: 1217586,1271544,1271545,1271547,1271548,CVE-2023-42366,CVE-2026-38752,CVE-2026-38753,CVE-2026-38754,CVE-2026-38755 This update for busybox fixes the following issues: - CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586). - CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544). - CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545). - CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547). - CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548). The following package changes have been done: - busybox-1.36.1-5.1 updated - container:SL-Micro-rt-container-2.1.3-7.232 updated - container:SL-Micro-container-2.1.3-6.239 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:43:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:43:45 +0200 (CEST) Subject: SUSE-IU-2026:6712-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260903074345.4C617FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6712-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.163 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.163 Severity : important Type : security References : 1226091 1235517 1235834 1258251 1268322 1273580 CVE-2023-49441 CVE-2026-16445 CVE-2026-2291 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 703 Released: Wed Sep 2 11:14:10 2026 Summary: Security update for dracut Type: security Severity: important References: 1226091,1235517,1235834,1258251,1268322,1273580,CVE-2023-49441,CVE-2026-16445,CVE-2026-2291,CVE-2026-6893 This update for dracut fixes the following issues: - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). - CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: - Update to version 059+suse.649.g0274006: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset * fix(network-manager): ensure safe content of /tmp/dhclient.'$ifname'.dhcpopts The following package changes have been done: - libopenssl3-3.1.4-slfo.1.1_13.1 updated - SL-Micro-release-6.1-slfo.1.12.72 updated - dracut-059+suse.649.g0274006-slfo.1.1_1.1 updated - container:SL-Micro-base-container-2.2.1-5.179 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:46:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:46:16 +0200 (CEST) Subject: SUSE-IU-2026:6713-1: Security update of suse/sl-micro/6.1/base-os-container Message-ID: <20260903074616.64293FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6713-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.179 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.179 Severity : important Type : security References : 1221342 1226091 1231775 1231776 1235517 1235834 1243992 1243997 1252930 1252931 1252932 1252933 1252934 1252935 1254157 1254158 1254159 1254160 1254480 1256525 1256526 1257010 1257364 1257365 1258020 1258251 1260754 1260755 1261957 1268322 1268395 1268396 1268397 1269947 1271171 1273580 CVE-2023-49441 CVE-2025-28162 CVE-2025-28162 CVE-2025-28164 CVE-2025-54770 CVE-2025-54771 CVE-2025-61661 CVE-2025-61662 CVE-2025-61663 CVE-2025-61664 CVE-2025-64505 CVE-2025-64505 CVE-2025-64506 CVE-2025-64506 CVE-2025-64720 CVE-2025-64720 CVE-2025-65018 CVE-2025-65018 CVE-2025-66293 CVE-2025-66293 CVE-2026-16445 CVE-2026-22695 CVE-2026-22695 CVE-2026-22801 CVE-2026-22801 CVE-2026-2291 CVE-2026-25646 CVE-2026-25646 CVE-2026-33416 CVE-2026-33416 CVE-2026-33636 CVE-2026-33636 CVE-2026-34757 CVE-2026-34757 CVE-2026-49853 CVE-2026-49854 CVE-2026-49855 CVE-2026-57585 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 536 Released: Wed May 20 07:42:10 2026 Summary: Recommended update for google-guest-oslogin Type: recommended Severity: important References: 1221342,1231775,1231776,1243992,1243997,1254157,1254158,1254159,1254160,1254480,1257010,CVE-2025-64505,CVE-2025-64506,CVE-2025-64720,CVE-2025-65018,CVE-2025-66293 This update for google-guest-oslogin fixes the following issues: - Update to version 20260430.00: * URLEncode request parameters sent to the metadata server. - Add /var/google-sudoers.d to tmpfile config * The /var/google-users.d directory is pre-created in the Makefile but the google-sudoers.d is not. - Update to version 20260227.00 (bsc#1257010) * Fix broken cache_refresh behavior when groups are disabled. + Implement a binary cache for OS Login passwd entries. This change introduces a new binary cache format for storing OS Login passwd information. It includes: - `OsLoginPasswdCacheWriter`: A C++ class to build and write the cache file. It buffers user entries, sorts them, and writes them to a temporary file before atomically renaming it. - `oslogin_passwd_cache_reader`: A C implementation for reading from the cache file using mmap. It provides functions compatible with NSS modules for looking up entries by UID, name, and iterating through all entries. - `eytzinger_layout.h`: A template function to convert a sorted vector into an Eytzinger layout, used for the name index to improve cache locality during lookups. - `oslogin_index_structs.h`: Defines the structures used for the UID and Name indices. - New unit tests (`eytzinger_layout_test.cc`, `oslogin_passwd_cache_reader_test.cc`, `round_trip_test.cc`) to validate the cache functionality, including concurrent read access. - The `Makefile` is updated to build and run the new tests. The `main` function is removed from `oslogin_utils_test.cc` as `gtest_main.cc` is now linked. + Fix incorrect cache_refresh return value. * Add google-guest-oslogin.conf and ggosl no var content (jsc#PED-14688) - Update SELinux module dir as macro to allow root path move from /var/lib/selinux to /etc/selinux (bsc#1221342) - Update to version 20251022.00: * Log the response body when an auth failure occurs; it usually has helpful info in it. - Update to version 20250821.00: * Check policy uses adminLogin for cloud run - from version 20250807.00: * Extract the principal from certs when cloud_run enabled - Update to version 20250710.00: * Add the cloudrun support - Update to version 20250624.00: * Pass c-strings to logging functions - from version 20241216.00: * Send the correct type to SysLogErr; the clang sanitizer dislikes the type mismatch. * Add Eric to the owners file. * Revert 'new client component and tests' - from version 20241214.00: * Remove pat from owners - from version 20241206.00: * Fix json include * build: remove oslogin_sshca from binaries list * Fix bad struct initialization pattern `= { 0 }` * Apply 'include what you use,' fixing missing include statements broadly. * Fix base64.h's missing includes and BSD types * Fix a bug where very large GIDs would cause integer overflow errors - from version 20241127.00: * Rename openbsd.h to base64.h and move it into the src/ folder - from version 20241126.01: * Follow the Google style guide by using the 'local include style' to include files from this project. - from version 20241126.00: * Delete oslogin_sshca binary, add it to the ignore list - from version 20241120.00: * OS Login agent searches for full fingerprint extension instead of equals - from version 20241116.00: * Log an error when user has no challenges configured ----------------------------------------------------------------- Advisory ID: 593 Released: Fri Jun 26 11:54:16 2026 Summary: Security update for python-tornado6 Type: security Severity: important References: 1256525,1256526,1257364,1257365,1258020,1268395,1268396,1268397,CVE-2025-28162,CVE-2025-28164,CVE-2026-22695,CVE-2026-22801,CVE-2026-25646,CVE-2026-49853,CVE-2026-49854,CVE-2026-49855 This update for python-tornado6 fixes the following issues - CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). - CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). - CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397). ----------------------------------------------------------------- Advisory ID: 660 Released: Thu Aug 6 15:56:28 2026 Summary: Security update for python-msgpack Type: security Severity: important References: 1260754,1260755,1269947,CVE-2026-33416,CVE-2026-33636,CVE-2026-57585 This update for python-msgpack fixes the following issue - CVE-2026-57585: `Unpacker` reuse after a caught error can lead to an out-of-bounds read and a crash (bsc#1269947). ----------------------------------------------------------------- Advisory ID: 680 Released: Thu Aug 20 10:24:36 2026 Summary: Recommended update for python-kiwi Type: recommended Severity: important References: 1261957,1271171,CVE-2026-34757 This update for python-kiwi fixes the following issues: - Recreate VTOC with fdasd before recreating partitions (bsc#1271171) Changing partitions with fdasd after a parted resize leads to an internal error because some internal structures mismatch. Work around that by recreating the partition table initially. ----------------------------------------------------------------- Advisory ID: 703 Released: Wed Sep 2 11:14:10 2026 Summary: Security update for dracut Type: security Severity: important References: 1226091,1235517,1235834,1258251,1268322,1273580,CVE-2023-49441,CVE-2026-16445,CVE-2026-2291,CVE-2026-6893 This update for dracut fixes the following issues: - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). - CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: - Update to version 059+suse.649.g0274006: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset * fix(network-manager): ensure safe content of /tmp/dhclient.'$ifname'.dhcpopts ----------------------------------------------------------------- Advisory ID: 702 Released: Wed Sep 2 11:15:54 2026 Summary: Security update for libpng16 Type: security Severity: important References: 1252930,1252931,1252932,1252933,1252934,1252935,CVE-2025-28162,CVE-2025-54770,CVE-2025-54771,CVE-2025-61661,CVE-2025-61662,CVE-2025-61663,CVE-2025-61664,CVE-2025-64505,CVE-2025-64506,CVE-2025-64720,CVE-2025-65018,CVE-2025-66293,CVE-2026-22695,CVE-2026-22801,CVE-2026-25646,CVE-2026-33416,CVE-2026-33636,CVE-2026-34757 This update for libpng16 fixes the following issues: Changes for libpng16: - Version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libpng16-16-1.6.58-slfo.1.1_1.1 updated - libopenssl3-3.1.4-slfo.1.1_13.1 updated - SL-Micro-release-6.1-slfo.1.12.72 updated - dracut-059+suse.649.g0274006-slfo.1.1_1.1 updated - openssl-3-3.1.4-slfo.1.1_13.1 updated - container:suse-toolbox-image-1.0.0-5.99 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:48:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:48:38 +0200 (CEST) Subject: SUSE-IU-2026:6714-1: Security update of suse/sl-micro/6.1/kvm-os-container Message-ID: <20260903074838.E966BFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6714-1 Image Tags : suse/sl-micro/6.1/kvm-os-container:2.2.1 , suse/sl-micro/6.1/kvm-os-container:2.2.1-5.183 , suse/sl-micro/6.1/kvm-os-container:latest Image Release : 5.183 Severity : important Type : security References : 1226091 1235517 1235834 1258251 1268322 1273580 CVE-2023-49441 CVE-2026-16445 CVE-2026-2291 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 703 Released: Wed Sep 2 11:14:10 2026 Summary: Security update for dracut Type: security Severity: important References: 1226091,1235517,1235834,1258251,1268322,1273580,CVE-2023-49441,CVE-2026-16445,CVE-2026-2291,CVE-2026-6893 This update for dracut fixes the following issues: - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). - CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: - Update to version 059+suse.649.g0274006: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset * fix(network-manager): ensure safe content of /tmp/dhclient.'$ifname'.dhcpopts The following package changes have been done: - libopenssl3-3.1.4-slfo.1.1_13.1 updated - SL-Micro-release-6.1-slfo.1.12.72 updated - dracut-059+suse.649.g0274006-slfo.1.1_1.1 updated - container:SL-Micro-base-container-2.2.1-5.179 updated From sle-container-updates at lists.suse.com Thu Sep 3 07:51:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 09:51:11 +0200 (CEST) Subject: SUSE-IU-2026:6715-1: Security update of suse/sl-micro/6.1/rt-os-container Message-ID: <20260903075111.8DD97FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6715-1 Image Tags : suse/sl-micro/6.1/rt-os-container:2.2.1 , suse/sl-micro/6.1/rt-os-container:2.2.1-5.176 , suse/sl-micro/6.1/rt-os-container:latest Image Release : 5.176 Severity : important Type : security References : 1226091 1235517 1235834 1258251 1268322 1273580 CVE-2023-49441 CVE-2026-16445 CVE-2026-2291 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sl-micro/6.1/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 703 Released: Wed Sep 2 11:14:10 2026 Summary: Security update for dracut Type: security Severity: important References: 1226091,1235517,1235834,1258251,1268322,1273580,CVE-2023-49441,CVE-2026-16445,CVE-2026-2291,CVE-2026-6893 This update for dracut fixes the following issues: - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). - CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: - Update to version 059+suse.649.g0274006: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset * fix(network-manager): ensure safe content of /tmp/dhclient.'$ifname'.dhcpopts The following package changes have been done: - libopenssl3-3.1.4-slfo.1.1_13.1 updated - SL-Micro-release-6.1-slfo.1.12.72 updated - dracut-059+suse.649.g0274006-slfo.1.1_1.1 updated - container:SL-Micro-container-2.2.1-7.163 updated From sle-container-updates at lists.suse.com Thu Sep 3 08:03:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 10:03:07 +0200 (CEST) Subject: SUSE-IU-2026:6717-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260903080307.A7B9CFDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6717-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.118 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.118 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1592 Released: Wed Sep 2 17:55:21 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-160000.10.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-5c5fcfc0cee70b6cd3816f890481d6edbec1ce894a0c5cdf655858697fa7a135-0 updated From sle-container-updates at lists.suse.com Thu Sep 3 08:11:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 10:11:58 +0200 (CEST) Subject: SUSE-IU-2026:6722-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260903081158.3F15FFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6722-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.61 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.61 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1592 Released: Wed Sep 2 17:55:21 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-160000.10.1 updated - openssl-3-3.5.0-160000.10.1 updated From sle-container-updates at lists.suse.com Thu Sep 3 08:20:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 10:20:26 +0200 (CEST) Subject: SUSE-IU-2026:6726-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260903082026.DC760FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6726-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.104 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.104 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1592 Released: Wed Sep 2 17:55:21 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-160000.10.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-5c5fcfc0cee70b6cd3816f890481d6edbec1ce894a0c5cdf655858697fa7a135-0 updated From sle-container-updates at lists.suse.com Thu Sep 3 08:29:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 10:29:07 +0200 (CEST) Subject: SUSE-IU-2026:6733-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260903082907.ABC05FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6733-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.136 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.136 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1592 Released: Wed Sep 2 17:55:21 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-160000.10.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-90087c69bfe8f3f2f003771e00c38e3ef8774752a892009d190874d4ee850eda-0 updated From sle-container-updates at lists.suse.com Thu Sep 3 08:40:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 10:40:25 +0200 (CEST) Subject: SUSE-CU-2026:9454-1: Recommended update of suse/ltss/sle15.6/bci-base-fips Message-ID: <20260903084025.4D490FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9454-1 Container Tags : suse/ltss/sle15.6/bci-base-fips:15.6 , suse/ltss/sle15.6/bci-base-fips:15.6-35.96 , suse/ltss/sle15.6/bci-base-fips:latest Container Release : 35.96 Severity : important Type : recommended References : 1242233 1243830 1277267 ----------------------------------------------------------------- The container suse/ltss/sle15.6/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - container:sles15-ltss-image-15.6.0-5.87 updated From sle-container-updates at lists.suse.com Thu Sep 3 08:42:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 3 Sep 2026 10:42:59 +0200 (CEST) Subject: SUSE-CU-2026:9455-1: Recommended update of suse/ltss/sle15.6/sle15 Message-ID: <20260903084259.1BC7AFDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9455-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.87 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.87 , suse/ltss/sle15.6/sle15:latest Container Release : 5.87 Severity : important Type : recommended References : 1242233 1243830 1277267 ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated From sle-container-updates at lists.suse.com Wed Sep 2 07:04:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 2 Sep 2026 09:04:09 +0200 (CEST) Subject: SUSE-IU-2026:6691-1: Security update of suse-sles-15-sp6-chost-byos-v20260827-x86_64-gen2 Message-ID: <20260902070409.E3A75FDCB@maintenance.suse.de> SUSE Image Update Advisory: suse-sles-15-sp6-chost-byos-v20260827-x86_64-gen2 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6691-1 Image Tags : suse-sles-15-sp6-chost-byos-v20260827-x86_64-gen2:20260827 Image Release : Severity : important Type : security References : 1158038 1185845 1197231 1239718 1240054 1243603 1246504 1247948 1249435 1252306 1252744 1253043 1253193 1253262 1253740 1254323 1255416 1255451 1256709 1257068 1257383 1257463 1257882 1258069 1258193 1258538 1258718 1259311 1259520 1259706 1259802 1259842 1260296 1260347 1260531 1261256 1261400 1261606 1261900 1261969 1261982 1261983 1262044 1262069 1262070 1262071 1262072 1262098 1262266 1262305 1262319 1262573 1262654 1262745 1262771 1262948 1262993 1263010 1263068 1263083 1263366 1263367 1263656 1263658 1263718 1263772 1263788 1263879 1263880 1263889 1264013 1264053 1264076 1264076 1264089 1264090 1264116 1264137 1264145 1264263 1264470 1264484 1264558 1264610 1264721 1264779 1264795 1264962 1265170 1265211 1265221 1265223 1265267 1265268 1265308 1265410 1265413 1265421 1265450 1265579 1265591 1265592 1265593 1265594 1265596 1265794 1265935 1265938 1266039 1266214 1266238 1266290 1266304 1266350 1266640 1266758 1266767 1266798 1266799 1266800 1266801 1266802 1266810 1266827 1266850 1266890 1266913 1267189 1267212 1267214 1267361 1267365 1267369 1267375 1267381 1267384 1267387 1267388 1267389 1267422 1267426 1267435 1267494 1267531 1267567 1267581 1267584 1267591 1267596 1267618 1267621 1267635 1267640 1267644 1267647 1267651 1267652 1267656 1267663 1267682 1267682 1267684 1267697 1267715 1267722 1267821 1267874 1267918 1267966 1267993 1267995 1268012 1268013 1268017 1268022 1268029 1268049 1268131 1268162 1268237 1268275 1268290 1268307 1268307 1268322 1268335 1268349 1268375 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 1268660 1268683 1268886 1268896 1268977 1268989 1269022 1269033 1269036 1269066 1269090 1269100 1269159 1269172 1269174 1269181 1269184 1269188 1269193 1269195 1269279 1269289 1269310 1269314 1269383 1269398 1269489 1269493 1269512 1269513 1269574 1269577 1269583 1269584 1269622 1269623 1269633 1269678 1269681 1269773 1269788 1269790 1269795 1269798 1269808 1269821 1269884 1269959 1269981 1269986 1269988 1269993 1269997 1270000 1270008 1270009 1270010 1270016 1270018 1270021 1270022 1270059 1270208 1270230 1270257 1270393 1270515 1270620 1270706 1270772 1270801 1270936 1270994 1271044 1271046 1271048 1271049 1271050 1271052 1271053 1271054 1271055 1271183 1271192 1271193 1271194 1271195 1271234 1271349 1271351 1271352 1271354 1271366 1271368 1271372 1271469 1271526 1271528 1271530 1271531 1271532 1271533 1271534 1271535 1271536 1271537 1271538 1271539 1271672 1271673 1271674 1271675 1271676 1271677 1271684 1271712 1271712 1271825 1271866 1271899 1271904 1271908 1271910 1271912 1271947 1271964 1271980 1271982 1271983 1271984 1271986 1271987 1271988 1271989 1271990 1272164 1272165 1272166 1272167 1272168 1272169 1272171 1272176 1272180 1272183 1272207 1272242 1272263 1272268 1272282 1272414 1272466 1272468 1272554 1272573 1272607 1272665 1272678 1272693 1272694 1272836 1272855 1272865 1272904 1272907 1272918 1273004 1273035 1273231 1274072 1274432 1274627 1275011 1275012 1275013 1275014 1275015 1275016 1275017 1275018 CVE-2023-2058 CVE-2024-58251 CVE-2025-10263 CVE-2025-31133 CVE-2025-52565 CVE-2025-54518 CVE-2025-59529 CVE-2025-68324 CVE-2026-0864 CVE-2026-10536 CVE-2026-10723 CVE-2026-10822 CVE-2026-11331 CVE-2026-11622 CVE-2026-11721 CVE-2026-11822 CVE-2026-11824 CVE-2026-11850 CVE-2026-11940 CVE-2026-11972 CVE-2026-11979 CVE-2026-12064 CVE-2026-12087 CVE-2026-12505 CVE-2026-12617 CVE-2026-13204 CVE-2026-13321 CVE-2026-13595 CVE-2026-1502 CVE-2026-15308 CVE-2026-15779 CVE-2026-15816 CVE-2026-23392 CVE-2026-25707 CVE-2026-27456 CVE-2026-3039 CVE-2026-31431 CVE-2026-31482 CVE-2026-31483 CVE-2026-31500 CVE-2026-31542 CVE-2026-31598 CVE-2026-31628 CVE-2026-31697 CVE-2026-31698 CVE-2026-31699 CVE-2026-31759 CVE-2026-31759 CVE-2026-31771 CVE-2026-32316 CVE-2026-3276 CVE-2026-3276 CVE-2026-33186 CVE-2026-33814 CVE-2026-33814 CVE-2026-33947 CVE-2026-34986 CVE-2026-34986 CVE-2026-35469 CVE-2026-3592 CVE-2026-3593 CVE-2026-39821 CVE-2026-39821 CVE-2026-39956 CVE-2026-39979 CVE-2026-40164 CVE-2026-40226 CVE-2026-40355 CVE-2026-40356 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-41579 CVE-2026-41676 CVE-2026-41677 CVE-2026-41678 CVE-2026-41681 CVE-2026-41898 CVE-2026-41991 CVE-2026-41992 CVE-2026-42327 CVE-2026-42493 CVE-2026-42494 CVE-2026-42495 CVE-2026-42767 CVE-2026-43023 CVE-2026-43033 CVE-2026-43046 CVE-2026-43056 CVE-2026-43074 CVE-2026-43077 CVE-2026-43109 CVE-2026-43198 CVE-2026-43276 CVE-2026-43440 CVE-2026-43475 CVE-2026-4360 CVE-2026-44431 CVE-2026-44605 CVE-2026-44662 CVE-2026-44932 CVE-2026-44933 CVE-2026-44941 CVE-2026-44942 CVE-2026-45409 CVE-2026-45784 CVE-2026-45878 CVE-2026-45886 CVE-2026-45904 CVE-2026-45932 CVE-2026-45984 CVE-2026-46037 CVE-2026-46052 CVE-2026-46056 CVE-2026-46071 CVE-2026-46076 CVE-2026-46080 CVE-2026-46084 CVE-2026-46090 CVE-2026-46109 CVE-2026-46116 CVE-2026-46117 CVE-2026-46120 CVE-2026-46123 CVE-2026-46126 CVE-2026-46144 CVE-2026-46145 CVE-2026-46150 CVE-2026-46159 CVE-2026-46173 CVE-2026-46174 CVE-2026-46193 CVE-2026-46197 CVE-2026-46209 CVE-2026-46227 CVE-2026-46229 CVE-2026-46242 CVE-2026-46243 CVE-2026-46253 CVE-2026-46266 CVE-2026-46273 CVE-2026-46274 CVE-2026-46289 CVE-2026-46319 CVE-2026-46320 CVE-2026-46323 CVE-2026-46324 CVE-2026-46330 CVE-2026-46331 CVE-2026-46333 CVE-2026-4786 CVE-2026-48522 CVE-2026-48523 CVE-2026-48524 CVE-2026-48525 CVE-2026-48526 CVE-2026-48863 CVE-2026-52909 CVE-2026-52918 CVE-2026-52923 CVE-2026-52924 CVE-2026-52933 CVE-2026-52943 CVE-2026-52955 CVE-2026-52956 CVE-2026-52958 CVE-2026-52967 CVE-2026-52969 CVE-2026-52972 CVE-2026-52986 CVE-2026-52993 CVE-2026-53016 CVE-2026-53041 CVE-2026-53050 CVE-2026-53052 CVE-2026-53053 CVE-2026-53071 CVE-2026-53072 CVE-2026-53129 CVE-2026-53131 CVE-2026-53133 CVE-2026-53177 CVE-2026-53178 CVE-2026-53182 CVE-2026-53196 CVE-2026-53224 CVE-2026-53246 CVE-2026-53250 CVE-2026-53253 CVE-2026-53256 CVE-2026-53262 CVE-2026-53267 CVE-2026-53297 CVE-2026-53324 CVE-2026-53354 CVE-2026-53357 CVE-2026-53359 CVE-2026-53362 CVE-2026-53366 CVE-2026-53375 CVE-2026-53388 CVE-2026-53391 CVE-2026-53402 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-5435 CVE-2026-54411 CVE-2026-5704 CVE-2026-57062 CVE-2026-57432 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-58055 CVE-2026-58216 CVE-2026-58218 CVE-2026-58221 CVE-2026-58222 CVE-2026-58224 CVE-2026-5946 CVE-2026-5950 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 CVE-2026-59856 CVE-2026-59857 CVE-2026-59858 CVE-2026-59995 CVE-2026-59996 CVE-2026-59997 CVE-2026-59998 CVE-2026-59999 CVE-2026-60000 CVE-2026-60001 CVE-2026-60002 CVE-2026-6019 CVE-2026-6019 CVE-2026-6100 CVE-2026-61548 CVE-2026-6238 CVE-2026-62423 CVE-2026-62424 CVE-2026-62425 CVE-2026-62426 CVE-2026-62427 CVE-2026-62428 CVE-2026-62429 CVE-2026-62430 CVE-2026-62431 CVE-2026-62432 CVE-2026-62433 CVE-2026-62434 CVE-2026-63794 CVE-2026-63802 CVE-2026-63806 CVE-2026-63807 CVE-2026-63824 CVE-2026-63826 CVE-2026-63829 CVE-2026-63884 CVE-2026-63893 CVE-2026-63912 CVE-2026-63917 CVE-2026-63919 CVE-2026-63921 CVE-2026-63922 CVE-2026-63924 CVE-2026-63946 CVE-2026-63952 CVE-2026-63968 CVE-2026-63971 CVE-2026-63975 CVE-2026-63984 CVE-2026-63994 CVE-2026-64106 CVE-2026-64189 CVE-2026-64530 CVE-2026-64560 CVE-2026-64561 CVE-2026-64564 CVE-2026-64600 CVE-2026-6893 CVE-2026-6949 CVE-2026-71401 CVE-2026-71402 CVE-2026-7210 CVE-2026-73070 CVE-2026-73071 CVE-2026-73072 CVE-2026-73074 CVE-2026-73075 CVE-2026-73076 CVE-2026-73077 CVE-2026-73078 CVE-2026-7774 CVE-2026-8286 CVE-2026-8328 CVE-2026-8376 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9149 CVE-2026-9150 CVE-2026-9375 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container suse-sles-15-sp6-chost-byos-v20260827-x86_64-gen2 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2486-1 Released: Mon Jun 22 14:07:07 2026 Summary: Security update for python-urllib3 Type: security Severity: important References: 1265267,CVE-2026-44431 This update for python-urllib3 fixes the following issue - CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied low-level redirects (bsc#1265267). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2528-1 Released: Tue Jun 23 11:06:07 2026 Summary: Security update for sqlite3 Type: security Severity: important References: 1268012,1268013,CVE-2026-11822,CVE-2026-11824 This update for sqlite3 fixes the following issues Update to 3.53.2: - CVE-2026-11822: memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution (bsc#1268012). - CVE-2026-11824: heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code (bsc#1268013). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2590-1 Released: Tue Jun 23 16:09:07 2026 Summary: Security update for libsolv, libzypp, zypper Type: security Severity: important References: 1158038,1239718,1246504,1247948,1249435,1252744,1253193,1253740,1257068,1257882,1258193,1259311,1259706,1259802,1259842,1265223,1265935,1265938,1266039,1267426,1267874,CVE-2026-25707,CVE-2026-44933,CVE-2026-44941,CVE-2026-44942,CVE-2026-48863,CVE-2026-9149,CVE-2026-9150 This update for libsolv, libzypp, zypper fixes the following issues - CVE-2026-9149: Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file (bsc#1265935). - CVE-2026-9150: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums (bsc#1265938). - CVE-2026-25707: Handcrafted repo metadata may cause arbitrary local files to be overwritten (bsc#1259802). - CVE-2026-44933: scan of the Mandatory signature verification plugin support (bsc#1265223). - CVE-2026-44941: path traversal via 'keyhint' (bsc#1267426). - CVE-2026-44942: .repo files can have an optional path which can lead to path traversal attacks (bsc#1267874). - CVE-2026-48863: Fix buffer overflow when parsing EdDSA signature (bsc#1266039). Changes in libzypp: Updated to version 17.38.13 (35): - A .repo files 'path=' entry must not refer to a location outside the repo (bsc#1267874, CVE-2026-44942) A 'path=' entry may solely denote a sub-directory of the baseurl where the metadata are located. A relative path trying to access data outside the baseurl is reported and sanitized. - Fix potential crash on malformed or malicious repository metadata (fixes #740) - Repo metadata: discard entries referring to a location outside the repo (bsc#1259802, CVE-2026-25707) Mirroring those data locally would refer to a location outside the repo's local cache directory. Those data entries are reported and discarded. - zypp.conf: Allow [env] section to add environment variables. This feature is designed to enable environment-specific settings or debugging options over an extended period. See zypp.conf(5). - Prevent configured scripts from escaping the sigcheck directory (bsc#1265223, CVE-2026-44933) - StringV: guard hasPrefix/hasPrefixCI against reading past the view end (fixes #735) - Mandatory signature verification plugin support (PED#11922) - Fix purge-kernel -rc kernel handling (bsc#1239718) - Explicitly_set_pool_DISTTYPE_RPM (fixes #726) - Check for trusted key updates when updating the general keyring (bsc#1259706) - Support multiple MirroredOrigin authorities (bsc#1253193) - Workaround doxygen bug: doxygen/doxygen#12057 - libzypp.spec: Add missing graphviz-gd BuildRequires (boo#1259842) - Fix preloader not caching packages from arch specific subrepos (bsc#1253740) - Deprioritize invalid mirrors (fixes openSUSE/zypper#636) - Fix Product::referencePackage lookup (bsc#1259311) Use a provided autoproduct() as hint to the package name of the release package. It might be that not just multiple versions of the same release package provide the same product version, but also different release packages. - specfile: on fedora use %{_prefix}/share as zyppconfdir if %{_distconfdir} is undefined (fixes #693) This will set '-DZYPPCONFDIR=%{zyppconfdir}' for cmake. - Fall back to a writable location when precaching packages without root (bsc#1247948) - Prepare a legacy /etc/zypp/zypp.conf to be installed on old distros. See the ZYPP.CONF(5) man page for details. - Fix runtime check for broken rpm --runposttrans (bsc#1257068) - Avoid libcurl-mini4 when building as it does not support ftp protocol. - Translation: updated .pot file. - zypp.conf: follow the UAPI configuration file specification (PED-14658) In short terms it means we will no longer ship an /etc/zypp/zypp.conf, but store our own defaults in /usr/etc/zypp/zypp.conf. The systems administrator may choose to keep a full copy in /etc/zypp/zypp.conf ignoring our config file settings completely, or - the preferred way - to overwrite specific settings via /etc/zypp/zypp.conf.d/*.conf overlay files. See the ZYPP.CONF(5) man page for details. - cmake: correctly detect rpm6 (fixes #689) - Use 'zypp.tmp' as temp directory component to ease setting up SELinux policies (bsc#1249435) - zyppng: Update Provider to current MediaCurl2 download approach, drop Metalink ( fixes #682 ) Changes in libsolv: Updated to version 0.7.39: - fix solv_chksum_free segfault when called with a NULL pointer - made repo_add_solv more robust against corrupt files [bsc#1265935] [CVE-2026-9149] - fix potential buffer overflow when verifying EdDSA signatures [bsc#1266039] [CVE-2026-48863] - added limit checks in multiple places to catch overflows - reduce the size of the language id cache - fixed Debian canon selection - fixed dbpath detection in repo_rpmdb_librpm - reduced stack usage in repo page compression (needed for musl) - fix parsing of sha512 checksums in debian repositories [bsc#1265938] [CVE-2026-9150] - improve speed of dirpool_add_dir makeing parsing of filelists.xml twice as fast - fix parsing of recommends in the old Mandriva synthesis format - respect the 'default' attribute in environment optionlist in the comps parser - support suse namespace deps in boolean dependencies [bsc#1258193] - support for the Elbrus2000 (e2k) architecture - support language() suse namespace rewriting Changes in zypper: Update to version 1.14.98: - Transactional systems: Delegate rw-commands to transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607) On a transactional system where the root filesystem is mounted read-only, zypper commands that modify the system cannot be executed directly. If the system provides a transactional-wrapper utility, zypper will automatically attempt to invoke it. The wrapper transparently executes the zypper command within a new, writable snapshot and manages the lifecycle of that snapshot based on the command's exit status. On transactional systems lacking a transactional-wrapper, users must manually invoke specialized tools -such as transactional-update- to install, update, or remove software. - Add --filter-version-change to zypper lu. Adds filtering by version change significance to reduce noise in update listings. Supports levels: rebuild (hides rebuild-only changes) and package (hides all release-only changes). - Autorefresh ris-services the way as plugin-services (bsc#1246504) It's actually wrong to treat service refreshes different depending on the service type. For the purpose of a service it makes no difference how the data about the repos to use are acquired. - Report download progress for command line rpms (fixes #613) - Hint to '-vv ref' to see the mirrors used to download the metadata (bsc#1257882) - Service: Allow 'zypper ls SERVICE ...' to test whether a service with this alias is defined (bsc#1252744) The command prints an abstract of all services passed on the command line. It returns 3-ZYPPER_EXIT_ERR_INVALID_ARGS if some argument does not name an existing service. - Keep repo data when updating the service settings (bsc#1252744) - info: Enhance pattern content table (bsc#1158038) Alternatives (multiple packages providing the same requirement) are now listed as a single entry in the content table. The entry shows either the installed package which satisfies the requirement or the requirement itself as type 'Provides'. Listing all potential alternatives was miss leading, especially if the alternatives were mutual exclusive. It looked like an installed pattern had not-installed requirements and it was not possible to install all requirements at the same time. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2626-1 Released: Thu Jun 25 10:10:54 2026 Summary: Security update for python-PyJWT Type: security Severity: important References: 1266798,1266799,1266800,1266801,1266802,CVE-2026-48522,CVE-2026-48523,CVE-2026-48524,CVE-2026-48525,CVE-2026-48526 This update for python-PyJWT fixes the following issues - CVE-2026-48522: `PyJWKClient` passes URI arguments directly to `urllib.request.urlopen()` and allows for SSRF and token forgery (bsc#1266798). - CVE-2026-48523: verifier-side algorithm allow-list bypass when `jwt.decode()` or `jwt.decode_complete()` are called with a PyJWK key (bsc#1266799). - CVE-2026-48524: unlimited processing of JWTs with unknown kid values by `PyJWKClient.get_signing_key()` leads to unbounded JWKS endpoint requests and DoS (bsc#1266800). - CVE-2026-48525: unbounded Base64URL decoding of unused payload segment in `b64=false` detached JWS allows for DoS (bsc#1266801). - CVE-2026-48526: no validation of use of JSON Web Keys in HMAC algorithm when decoding JSON Web Tokens allows for forged HS256 tokens (bsc#1266802). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2632-1 Released: Thu Jun 25 14:35:58 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1255416,1258538,1260531,1261256,1262993,1263879,1263880,1264076,1264116,1264137,1264145,1264263,1264470,1264610,1265170,1265211,1265579,1266214,1266290,1266767,1266810,1266827,1267214,1267361,1267381,1267387,1267388,1267531,1267621,1267640,1267651,1267652,1267663,1267682,1267697,1268307,CVE-2025-10263,CVE-2025-68324,CVE-2026-23392,CVE-2026-31500,CVE-2026-31697,CVE-2026-31698,CVE-2026-31699,CVE-2026-31759,CVE-2026-31771,CVE-2026-43023,CVE-2026-43074,CVE-2026-43077,CVE-2026-43198,CVE-2026-45878,CVE-2026-45886,CVE-2026-45932,CVE-2026-45984,CVE-2026-46037,CVE-2026-46090,CVE-2026-46120,CVE-2026-46123,CVE-2026-46150,CVE-2026-46159,CVE-2026-46197,CVE-2026-46209,CVE-2026-46227,CVE-2026-46273 The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). - CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). - CVE-2026-23392: netfilter: nf_tables: release flowtable after rcu grace period on error (bsc#1260531). - CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). - CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). - CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). - CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). - CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). - CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). - CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). - CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). - CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). - CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). - CVE-2026-45878: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (bsc#1266767). - CVE-2026-45886: bpf: Fix bpf_xdp_store_bytes proto for read-only arg (bsc#1266810). - CVE-2026-45932: bpf: Fix tcx/netkit detach permissions when prog fd isn't given (bsc#1266827). - CVE-2026-45984: gfs2: Move the inode glock locking to gfs2_file_buffered_write (bsc#1267214). - CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). - CVE-2026-46090: ALSA: aloop: Use guard() for spin locks (bsc#1267531). - CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). - CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). - CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). - CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652). - CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). - CVE-2026-46209: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (bsc#1267663). - CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). - CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1265211 bsc#1267651). The following non security issues were fixed: - bnxt_en: Fix NULL pointer dereference (bsc#1268307). - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes). - ethtool: provide customized dim profile management (bsc#1261256). - hv: utils: handle and propagate errors in kvp_register (git-fixes). - hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). - linux/dim: move useful macros to .h file (bsc#1261256). - net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). - net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). - net: mana: Add support for RX CQE Coalescing (bsc#1261256). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2639-1 Released: Fri Jun 26 09:04:53 2026 Summary: Security update for containerd Type: security Severity: important References: 1260296,1262948,1265794,1266640,CVE-2026-33186,CVE-2026-33814,CVE-2026-34986,CVE-2026-39821 This update for containerd fixes the following issues - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260296). - CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265794). - CVE-2026-34986: github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262948). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266640). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2676-1 Released: Mon Jun 29 11:53:47 2026 Summary: Security update for bind Type: security Severity: important References: 1265591,1265592,1265593,1265594,1265596,CVE-2026-3039,CVE-2026-3592,CVE-2026-3593,CVE-2026-5946,CVE-2026-5950 This update for bind fixes the following issues - CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591). - CVE-2026-3592: Amplification vulnerabilities via self-pointed glue records (bsc#1265592). - CVE-2026-5946: Invalid handling of CLASS != IN (bsc#1265594). - CVE-2026-5950: Unbounded resend loop in BIND 9 resolver (bsc#1265596). - CVE-2026-3593: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation (bsc#1265593). Changes for bind: - Update to release 9.18.49 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2699-1 Released: Tue Jun 30 11:19:23 2026 Summary: Security update for cifs-utils Type: security Severity: important References: 1267389,CVE-2026-12505 This update for cifs-utils fixes the following issue - CVE-2026-12505: cifs.upcall local privilege escalation via request_key-controlled namespace switch and NSS loading (bsc#1267389). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2714-1 Released: Tue Jun 30 14:02:53 2026 Summary: Security update for tar Type: security Severity: important References: 1261900,1265450,1267189,CVE-2026-5704 This update for tar fixes the following issues Security fixes: - CVE-2026-5704: crafted archives can be used to to hide file injection (bsc#1261900). Other fixes: - Fix tar changing dir permissions temporarily even when using --no-overwrite-dir. - Fix --dereference/-h not working properly after CVE-2025-45582 fix (bsc#1265450). - Fix extraction failure for paths like 'a/./b' caused by the gnulib openat2 implementation (bsc#1267189). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2736-1 Released: Fri Jul 3 08:00:55 2026 Summary: Recommended update for cloud-init Type: recommended Severity: important References: 1267422 This update for cloud-init fixes the following issues: - Fix: Cloud init failures observed [ thread::1hcnhpN0LIaV02LMM-IqGis:: ] (bsc#1267422) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2803-1 Released: Wed Jul 8 21:31:25 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,CVE-2026-6893 This update for dracut fixes the following issue - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: - Update to version 059+suse.565.g682306ec5: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2828-1 Released: Thu Jul 9 20:30:03 2026 Summary: Security update for python-idna Type: security Severity: moderate References: 1265413,CVE-2026-45409 This update for python-idna fixes the following issue - CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2836-1 Released: Fri Jul 10 08:27:12 2026 Summary: Recommended update for sysconfig Type: recommended Severity: moderate References: 1263889 This update for sysconfig fixes the following issues: - Update to version 0.85.11: * netconfig: Do not remove custom /etc/{resolv,yp}.conf on uninstall of sysconfig-netconfig, but only the symlinks to /run/netconfig files created by netconfig or tmpfiles.d(5) (bsc#1263889). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2926-1 Released: Mon Jul 13 19:55:06 2026 Summary: Security update for curl Type: security Severity: important References: 1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2951-1 Released: Tue Jul 14 11:32:32 2026 Summary: Recommended update for dmidecode Type: recommended Severity: moderate References: This update for dmidecode fixes the following issues: - Update to upstream version 3.7 (jsc#PED-16217): * Support for SMBIOS 3.8.0. This includes a new processor family. * Support for SMBIOS 3.9.0. This includes chassis type name adjustments, new rack attributes, slot ID for more slot types, and new memory device form factors and types. * Decode HPE OEM records 193, 195, 202, 211, 226, 229, 232 and 244. * Update HPE OEM records 203, 216, 242 and 245. * EDSFF slot names now include their .S/.L suffix. - Preserve the use of term 'BIOS' to avoid breaking customer scripts. - Preserve the use of non-binary units to avoid breaking customer scripts. - Drop legacy 'Provides:' and 'Obsoletes:' tags. The split from the pmtools package happened 15 years ago so they are no longer relevant. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2983-1 Released: Tue Jul 14 15:19:38 2026 Summary: Security update for jq Type: security Severity: moderate References: 1262044,1262069,1262070,1262071,1262072,CVE-2026-32316,CVE-2026-33947,CVE-2026-39956,CVE-2026-39979,CVE-2026-40164 This update for jq fixes the following issues: - CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). - CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). - CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). - CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). - CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre-computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3004-1 Released: Wed Jul 15 09:26:06 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1266350,CVE-2026-42767 This update for openssl-3 fixes the following issue - CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3015-1 Released: Wed Jul 15 11:07:54 2026 Summary: Recommended update for suseconnect-ng Type: recommended Severity: moderate References: 1197231,1263772,1265410,1268017 This update for suseconnect-ng fixes the following issues: - Update version to 1.22.1: - Allow clients to disable the token handling mechanism - Ensure updated system certs are included when creating HTTP client connections (bsc#1268017, jsc#SCC-804) - Update version to 1.22: - Fix keepalive service failing on unregistered system (bsc#1263772) - Add collector support for gathering RKE2 & K3s kubernetes provider info if enabled on a system - Add email address validation to SUSEConnect -e/--email option. (bsc#1197231) - Add collector support for detecting if system is running pacemaker - Avoid double slash at start of request URL path component - Use product identifier when finding product packages during migrations (bsc#1265410) - Add opt in/out support for collectors - Update config parser for suseconnect to be YAML based ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3026-1 Released: Wed Jul 15 11:49:35 2026 Summary: Security update for python-cryptography Type: security Severity: important References: 1270208,1270515,1270620,1270706,1270772,1270801,1270936,1270994,CVE-2026-41676,CVE-2026-41677,CVE-2026-41678,CVE-2026-41681,CVE-2026-41898,CVE-2026-42327,CVE-2026-44662,CVE-2026-45784 This update for python-cryptography fixes the following issues - CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). - CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270620). - CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270706). - CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270772). - CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270801). - CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270515). - CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate (bsc#1270936). - CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270994). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3051-1 Released: Wed Jul 15 15:10:27 2026 Summary: Security update for runc Type: security Severity: important References: This update for runc rebuilds it against the current go security release. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3052-1 Released: Wed Jul 15 15:11:55 2026 Summary: Security update for containerd Type: security Severity: important References: This update for containerd rebuilds it against the current go security release. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3077-1 Released: Thu Jul 16 17:53:44 2026 Summary: Security update for rpcbind Type: security Severity: moderate References: 1267212 This update for rpcbind fixes the following issue - Fix several memory leaks and buffer overflow (bsc#1267212). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3081-1 Released: Thu Jul 16 17:57:17 2026 Summary: Recommended update for supportutils Type: recommended Severity: moderate References: 1256709,1257383,1258069,1259520 This update for supportutils fixes the following issues: - Changes to version 3.2.14: * Integrates supportutils-scrub for data obfuscation, use -j (PED-7324, bsc#1259520) * Santize env.txt * ha.txt: Collect hacluster passwd entry * Added systemd cat unit.service output * Added softirqs to proc (bsc#1258069) * Check for /usr/lib/pam.d * Ignore deprecated crash variable message * Update supportconfig with note about bpftool * Added /boot/grub2/grubenv (bsc#1257383) * Verify procps pkg - scplugin.rc is restored in package 3.2.12.1 for continued compatibility. There is no furture development for scplugin.rc. Use supportconfig.rc. Package version 3.2.12.2 does not have scplugin.rc. (bsc#1256709) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3096-1 Released: Fri Jul 17 13:38:59 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3104-1 Released: Fri Jul 17 15:31:14 2026 Summary: Security update for python311 Type: security Severity: important References: 1261969,1262098,1262319,1262654,CVE-2026-1502,CVE-2026-4786,CVE-2026-6019,CVE-2026-6100 This update for python311 fixes the following issues - CVE-2026-1502: CR/LF bytes not rejected by HTTP client proxy tunnel headers or host (bsc#1261969). - CVE-2026-4786: URLs containing `%action` can bypass mitigation that allows command injection via the `webbrowser.open()` API (bsc#1262319). - CVE-2026-6019: HTML parser-sensitive sequence not neutralized by `http.cookies.Morsel.js_output()` (bsc#1262654). - CVE-2026-6100: use-after-free in decompression modules when a memory allocation fails with a `MemoryError` and the decompression instance is re-used (bsc#1262098). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3106-1 Released: Fri Jul 17 16:02:05 2026 Summary: Recommended update for kmod Type: recommended Severity: moderate References: This update for kmod fixes the following issues: - Use in-kernel decompression if available (jsc#PED-16303): * libkmod: + Add a separate function to load the file contents when it's needed. When it's not needed on the path of loading modules via finit_module(), there is no need to mmap the file. + Extract 2 functions to handle finit_module vs init_modules differences, with a fallback from the former to the latter. + Don't only set the type as direct, but also keep track of the compression being used. + When creating the context, read /sys/kernel/compression to check. what's the compression type supported by the kernel. + Use kernel decompression when available + add fallback MODULE_INIT_COMPRESSED_FILE define ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3107-1 Released: Fri Jul 17 16:03:04 2026 Summary: Recommended update for bind Type: recommended Severity: moderate References: 1268896 This update for bind fixes the following issues: - Force python3.11 for integration tests (bsc#1268896) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3153-1 Released: Tue Jul 21 14:54:24 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3156-1 Released: Tue Jul 21 15:34:44 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1264484,1265421,1267365,1267369,1267494,1267567,1267591,1267618,1267635,1267684,1267722,1267918,1267966,1267993,1268022,1268049,1268237,1268335,1268660,1268989,1269022,1269033,1269036,1269090,1269100,1269159,1269172,1269174,1269184,1269193,1269195,1269310,1269314,1269398,1269493,1269574,1269678,1269681,1269795,1269798,1269821,1269884,1269986,1269993,1270022,1270059,1270257,1271050,1271366,CVE-2026-43109,CVE-2026-46052,CVE-2026-46071,CVE-2026-46076,CVE-2026-46116,CVE-2026-46173,CVE-2026-46229,CVE-2026-46242,CVE-2026-46253,CVE-2026-46266,CVE-2026-46274,CVE-2026-46289,CVE-2026-46319,CVE-2026-46320,CVE-2026-46330,CVE-2026-46331,CVE-2026-52909,CVE-2026-52918,CVE-2026-52923,CVE-2026-52924,CVE-2026-52933,CVE-2026-52943,CVE-2026-52955,CVE-2026-52956,CVE-2026-52958,CVE-2026-52969,CVE-2026-52972,CVE-2026-52993,CVE-2026-53016,CVE-2026-53041,CVE-2026-53052,CVE-2026-53053,CVE-2026-53071,CVE-2026-53072,CVE-2026-53133,CVE-2026-53178,CVE-2026-53182,CVE-2026-53196,CVE-2026-53253,CVE-2026 -53256,CVE-2026-53357,CVE-2026-53359,CVE-2026-53362,CVE-2026-53366 The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). - CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). - CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). - CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). - CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). - CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). - CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). - CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). - CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). - CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). - CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). - CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). - CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). - CVE-2026-46330: Revert 'net/smc: Introduce TCP ULP support' (bsc#1268049). - CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). - CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). - CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). - CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). - CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). - CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). - CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). - CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). - CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). - CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). - CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). - CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). - CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). - CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). - CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). - CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). - CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). - CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). - CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). - CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). - CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). - CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). - CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). - CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). - CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). - CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). - CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). - CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271366). The following non security issues were fixed: - hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). - ipv4: account for fraggap on the paged allocation path (git-fixes). - ipv6: account for fraggap on the paged allocation path (git-fixes). - KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). - KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). - KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). - KVM: x86: Fix shadow paging use-after-free due to unexpected role (git-fixes). - loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). - loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). - module: fix init_module_from_file() error handling (jsc#PED-16303). - module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). - module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). - module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). - module: warn about excessively long module waits (jsc#PED-16303). - modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). - net: mana: Add support for PF device 0x00C1 (bsc#1268237). - net: mana: Allocate interrupt context for each EQ when creating vPort (git-fixes). - net: mana: Create separate EQs for each vPort (git-fixes). - net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-fixes). - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git-fixes). - net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). - net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). - net: mana: Optimize irq affinity for low vcpu configs (git-fixes). - net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). - net: mana: Use GIC functions to allocate global EQs (git-fixes). - RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). - RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). - scsi: storvsc: Replace symbolic permissions with octal (git-fixes). - scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). - x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). - x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3218-1 Released: Thu Jul 23 19:34:12 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1255451,CVE-2025-59529 This update for avahi fixes the following issue: - CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3223-1 Released: Thu Jul 23 20:31:22 2026 Summary: Security update for net-tools Type: security Severity: moderate References: 1254323,CVE-2024-58251 This update for net-tools fixes the following issues: - CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254323). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3243-1 Released: Fri Jul 24 15:09:32 2026 Summary: Security update for gpg2 Type: security Severity: low References: 1269279,CVE-2026-57062 This update for gpg2 fixes the following issue: - CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3261-1 Released: Mon Jul 27 07:51:01 2026 Summary: Recommended update for cifs-utils Type: recommended Severity: important References: 1271183,1271234 This update for cifs-utils fixes the following issues: - cifs.upcall: fix regression with krb5 + creduid (bsc#1271183, bsc#1271234) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3364-1 Released: Tue Jul 28 14:19:32 2026 Summary: Security update for samba Type: security Severity: important References: 1271469,1271672,1271673,1271674,1271675,1271676,1271677,CVE-2026-15779,CVE-2026-58216,CVE-2026-58218,CVE-2026-58221,CVE-2026-58222,CVE-2026-58224,CVE-2026-6949 This update for samba fixes the following issues - CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672). - CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation (bsc#1271469). - CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674). - CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675). - CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676). - CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677). - CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3397-1 Released: Tue Jul 28 20:31:23 2026 Summary: Security update for python-urllib3 Type: security Severity: moderate References: 1268683,CVE-2026-9375 This update for python-urllib3 fixes the following issue - CVE-2026-9375: decompression bomb bypass in the streaming API when using Brotli support can lead to a denial of service (bsc#1268683). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3398-1 Released: Wed Jul 29 09:44:21 2026 Summary: Security update for rsyslog Type: security Severity: important References: 1271910 This update for rsyslog fixes the following issue - input sequence during oversize-frame recovery in imptcp can cause denial of service (bsc#1271910). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3409-1 Released: Wed Jul 29 13:18:15 2026 Summary: Security update for xen Type: security Severity: important References: 1271528,1271530,1271531,1271532,1271533,1271534,1271535,1271536,1271537,1271538,1271539,1271947,CVE-2026-42493,CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425,CVE-2026-62426,CVE-2026-62427,CVE-2026-62428,CVE-2026-62429,CVE-2026-62430,CVE-2026-62431,CVE-2026-62432,CVE-2026-62433,CVE-2026-62434 This update for xen fixes the following issues - CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528). - CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425: buffer overruns in libfsimage iso9660 handling (bsc#1271530). - CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse (bsc#1271531). - CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532). - CVE-2026-62429: vNUMA domain cleanup may race other operations (bsc#1271534). - CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535). - CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536). - CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537). - CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538). - CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539). - pygrub is only supported in de-privileged mode (XSA-508) (bsc#1271947). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3433-1 Released: Thu Jul 30 20:54:35 2026 Summary: Security update for runc Type: security Severity: low References: 1268275,CVE-2025-31133,CVE-2025-52565,CVE-2026-41579 This update for runc fixes the following issues: Update to 1.3.6. - CVE-2026-41579: malicious image with a `/dev` symlink can trigger limited host filesystem integrity violations (bsc#1268275). Other updates and bugfixes: - Version 1.3.6: * When masking directories with `maskPaths`, runc will now re- use a single `tmpfs` instance (which is not writeable) to reduce the number `tmpfs` superblocks that need to be reaped when containers die (in particular, Kubernetes applies masks to per-CPU sysfs directories which get expensive quickly). - Version 1.3.5: * Recursive atime-related mount flags (rrelatime et al.) are now applied properly. * PR #4757 caused a regression that resulted in spurious cannot start a container that has stopped errors when running runc create and has thus been reverted. * Updated builds to Go 1.25, libseccomp v2.6.0. * Minor signing keyring updates. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3442-1 Released: Fri Jul 31 21:22:00 2026 Summary: Security update for rsyslog Type: security Severity: important References: 1272414,CVE-2026-61548 This update for rsyslog fixes the following issue: - CVE-2026-61548: parsing of crafted RFC 5424 messages in `mmpstrucdata` can lead to a stack buffer overflow (bsc#1272414). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3450-1 Released: Mon Aug 3 13:26:37 2026 Summary: Security update for containerd Type: security Severity: moderate References: 1262266,CVE-2026-33814,CVE-2026-34986,CVE-2026-35469,CVE-2026-39821 This update for containerd fixes the following issues: - CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262266). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3452-1 Released: Mon Aug 3 13:34:50 2026 Summary: Security update for bind Type: security Severity: important References: 1271982,1271983,1271984,1271986,1271987,1271988,1271989,1271990,CVE-2026-10723,CVE-2026-10822,CVE-2026-11331,CVE-2026-11622,CVE-2026-11721,CVE-2026-12617,CVE-2026-13204,CVE-2026-13321 This update for bind fixes the following issues: - CVE-2026-10723: accepting incorrect child-zone NSEC3 records as valid can allow an attacker to forge authenticated NXDOMAIN responses for sibling zones (bsc#1271982). - CVE-2026-10822: storing a DNS key record with an invalid PRIVATEDNS algorithm identifier length can trigger a consistency check failure (bsc#1271983). - CVE-2026-11331: handling NAMETOOLONG error conditions incorrectly during RPZ wildcard CNAME processing can allow bypassing RPZ rules or triggering process exits (bsc#1271984). - CVE-2026-11622: DNSSEC validating resolver under a random subdomain attack can suffer from runaway memory usage exceeding max-cache-size and affecting response rate (bsc#1271986). - CVE-2026-11721: RRSIG with fewer labels than its containing zone when synth-from-dnssec is enabled can lead to wildcard generation (bsc#1271987). - CVE-2026-12617: delayed or specific CNAME/DNAME query responses combined with positive A record responses can trigger an assertion failure (bsc#1271988). - CVE-2026-13204: validating a domain covered by both NSEC and NSEC3 with an RRSIG for only one type can trigger an assertion failure (bsc#1271989). - CVE-2026-13321: NSEC records with a `Next Domain Name` pointing outside the signer's zone can allow cross-zone cache poisoning and authenticated denial-of-service responses (bsc#1271990). - Update to release 9.18.50: * Remove ineffective TCP fallback after repeated UDP timeouts. * Fall back to TCP on receipt of a UDP response with a mismatched query ID. * Fix DNS64 owner case after DNAME restart. * Clear REDIRECT flag when it isn't needed. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3458-1 Released: Mon Aug 3 14:00:20 2026 Summary: Security update for vim Type: security Severity: important References: 1268162,1271193,1271194,1271195,1271684,CVE-2026-59856,CVE-2026-59857,CVE-2026-59858 This update for vim fixes the following issues: This update for vim fixes the following issues: Security issues fixed: - CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194). - CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195). - CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193). Non security issue fixed: - Guard suse.vimrc against re-entry to prevent an infinite sourcing loop (bsc#1271684). - allow 'wrap' and 'linebreak' to be set from a modeline (bsc#1268162). Changes for vim: - Updated to version 9.2.0780: * filetype detect missing from completion (9.2.0726). * popup images not rendered correctly when unfocused (9.2.0727). * filetype: supertux info pattern is relative to current dir (9.2.0728). * % skips parens on continued quoted lines (9.2.0729). * GTK4 GUI tabline is not updated (9.2.0730). * GTK4 GUI scrollbar size not updated when restoring a session (9.2.0731). * session: terminal restored using absolute columns/rows (9.2.0732). * GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733). * function pointer passed to STRNCMP() instead of a length (9.2.0734). * tests: comment test can be improved (9.2.0737). * completion: 'autocompletedelay' blocks the main loop and drops autocommands (9.2.0739). * GTK4: scrollbar wrongly displayed (9.2.0740). * complete_check() does not return TRUE for mapped input (9.2.0741). * filetype: SSH keys and related filetypes not recognized (9.2.0742). * string macros silently accept a size of the wrong type (9.2.0743). * popup_atcursor() closes immediately on white space (9.2.0744). * cscope: connection leak when growing the array fails (9.2.0747). * 'autocompletedelay' interferes with CTRL-G U (9.2.0748). * 'autocompletedelay' interferes with i_CTRL-K (9.2.0749). * completion: 'autocompletedelay' deferral leaks state (9.2.0750). * GTK3 GUI is slow under Wayland (9.2.0751). * GTK4: drag-and-drop does not support HTML (9.2.0752). * GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753). * repeated completion length lookup in search_for_exact_line (9.2.0754). * 'autocomplete' behaves inconsistently when recording (9.2.0755). * session with multiple tabpages sets 'winminheight' to 0 (9.2.0756). * pum: no opacity when background not set for Popup menu group (9.2.0758). * some code for 'autocompletedelay' is no longer needed (9.2.0759). * compiler warning for using potentially uninitialized var (9.2.0760). * runtime(netrw): Unix: unable to open '\' file (9.2.0761). * duplicated sub-option name check in :set completion (9.2.0762). * compiler warning about unused function (9.2.0764). * popup: opacity popup over a terminal is not cleared when moved (9.2.0765). * quick_tab entries for empty letters point to the wrong index (9.2.0766). * legacy/vim9cmd modifiers do not set script version for options values (9.2.0767). * legacy/vim9cmd modifiers are not exclusive (9.2.0768). * conversion to utf-16be using iconv is inconsistent (9.2.0769). * dict_add_dict() has inconsistent ownership on failure (9.2.0770). * dict_add_list() has inconsistent ownership on failure (9.2.0771). * Vim9: null dereference inside alloc_type() (9.2.0772). * memory leak in evalfunc.c on alloc failure (9.2.0773). * memory leak in f_getscriptinfo() on alloc failure (9.2.0774). * memory leak in highlight_get_info() on alloc failure (9.2.0775). * memory leak in sign_getlist() on alloc failure (9.2.0776). * memory leak in add_defer() on alloc failure (9.2.0777). * memory leak in compile_dict() on alloc failure (9.2.0778). * memory leak in type_name_func() on alloc failure (9.2.0779). * memory leak in evalvars.c on alloc failure (9.2.0780). - Updated to version 9.2.0725: * GTK: preedit font size is wrong for fractional point sizes (9.2.0532). * '[ mark moved to end of inserted text after CTRL-R CTRL-P paste (9.2.0533). * GTK UI does not support fullscreen mode (9.2.0534). * GTK4: mouse popup menu does not show up at mouse pointer (9.2.0537). * Cannot keep leading whitespace in %{} statusline expr (9.2.0538). * filetype: too many Bitbake include files are recognized (9.2.0539). * Vim9: endclass/endenum/endinterface can give errors (9.2.0541). * Vim9: wrong error when redeclaring a typed variable (9.2.0543). * GTK4: window blank after a resize or drag (9.2.0544). * popup: blending uses hardcoded fallback colors (9.2.0545). * configure: GTK4 build requires GTK >= 4.10 (9.2.0546). * '%v' in 'errorformat' is affected by 'tabstop' (9.2.0547). * GTK4: terminal and pty job output is not processed (9.2.0548). * Cursor wrong after autoindent strip is skipped (9.2.0549). * GTK4: 'mousehide' unhides cursor when switching tabs (9.2.0550). * filetype: Tolk files are not recognized (9.2.0551). * GTK4: F10 does nothing when the menubar is hidden (9.2.0552). * runtime(netrw): netrw rejects hostnames containing _ (9.2.0553). * GTK4: memory leak in free_menu() (9.2.0554). * too many strlen() in ex_substitute() (9.2.0555). * GTK4: scrollbars not shown and do not respond to clicks (9.2.0556). * filetype: Kawasaki Robots files are not recognized (9.2.0557). * filetype: Popcap Reanimation files are not recognized (9.2.0558). * filetype: Kaitai struct files are not recogonized (9.2.0559). * filetype: busybox shebang lines are not recognized (9.2.0560). * [security]: possible code execution with python3complete (9.2.0561). * filetype: SGF files are not recognized (9.2.0562). * GTK3/Wayland: crash with right mouse-button in tabline (9.2.0563). * GTK4: tabline does not respond to mouse clicks (9.2.0564). * [security]: out-of-bounds read in update_snapshot() (9.2.0565). * f duplicates window if do_ecmd() is aborted (9.2.0566). * dict function name allocation failure not handled (9.2.0567). * pythoncomplete: g:pythoncomplete_allow_import had no effect (9.2.0568). * out-of-bounds access in libvterm CSI 8 t resize (9.2.0569). * GTK4: mouse wheel scrolling does not work correctly (9.2.0570). * Vim9: memory leak in compile_nested_function() on failure (9.2.0571). * lines disappear with wrapping virtual text after a double-width char (9.2.0572). * Vim9: missing EX_WHOLE on some block keywords (9.2.0573). * popup_create() not blocked in secure/sandbox (9.2.0576). * GTK4: window resizing issues (9.2.0577). * GTK4: :unmenu does not remove entries from the menubar (9.2.0578). * :mksession, :mkview and :mkvimrc emit legacy Vim script (9.2.0579). * xxd: binary output is not colored with -R (9.2.0580). * After maximizing and deleting the quickfix buffer, window height is wrong (9.2.0581). * GTK4: compile error when XFONTSET is defined (9.2.0582). * completion: indent not ignored for fuzzy line completion (9.2.0583). * GTK4: missing UI features (9.2.0584). * line number wrong after undoing a deletion in quickfix buffer (9.2.0585). * Crash with TextPut autocmd when pasting in terminal buffer (9.2.0586). * GTK4: left scrollbar overlaps drawarea (9.2.0587). * GTK4: drawing area loses focus after closing a menubar popover (9.2.0588). * filetype: xinitrc files are not recognized (9.2.0589). * GTK4: drawing area loses focus shape on popup menu open (9.2.0590). * 'scrolljump' ignored when scrolling up (9.2.0591). * Error when restoring session with terminal window (9.2.0592). * :wqall ignores term_setkill() on running terminal buffers (9.2.0593). * Use-after-free with ':wqall' and a running terminal job (9.2.0594). * MS-Windows: Wrong buffer size calculation for gvimext (9.2.0595). * cmdline completion popup cannot be scrolled with the mouse (9.2.0596). * [security]: possible code execution with python complete (9.2.0597). * popup: title set with popup_setoptions() is not shown (9.2.0599). * clientserver method needs to be given as argument (9.2.0600). * matchfuzzypos() returns garbage positions for long candidates (9.2.0601). * popup: No opacity when background not set for Popup group (9.2.0602). * possible heap-buffer-overflow when resizing the GUI (9.2.0603). * GTK4: does not support all clipboard formats (9.2.0606). * GTK4: inputdialog() does not work as expected (9.2.0607). * popup_setoptions()/ch_setoptions() does not check secure mode (9.2.0608). * completion info popup cannot be scrolled with the keyboard (9.2.0609). * cindent: closing brace in a comment affects the next line's indent (9.2.0610). * MS-Windows: evim.exe not working with VIMDLL (9.2.0611). * Cannot render images in popup windows (9.2.0612). * opacity popup leaves stale cells (9.2.0614). * sixel encoder drops pixels on the right edge of shapes (9.2.0615). * GTK4: use-after-free on clipboard read timeout (9.2.0616). * GvimExt: does not support different runtime dirs (9.2.0617). * use-after-free in popup_getoptions() on dict_add() failure (9.2.0618). * integer overflow in popup image size validation (9.2.0619). * runtime(netrw): fix 2match pattern rebuild (9.2.0620). * 'autoindent' not stripped with virtualedit=onemore (9.2.0621). * str2blob() does not work with wide UTF-16 encoding (9.2.0622). * possible integer overflow in spellfile tree bounds check (9.2.0623). * C-N/C-P cannot be mapped in complete() completion (9.2.0624). * GTK4: Link error when Wayland is disabled (9.2.0625). * Vim9: illegal characters allowed in dict key names with dot notation (9.2.0626). * :vim9cmd source handles all scripts as Vim9 script (9.2.0627). * popup image: wrong overlap layering, kitty laggy (9.2.0628). * 0x80 and 0x9b byte not unescaped when check for valid abbr (9.2.0629). * popup images: kitty images output in GUI mode (9.2.0630). * DECRQM and SGR Mouse not supported in foot terminal (9.2.0631). * GTK4: no support for hardware-accelerated rendering (9.2.0632). * MS-Windows: No support for kitty graphics support in terminal (9.2.0633). * GTK4: no minimum resize limit (9.2.0634). * checking the syntax contains/cluster list is slow (9.2.0635). * popup image: stale pixels under RGBA animation frames (9.2.0636). * sixel: anti-aliased RGBA images render with visible outline (9.2.0637). * cannot return matches containing spaces from a custom completion (9.2.0638). * gq with 'formatprg' fails on an empty buffer (9.2.0639). * the '%' command jumps to parens and braces inside comments (9.2.0640). * GTK4: crash in gui_mch_menu_hidden() (9.2.0641). * statusline: buffer overflow with item groups (9.2.0642). * Missing Image ifdefs (9.2.0643). * popup image: duplicate sync-output code (9.2.0644). * Composing chars no longer accepted in end-id abbr (9.2.0645). * GTK3 GUI slow on HiDPI/4K with software rendering (9.2.0646). * matchfuzzypos() false exact match for long equal-length candidates (9.2.0647). * MS-Windows: Compile warnings (9.2.0648). * filetype: tf files sometimes incorrectly recognized (9.2.0649). * Vim aborts at startup when built with the example -O2 CFLAGS (9.2.0650). * completion: 'smartcase' doesn't work with 'longest' (9.2.0651). * popup: stale kitty image after clipwindow scrolls out of view (9.2.0652). * [security]: out-of-bounds write in tree_count_words() (9.2.0653). * GTK4: using uninitialised colors in gui_mch_init() (9.2.0654). * GTK4: missing NULL checks in vim_form_measure() (9.2.0655). * completion: using wrong tolower() in smartcase filtering (9.2.0656). * GTK4: missing menu when right-clicking in tabline (9.2.0657). * xxd: signed integer overflow in huntype() (9.2.0658). * GTK4: no balloon support in GUI (9.2.0659). * Dragging the scrollbar does not trigger WinScrolled (9.2.0660). * unintended wipe of Vim's temp dir, causes errors (9.2.0661). * [security] Stack out-of-bounds write in dump_prefixes() (9.2.0662). * [security]: runtime(netrw): code injection in local file deletion (9.2.0663). * GTK4: GTK critical error on exit printed (9.2.0665). * Terminal-Normal mode does not color empty lines with a background color (9.2.0666). * patch 9.2.0590 was wrong (9.2.0667). * GTK4: minimum horizontal size is too small (9.2.0668). * GTK4: toolbar can be improved (9.2.0669). * [security]: Out-of-bounds read with text properties (9.2.0670). * [security]: possible out-of-bounds read with sodium encrypted files (9.2.0671). * corrupted text property causes internal error (9.2.0672). * configure: clears dynamic ruby linker flags (9.2.0674). * MS-Windows: cannot switch to a buffer with '%' in its name (9.2.0676). * Cannot clear the alternate file register # (9.2.0677). * [security]: potential powershell code execution in zip.vim (9.2.0678). * [security]: Out-of-bounds read with text property virtual text (9.2.0679). * keytrans() doesn't replace '|' and '\' (9.2.0680). * configure: -lruby added even for a dynamic ruby build (9.2.0681). * Wrong dot-repeat when calling complete() while filtering completion (9.2.0682). * filetype completion mishandles finished sub options (9.2.0683). * :reg # does not display the value of the '#' register (9.2.0684). * clipboard.c does not get the Wayland CFLAGS on GTK2 (9.2.0685). * style: strcmp usage is inconsistent (9.2.0686). * popup_image_composites_frames() has improper if block scope (9.2.0687). * Terminal-Normal mode does not show the Visual selection on a colored empty line (9.2.0688). * the '%' command is slow on a long line with many slashes (9.2.0689). * Solaris: swap file names are too long (9.2.0690). * Solaris: Test_terminal_composing_unicode() fails (9.2.0691). * GTK2: build failure, popup images not drawn correctly (9.2.0692). * Solaris: some tests faiures due to Solaris peculiarities (9.2.0694). * Solaris: test_delete_temp_dir() fails because of missing flock (9.2.0695). * GTK4: A few issues with toolbar support (9.2.0696). * possible overflow when parsing CSI keys (9.2.0697). * [security]: Out-of-bounds write with soundfold() (9.2.0698). * [security]: possible code execution with python complete (9.2.0699). * configure: -lrt requirement for timer_create not detected (9.2.0700). * :windo and :tabdo create an extra window with 'winfixbuf' (9.2.0702). * session file does not store relative Vim9 autoload imports (9.2.0703). * GTK4: not handling mouse events (9.2.0704). * :delete # silently fails to update '# and clobbers '0 (9.2.0705). * completion: popup misplaced when text before it is concealed (9.2.0707). * Leaks in do_autocmd in error case (9.2.0708). * GTK4: a few minor issues (9.2.0709). * GTK4 GUI resize handling can be improved (9.2.0710). * leak in ins_compl_infercase_gettext() in error case (9.2.0711). * GTK4: dialogs not handling mnemonics correctly (9.2.0712). * completion: ruler not updated correctly when the popup menu is visible (9.2.0713). * Coverity warns for NULL deref (9.2.0714). * Coverity warns about copy/paste error in hl_blend_attr() (9.2.0715). * filetype: not all supertux files are recognized (9.2.0716). * :syn sync without an argument also lists syntax cluster (9.2.0718). * GTK4: default menu is lacking (9.2.0719). * GTK4: no support for browsefilter (9.2.0720). * serverlist() returns strings separated by \n (9.2.0721). * GTK4: find/replace dialog can be improved (9.2.0722). * term_start() does not support 'noclose' (9.2.0723). * use-after-free when freeing exit_cb job on exit (9.2.0724). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3515-1 Released: Thu Aug 6 13:08:56 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3516-1 Released: Thu Aug 6 13:09:13 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1271712 This update for openssl-3 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3560-1 Released: Mon Aug 10 20:09:08 2026 Summary: Security update for python311 Type: security Severity: important References: 1264962,1265268,1267581,1267821,1268375,1268977,1269066,1269788,1269959,1271192,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-3276,CVE-2026-4360,CVE-2026-7210,CVE-2026-7774,CVE-2026-8328 This update for python311 fixes the following issues: Security issues fixed: - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581). - CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). - CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection (bsc#1264962). - CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). Non security issue fixed: - [kernel 7.1] udplite was removed -> python fails in tests (bsc#1268375). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3566-1 Released: Tue Aug 11 07:33:57 2026 Summary: Recommended update for grub2 Type: recommended Severity: important References: 1271980 This update for grub2 fixes the following issues: - Fix crash in booting kernel on some AMD systems (bsc#1271980) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3602-1 Released: Wed Aug 12 20:35:45 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1185845,1243603,1253262,1258718,1260347,1262573,1262745,1262771,1263010,1263068,1263718,1263788,1264013,1264053,1264076,1264089,1264090,1264558,1264779,1264795,1265308,1266238,1266758,1266850,1266890,1266913,1267375,1267384,1267435,1267584,1267596,1267656,1267682,1267715,1267995,1268029,1268307,1269181,1269188,1269289,1269383,1269512,1269513,1269577,1269633,1269773,1269808,1269981,1269988,1269997,1270000,1270230,1271349,1271368,1271526,1271825,1271866,1271899,1271904,1271908,1271912,1271964,1272176,1272180,1272183,1272207,1272242,1272263,1272268,1272282,1272466,1272468,1272573,1272607,1272665,1272678,1272693,1272694,1272836,1272855,1272865,1272904,1272907,1272918,1273004,1273035,1273231,1274072,CVE-2023-2058,CVE-2025-54518,CVE-2026-31431,CVE-2026-31482,CVE-2026-31483,CVE-2026-31542,CVE-2026-31598,CVE-2026-31628,CVE-2026-31759,CVE-2026-43033,CVE-2026-43046,CVE-2026-43056,CVE-2026-43276,CVE-2026-43440,CVE-2026-43475,CVE-2026-45904,CVE-2026-46056,CVE-2026-46080,CVE-2026-460 84,CVE-2026-46109,CVE-2026-46117,CVE-2026-46126,CVE-2026-46144,CVE-2026-46145,CVE-2026-46174,CVE-2026-46193,CVE-2026-46243,CVE-2026-46323,CVE-2026-46324,CVE-2026-46333,CVE-2026-52967,CVE-2026-52986,CVE-2026-53050,CVE-2026-53129,CVE-2026-53131,CVE-2026-53177,CVE-2026-53224,CVE-2026-53246,CVE-2026-53250,CVE-2026-53262,CVE-2026-53267,CVE-2026-53297,CVE-2026-53324,CVE-2026-53354,CVE-2026-53375,CVE-2026-53388,CVE-2026-53391,CVE-2026-53402,CVE-2026-63794,CVE-2026-63802,CVE-2026-63806,CVE-2026-63807,CVE-2026-63824,CVE-2026-63826,CVE-2026-63829,CVE-2026-63884,CVE-2026-63893,CVE-2026-63912,CVE-2026-63917,CVE-2026-63919,CVE-2026-63921,CVE-2026-63922,CVE-2026-63924,CVE-2026-63946,CVE-2026-63952,CVE-2026-63968,CVE-2026-63971,CVE-2026-63975,CVE-2026-63984,CVE-2026-63994,CVE-2026-64106,CVE-2026-64189,CVE-2026-64530,CVE-2026-64560,CVE-2026-64561,CVE-2026-64564,CVE-2026-64600 The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (bsc#1267435). - CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656). - CVE-2026-46324: netfilter: nf_tables: Introduce functions freeing nft_hook objects (bsc#1267995). - CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181). - CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289). - CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). - CVE-2026-53129: fs/mbcache: cancel shrink work before destroying the cache (bsc#1269633). - CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773). - CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997). - CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988). - CVE-2026-53250: xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() (bsc#1269808). - CVE-2026-53262: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() (bsc#1270000). - CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577). - CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1270230). - CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899). - CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825). - CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904). - CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908). - CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964). - CVE-2026-63802: blk-cgroup: fix UAF in __blkcg_rstat_flush() (bsc#1272282). - CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (bsc#1272268). - CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (bsc#1272263). - CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2() (bsc#1272180). - CVE-2026-63826: fbdev: fix use-after-free in store_modes() (bsc#1272183). - CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176). - CVE-2026-63884: drm/i915: Fix potential UAF in TTM object purge (bsc#1272573). - CVE-2026-63893: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (bsc#1272607). - CVE-2026-63912: xfrm: esp: restore combined single-frag length gate (bsc#1272836). - CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904). - CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907). - CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918). - CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: refresh nh after handling HAO option (bsc#1272855). - CVE-2026-63946: Bluetooth: ISO: fix UAF in iso_recv_frame (bsc#1272665). - CVE-2026-63952: memfd: deny writeable mappings when implying SEAL_WRITE (bsc#1272468). - CVE-2026-63968: ipv6: fix possible infinite loop in fib6_select_path() (bsc#1272466). - CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678). - CVE-2026-63975: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (bsc#1272694). - CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865). - CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035). - CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242). - CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207). - CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1273004). - CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231). - CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072). - CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526). The following non security issues were fixed: - Drivers: hv: vmbus: Set DMA coherent mask for VMBus devices (git-fixes). - hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912). - ice: don't check has_ready_bitmap in E810 functions (bsc#1269981). - ice: factor out ice_ptp_rebuild_owner() (bsc#1269981). - ice: fix PTP Call Trace during PTP release (bsc#1269981). - ice: Fix PTP NULL pointer dereference during VSI rebuild (bsc#1269981). - ice: introduce PTP state machine (bsc#1269981). - ice: pass reset type to PTP reset functions (bsc#1269981). - ice: rename ice_ptp_tx_cfg_intr (bsc#1269981). - ice: rename verify_cached to has_ready_bitmap (bsc#1269981). - ice: stop destroying and reinitalizing Tx tracker during reset (bsc#1269981). - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - KVM: x86/mmu: Fix use-after-free on vendor module reload (git-fixes). - KVM: x86/mmu: Preserve nested TDP shadow page tables if they are used as roots (git-fixes). - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - KVM: x86: Fix SRCU list traversal in kvm_fire_mask_notifiers() (git-fixes). - KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer (git-fixes). - KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git-fixes). - KVM: x86: hyper-v: Validate all GVAs during PV TLB flush (git-fixes). - mkspec-dtb: Skip missing DTBs. - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (bsc#1271866). - net: mana: Add Interrupt Moderation support (bsc#1271368). - net: mana: Return error code from mana_create_rxq() (git-fixes). - net: mana: Validate the packet length reported by the NIC (git-fixes). - pkspec-dtb: Fix dtb-al rename. - posix-cpu-timers: Cleanup the firing logic (bsc#1271912). - posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912). - posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912). - posix-cpu-timers: Handle interval timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set() (bsc#1271912). - posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912). - posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912). - posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912). - posix-timers: Add proper state tracking (bsc#1271912). - posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912). - posix-timers: Clarify posix_timer_fn() comments (bsc#1271912). - posix-timers: Clear overrun in common_timer_set() (bsc#1271912). - posix-timers: Consolidate signal queueing (bsc#1271912). - posix-timers: Consolidate timer setup (bsc#1271912). - posix-timers: Cure si_sys_private race (bsc#1271912). - posix-timers: Document common_clock_get() correctly (bsc#1271912). - posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912). - posix-timers: Polish coding style in a few places (bsc#1271912). - posix-timers: Retrieve interval in common timer_settime() code (bsc#1271912). - RDMA/mana_ib: initialize err for empty send WR lists (git-fixes). - sctp: validate embedded address parameter length (git-fixes). - time: Switch to hrtimer_setup() (bsc#1271912). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3605-1 Released: Thu Aug 13 08:35:24 2026 Summary: Security update for openssh Type: security Severity: important References: 1271044,1271046,1271048,1271049,1271052,1271053,1271054,1271055,CVE-2026-59995,CVE-2026-59996,CVE-2026-59997,CVE-2026-59998,CVE-2026-59999,CVE-2026-60000,CVE-2026-60001,CVE-2026-60002 This update for openssh fixes the following issues: - Backported support for the mlkemx25519 key exchange from upstream (jsc#PED-16473). - CVE-2026-59995: sftp: location of downloaded files not properly constrained when `sftp server:/path .` is used with an attacker-controlled server (bsc#1271044). - CVE-2026-59996: scp: file placed in the parent directory of an intended target directory when copy occurs between two remote destinations (bsc#1271046). - CVE-2026-59997: sshd: `internal-sftp` command lines are silently truncated after the 9th argument (bsc#1271048). - CVE-2026-59998: sshd: undocumented security-relevant `GSSAPIStrictAcceptorCheck` behavior in Windows Active Directory is not documented (bsc#1271049). - CVE-2026-59999: sshd: `DisableForwarding=yes` does not override `PermitTunnel=yes` (bsc#1271052). - CVE-2026-60000: sshd: pre-authentication denial of service when GSSAPIAuthentication is enabled (bsc#1271053). - CVE-2026-60001: sshd: minimum authentication delay is not honored (bsc#1271054). - CVE-2026-60002: ssh: client-side use-after-free when a server changes its host key during a key reexchange (bsc#1271055). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3612-1 Released: Thu Aug 13 19:58:56 2026 Summary: Security update for dracut Type: security Severity: important References: 1274432,CVE-2026-15816 This update for dracut fixes the following issue: Update to version 059+suse.567.gf5cfeb7f7. Securitys issue fixed: - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()` (bsc#1274432). Other updates and bugfixes: - Fix(base): sanitize message written by `die()` to the emergency hook. - Feat(base): add escape function implementing `printf %q`. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3646-1 Released: Wed Aug 19 07:40:47 2026 Summary: Recommended update for rsyslog Type: recommended Severity: important References: 1264721 This update for rsyslog fixes the following issues: - Added a devel subpackage, with requires (bsc#1264721) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3648-1 Released: Wed Aug 19 11:54:08 2026 Summary: Security update for python311 Type: security Severity: important References: 1263083,CVE-2026-3276,CVE-2026-6019 This update for python311 fixes the following issues: - Regression in `http.cookies` (bsc#1263083). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3670-1 Released: Fri Aug 21 09:15:07 2026 Summary: Security update for containerd Type: security Severity: important References: This update for containerd rebuilds it against the current go security release. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3680-1 Released: Fri Aug 21 16:21:23 2026 Summary: Security update for vim Type: security Severity: important References: 1275011,1275012,1275013,1275014,1275015,1275016,1275017,1275018,CVE-2026-73070,CVE-2026-73071,CVE-2026-73072,CVE-2026-73074,CVE-2026-73075,CVE-2026-73076,CVE-2026-73077,CVE-2026-73078 This update for vim fixes the following issues: - CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018). - CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017). - CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution (bsc#1275016). - CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution (bsc#1275015). - CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014). - CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013). - CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012). - CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011). Changes for vim: - Updated to version 9.2.0957. * tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781). * tests: missing cleanup in test_mksession.vim (9.2.0782). * tests: personal spell files leak into later tests (9.2.0783). * crash when borrowing statusline highlight in silent Ex mode (9.2.0784). * WinResized not triggered when the whole Vim is resized (9.2.0785). * filetype: containerfile is not recognized (9.2.0786). * regexp: code 0x1ecb duplicated for equivalence class (9.2.0787). * filetype: hip files are not recognized (9.2.0788). * 'statuslineopt' status line too high after a window is minimized (9.2.0789). * 'completeslash' breaks :find completion with 'findfunc' (9.2.0790). * wincol() counts from right side for 'rightleft' (9.2.0791). * runtime(netrw): explore without optional dir broken (9.2.0792). * if session restored a tiny window, restore fails (9.2.0793). * extend() and extendnew() don't handle NULL expr2 properly (9.2.0794). * popup menu shadow is not cleared when the menu shrinks (9.2.0795). * Visual block reselection wrong with 'virtualedit' (9.2.0796). * memory leak in get_qfline_items() on alloc failure (9.2.0797). * memory leak in compile_expr6() on alloc failure (9.2.0798). * memory leak in compile_def_function_body() on alloc failure (9.2.0799). * memory leak in call_func() on alloc failure (9.2.0800). * memory leak in f_getreginfo() on alloc failure (9.2.0801). * memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802). * memory leak on alloc failure with taglist/gettagstack() (9.2.0803). * wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804). * screenpos() 'curscol' is wrong with 'rightleft' (9.2.0805). * 'showcmd' may show internal command keys (9.2.0806). * MS-Windows: ellipsis character is garbled (9.2.0807). * getregionpos: double-free on alloc failure (9.2.0808). * getframelayout() uses wrong function to free lists (9.2.0809). * add_llist_tags() uses wrong function to free dict (9.2.0810). * mksession writes terminal command unquoted (9.2.0811). * :argdelete with pattern leads to wrong argidx() (9.2.0812). * dict_add_func() may corrupt funcref count on failure (9.2.0813). * Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814). * deeply nested regexp patterns may cause stack overflow (9.2.0815). * GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816). * crash when building a stacktrace during an autocommand (9.2.0817). * tests: client-server test fails without X11 server (9.2.0818). * MS-Windows: sixel image shown as raw text in the console (9.2.0819). * GUI: hidden popup image is displayed and not erased (9.2.0820). * filetype: msmtp system-wide rc file not detected (9.2.0821). * GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822). * tests: Test_clientserver_servlist_list may fail (9.2.0823). * Makefile: make tags depends on configure (9.2.0824). * regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825). * highlighting for broken terminals can be improved (9.2.0826). * :startinsert enters Insert mode in a non-modifiable buffer (9.2.0827). * GTK4: hardware rendering can be improved (9.2.0828). * sessions do not preserve script version for expression options (9.2.0829). * the completion menu is not used on terminals without colors (9.2.0830). * diff highlighting hard to read with syntax enabled (9.2.0831). * socketserver: remote commands can be processed in reverse order (9.2.0832). * GTK4: menu mnemonics do not work properly (9.2.0833). * cleared last search pattern is restored from viminfo (9.2.0834). * features in version.c are not sorted (9.2.0835). * filetype: .git-blame-ignore-revs file is not recognized (9.2.0836). * using wrong colors in hl_blend_attr() (9.2.0837). * searchcount() returns wrong cached maxcount (9.2.0838). * [security]: arbitrary code execution via keyword lookup (9.2.0839). * [security]: code injection in netrw via bookmarks (9.2.0840). * [security]: heap overflow when adding > 65535 text properties (9.2.0841). * [security]: stack buffer overflow in socket server (9.2.0842). * [security]: popup: opacity mask indexed out of bounds (9.2.0843). * [security]: use-after-free on json decode error (9.2.0844). * [security]: arbitrary Ex command execution during C omni-completion (9.2.0845). * [security]: heap buffer overflow in set_sofo() (9.2.0846). * [security]: vimball: code execution via .VimballRecord file (9.2.0847). * tagfunc 'cmd' with a generic Ex command corrupts the tag entry (9.2.0848). * filetype: osquery config files are not recognized (9.2.0849). * MS-Windows: commands from a client can be lost (9.2.0850). * focus autocommands triggered inconsistently (9.2.0851). * GTK: ligatures not correctly displayed (9.2.0852). * popup: popup images do not support scaling (9.2.0853). * memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854). * 'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855). * GTK4: undercurl rendering is inefficient (9.2.0856). * popup: opacity popup over a terminal is not cleared when closed (9.2.0857). * MS-Windows GUI: white flash when VimEnter is slow (9.2.0858). * GTK2: link error (9.2.0859). * filetype: xilinx design constraint files are not recognized (9.2.0860). * GTK4: bleed region updates in jumps (9.2.0861). * missing test change from v9.2.0857 (9.2.0862). * MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863). * using some dead code in Wayland feature (9.2.0864). * GTK4: non-hardware accelerated UI is too slow (9.2.0865). * MS-Windows: ':language messages' only works once (9.2.0866). * MS-Windows: messages are not in the display language (9.2.0867). * GTK: window Manager hint prevents giving focus to dialog (9.2.0868). * buf_copy_options() can lose the P_INSECURE flag (9.2.0869). * filetype: marko files are not recognized (9.2.0870). * screen line is lost when splitting a 'winfixheight' window (9.2.0871). * popup with opacity does not use the font of the highlight group (9.2.0872). * :redrawstatus does not update the ruler of the last window (9.2.0873). * fold size is compared against 'foldminlines' of the wrong window (9.2.0874). * GTK4: GUI does not support command-line arguments (9.2.0875). * GTK4: compile error with disabled netbeans feat (9.2.0876). * Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877). * Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878). * popup: 'maxwidth' is not respected when 'wrap' is off (9.2.0879). * scroll: window scrolls when using the autocommand window (9.2.0880). * 'smoothscroll' position is lost when the window height changes (9.2.0881). * :bwipe crashes if WinLeave wipes all other buffers (9.2.0882). * scroll: 'smoothscroll' position is lost when using '|' (9.2.0883). * scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884). * scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885). * :set completion works for an invalid sub-option name (9.2.0886). * scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887). * mapping: modifier is not recognized after a partial mapping (9.2.0888). * VMS: spurious 'INVALID DECC FEATURE VALUE' message at every startup (9.2.0889). * test: test for patch v9.2.0888 can be clarified (9.2.0890). * MS-Windows: filename-modifier ':8:t' causes underflow (9.2.0891). * highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892). * MS-Windows: '*.vim' also matches files with a longer extension (9.2.0893). * filetype: ed script files not recognised (9.2.0894). * test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895). * scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896). * GTK3 X11 redraws are not coalesced (9.2.0897). * printing support is lacking (9.2.0898). * command output temporary files may collide (9.2.0899). * FocusGained still triggered when closing dialog (9.2.0900). * textprop: wrong cursor line with truncated virtual text (9.2.0901). * Vim9: iterating over a tuple leaks memory (9.2.0902). * Vim9: cannot use an exported function of an autoload import (9.2.0903). * 'zb' scrolls incorrectly with cursor just above fold (9.2.0904). * MS-Windows: ghost cursor with ligatures (9.2.0905). * slow transstr() with long strings (9.2.0906). * popup: virtual text is not redrawn when a text property changes (9.2.0907). * cannot use a {} block in a nested :autocmd (9.2.0908). * insert completion is slow to collect many matches (9.2.0909). * runtime(vim): update syntax, contain Ex commands (9.2.0910). * makefiles do not build hardcopy_postscript.c (9.2.0911). * hardcopy: prototypes are hand-written instead of generated (9.2.0912). * statusline: cell below the vertical separator keeps the old highlight (9.2.0913). * diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914). * tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915). * configure: honor `--disable-hardcopy-pango` with GTK UI (9.2.0916). * :quitall not allowed in the command-line window (9.2.0917). * screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918). * screen: the wrong array is copied into ScreenCols on a resize (9.2.0919). * filetype: json-ld files are not recognized (9.2.0920). * test: terminal tests fail on FreeBSD (9.2.0921). * Wayland: modeless selection not redrawn (9.2.0922). * tabpage: closing a tab page loses the alternate tab page (9.2.0923). * tests: Test_termwinscroll() fails on FreeBSD (9.2.0924). * crash when getcompletiontype() gets a NULL string (9.2.0925). * filetype: business Central files are not recognized (9.2.0926). * curswant not set on 8g8 (9.2.0927). * MinGW: tests hang when Vim is built with coverage enabled (9.2.0928). * incorrect completion for 'pumopt' and 'pumborder' (9.2.0929). * floating point exception when displaying pum (9.2.0930). * the GTK4 GUI is still experimental and untested by CI (9.2.0931). * NFA engine fallback can double free the compiled program (9.2.0932). * u_read_undo() leaks the file name when the undo file owner differs (9.2.0933). * filetype: hlsl files are not recognized (9.2.0934). * reading an undo file is slow with many undo headers (9.2.0935). * stringifying a list or dict can free the item being iterated (9.2.0936). * sort() with a numeric option converts each item on every comparison (9.2.0937). * cursorbind: cursor in the other window is not updated after undo (9.2.0938). * mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939). * GTK4: columns are lost when a scrollbar appears (9.2.0940). * tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941). * test: test_mksession_winpos() fails on GTK4 UI (9.2.0942). * test: test_hardcopy fails on GTK4 UI (9.2.0943). * test: tests fail when checking for GTK4 feature (9.2.0944). * sort() with a numeric option can be improved (9.2.0945). * GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946). * GTK4: screen is cleared when moving the mouse after startup (9.2.0947). * GTK4: mouse move starts Visual selection after a dialog (9.2.0948). * GDK_KEY_VoidSymbol might be undefined (9.2.0949). * transstr() can be improved (after 9.2.0906) (9.2.0950). * GTK3: cursor does no longer blink (9.2.0951). * locking a container while stringifying can be improved (9.2.0952). * insert completion code can be improved (9.2.0953). * u_read_undo() can be improved (after 9.2.0935) (9.2.0954). * tests: terminal tests are flaky (9.2.0955). * GTK4: crash when the window is resized while redrawing (9.2.0956). * filetype: ArgoCD config file is not recognized (9.2.0957). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3685-1 Released: Fri Aug 21 20:23:55 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3783-1 Released: Tue Aug 25 10:10:55 2026 Summary: Security update for containerd Type: security Severity: important References: This update for containerd rebuilds it against the current go security release. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3787-1 Released: Tue Aug 25 10:15:16 2026 Summary: Security update for runc Type: security Severity: important References: This update for runc rebuilds it against the current go security release. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3840-1 Released: Thu Aug 27 14:21:12 2026 Summary: Security update for wicked Type: security Severity: important References: 1265221,1274627,CVE-2026-44932,CVE-2026-71401,CVE-2026-71402 This update for wicked fixes the following issues: Update to version 0.6.79. - CVE-2026-44932: indirect remote shell command injection due to insufficient sanitization of DHCP options written to `/run/wicked/leaseinfo.*` files (bsc#1265221). - CVE-2026-71401: out-of-bounds read due to IP length underflow in checksum handling of DHCPv4 capture parsing (bsc#1274627). - CVE-2026-71402: out-of-bounds read due to DHCP option reader being extended beyond provided allocation in DHCPv4 capture parsing (bsc#1274627). Changes for wicked: - Version 0.6.79: - Fix to escape single-quotes in leaseinfo dump output used by the `wicked test dhcp4` and `wicked test dhcp6` and written to the `/run/wicked/leaseinfo.*` files, e.g. to pass them to `netconfig`. - Fix `posix-tz-dbname` and `tz-string` option processing checks to permit only valid characters according to RFC4833. - Discard string values containing single-quotes in other options. - Trigger to regenerate `initrd` that may contain wicked binaries on updates from wicked versions <= 0.6.78. - Version 0.6.78: - `man`: small fixes in wireless manpage (gh#opensuse/wicked#1053) - `rtnetlink`: fix `RTM_NEWLINK` name resolution in debug (gh#opensuse/wicked#1052) - Add support for IPVLAN/IPVTAP (jsc#PED-1942, gh#opensuse/wicked#1050, gh#opensuse/wicked#1051) - `fsm`: remove children reference array from worker (gh#opensuse/wicked#1049) - `ifxml`: migrate and generate lower configs/policies (gh#opensuse/wicked#1048) - `fsm`: use refcount and array macros in worker and policy (gh#opensuse/wicked#1047) - `route`: use refcounted array and fix error leaks (gh#opensuse/wicked#1046) - `utils`: add support for refcounted objects in generic array (gh#openSUSE/wicked#1045) The following package changes have been done: - bind-utils-9.18.50-150600.3.32.1 updated - cifs-utils-6.15-150400.3.24.1 updated - cloud-init-config-suse-25.1.3-150400.15.10.2 updated - cloud-init-25.1.3-150400.15.10.2 updated - containerd-ctr-1.7.29-150000.146.1 updated - containerd-1.7.29-150000.146.1 updated - curl-8.14.1-150600.4.46.1 updated - dmidecode-3.7-150400.16.14.1 updated - dracut-059+suse.567.gf5cfeb7f7-150600.3.32.1 updated - gawk-4.2.1-150000.3.6.1 updated - glib2-tools-2.78.6-150600.4.38.1 updated - glibc-locale-base-2.38-150600.14.52.1 updated - glibc-2.38-150600.14.52.1 updated - gpg2-2.4.4-150600.3.18.1 updated - grub2-i386-pc-2.12-150600.8.55.1 updated - grub2-snapper-plugin-2.12-150600.8.55.1 updated - grub2-x86_64-efi-2.12-150600.8.55.1 updated - grub2-2.12-150600.8.55.1 updated - gzip-1.10-150200.16.1 updated - jq-1.6-150000.3.20.1 updated - kernel-default-6.4.0-150600.23.130.1 updated - kmod-29-150600.13.6.1 updated - krb5-1.20.1-150600.11.19.1 updated - libavahi-client3-0.8-150600.15.21.1 updated - libavahi-common3-0.8-150600.15.21.1 updated - libblkid1-2.39.3-150600.4.26.1 updated - libcurl4-8.14.1-150600.4.46.1 updated - libfdisk1-2.39.3-150600.4.26.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libgio-2_0-0-2.78.6-150600.4.38.1 updated - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libgmodule-2_0-0-2.78.6-150600.4.38.1 updated - libgobject-2_0-0-2.78.6-150600.4.38.1 updated - libjq1-1.6-150000.3.20.1 updated - libkmod2-29-150600.13.6.1 updated - libmount1-2.39.3-150600.4.26.1 updated - libnghttp2-14-1.40.0-150600.25.8.1 updated - libopenssl1_1-1.1.1w-150600.5.35.2 updated - libopenssl3-3.1.4-150600.5.59.1 updated - libpng16-16-1.6.58-150600.3.23.1 updated - libpython3_11-1_0-3.11.15-150600.3.65.1 updated - libsmartcols1-2.39.3-150600.4.26.1 updated - libsolv-tools-base-0.7.39-150600.8.24.1 updated - libsqlite3-0-3.53.2-150000.3.42.1 updated - libssh-config-0.9.8-150600.11.15.1 updated - libssh4-0.9.8-150600.11.15.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - libsystemd0-254.27-150600.4.71.2 updated - libudev1-254.27-150600.4.71.2 updated - libuuid1-2.39.3-150600.4.26.1 updated - libxml2-2-2.10.3-150500.5.41.1 updated - libxml2-tools-2.10.3-150500.5.41.1 updated - libzypp-17.38.13-150600.3.92.1 updated - login_defs-4.17.2-150600.17.21.1 updated - net-tools-2.0+git20170221.479bb4a-150000.5.18.1 updated - openssh-clients-9.6p1-150600.6.49.1 updated - openssh-common-9.6p1-150600.6.49.1 updated - openssh-server-9.6p1-150600.6.49.1 updated - openssh-9.6p1-150600.6.49.1 updated - openssl-3-3.1.4-150600.5.59.1 updated - pam-1.3.0-150000.6.89.1 updated - perl-base-5.26.1-150300.17.23.1 updated - perl-5.26.1-150300.17.23.1 updated - python311-PyJWT-2.8.0-150400.8.13.1 updated - python311-base-3.11.15-150600.3.65.1 updated - python311-configobj-5.0.8-150400.12.7.1 updated - python311-cryptography-41.0.3-150600.23.9.1 updated - python311-idna-3.4-150400.11.13.1 updated - python311-jsonpatch-1.32-150400.10.7.1 updated - python311-jsonpointer-2.3-150400.11.7.1 updated - python311-pyserial-3.5-150400.12.7.1 updated - python311-urllib3-2.0.7-150400.7.33.1 updated - python311-3.11.15-150600.3.65.1 updated - rpcbind-0.2.3-150000.5.12.1 updated - rpm-ndb-4.14.3-150400.59.19.1 updated - rsyslog-module-relp-8.2406.0-150600.12.19.2 updated - rsyslog-8.2406.0-150600.12.19.2 updated - runc-1.3.6-150000.103.1 updated - samba-client-libs-4.19.8+git.501.67274891bc-150600.3.29.1 updated - scap-security-guide-0.1.80-150600.1.27 updated - shadow-4.17.2-150600.17.21.1 updated - supportutils-3.2.14.2-150600.3.12.1 updated - suseconnect-ng-1.22.1-150600.3.21.1 updated - sysconfig-netconfig-0.85.11-150200.18.1 updated - sysconfig-0.85.11-150200.18.1 updated - systemd-254.27-150600.4.71.2 updated - tar-1.34-150000.3.42.1 updated - timezone-2026c-150600.91.12.1 updated - udev-254.27-150600.4.71.2 updated - util-linux-systemd-2.39.3-150600.4.26.1 updated - util-linux-2.39.3-150600.4.26.1 updated - vim-data-common-9.2.0957-150500.20.64.1 updated - vim-9.2.0957-150500.20.64.1 updated - wicked-service-0.6.79-150600.11.20.1 updated - wicked-0.6.79-150600.11.20.1 updated - xen-libs-4.18.5_20-150600.3.53.3 updated - zypper-1.14.98-150600.10.55.1 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:08:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:08:14 +0200 (CEST) Subject: SUSE-IU-2026:6740-1: Security update of suse/sle-micro/base-5.5 Message-ID: <20260904070814.608ABFDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6740-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.311 , suse/sle-micro/base-5.5:latest Image Release : 5.8.311 Severity : moderate Type : security References : 1262633 1263440 1264971 1268412 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3958-1 Released: Thu Sep 3 15:31:59 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) The following package changes have been done: - libcurl4-8.14.1-150400.5.91.1 updated - curl-8.14.1-150400.5.91.1 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:10:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:10:54 +0200 (CEST) Subject: SUSE-IU-2026:6741-1: Security update of suse/sle-micro/kvm-5.5 Message-ID: <20260904071054.BA244FDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/kvm-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6741-1 Image Tags : suse/sle-micro/kvm-5.5:2.0.4 , suse/sle-micro/kvm-5.5:2.0.4-3.5.599 , suse/sle-micro/kvm-5.5:latest Image Release : 3.5.599 Severity : moderate Type : security References : 1262633 1263440 1264971 1268412 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/sle-micro/kvm-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3958-1 Released: Thu Sep 3 15:31:59 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) The following package changes have been done: - libcurl4-8.14.1-150400.5.91.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.311 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:14:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:14:51 +0200 (CEST) Subject: SUSE-IU-2026:6742-1: Security update of suse/sle-micro/rt-5.5 Message-ID: <20260904071451.65766FDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6742-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.707 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.707 Severity : moderate Type : security References : 1262633 1263440 1264971 1268412 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3958-1 Released: Thu Sep 3 15:31:59 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) The following package changes have been done: - libcurl4-8.14.1-150400.5.91.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.100 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:18:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:18:01 +0200 (CEST) Subject: SUSE-IU-2026:6743-1: Security update of suse/sle-micro/5.5 Message-ID: <20260904071801.A8157FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6743-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.100 , suse/sle-micro/5.5:latest Image Release : 5.8.100 Severity : moderate Type : security References : 1262633 1263440 1264971 1268412 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3958-1 Released: Thu Sep 3 15:31:59 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) The following package changes have been done: - libcurl4-8.14.1-150400.5.91.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.311 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:24:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:24:21 +0200 (CEST) Subject: SUSE-CU-2026:9458-1: Recommended update of private-registry/1.2/harbor-core Message-ID: <20260904072421.6C240FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9458-1 Container Tags : private-registry/1.2/harbor-core:1.2.1 , private-registry/1.2/harbor-core:1.2.1-1.85 , private-registry/1.2/harbor-core:latest Container Release : 1.85 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/1.2/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.15.2-150700.1.7 updated - harbor-core-2.15.2-150700.1.7 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:24:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:24:40 +0200 (CEST) Subject: SUSE-CU-2026:9459-1: Recommended update of private-registry/1.2/harbor-exporter Message-ID: <20260904072440.A330BFCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9459-1 Container Tags : private-registry/1.2/harbor-exporter:1.2.1 , private-registry/1.2/harbor-exporter:1.2.1-1.85 , private-registry/1.2/harbor-exporter:latest Container Release : 1.85 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/1.2/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - harbor-exporter-2.15.2-150700.1.7 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.15.2-150700.1.7 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:25:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:25:00 +0200 (CEST) Subject: SUSE-CU-2026:9460-1: Recommended update of private-registry/1.2/harbor-jobservice Message-ID: <20260904072500.9A2DEFCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9460-1 Container Tags : private-registry/1.2/harbor-jobservice:1.2.1 , private-registry/1.2/harbor-jobservice:1.2.1-1.83 , private-registry/1.2/harbor-jobservice:latest Container Release : 1.83 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/1.2/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.15.2-150700.1.7 updated - harbor-jobservice-2.15.2-150700.1.7 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:25:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:25:26 +0200 (CEST) Subject: SUSE-CU-2026:9461-1: Recommended update of private-registry/1.2/harbor-portal Message-ID: <20260904072526.48802FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9461-1 Container Tags : private-registry/1.2/harbor-portal:1.2.1 , private-registry/1.2/harbor-portal:1.2.1-1.94 , private-registry/1.2/harbor-portal:latest Container Release : 1.94 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.15.2-150700.1.7 updated - harbor-portal-2.15.2-150700.1.7 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:25:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:25:48 +0200 (CEST) Subject: SUSE-CU-2026:9462-1: Recommended update of private-registry/1.2/harbor-registry Message-ID: <20260904072548.88D3EFCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9462-1 Container Tags : private-registry/1.2/harbor-registry:1.2.1 , private-registry/1.2/harbor-registry:1.2.1-1.85 , private-registry/1.2/harbor-registry:latest Container Release : 1.85 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.15.2-150700.1.7 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:26:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:26:07 +0200 (CEST) Subject: SUSE-CU-2026:9463-1: Recommended update of private-registry/1.2/harbor-registryctl Message-ID: <20260904072607.22AE9FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9463-1 Container Tags : private-registry/1.2/harbor-registryctl:1.2.1 , private-registry/1.2/harbor-registryctl:1.2.1-1.85 , private-registry/1.2/harbor-registryctl:latest Container Release : 1.85 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.15.2-150700.1.7 updated - harbor-registryctl-2.15.2-150700.1.7 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:26:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:26:32 +0200 (CEST) Subject: SUSE-CU-2026:9464-1: Recommended update of private-registry/1.2/harbor-trivy-adapter Message-ID: <20260904072632.2815EFCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9464-1 Container Tags : private-registry/1.2/harbor-trivy-adapter:1.2.1 , private-registry/1.2/harbor-trivy-adapter:1.2.1-1.94 , private-registry/1.2/harbor-trivy-adapter:latest Container Release : 1.94 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/1.2/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - harbor-scanner-trivy-0.38.0-150700.1.7 updated - system-user-harbor-2.15.2-150700.1.7 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:27:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:27:40 +0200 (CEST) Subject: SUSE-CU-2026:9465-1: Recommended update of private-registry/harbor-core Message-ID: <20260904072740.F2BFBFCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9465-1 Container Tags : private-registry/harbor-core:1.1.3 , private-registry/harbor-core:1.1.3-2.98 , private-registry/harbor-core:latest Container Release : 2.98 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.14.4-150700.1.37 updated - harbor-core-2.14.4-150700.1.37 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:28:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:28:59 +0200 (CEST) Subject: SUSE-CU-2026:9466-1: Recommended update of private-registry/harbor-exporter Message-ID: <20260904072859.9EE26FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9466-1 Container Tags : private-registry/harbor-exporter:1.1.3 , private-registry/harbor-exporter:1.1.3-2.99 , private-registry/harbor-exporter:latest Container Release : 2.99 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - harbor-exporter-2.14.4-150700.1.37 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.14.4-150700.1.37 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:30:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:30:12 +0200 (CEST) Subject: SUSE-CU-2026:9467-1: Recommended update of private-registry/harbor-jobservice Message-ID: <20260904073012.46DD7FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9467-1 Container Tags : private-registry/harbor-jobservice:1.1.3 , private-registry/harbor-jobservice:1.1.3-2.98 , private-registry/harbor-jobservice:latest Container Release : 2.98 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.14.4-150700.1.37 updated - harbor-jobservice-2.14.4-150700.1.37 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:31:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:31:36 +0200 (CEST) Subject: SUSE-CU-2026:9468-1: Recommended update of private-registry/harbor-portal Message-ID: <20260904073136.BC631FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9468-1 Container Tags : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.111 , private-registry/harbor-portal:latest Container Release : 2.111 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.14.4-150700.1.37 updated - harbor-portal-2.14.4-150700.1.37 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:32:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:32:13 +0200 (CEST) Subject: SUSE-CU-2026:9469-1: Recommended update of private-registry/harbor-registry Message-ID: <20260904073213.6C8B9FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9469-1 Container Tags : private-registry/harbor-registry:1.1.3 , private-registry/harbor-registry:1.1.3-2.99 , private-registry/harbor-registry:latest Container Release : 2.99 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.14.4-150700.1.37 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:33:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:33:39 +0200 (CEST) Subject: SUSE-CU-2026:9470-1: Recommended update of private-registry/harbor-registryctl Message-ID: <20260904073339.00F5BFCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9470-1 Container Tags : private-registry/harbor-registryctl:1.1.3 , private-registry/harbor-registryctl:1.1.3-2.100 , private-registry/harbor-registryctl:latest Container Release : 2.100 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.14.4-150700.1.37 updated - harbor-registryctl-2.14.4-150700.1.37 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:35:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:35:03 +0200 (CEST) Subject: SUSE-CU-2026:9471-1: Recommended update of private-registry/harbor-trivy-adapter Message-ID: <20260904073503.2EBECFCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9471-1 Container Tags : private-registry/harbor-trivy-adapter:1.1.3 , private-registry/harbor-trivy-adapter:1.1.3-2.110 , private-registry/harbor-trivy-adapter:latest Container Release : 2.110 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - harbor-scanner-trivy-0.36.0-150700.1.23 updated - system-user-harbor-2.14.4-150700.1.37 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:35:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:35:18 +0200 (CEST) Subject: SUSE-CU-2026:9472-1: Recommended update of private-registry/harbor-core Message-ID: <20260904073518.13AF4FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9472-1 Container Tags : private-registry/harbor-core:2.13 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5-1.50 , private-registry/harbor-core:2.13.5-1.50 , private-registry/harbor-core:latest Container Release : 1.50 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.13.5-150700.1.27 updated - harbor213-core-2.13.5-150700.1.27 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:35:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:35:33 +0200 (CEST) Subject: SUSE-CU-2026:9473-1: Recommended update of private-registry/harbor-exporter Message-ID: <20260904073533.E1303FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9473-1 Container Tags : private-registry/harbor-exporter:2.13 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5-1.50 , private-registry/harbor-exporter:2.13.5-1.50 , private-registry/harbor-exporter:latest Container Release : 1.50 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - harbor213-exporter-2.13.5-150700.1.27 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.13.5-150700.1.27 updated From sle-container-updates at lists.suse.com Fri Sep 4 07:35:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 4 Sep 2026 09:35:49 +0200 (CEST) Subject: SUSE-CU-2026:9474-1: Recommended update of private-registry/harbor-jobservice Message-ID: <20260904073549.6F830FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9474-1 Container Tags : private-registry/harbor-jobservice:2.13 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5-1.50 , private-registry/harbor-jobservice:2.13.5-1.50 , private-registry/harbor-jobservice:latest Container Release : 1.50 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.13.5-150700.1.27 updated - harbor213-jobservice-2.13.5-150700.1.27 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:11:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:11:49 +0200 (CEST) Subject: SUSE-IU-2026:6745-1: Security update of suse/sle-micro/5.5 Message-ID: <20260905071149.85327FDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6745-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.101 , suse/sle-micro/5.5:latest Image Release : 5.8.101 Severity : important Type : security References : ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3974-1 Released: Fri Sep 4 10:45:50 2026 Summary: Security update for podman Type: security Severity: important References: This update for podman rebuilds it against the current go security release. The following package changes have been done: - podman-4.9.5-150500.3.82.1 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:17:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:17:49 +0200 (CEST) Subject: SUSE-CU-2026:9474-1: Recommended update of private-registry/harbor-jobservice Message-ID: <20260905071749.02C96FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9474-1 Container Tags : private-registry/harbor-jobservice:2.13 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5-1.50 , private-registry/harbor-jobservice:2.13.5-1.50 , private-registry/harbor-jobservice:latest Container Release : 1.50 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.13.5-150700.1.27 updated - harbor213-jobservice-2.13.5-150700.1.27 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:18:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:18:07 +0200 (CEST) Subject: SUSE-CU-2026:9477-1: Recommended update of private-registry/harbor-portal Message-ID: <20260905071807.61815FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9477-1 Container Tags : private-registry/harbor-portal:2.13 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5-1.55 , private-registry/harbor-portal:2.13.5-1.55 , private-registry/harbor-portal:latest Container Release : 1.55 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.13.5-150700.1.27 updated - harbor213-portal-2.13.5-150700.1.27 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:18:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:18:24 +0200 (CEST) Subject: SUSE-CU-2026:9478-1: Recommended update of private-registry/harbor-registry Message-ID: <20260905071824.6626CFCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9478-1 Container Tags : private-registry/harbor-registry:2.8.3 , private-registry/harbor-registry:2.8.3-1.51 , private-registry/harbor-registry:latest Container Release : 1.51 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.13.5-150700.1.27 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:18:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:18:41 +0200 (CEST) Subject: SUSE-CU-2026:9479-1: Recommended update of private-registry/harbor-registryctl Message-ID: <20260905071841.E1523FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9479-1 Container Tags : private-registry/harbor-registryctl:2.13 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5-1.50 , private-registry/harbor-registryctl:2.13.5-1.50 , private-registry/harbor-registryctl:latest Container Release : 1.50 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.13.5-150700.1.27 updated - harbor213-registryctl-2.13.5-150700.1.27 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:18:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:18:59 +0200 (CEST) Subject: SUSE-CU-2026:9480-1: Recommended update of private-registry/harbor-trivy-adapter Message-ID: <20260905071859.89463FCEE@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9480-1 Container Tags : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.54 , private-registry/harbor-trivy-adapter:latest Container Release : 1.54 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - system-user-harbor-2.13.5-150700.1.27 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:23:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:23:49 +0200 (CEST) Subject: SUSE-CU-2026:9481-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260905072349.CA37DFCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9481-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.178 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.178 Severity : moderate Type : security References : 1262633 1263440 1264971 1268412 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3958-1 Released: Thu Sep 3 15:31:59 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) The following package changes have been done: - curl-8.14.1-150400.5.91.1 updated - libcurl4-8.14.1-150400.5.91.1 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:26:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:26:30 +0200 (CEST) Subject: SUSE-CU-2026:9482-1: Security update of suse/sle-micro/5.4/toolbox Message-ID: <20260905072630.44D6CFCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9482-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.277 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.277 Severity : moderate Type : security References : 1262633 1263440 1264971 1268412 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3958-1 Released: Thu Sep 3 15:31:59 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) The following package changes have been done: - curl-8.14.1-150400.5.91.1 updated - libcurl4-8.14.1-150400.5.91.1 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:28:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:28:35 +0200 (CEST) Subject: SUSE-CU-2026:9483-1: Security update of suse/sle-micro/5.5/toolbox Message-ID: <20260905072835.5E0A0FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9483-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.187 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.187 Severity : moderate Type : security References : 1262633 1263440 1264971 1268412 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3958-1 Released: Thu Sep 3 15:31:59 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) The following package changes have been done: - curl-8.14.1-150400.5.91.1 updated - libcurl4-8.14.1-150400.5.91.1 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:31:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:31:05 +0200 (CEST) Subject: SUSE-IU-2026:6746-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260905073105.73600FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6746-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.241 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.241 Severity : moderate Type : security References : 1266664 1266667 1272340 CVE-2026-16461 CVE-2026-23679 CVE-2026-47104 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 877 Released: Thu Sep 3 10:09:27 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,1266667,CVE-2026-23679,CVE-2026-47104 This update for libusb-1_0 fixes the following issues: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). - CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667). ----------------------------------------------------------------- Advisory ID: 879 Released: Thu Sep 3 10:09:27 2026 Summary: Security update for rpcbind Type: security Severity: moderate References: 1272340,CVE-2026-16461 This update for rpcbind fixes the following issue: - CVE-2026-16461: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting (bsc#1272340). The following package changes have been done: - SL-Micro-release-6.0-25.130 updated - libusb-1_0-0-1.0.27-2.1 updated - rpcbind-1.2.9-2.1 updated - container:SL-Micro-base-container-2.1.3-7.206 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:31:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:31:06 +0200 (CEST) Subject: SUSE-IU-2026:6747-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260905073106.78B6DFDCF@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6747-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.242 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.242 Severity : important Type : security References : 1274774 1274788 1274790 1274795 1274797 1275837 CVE-2026-54874 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 882 Released: Fri Sep 4 11:08:57 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). - CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797). - CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790). The following package changes have been done: - libopenssl3-3.1.4-17.1 updated - SL-Micro-release-6.0-25.131 updated - container:SL-Micro-base-container-2.1.3-7.207 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:33:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:33:38 +0200 (CEST) Subject: SUSE-IU-2026:6748-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260905073338.E6C82FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6748-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.206 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.206 Severity : moderate Type : security References : 1266664 1266667 CVE-2026-23679 CVE-2026-47104 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 877 Released: Thu Sep 3 10:09:27 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,1266667,CVE-2026-23679,CVE-2026-47104 This update for libusb-1_0 fixes the following issues: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). - CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667). The following package changes have been done: - SL-Micro-release-6.0-25.130 updated - libusb-1_0-0-1.0.27-2.1 updated - container:suse-toolbox-image-1.0.0-9.162 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:33:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:33:40 +0200 (CEST) Subject: SUSE-IU-2026:6749-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260905073340.11166FDCF@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6749-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.207 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.207 Severity : important Type : security References : 1274774 1274788 1274790 1274795 1274797 1275837 CVE-2026-54874 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 882 Released: Fri Sep 4 11:08:57 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). - CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797). - CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790). The following package changes have been done: - libopenssl3-3.1.4-17.1 updated - SL-Micro-release-6.0-25.131 updated - openssl-3-3.1.4-17.1 updated - container:suse-toolbox-image-1.0.0-9.163 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:36:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:36:36 +0200 (CEST) Subject: SUSE-IU-2026:6751-1: Security update of suse/sl-micro/6.0/kvm-os-container Message-ID: <20260905073636.0F682FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6751-1 Image Tags : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.217 , suse/sl-micro/6.0/kvm-os-container:latest Image Release : 6.217 Severity : important Type : security References : 1274774 1274788 1274790 1274795 1274797 1275837 CVE-2026-54874 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 882 Released: Fri Sep 4 11:08:57 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). - CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797). - CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790). The following package changes have been done: - libopenssl3-3.1.4-17.1 updated - SL-Micro-release-6.0-25.131 updated - container:SL-Micro-base-container-2.1.3-7.207 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:39:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:39:36 +0200 (CEST) Subject: SUSE-IU-2026:6753-1: Security update of suse/sl-micro/6.0/rt-os-container Message-ID: <20260905073936.B8F1BFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6753-1 Image Tags : suse/sl-micro/6.0/rt-os-container:2.1.3 , suse/sl-micro/6.0/rt-os-container:2.1.3-7.235 , suse/sl-micro/6.0/rt-os-container:latest Image Release : 7.235 Severity : important Type : security References : 1274774 1274788 1274790 1274795 1274797 1275837 CVE-2026-54874 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 882 Released: Fri Sep 4 11:08:57 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). - CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797). - CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790). The following package changes have been done: - libopenssl3-3.1.4-17.1 updated - SL-Micro-release-6.0-25.131 updated - container:SL-Micro-container-2.1.3-6.242 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:50:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:50:31 +0200 (CEST) Subject: SUSE-CU-2026:9492-1: Security update of suse/sl-micro/6.0/toolbox Message-ID: <20260905075031.DC109FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9492-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.162 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.162 Severity : moderate Type : security References : 1266664 1266667 CVE-2026-23679 CVE-2026-47104 ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 877 Released: Thu Sep 3 10:09:27 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,1266667,CVE-2026-23679,CVE-2026-47104 This update for libusb-1_0 fixes the following issues: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). - CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667). The following package changes have been done: - SL-Micro-release-6.0-25.130 updated - libusb-1_0-0-1.0.27-2.1 updated - skelcd-EULA-SL-Micro-2024.01.19-8.129 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:50:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:50:33 +0200 (CEST) Subject: SUSE-CU-2026:9493-1: Security update of suse/sl-micro/6.0/toolbox Message-ID: <20260905075033.0D977FDCF@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9493-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.163 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.163 Severity : important Type : security References : 1274774 1274788 1274790 1274795 1274797 1275837 CVE-2026-54874 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 882 Released: Fri Sep 4 11:08:57 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). - CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797). - CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790). The following package changes have been done: - SL-Micro-release-6.0-25.131 updated - libopenssl3-3.1.4-17.1 updated - skelcd-EULA-SL-Micro-2024.01.19-8.130 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:52:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:52:59 +0200 (CEST) Subject: SUSE-IU-2026:6754-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260905075259.362D8FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6754-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.164 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.164 Severity : moderate Type : security References : 1248093 1260414 1261938 1266664 1266667 1272340 CVE-2025-55199 CVE-2026-16461 CVE-2026-23679 CVE-2026-33554 CVE-2026-35206 CVE-2026-47104 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 706 Released: Thu Sep 3 10:48:19 2026 Summary: Security update for rpcbind Type: security Severity: moderate References: 1260414,1272340,CVE-2026-16461,CVE-2026-33554 This update for rpcbind fixes the following issue: - CVE-2026-16461: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting (bsc#1272340). ----------------------------------------------------------------- Advisory ID: 705 Released: Thu Sep 3 10:49:13 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1248093,1261938,1266664,1266667,CVE-2025-55199,CVE-2026-23679,CVE-2026-35206,CVE-2026-47104 This update for libusb-1_0 fixes the following issues: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). - CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667). The following package changes have been done: - SL-Micro-release-6.1-slfo.1.12.73 updated - libusb-1_0-0-1.0.27-slfo.1.1_2.1 updated - rpcbind-1.2.9-slfo.1.1_2.1 updated - container:SL-Micro-base-container-2.2.1-5.180 updated From sle-container-updates at lists.suse.com Sat Sep 5 07:55:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 09:55:33 +0200 (CEST) Subject: SUSE-IU-2026:6756-1: Security update of suse/sl-micro/6.1/base-os-container Message-ID: <20260905075533.17550FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6756-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.180 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.180 Severity : moderate Type : security References : 1248093 1261938 1266664 1266667 CVE-2025-55199 CVE-2026-23679 CVE-2026-35206 CVE-2026-47104 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 705 Released: Thu Sep 3 10:49:13 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1248093,1261938,1266664,1266667,CVE-2025-55199,CVE-2026-23679,CVE-2026-35206,CVE-2026-47104 This update for libusb-1_0 fixes the following issues: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). - CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667). The following package changes have been done: - SL-Micro-release-6.1-slfo.1.12.73 updated - libusb-1_0-0-1.0.27-slfo.1.1_2.1 updated - container:suse-toolbox-image-1.0.0-5.100 updated From sle-container-updates at lists.suse.com Sat Sep 5 08:13:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 10:13:26 +0200 (CEST) Subject: SUSE-IU-2026:6762-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260905081326.C8085FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6762-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.121 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.121 Severity : moderate Type : security References : 1273100 CVE-2026-52791 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1601 Released: Thu Sep 3 22:12:47 2026 Summary: Security update for fuse-overlayfs Type: security Severity: moderate References: 1273100,CVE-2026-52791 This update for fuse-overlayfs fixes the following issue: - CVE-2026-52791: privilege escalation due to SUID/SGID bit preservation after truncate operation (bsc#1273100). The following package changes have been done: - fuse-overlayfs-1.15-160000.3.1 updated From sle-container-updates at lists.suse.com Sat Sep 5 08:13:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 10:13:28 +0200 (CEST) Subject: SUSE-IU-2026:6763-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260905081328.10A8FFDCF@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6763-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.122 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.122 Severity : important Type : security References : 1237515 1254924 1259418 1259650 1261400 1268322 1271444 1273580 1274856 1274857 1274858 CVE-2026-16445 CVE-2026-16742 CVE-2026-29111 CVE-2026-40226 CVE-2026-4105 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1595 Released: Thu Sep 3 16:47:52 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: 1597 Released: Thu Sep 3 18:40:31 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: Update to version 059+suse.730.g73d3411aa. - CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` (bsc#1268322). - CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` during system boot (bsc#1273580). Changes for dracut: - Update to version 059+suse.730.g73d3411aa: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ----------------------------------------------------------------- Advisory ID: 1602 Released: Thu Sep 3 22:41:28 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1237515,1254924,1259418,1259650,1261400,1271444,CVE-2026-16742,CVE-2026-29111,CVE-2026-40226,CVE-2026-4105 This update for systemd fixes the following issue: Security issue fixed: - CVE-2026-16742: `systemd-homed`: local privilege escalation due to missing home record signature verification on the authentication path (bsc#1271444). Non security issue fixed: - `systemd-resolved` fails to start due to write access to `tmpfs` denied (bsc#1237515). The following package changes have been done: - libudev1-257.13-160000.4.1 updated - libsystemd0-257.13-160000.4.1 updated - cpio-2.15-160000.3.1 updated - systemd-257.13-160000.4.1 updated - udev-257.13-160000.4.1 updated - dracut-059+suse.730.g73d3411aa-160000.1.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-afd566f18c4eb0f88eac54fec12989fa838feff103a3f4065dd1d4af4b90c19e-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:06:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:06:09 +0200 (CEST) Subject: SUSE-IU-2026:6763-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260905110609.EBFEBFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6763-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.122 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.122 Severity : important Type : security References : 1237515 1254924 1259418 1259650 1261400 1268322 1271444 1273580 1274856 1274857 1274858 CVE-2026-16445 CVE-2026-16742 CVE-2026-29111 CVE-2026-40226 CVE-2026-4105 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1595 Released: Thu Sep 3 16:47:52 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: 1597 Released: Thu Sep 3 18:40:31 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: Update to version 059+suse.730.g73d3411aa. - CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` (bsc#1268322). - CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` during system boot (bsc#1273580). Changes for dracut: - Update to version 059+suse.730.g73d3411aa: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ----------------------------------------------------------------- Advisory ID: 1602 Released: Thu Sep 3 22:41:28 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1237515,1254924,1259418,1259650,1261400,1271444,CVE-2026-16742,CVE-2026-29111,CVE-2026-40226,CVE-2026-4105 This update for systemd fixes the following issue: Security issue fixed: - CVE-2026-16742: `systemd-homed`: local privilege escalation due to missing home record signature verification on the authentication path (bsc#1271444). Non security issue fixed: - `systemd-resolved` fails to start due to write access to `tmpfs` denied (bsc#1237515). The following package changes have been done: - libudev1-257.13-160000.4.1 updated - libsystemd0-257.13-160000.4.1 updated - cpio-2.15-160000.3.1 updated - systemd-257.13-160000.4.1 updated - udev-257.13-160000.4.1 updated - dracut-059+suse.730.g73d3411aa-160000.1.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-afd566f18c4eb0f88eac54fec12989fa838feff103a3f4065dd1d4af4b90c19e-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:06:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:06:12 +0200 (CEST) Subject: SUSE-IU-2026:6764-1: Recommended update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260905110612.0B6E3FDCF@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6764-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.124 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.124 Severity : moderate Type : recommended References : 1265400 1273901 1274861 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1608 Released: Fri Sep 4 14:36:16 2026 Summary: Recommended update for selinux-policy Type: recommended Severity: moderate References: 1265400,1273901,1274861 This update for selinux-policy fixes the following issues: - Update to version 20250627+git392.40ceb80be: * Label the postgresql executables correctly (bsc#1274861) - Update to version 20250627+git390.01f688865: * (open)SUSE only sendmail fixes (bsc#1273901) - Update to version 20250627+git388.83e19dbcd: * Support vfs_snapper to work with samba_share_t (bsc#1265400) * vfs_samba uses dbus to communicate with snapper (bsc#1265400) The following package changes have been done: - selinux-policy-20250627+git392.40ceb80be-160000.1.1 updated - selinux-policy-targeted-20250627+git392.40ceb80be-160000.1.1 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:06:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:06:13 +0200 (CEST) Subject: SUSE-IU-2026:6765-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260905110613.11E24FEC9@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6765-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.125 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.125 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1610 Released: Fri Sep 4 15:48:44 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the `bzip2recover` utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-160000.3.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-464538744baea68dd2d851111f85fd50ed1eb8b62dbfe83cab52d4d371efd614-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:14:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:14:14 +0200 (CEST) Subject: SUSE-IU-2026:6774-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260905111414.8FB42FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6774-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.64 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.64 Severity : important Type : security References : 1237515 1254924 1259418 1259650 1261400 1268322 1271444 1273580 1274856 1274857 1274858 CVE-2026-16445 CVE-2026-16742 CVE-2026-29111 CVE-2026-40226 CVE-2026-4105 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1595 Released: Thu Sep 3 16:47:52 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: 1597 Released: Thu Sep 3 18:40:31 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: Update to version 059+suse.730.g73d3411aa. - CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` (bsc#1268322). - CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` during system boot (bsc#1273580). Changes for dracut: - Update to version 059+suse.730.g73d3411aa: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ----------------------------------------------------------------- Advisory ID: 1602 Released: Thu Sep 3 22:41:28 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1237515,1254924,1259418,1259650,1261400,1271444,CVE-2026-16742,CVE-2026-29111,CVE-2026-40226,CVE-2026-4105 This update for systemd fixes the following issue: Security issue fixed: - CVE-2026-16742: `systemd-homed`: local privilege escalation due to missing home record signature verification on the authentication path (bsc#1271444). Non security issue fixed: - `systemd-resolved` fails to start due to write access to `tmpfs` denied (bsc#1237515). The following package changes have been done: - libudev1-257.13-160000.4.1 updated - libsystemd0-257.13-160000.4.1 updated - cpio-2.15-160000.3.1 updated - systemd-257.13-160000.4.1 updated - udev-257.13-160000.4.1 updated - dracut-059+suse.730.g73d3411aa-160000.1.1 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:14:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:14:15 +0200 (CEST) Subject: SUSE-IU-2026:6775-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260905111415.89564FDCF@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6775-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.65 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.65 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1610 Released: Fri Sep 4 15:48:44 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the `bzip2recover` utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-160000.3.1 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:20:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:20:59 +0200 (CEST) Subject: SUSE-IU-2026:6780-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260905112059.1E686FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6780-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.108 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.108 Severity : important Type : security References : 1237515 1254924 1259418 1259650 1261400 1268322 1271444 1273580 1274856 1274857 1274858 CVE-2026-16445 CVE-2026-16742 CVE-2026-29111 CVE-2026-40226 CVE-2026-4105 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1595 Released: Thu Sep 3 16:47:52 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: 1597 Released: Thu Sep 3 18:40:31 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: Update to version 059+suse.730.g73d3411aa. - CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` (bsc#1268322). - CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` during system boot (bsc#1273580). Changes for dracut: - Update to version 059+suse.730.g73d3411aa: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ----------------------------------------------------------------- Advisory ID: 1602 Released: Thu Sep 3 22:41:28 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1237515,1254924,1259418,1259650,1261400,1271444,CVE-2026-16742,CVE-2026-29111,CVE-2026-40226,CVE-2026-4105 This update for systemd fixes the following issue: Security issue fixed: - CVE-2026-16742: `systemd-homed`: local privilege escalation due to missing home record signature verification on the authentication path (bsc#1271444). Non security issue fixed: - `systemd-resolved` fails to start due to write access to `tmpfs` denied (bsc#1237515). The following package changes have been done: - libudev1-257.13-160000.4.1 updated - libsystemd0-257.13-160000.4.1 updated - cpio-2.15-160000.3.1 updated - systemd-257.13-160000.4.1 updated - udev-257.13-160000.4.1 updated - dracut-059+suse.730.g73d3411aa-160000.1.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-afd566f18c4eb0f88eac54fec12989fa838feff103a3f4065dd1d4af4b90c19e-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:21:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:21:01 +0200 (CEST) Subject: SUSE-IU-2026:6782-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260905112101.ECE46FDCF@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6782-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.110 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.110 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1610 Released: Fri Sep 4 15:48:44 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the `bzip2recover` utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-160000.3.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-464538744baea68dd2d851111f85fd50ed1eb8b62dbfe83cab52d4d371efd614-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:27:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:27:54 +0200 (CEST) Subject: SUSE-IU-2026:6793-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260905112754.3EEAEFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6793-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.141 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.141 Severity : important Type : security References : 1237515 1254924 1259418 1259650 1261400 1268322 1271444 1273580 1274856 1274857 1274858 CVE-2026-16445 CVE-2026-16742 CVE-2026-29111 CVE-2026-40226 CVE-2026-4105 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1595 Released: Thu Sep 3 16:47:52 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: 1597 Released: Thu Sep 3 18:40:31 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: Update to version 059+suse.730.g73d3411aa. - CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` (bsc#1268322). - CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` during system boot (bsc#1273580). Changes for dracut: - Update to version 059+suse.730.g73d3411aa: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ----------------------------------------------------------------- Advisory ID: 1602 Released: Thu Sep 3 22:41:28 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1237515,1254924,1259418,1259650,1261400,1271444,CVE-2026-16742,CVE-2026-29111,CVE-2026-40226,CVE-2026-4105 This update for systemd fixes the following issue: Security issue fixed: - CVE-2026-16742: `systemd-homed`: local privilege escalation due to missing home record signature verification on the authentication path (bsc#1271444). Non security issue fixed: - `systemd-resolved` fails to start due to write access to `tmpfs` denied (bsc#1237515). The following package changes have been done: - libudev1-257.13-160000.4.1 updated - libsystemd0-257.13-160000.4.1 updated - cpio-2.15-160000.3.1 updated - systemd-257.13-160000.4.1 updated - udev-257.13-160000.4.1 updated - dracut-059+suse.730.g73d3411aa-160000.1.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-5326c78245c2601103244f0121f243b17dae6b17bf5661486c34b7b469de7b6a-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:27:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:27:58 +0200 (CEST) Subject: SUSE-IU-2026:6796-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260905112758.4895AFDCF@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6796-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.144 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.144 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1610 Released: Fri Sep 4 15:48:44 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the `bzip2recover` utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-160000.3.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-d6a20068d9e9c7017bd06f068b79a9b0b67261f2fb7707316a6c6af7bd5f62ab-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:37:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:37:42 +0200 (CEST) Subject: SUSE-CU-2026:9455-1: Recommended update of suse/ltss/sle15.6/sle15 Message-ID: <20260905113742.B9EF7FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9455-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.87 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.87 , suse/ltss/sle15.6/sle15:latest Container Release : 5.87 Severity : important Type : recommended References : 1242233 1243830 1277267 ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:38:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:38:36 +0200 (CEST) Subject: SUSE-CU-2026:9502-1: Security update of bci/dotnet-aspnet Message-ID: <20260905113836.15F92F771@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9502-1 Container Tags : bci/dotnet-aspnet:10.0 , bci/dotnet-aspnet:10.0-sles15 , bci/dotnet-aspnet:10.0.11 , bci/dotnet-aspnet:10.0.11-28.6 , bci/dotnet-aspnet:latest Container Release : 28.6 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:39:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:39:46 +0200 (CEST) Subject: SUSE-CU-2026:9503-1: Security update of bci/dotnet-aspnet Message-ID: <20260905113946.8D549F771@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9503-1 Container Tags : bci/dotnet-aspnet:8.0 , bci/dotnet-aspnet:8.0-sles15 , bci/dotnet-aspnet:8.0.30 , bci/dotnet-aspnet:8.0.30-98.6 Container Release : 98.6 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:40:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:40:57 +0200 (CEST) Subject: SUSE-CU-2026:9504-1: Security update of bci/dotnet-aspnet Message-ID: <20260905114057.77C2EF771@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9504-1 Container Tags : bci/dotnet-aspnet:9.0 , bci/dotnet-aspnet:9.0-sles15 , bci/dotnet-aspnet:9.0.19 , bci/dotnet-aspnet:9.0.19-57.6 Container Release : 57.6 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:41:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:41:57 +0200 (CEST) Subject: SUSE-CU-2026:9505-1: Security update of bci/bci-base-fips Message-ID: <20260905114157.B67ABF771@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9505-1 Container Tags : bci/bci-base-fips:15.7 , bci/bci-base-fips:15.7-22.24 , bci/bci-base-fips:latest Container Release : 22.24 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259542 1259652 1261678 1266344 1266347 1275902 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:42:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:42:17 +0200 (CEST) Subject: SUSE-CU-2026:9506-1: Security update of bci/bci-busybox Message-ID: <20260905114217.05196F771@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-busybox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9506-1 Container Tags : bci/bci-busybox:15.7 , bci/bci-busybox:15.7-25.19 , bci/bci-busybox:latest Container Release : 25.19 Severity : moderate Type : security References : 1217586 1271544 1271545 1271547 1271548 CVE-2023-42366 CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755 ----------------------------------------------------------------- The container bci/bci-busybox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3933-1 Released: Thu Sep 3 09:21:28 2026 Summary: Security update for busybox Type: security Severity: moderate References: 1217586,1271544,1271545,1271547,1271548,CVE-2023-42366,CVE-2026-38752,CVE-2026-38753,CVE-2026-38754,CVE-2026-38755 This update for busybox fixes the following issues: - CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586). - CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544). - CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545). - CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547). - CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548). The following package changes have been done: - busybox-1.37.0-150700.18.21.1 updated - busybox-xz-1.37.0-150700.12.15.1 updated - busybox-whois-1.37.0-150700.12.15.1 updated - busybox-which-1.37.0-150700.12.15.1 updated - busybox-wget-1.37.0-150700.12.15.1 updated - busybox-vlan-1.37.0-150700.12.15.1 updated - busybox-vi-1.37.0-150700.12.15.1 updated - busybox-util-linux-1.37.0-150700.12.15.1 updated - busybox-unzip-1.37.0-150700.12.15.1 updated - busybox-udhcpc-1.37.0-150700.12.15.1 updated - busybox-tunctl-1.37.0-150700.12.15.1 updated - busybox-traceroute-1.37.0-150700.12.15.1 updated - busybox-time-1.37.0-150700.12.15.1 updated - busybox-tftp-1.37.0-150700.12.15.1 updated - busybox-telnet-1.37.0-150700.12.15.1 updated - busybox-tar-1.37.0-150700.12.15.1 updated - busybox-sysvinit-tools-1.37.0-150700.12.15.1 updated - busybox-syslogd-1.37.0-150700.12.15.1 updated - busybox-sharutils-1.37.0-150700.12.15.1 updated - busybox-sha3sum-1.37.0-150700.12.15.1 updated - busybox-sh-1.37.0-150700.12.15.1 updated - busybox-sendmail-1.37.0-150700.12.15.1 updated - busybox-selinux-tools-1.37.0-150700.12.15.1 updated - busybox-sed-1.37.0-150700.12.15.1 updated - busybox-psmisc-1.37.0-150700.12.15.1 updated - busybox-procps-1.37.0-150700.12.15.1 updated - busybox-policycoreutils-1.37.0-150700.12.15.1 updated - busybox-patch-1.37.0-150700.12.15.1 updated - busybox-netcat-1.37.0-150700.12.15.1 updated - busybox-net-tools-1.37.0-150700.12.15.1 updated - busybox-ncurses-utils-1.37.0-150700.12.15.1 updated - busybox-misc-1.37.0-150700.12.15.1 updated - busybox-man-1.37.0-150700.12.15.1 updated - busybox-less-1.37.0-150700.12.15.1 updated - busybox-kbd-1.37.0-150700.12.15.1 updated - busybox-iputils-1.37.0-150700.12.15.1 updated - busybox-iproute2-1.37.0-150700.12.15.1 updated - busybox-hostname-1.37.0-150700.12.15.1 updated - busybox-hexedit-1.37.0-150700.12.15.1 updated - busybox-grep-1.37.0-150700.12.15.1 updated - busybox-gawk-1.37.0-150700.12.15.1 updated - busybox-findutils-1.37.0-150700.12.15.1 updated - busybox-ed-1.37.0-150700.12.15.1 updated - busybox-dos2unix-1.37.0-150700.12.15.1 updated - busybox-diffutils-1.37.0-150700.12.15.1 updated - busybox-cpio-1.37.0-150700.12.15.1 updated - busybox-coreutils-1.37.0-150700.12.15.1 updated - busybox-bzip2-1.37.0-150700.12.15.1 updated - busybox-bind-utils-1.37.0-150700.12.15.1 updated - busybox-bc-1.37.0-150700.12.15.1 updated - busybox-attr-1.37.0-150700.12.15.1 updated - busybox-gzip-1.37.0-150700.12.15.1 updated - busybox-adduser-1.37.0-150700.12.15.1 updated - busybox-links-1.37.0-150700.12.15.1 updated - container:bci-bci-base-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:43:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:43:03 +0200 (CEST) Subject: SUSE-CU-2026:9507-1: Security update of bci/dotnet-sdk Message-ID: <20260905114303.8834DF771@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9507-1 Container Tags : bci/dotnet-sdk:10.0 , bci/dotnet-sdk:10.0-sles15 , bci/dotnet-sdk:10.0.11 , bci/dotnet-sdk:10.0.11-28.6 , bci/dotnet-sdk:latest Container Release : 28.6 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:44:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:44:09 +0200 (CEST) Subject: SUSE-CU-2026:9508-1: Security update of bci/dotnet-sdk Message-ID: <20260905114409.787A3F771@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9508-1 Container Tags : bci/dotnet-sdk:8.0 , bci/dotnet-sdk:8.0-sles15 , bci/dotnet-sdk:8.0.30 , bci/dotnet-sdk:8.0.30-98.6 Container Release : 98.6 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:45:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:45:23 +0200 (CEST) Subject: SUSE-CU-2026:9509-1: Security update of bci/dotnet-sdk Message-ID: <20260905114523.9C7A6F771@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9509-1 Container Tags : bci/dotnet-sdk:9.0 , bci/dotnet-sdk:9.0-sles15 , bci/dotnet-sdk:9.0.19 , bci/dotnet-sdk:9.0.19-58.6 Container Release : 58.6 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:46:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:46:35 +0200 (CEST) Subject: SUSE-CU-2026:9510-1: Security update of bci/dotnet-runtime Message-ID: <20260905114635.A07B4F771@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9510-1 Container Tags : bci/dotnet-runtime:10.0 , bci/dotnet-runtime:10.0-sles15 , bci/dotnet-runtime:10.0.11 , bci/dotnet-runtime:10.0.11-28.6 , bci/dotnet-runtime:latest Container Release : 28.6 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:48:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:48:02 +0200 (CEST) Subject: SUSE-CU-2026:9511-1: Security update of bci/dotnet-runtime Message-ID: <20260905114802.0B063F771@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9511-1 Container Tags : bci/dotnet-runtime:8.0 , bci/dotnet-runtime:8.0-sles15 , bci/dotnet-runtime:8.0.30 , bci/dotnet-runtime:8.0.30-98.6 Container Release : 98.6 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sat Sep 5 11:49:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 5 Sep 2026 13:49:08 +0200 (CEST) Subject: SUSE-CU-2026:9512-1: Security update of bci/dotnet-runtime Message-ID: <20260905114908.C04EFF771@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9512-1 Container Tags : bci/dotnet-runtime:9.0 , bci/dotnet-runtime:9.0-sles15 , bci/dotnet-runtime:9.0.19 , bci/dotnet-runtime:9.0.19-57.6 Container Release : 57.6 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:24:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:24:26 +0200 (CEST) Subject: SUSE-CU-2026:9512-1: Security update of bci/dotnet-runtime Message-ID: <20260906072426.79B39FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9512-1 Container Tags : bci/dotnet-runtime:9.0 , bci/dotnet-runtime:9.0-sles15 , bci/dotnet-runtime:9.0.19 , bci/dotnet-runtime:9.0.19-57.6 Container Release : 57.6 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:24:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:24:28 +0200 (CEST) Subject: SUSE-CU-2026:9513-1: Security update of bci/golang Message-ID: <20260906072428.CA7D8FDCF@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9513-1 Container Tags : bci/golang:1.25 , bci/golang:1.25-sles15 , bci/golang:1.25.14 , bci/golang:1.25.14-3.72.1 , bci/golang:oldoldstable Container Release : 72.1 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:25:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:25:37 +0200 (CEST) Subject: SUSE-CU-2026:9514-1: Security update of bci/golang Message-ID: <20260906072537.CABC8FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9514-1 Container Tags : bci/golang:1.26 , bci/golang:1.26-sles15 , bci/golang:1.26.7 , bci/golang:1.26.7-2.73.1 , bci/golang:oldstable Container Release : 73.1 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:26:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:26:51 +0200 (CEST) Subject: SUSE-CU-2026:9515-1: Security update of bci/golang Message-ID: <20260906072651.A2070FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9515-1 Container Tags : bci/golang:1.25-openssl , bci/golang:1.25-sles15-openssl , bci/golang:1.25.14-openssl , bci/golang:1.25.14-openssl-90.5 , bci/golang:oldstable-openssl Container Release : 90.5 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - libopenssl-3-devel-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:27:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:27:56 +0200 (CEST) Subject: SUSE-CU-2026:9516-1: Security update of bci/golang Message-ID: <20260906072756.A222AFCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9516-1 Container Tags : bci/golang:1.27 , bci/golang:1.27-sles15 , bci/golang:1.27.0 , bci/golang:1.27.0-1.73.1 , bci/golang:latest , bci/golang:stable Container Release : 73.1 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:29:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:29:04 +0200 (CEST) Subject: SUSE-CU-2026:9517-1: Security update of bci/golang Message-ID: <20260906072904.06A4BFCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9517-1 Container Tags : bci/golang:1.26-openssl , bci/golang:1.26-sles15-openssl , bci/golang:1.26.7-openssl , bci/golang:1.26.7-openssl-90.5 , bci/golang:latest , bci/golang:stable-openssl Container Release : 90.5 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - libopenssl-3-devel-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:29:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:29:05 +0200 (CEST) Subject: SUSE-CU-2026:9518-1: Security update of suse/hpc/warewulf4-x86_64/sle-hpc-node Message-ID: <20260906072905.F0E58FDCF@maintenance.suse.de> SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9518-1 Container Tags : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7.20.8.150 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest Container Release : 20.8.150 Severity : critical Type : security References : 1001888 1006827 1008935 1012628 1012628 1012628 1029961 1047884 1065729 1082318 1098094 1098228 1103388 1104120 1106523 1121410 1133233 1139073 1144060 1158038 1168806 1170160 1170160 1170284 1170554 1176006 1180422 1180482 1181400 1181869 1182482 1182482 1182850 1185697 1185845 1185897 1186749 1187536 1187948 1189139 1190091 1191375 1192862 1194338 1194869 1194869 1196332 1196332 1199026 1200110 1203823 1204142 1204315 1205462 1205462 1205502 1206627 1206798 1207266 1212533 1213061 1213545 1213666 1214073 1214285 1214285 1214635 1214806 1214847 1214928 1214953 1214954 1215143 1215146 1215150 1215199 1215199 1215199 1215199 1215211 1215344 1215696 1216062 1216396 1216436 1216436 1216527 1216950 1216976 1218644 1219165 1219338 1220186 1220419 1220419 1221126 1221858 1222323 1222465 1223731 1223800 1224138 1224386 1224590 1225498 1225707 1225811 1225897 1227082 1227555 1228081 1228490 1228664 1229003 1229165 1229750 1229997 1230062 1230216 1230262 1230267 1230557 1230708 1231055 1232089 1232223 1232234 1232526 1232526 1233120 1233265 1233300 1233529 1233563 1234100 1234101 1234102 1234103 1234104 1234163 1234634 1234736 1234842 1234959 1235463 1235475 1235515 1235566 1235613 1235837 1236136 1236333 1236599 1236743 1236743 1236897 1236897 1237143 1237236 1237240 1237241 1237242 1237442 1237449 1237452 1237595 1237776 1237888 1238491 1238491 1238782 1238896 1239061 1239206 1239461 1239470 1239511 1239566 1239566 1239618 1239718 1239938 1239938 1240054 1240058 1240323 1240324 1240696 1240708 1240788 1240788 1240871 1240885 1240890 1240966 1240969 1240998 1241038 1241166 1241166 1241166 1241166 1241200 1241219 1241292 1241345 1241345 1241353 1241437 1241537 1241549 1241612 1241866 1242034 1242086 1242233 1242414 1242505 1242754 1242837 1242909 1242960 1242960 1242965 1242993 1243005 1243014 1243042 1243055 1243068 1243100 1243100 1243112 1243112 1243112 1243195 1243208 1243381 1243443 1243443 1243459 1243474 1243479 1243564 1243603 1243603 1243603 1243662 1243669 1243677 1243678 1243678 1243794 1243806 1243830 1243991 1243991 1244050 1244050 1244116 1244309 1244337 1244449 1244457 1244553 1244553 1244553 1244734 1244735 1244749 1244750 1244792 1244801 1244930 1244939 1245084 1245151 1245190 1245193 1245193 1245193 1245199 1245201 1245202 1245216 1245223 1245260 1245260 1245410 1245431 1245440 1245449 1245457 1245498 1245499 1245504 1245506 1245508 1245510 1245538 1245538 1245540 1245598 1245599 1245621 1245646 1245647 1245649 1245650 1245654 1245658 1245660 1245663 1245664 1245665 1245666 1245668 1245669 1245670 1245671 1245675 1245676 1245677 1245679 1245682 1245683 1245684 1245686 1245688 1245689 1245690 1245691 1245695 1245700 1245705 1245708 1245710 1245711 1245713 1245714 1245719 1245723 1245728 1245728 1245729 1245730 1245731 1245735 1245737 1245744 1245745 1245746 1245747 1245748 1245749 1245750 1245751 1245752 1245757 1245758 1245765 1245767 1245768 1245769 1245777 1245780 1245781 1245789 1245812 1245815 1245937 1245945 1245951 1245952 1245953 1245954 1245955 1245956 1245957 1245963 1245966 1245970 1245973 1245976 1245977 1245980 1245983 1245986 1246000 1246002 1246005 1246006 1246008 1246012 1246013 1246020 1246022 1246023 1246029 1246031 1246037 1246041 1246042 1246044 1246045 1246047 1246049 1246050 1246052 1246055 1246057 1246073 1246093 1246098 1246109 1246113 1246113 1246122 1246125 1246125 1246134 1246157 1246171 1246173 1246178 1246179 1246181 1246182 1246182 1246183 1246184 1246186 1246188 1246190 1246193 1246195 1246197 1246203 1246212 1246217 1246220 1246221 1246231 1246236 1246237 1246240 1246243 1246244 1246246 1246248 1246249 1246250 1246253 1246258 1246262 1246264 1246266 1246268 1246273 1246283 1246285 1246286 1246287 1246290 1246292 1246293 1246295 1246297 1246298 1246328 1246333 1246334 1246337 1246342 1246349 1246354 1246358 1246361 1246364 1246370 1246375 1246384 1246385 1246386 1246387 1246399 1246438 1246443 1246447 1246449 1246453 1246473 1246490 1246504 1246505 1246506 1246509 1246522 1246547 1246602 1246602 1246604 1246644 1246691 1246695 1246777 1246781 1246782 1246806 1246835 1246835 1246852 1246870 1246879 1246911 1246912 1246965 1246974 1247018 1247021 1247023 1247028 1247030 1247031 1247033 1247035 1247057 1247061 1247062 1247064 1247076 1247078 1247079 1247089 1247091 1247097 1247098 1247099 1247101 1247103 1247104 1247112 1247113 1247116 1247118 1247118 1247119 1247123 1247125 1247126 1247128 1247132 1247136 1247137 1247138 1247141 1247143 1247144 1247145 1247146 1247147 1247148 1247149 1247150 1247151 1247152 1247153 1247154 1247155 1247156 1247160 1247162 1247164 1247167 1247169 1247170 1247171 1247172 1247174 1247176 1247177 1247178 1247180 1247181 1247209 1247210 1247222 1247223 1247227 1247229 1247233 1247234 1247236 1247238 1247239 1247241 1247243 1247251 1247252 1247253 1247255 1247262 1247265 1247271 1247273 1247274 1247276 1247277 1247278 1247279 1247280 1247282 1247284 1247285 1247288 1247289 1247290 1247293 1247308 1247311 1247313 1247314 1247317 1247347 1247348 1247349 1247374 1247432 1247437 1247442 1247450 1247455 1247463 1247483 1247498 1247500 1247500 1247500 1247509 1247683 1247683 1247712 1247712 1247712 1247819 1247831 1247850 1247858 1247938 1247939 1247948 1247963 1247976 1248088 1248097 1248108 1248111 1248111 1248121 1248164 1248166 1248175 1248178 1248179 1248180 1248183 1248186 1248192 1248194 1248196 1248198 1248199 1248200 1248202 1248205 1248206 1248208 1248209 1248211 1248211 1248212 1248213 1248214 1248216 1248217 1248223 1248225 1248227 1248228 1248229 1248230 1248232 1248235 1248240 1248255 1248296 1248297 1248306 1248312 1248333 1248334 1248334 1248337 1248338 1248340 1248341 1248343 1248345 1248349 1248350 1248354 1248355 1248356 1248357 1248360 1248361 1248363 1248365 1248368 1248370 1248374 1248377 1248378 1248380 1248386 1248390 1248392 1248395 1248399 1248401 1248501 1248511 1248512 1248517 1248573 1248575 1248577 1248586 1248600 1248609 1248610 1248614 1248616 1248617 1248619 1248621 1248622 1248626 1248628 1248630 1248634 1248636 1248639 1248643 1248647 1248647 1248648 1248652 1248655 1248660 1248666 1248669 1248674 1248681 1248733 1248734 1248735 1248735 1248746 1248748 1248754 1248754 1248775 1248847 1248886 1248886 1249022 1249055 1249088 1249104 1249122 1249123 1249123 1249124 1249125 1249126 1249143 1249156 1249159 1249161 1249163 1249164 1249166 1249169 1249170 1249172 1249176 1249177 1249182 1249183 1249186 1249190 1249191 1249193 1249194 1249195 1249196 1249199 1249200 1249201 1249202 1249203 1249204 1249206 1249215 1249220 1249221 1249224 1249254 1249255 1249256 1249257 1249258 1249260 1249262 1249263 1249265 1249266 1249271 1249272 1249273 1249274 1249278 1249279 1249281 1249282 1249284 1249285 1249286 1249288 1249290 1249292 1249295 1249296 1249299 1249300 1249302 1249303 1249304 1249305 1249306 1249307 1249308 1249312 1249315 1249317 1249318 1249319 1249320 1249321 1249323 1249324 1249333 1249334 1249338 1249346 1249348 1249367 1249374 1249375 1249385 1249397 1249413 1249435 1249479 1249481 1249482 1249486 1249488 1249489 1249490 1249494 1249504 1249506 1249508 1249510 1249512 1249513 1249515 1249516 1249522 1249523 1249524 1249526 1249533 1249538 1249540 1249542 1249545 1249547 1249548 1249554 1249566 1249584 1249587 1249595 1249598 1249604 1249608 1249608 1249615 1249640 1249641 1249642 1249658 1249662 1249672 1249673 1249677 1249678 1249679 1249682 1249687 1249698 1249707 1249712 1249730 1249735 1249756 1249758 1249761 1249762 1249768 1249770 1249774 1249779 1249780 1249785 1249787 1249795 1249815 1249820 1249823 1249824 1249825 1249826 1249833 1249842 1249845 1249849 1249850 1249853 1249856 1249861 1249863 1249864 1249865 1249866 1249869 1249870 1249880 1249883 1249887 1249888 1249894 1249896 1249897 1249901 1249904 1249906 1249911 1249912 1249915 1249917 1249919 1249923 1249926 1249938 1249949 1249950 1249952 1249974 1249975 1249979 1249982 1249984 1249988 1249990 1249993 1249994 1249997 1249998 1250002 1250004 1250006 1250007 1250012 1250021 1250022 1250024 1250025 1250028 1250029 1250032 1250032 1250034 1250035 1250049 1250055 1250057 1250058 1250062 1250063 1250065 1250066 1250067 1250069 1250070 1250073 1250074 1250082 1250088 1250089 1250106 1250112 1250117 1250119 1250120 1250125 1250127 1250128 1250145 1250150 1250156 1250157 1250161 1250163 1250166 1250167 1250169 1250171 1250176 1250177 1250179 1250180 1250186 1250196 1250198 1250199 1250201 1250202 1250203 1250204 1250205 1250206 1250208 1250232 1250233 1250234 1250237 1250237 1250241 1250242 1250243 1250247 1250249 1250251 1250252 1250262 1250263 1250266 1250267 1250268 1250274 1250275 1250276 1250281 1250290 1250291 1250292 1250294 1250296 1250297 1250298 1250313 1250319 1250323 1250325 1250329 1250334 1250336 1250337 1250343 1250344 1250358 1250365 1250371 1250377 1250379 1250384 1250388 1250389 1250395 1250397 1250400 1250402 1250406 1250407 1250426 1250450 1250455 1250459 1250491 1250519 1250522 1250530 1250553 1250574 1250593 1250650 1250655 1250655 1250664 1250702 1250704 1250705 1250705 1250712 1250713 1250721 1250722 1250732 1250736 1250741 1250742 1250748 1250754 1250758 1250759 1250763 1250765 1250807 1250808 1250809 1250812 1250813 1250815 1250816 1250820 1250823 1250825 1250827 1250830 1250831 1250837 1250841 1250861 1250863 1250867 1250872 1250873 1250878 1250905 1250907 1250917 1250918 1250923 1250926 1250928 1250929 1250930 1250931 1250941 1250942 1250946 1250949 1250952 1250957 1250964 1251024 1251027 1251028 1251031 1251035 1251038 1251043 1251045 1251052 1251053 1251054 1251056 1251057 1251059 1251060 1251065 1251066 1251067 1251068 1251071 1251076 1251079 1251081 1251083 1251084 1251100 1251105 1251106 1251108 1251113 1251114 1251119 1251120 1251123 1251126 1251132 1251134 1251135 1251135 1251143 1251146 1251150 1251152 1251153 1251159 1251161 1251170 1251177 1251180 1251186 1251198 1251199 1251206 1251215 1251216 1251222 1251230 1251232 1251233 1251247 1251263 1251264 1251268 1251269 1251270 1251282 1251283 1251286 1251290 1251319 1251321 1251323 1251328 1251529 1251721 1251732 1251742 1251743 1251746 1251748 1251749 1251750 1251752 1251754 1251755 1251756 1251758 1251759 1251760 1251762 1251763 1251764 1251769 1251771 1251772 1251777 1251780 1251786 1251804 1251810 1251930 1251942 1251966 1251967 1251971 1251971 1252008 1252033 1252035 1252039 1252044 1252046 1252047 1252051 1252052 1252056 1252060 1252062 1252063 1252064 1252065 1252069 1252070 1252072 1252073 1252074 1252075 1252078 1252079 1252081 1252082 1252083 1252148 1252160 1252236 1252253 1252265 1252266 1252266 1252267 1252269 1252303 1252306 1252330 1252332 1252336 1252338 1252342 1252346 1252348 1252349 1252352 1252353 1252364 1252365 1252366 1252368 1252370 1252425 1252469 1252479 1252481 1252489 1252490 1252492 1252495 1252496 1252499 1252511 1252534 1252536 1252537 1252550 1252553 1252559 1252561 1252564 1252565 1252566 1252632 1252668 1252678 1252679 1252681 1252685 1252686 1252688 1252712 1252734 1252735 1252744 1252763 1252772 1252773 1252774 1252775 1252776 1252780 1252785 1252787 1252789 1252790 1252794 1252795 1252797 1252803 1252808 1252809 1252817 1252819 1252821 1252822 1252824 1252826 1252836 1252841 1252845 1252848 1252849 1252850 1252851 1252854 1252858 1252861 1252862 1252865 1252866 1252873 1252891 1252900 1252902 1252904 1252909 1252911 1252912 1252915 1252917 1252918 1252919 1252921 1252923 1252924 1252928 1252930 1252931 1252932 1252933 1252934 1252935 1252939 1252973 1253018 1253029 1253043 1253043 1253049 1253049 1253060 1253087 1253122 1253129 1253129 1253155 1253176 1253193 1253260 1253262 1253262 1253275 1253318 1253324 1253330 1253340 1253342 1253348 1253349 1253352 1253355 1253360 1253362 1253363 1253365 1253367 1253369 1253386 1253393 1253394 1253395 1253400 1253402 1253403 1253407 1253408 1253409 1253412 1253413 1253416 1253421 1253423 1253424 1253425 1253427 1253428 1253431 1253433 1253436 1253438 1253440 1253441 1253442 1253443 1253445 1253448 1253449 1253451 1253453 1253455 1253456 1253458 1253463 1253471 1253472 1253623 1253644 1253647 1253648 1253674 1253674 1253679 1253691 1253739 1253739 1253740 1253741 1253754 1253757 1253779 1254087 1254094 1254094 1254119 1254126 1254157 1254158 1254159 1254160 1254181 1254202 1254214 1254221 1254235 1254235 1254244 1254244 1254264 1254293 1254297 1254299 1254306 1254324 1254363 1254373 1254378 1254415 1254441 1254441 1254447 1254465 1254477 1254480 1254510 1254518 1254518 1254520 1254541 1254563 1254599 1254606 1254611 1254613 1254615 1254616 1254621 1254623 1254624 1254626 1254648 1254649 1254653 1254655 1254657 1254660 1254661 1254662 1254663 1254666 1254669 1254670 1254670 1254677 1254678 1254688 1254690 1254691 1254693 1254695 1254698 1254701 1254704 1254705 1254707 1254712 1254715 1254717 1254723 1254724 1254732 1254733 1254737 1254739 1254742 1254743 1254749 1254750 1254753 1254754 1254758 1254761 1254762 1254765 1254767 1254782 1254791 1254793 1254794 1254795 1254796 1254797 1254798 1254813 1254815 1254824 1254825 1254827 1254828 1254829 1254830 1254832 1254835 1254839 1254840 1254842 1254843 1254845 1254846 1254847 1254849 1254850 1254851 1254852 1254854 1254856 1254858 1254860 1254864 1254869 1254871 1254878 1254894 1254918 1254928 1254957 1254959 1254983 1254992 1254996 1255005 1255009 1255025 1255026 1255029 1255030 1255033 1255034 1255035 1255039 1255041 1255042 1255046 1255057 1255062 1255064 1255065 1255068 1255071 1255072 1255075 1255077 1255081 1255082 1255083 1255084 1255085 1255087 1255092 1255094 1255095 1255097 1255100 1255101 1255102 1255116 1255120 1255121 1255122 1255124 1255128 1255129 1255131 1255134 1255135 1255136 1255138 1255140 1255142 1255145 1255146 1255149 1255152 1255154 1255155 1255157 1255160 1255163 1255164 1255167 1255169 1255171 1255172 1255175 1255179 1255181 1255182 1255187 1255190 1255193 1255196 1255197 1255199 1255202 1255203 1255206 1255209 1255216 1255218 1255220 1255221 1255224 1255226 1255227 1255230 1255233 1255234 1255241 1255242 1255245 1255246 1255247 1255251 1255252 1255253 1255255 1255256 1255259 1255260 1255261 1255262 1255265 1255266 1255268 1255269 1255272 1255273 1255274 1255276 1255279 1255280 1255281 1255285 1255297 1255316 1255318 1255325 1255327 1255329 1255346 1255346 1255349 1255351 1255357 1255357 1255377 1255379 1255380 1255395 1255401 1255403 1255415 1255416 1255417 1255428 1255433 1255434 1255463 1255480 1255482 1255483 1255488 1255489 1255493 1255495 1255505 1255507 1255530 1255537 1255538 1255539 1255540 1255544 1255545 1255547 1255548 1255549 1255550 1255552 1255553 1255557 1255558 1255563 1255564 1255567 1255568 1255569 1255570 1255578 1255579 1255580 1255583 1255591 1255601 1255603 1255605 1255611 1255614 1255615 1255616 1255617 1255618 1255621 1255622 1255628 1255629 1255630 1255632 1255636 1255687 1255688 1255691 1255695 1255698 1255702 1255703 1255704 1255706 1255707 1255709 1255715 1255722 1255723 1255724 1255731 1255732 1255733 1255734 1255752 1255752 1255758 1255759 1255760 1255763 1255769 1255770 1255772 1255774 1255775 1255776 1255780 1255785 1255786 1255789 1255790 1255792 1255793 1255795 1255798 1255800 1255801 1255806 1255807 1255809 1255810 1255811 1255812 1255814 1255820 1255838 1255842 1255843 1255872 1255875 1255879 1255883 1255884 1255886 1255888 1255890 1255891 1255892 1255899 1255902 1255907 1255911 1255915 1255918 1255921 1255924 1255925 1255930 1255931 1255932 1255934 1255943 1255944 1255949 1255951 1255952 1255955 1255957 1255961 1255963 1255964 1255967 1255974 1255978 1255984 1255988 1255990 1255992 1255993 1255994 1255996 1256033 1256034 1256045 1256050 1256058 1256071 1256074 1256081 1256082 1256083 1256084 1256085 1256090 1256093 1256094 1256095 1256096 1256099 1256100 1256104 1256105 1256106 1256107 1256117 1256119 1256121 1256145 1256153 1256178 1256197 1256231 1256233 1256234 1256238 1256243 1256244 1256246 1256263 1256267 1256268 1256271 1256273 1256274 1256279 1256280 1256285 1256291 1256292 1256300 1256301 1256302 1256335 1256341 1256348 1256351 1256354 1256358 1256361 1256364 1256366 1256367 1256368 1256369 1256370 1256371 1256373 1256375 1256379 1256387 1256389 1256390 1256394 1256395 1256396 1256427 1256437 1256504 1256525 1256526 1256528 1256528 1256564 1256564 1256568 1256579 1256582 1256584 1256586 1256591 1256592 1256593 1256594 1256597 1256605 1256606 1256607 1256608 1256609 1256610 1256611 1256612 1256613 1256616 1256617 1256619 1256622 1256623 1256625 1256627 1256628 1256630 1256638 1256640 1256641 1256645 1256645 1256646 1256647 1256650 1256651 1256653 1256654 1256655 1256659 1256660 1256661 1256664 1256665 1256668 1256674 1256675 1256679 1256680 1256682 1256683 1256688 1256689 1256690 1256690 1256708 1256716 1256726 1256728 1256730 1256733 1256737 1256741 1256742 1256744 1256748 1256749 1256752 1256754 1256755 1256756 1256757 1256759 1256760 1256761 1256763 1256766 1256770 1256773 1256774 1256777 1256779 1256781 1256784 1256785 1256792 1256794 1256802 1256804 1256805 1256807 1256808 1256809 1256810 1256811 1256812 1256822 1256829 1256830 1256831 1256832 1256833 1256834 1256835 1256836 1256837 1256838 1256839 1256840 1256861 1256863 1256863 1256863 1257005 1257007 1257009 1257035 1257049 1257053 1257068 1257144 1257153 1257154 1257155 1257158 1257159 1257163 1257164 1257167 1257168 1257179 1257180 1257183 1257202 1257204 1257207 1257208 1257209 1257215 1257217 1257218 1257220 1257221 1257227 1257228 1257231 1257232 1257234 1257236 1257244 1257245 1257246 1257274 1257277 1257279 1257282 1257296 1257332 1257353 1257354 1257355 1257359 1257364 1257365 1257396 1257463 1257463 1257466 1257466 1257472 1257472 1257473 1257473 1257476 1257496 1257506 1257552 1257553 1257554 1257556 1257557 1257559 1257560 1257561 1257562 1257570 1257573 1257576 1257579 1257580 1257586 1257593 1257594 1257595 1257603 1257605 1257631 1257635 1257661 1257679 1257682 1257687 1257704 1257706 1257707 1257709 1257714 1257715 1257716 1257718 1257722 1257723 1257729 1257732 1257734 1257735 1257739 1257740 1257741 1257742 1257743 1257745 1257749 1257750 1257755 1257757 1257758 1257759 1257761 1257762 1257763 1257765 1257768 1257770 1257772 1257773 1257775 1257776 1257777 1257777 1257788 1257789 1257790 1257805 1257808 1257809 1257811 1257813 1257814 1257815 1257816 1257830 1257882 1257891 1257942 1257952 1258002 1258020 1258022 1258037 1258045 1258049 1258054 1258080 1258081 1258153 1258176 1258181 1258184 1258193 1258222 1258226 1258229 1258234 1258237 1258245 1258249 1258252 1258256 1258259 1258265 1258272 1258273 1258277 1258278 1258279 1258280 1258286 1258293 1258297 1258298 1258299 1258303 1258304 1258305 1258309 1258311 1258313 1258317 1258319 1258321 1258326 1258330 1258337 1258338 1258340 1258349 1258354 1258358 1258374 1258376 1258377 1258379 1258389 1258392 1258394 1258395 1258397 1258411 1258414 1258415 1258419 1258422 1258424 1258429 1258442 1258447 1258464 1258465 1258468 1258469 1258476 1258484 1258517 1258518 1258518 1258519 1258520 1258524 1258538 1258544 1258568 1258660 1258718 1258718 1258824 1258826 1258832 1258849 1258849 1258850 1258850 1258854 1258855 1258856 1258857 1258859 1258860 1258928 1258961 1259051 1259070 1259090 1259130 1259132 1259186 1259188 1259199 1259204 1259222 1259311 1259314 1259327 1259362 1259363 1259364 1259365 1259377 1259418 1259441 1259461 1259484 1259485 1259535 1259542 1259543 1259558 1259580 1259580 1259619 1259642 1259650 1259652 1259672 1259697 1259706 1259707 1259711 1259726 1259729 1259764 1259795 1259797 1259799 1259802 1259806 1259825 1259842 1259845 1259857 1259857 1259865 1259866 1259868 1259869 1259870 1259871 1259873 1259878 1259886 1259889 1259891 1259924 1259985 1259995 1259997 1259998 1260005 1260009 1260010 1260012 1260012 1260018 1260078 1260082 1260347 1260347 1260428 1260441 1260442 1260443 1260444 1260445 1260464 1260468 1260471 1260481 1260483 1260484 1260485 1260486 1260489 1260497 1260500 1260501 1260502 1260504 1260505 1260507 1260522 1260523 1260526 1260527 1260528 1260529 1260530 1260531 1260531 1260532 1260533 1260536 1260537 1260538 1260541 1260544 1260546 1260548 1260549 1260550 1260551 1260552 1260553 1260555 1260561 1260562 1260566 1260572 1260580 1260581 1260584 1260593 1260728 1260729 1260730 1260731 1260732 1260735 1260754 1260755 1260799 1260800 1260801 1260811 1260989 1261020 1261191 1261206 1261250 1261256 1261256 1261271 1261280 1261287 1261295 1261348 1261400 1261412 1261427 1261427 1261430 1261430 1261441 1261496 1261498 1261503 1261504 1261505 1261507 1261555 1261562 1261562 1261581 1261582 1261584 1261585 1261591 1261601 1261602 1261604 1261606 1261606 1261618 1261619 1261628 1261632 1261636 1261637 1261638 1261641 1261644 1261645 1261648 1261669 1261678 1261678 1261679 1261685 1261686 1261687 1261692 1261694 1261700 1261702 1261703 1261707 1261710 1261713 1261714 1261719 1261738 1261750 1261751 1261752 1261768 1261778 1261779 1261780 1261781 1261786 1261788 1261789 1261791 1261796 1261797 1261809 1261813 1261833 1261896 1261900 1261957 1261982 1261983 1262019 1262020 1262043 1262044 1262053 1262054 1262055 1262061 1262063 1262069 1262070 1262071 1262072 1262074 1262078 1262085 1262086 1262087 1262099 1262100 1262101 1262144 1262179 1262181 1262223 1262250 1262305 1262391 1262392 1262395 1262464 1262465 1262480 1262526 1262573 1262573 1262599 1262602 1262603 1262605 1262606 1262614 1262615 1262616 1262617 1262618 1262619 1262620 1262622 1262624 1262631 1262632 1262633 1262634 1262635 1262636 1262637 1262638 1262639 1262649 1262649 1262653 1262655 1262656 1262658 1262659 1262663 1262665 1262668 1262671 1262673 1262674 1262678 1262684 1262709 1262723 1262725 1262731 1262734 1262745 1262746 1262748 1262751 1262752 1262755 1262757 1262758 1262765 1262768 1262771 1262798 1262992 1262993 1263001 1263006 1263008 1263010 1263011 1263012 1263013 1263014 1263016 1263017 1263018 1263020 1263025 1263030 1263031 1263045 1263055 1263057 1263059 1263064 1263065 1263068 1263068 1263068 1263072 1263073 1263075 1263077 1263085 1263093 1263095 1263097 1263104 1263111 1263115 1263122 1263123 1263124 1263128 1263131 1263134 1263137 1263139 1263140 1263141 1263142 1263143 1263145 1263149 1263152 1263165 1263167 1263169 1263170 1263173 1263175 1263176 1263178 1263255 1263319 1263366 1263367 1263440 1263491 1263493 1263495 1263539 1263556 1263560 1263562 1263562 1263563 1263568 1263573 1263578 1263581 1263582 1263592 1263593 1263595 1263596 1263598 1263600 1263656 1263657 1263658 1263668 1263718 1263723 1263724 1263769 1263774 1263776 1263777 1263778 1263780 1263782 1263785 1263786 1263788 1263790 1263797 1263806 1263815 1263876 1263877 1263879 1263880 1263882 1263883 1263889 1263901 1263904 1263905 1263911 1263923 1263930 1263931 1263932 1263933 1263934 1263940 1263945 1263975 1263993 1263995 1263996 1263998 1263999 1264000 1264001 1264003 1264006 1264007 1264008 1264009 1264011 1264013 1264013 1264013 1264014 1264014 1264015 1264019 1264030 1264032 1264033 1264035 1264039 1264040 1264041 1264044 1264045 1264048 1264053 1264056 1264059 1264063 1264065 1264070 1264071 1264073 1264074 1264075 1264076 1264076 1264079 1264080 1264082 1264084 1264087 1264088 1264089 1264090 1264091 1264093 1264097 1264100 1264101 1264110 1264116 1264121 1264122 1264124 1264125 1264129 1264137 1264142 1264145 1264180 1264183 1264184 1264184 1264188 1264189 1264190 1264197 1264228 1264230 1264231 1264236 1264237 1264239 1264241 1264243 1264245 1264247 1264254 1264255 1264257 1264258 1264261 1264263 1264266 1264270 1264286 1264294 1264296 1264300 1264302 1264304 1264308 1264313 1264315 1264317 1264319 1264320 1264321 1264322 1264328 1264331 1264333 1264336 1264337 1264338 1264339 1264340 1264365 1264377 1264379 1264386 1264387 1264388 1264409 1264414 1264415 1264416 1264417 1264418 1264419 1264422 1264423 1264424 1264425 1264427 1264429 1264430 1264431 1264436 1264437 1264442 1264444 1264449 1264449 1264449 1264449 1264451 1264452 1264469 1264470 1264473 1264476 1264477 1264479 1264480 1264482 1264484 1264484 1264511 1264512 1264513 1264514 1264515 1264520 1264526 1264531 1264532 1264534 1264537 1264538 1264539 1264540 1264543 1264544 1264545 1264548 1264549 1264551 1264553 1264556 1264558 1264560 1264561 1264562 1264564 1264568 1264580 1264584 1264590 1264592 1264594 1264595 1264598 1264600 1264601 1264603 1264610 1264612 1264613 1264615 1264616 1264618 1264620 1264624 1264626 1264630 1264633 1264634 1264637 1264640 1264642 1264644 1264645 1264651 1264661 1264668 1264669 1264671 1264672 1264674 1264677 1264706 1264707 1264708 1264712 1264716 1264719 1264720 1264722 1264726 1264731 1264734 1264739 1264741 1264744 1264746 1264748 1264758 1264763 1264765 1264768 1264779 1264780 1264781 1264782 1264783 1264785 1264788 1264790 1264791 1264793 1264794 1264795 1264801 1264803 1264805 1264809 1264814 1264815 1264816 1264819 1264821 1264822 1264826 1264827 1264830 1264832 1264835 1264835 1264837 1264844 1264846 1264848 1264853 1264965 1264971 1264974 1264978 1264987 1264988 1264989 1264991 1264993 1264997 1265009 1265019 1265020 1265023 1265032 1265037 1265041 1265044 1265047 1265054 1265073 1265074 1265078 1265079 1265080 1265085 1265089 1265090 1265092 1265093 1265096 1265100 1265101 1265102 1265103 1265105 1265110 1265112 1265113 1265116 1265119 1265126 1265128 1265133 1265138 1265141 1265142 1265143 1265144 1265170 1265209 1265209 1265221 1265223 1265240 1265249 1265257 1265264 1265296 1265308 1265308 1265349 1265360 1265421 1265421 1265449 1265450 1265456 1265579 1265620 1265626 1265627 1265628 1265629 1265846 1265925 1265928 1265935 1265938 1265960 1266000 1266001 1266003 1266008 1266009 1266036 1266039 1266214 1266238 1266238 1266290 1266304 1266307 1266340 1266341 1266342 1266343 1266344 1266345 1266347 1266349 1266350 1266351 1266352 1266353 1266355 1266356 1266357 1266390 1266394 1266395 1266396 1266397 1266399 1266400 1266402 1266411 1266412 1266414 1266452 1266458 1266467 1266468 1266677 1266679 1266684 1266685 1266686 1266688 1266692 1266695 1266696 1266697 1266698 1266700 1266703 1266704 1266705 1266707 1266710 1266711 1266715 1266717 1266720 1266721 1266722 1266726 1266729 1266732 1266734 1266739 1266740 1266741 1266743 1266744 1266751 1266755 1266758 1266759 1266762 1266765 1266767 1266773 1266774 1266775 1266777 1266780 1266805 1266806 1266810 1266813 1266816 1266826 1266827 1266830 1266831 1266832 1266834 1266836 1266838 1266839 1266840 1266841 1266842 1266846 1266847 1266850 1266854 1266855 1266863 1266864 1266869 1266870 1266872 1266876 1266878 1266879 1266880 1266883 1266884 1266886 1266888 1266889 1266890 1266891 1266893 1266894 1266895 1266896 1266898 1266899 1266900 1266901 1266903 1266904 1266908 1266910 1266913 1266916 1266917 1266918 1266920 1266922 1266925 1266927 1266928 1266929 1266933 1266934 1266935 1266939 1266947 1266969 1266972 1267021 1267025 1267027 1267189 1267198 1267203 1267204 1267205 1267208 1267210 1267212 1267213 1267214 1267218 1267220 1267222 1267226 1267228 1267234 1267251 1267251 1267360 1267361 1267365 1267367 1267369 1267375 1267380 1267381 1267384 1267387 1267426 1267427 1267430 1267431 1267432 1267435 1267436 1267437 1267439 1267445 1267448 1267449 1267458 1267466 1267472 1267473 1267479 1267491 1267493 1267494 1267495 1267496 1267497 1267502 1267524 1267531 1267555 1267565 1267567 1267570 1267571 1267582 1267583 1267584 1267591 1267592 1267595 1267596 1267611 1267615 1267616 1267618 1267621 1267623 1267624 1267626 1267627 1267628 1267630 1267632 1267635 1267636 1267637 1267638 1267640 1267643 1267644 1267646 1267647 1267649 1267651 1267652 1267654 1267656 1267658 1267661 1267662 1267663 1267666 1267667 1267669 1267676 1267677 1267678 1267680 1267682 1267682 1267683 1267684 1267685 1267689 1267690 1267691 1267693 1267697 1267701 1267702 1267704 1267712 1267714 1267715 1267717 1267719 1267722 1267725 1267726 1267728 1267732 1267744 1267823 1267825 1267874 1267918 1267922 1267932 1267937 1267939 1267943 1267948 1267953 1267966 1267968 1267986 1267987 1267990 1267991 1267992 1267993 1267994 1267995 1268012 1268013 1268022 1268024 1268029 1268037 1268049 1268049 1268051 1268131 1268144 1268145 1268159 1268162 1268220 1268221 1268223 1268237 1268290 1268307 1268307 1268322 1268322 1268335 1268349 1268352 1268353 1268402 1268407 1268409 1268412 1268413 1268415 1268416 1268417 1268420 1268422 1268427 1268428 1268648 1268659 1268660 1268661 1268886 1268966 1268967 1268981 1268983 1268986 1268989 1269001 1269002 1269003 1269008 1269022 1269024 1269025 1269027 1269030 1269031 1269033 1269036 1269039 1269040 1269041 1269042 1269043 1269044 1269045 1269046 1269047 1269048 1269049 1269050 1269051 1269052 1269053 1269054 1269055 1269056 1269057 1269058 1269060 1269081 1269090 1269094 1269095 1269098 1269100 1269103 1269104 1269106 1269111 1269112 1269115 1269116 1269117 1269118 1269119 1269124 1269125 1269129 1269131 1269132 1269133 1269134 1269135 1269136 1269137 1269138 1269141 1269151 1269153 1269154 1269159 1269164 1269172 1269174 1269177 1269178 1269181 1269184 1269185 1269186 1269187 1269188 1269190 1269193 1269195 1269199 1269229 1269230 1269233 1269236 1269239 1269240 1269245 1269254 1269255 1269257 1269258 1269262 1269270 1269272 1269273 1269279 1269281 1269283 1269289 1269290 1269304 1269307 1269310 1269314 1269318 1269362 1269364 1269376 1269378 1269383 1269385 1269386 1269389 1269392 1269397 1269398 1269403 1269404 1269410 1269414 1269418 1269493 1269493 1269505 1269506 1269512 1269513 1269519 1269527 1269532 1269537 1269556 1269574 1269577 1269583 1269584 1269587 1269617 1269622 1269623 1269633 1269637 1269643 1269644 1269645 1269646 1269651 1269652 1269654 1269658 1269659 1269660 1269661 1269663 1269669 1269670 1269672 1269674 1269675 1269677 1269678 1269680 1269681 1269682 1269684 1269688 1269689 1269690 1269691 1269694 1269697 1269700 1269709 1269710 1269711 1269714 1269719 1269724 1269726 1269733 1269734 1269768 1269770 1269772 1269773 1269786 1269790 1269795 1269796 1269797 1269798 1269799 1269808 1269809 1269810 1269811 1269814 1269817 1269819 1269821 1269826 1269877 1269884 1269886 1269889 1269892 1269898 1269899 1269904 1269964 1269976 1269981 1269984 1269986 1269988 1269989 1269990 1269991 1269992 1269993 1269994 1269996 1269997 1269998 1270000 1270008 1270009 1270010 1270016 1270018 1270021 1270022 1270042 1270058 1270059 1270059 1270102 1270112 1270113 1270132 1270185 1270226 1270230 1270241 1270244 1270248 1270249 1270257 1270260 1270263 1270268 1270302 1270393 1270396 1271040 1271044 1271046 1271048 1271049 1271050 1271052 1271053 1271054 1271055 1271193 1271194 1271195 1271248 1271249 1271250 1271283 1271285 1271287 1271291 1271349 1271351 1271352 1271354 1271366 1271368 1271372 1271402 1271402 1271526 1271602 1271684 1271712 1271717 1271731 1271813 1271818 1271825 1271826 1271827 1271831 1271832 1271833 1271834 1271858 1271866 1271869 1271870 1271899 1271904 1271908 1271912 1271937 1271955 1271964 1271967 1271980 1272146 1272149 1272164 1272165 1272166 1272167 1272168 1272169 1272171 1272176 1272180 1272183 1272187 1272194 1272197 1272204 1272207 1272211 1272242 1272246 1272263 1272268 1272282 1272296 1272325 1272360 1272361 1272362 1272373 1272374 1272380 1272384 1272387 1272389 1272406 1272434 1272466 1272467 1272468 1272470 1272472 1272474 1272478 1272480 1272482 1272483 1272489 1272492 1272494 1272499 1272500 1272501 1272513 1272517 1272522 1272523 1272554 1272573 1272578 1272591 1272600 1272607 1272614 1272617 1272620 1272642 1272646 1272659 1272664 1272665 1272668 1272670 1272671 1272678 1272681 1272685 1272686 1272689 1272690 1272691 1272693 1272694 1272706 1272781 1272785 1272787 1272797 1272800 1272807 1272836 1272843 1272850 1272853 1272855 1272863 1272865 1272871 1272891 1272892 1272897 1272903 1272904 1272907 1272918 1272920 1272973 1273004 1273023 1273035 1273044 1273117 1273231 1273429 1273430 1273431 1273432 1273433 1273434 1273435 1273436 1273437 1273438 1273439 1273440 1273441 1273550 1273580 1274072 1274432 1274627 1275011 1275012 1275013 1275014 1275015 1275016 1275017 1275018 1275902 1277267 510058 529469 837347 916845 977572 CVE-2013-4235 CVE-2019-11135 CVE-2022-50253 CVE-2023-2058 CVE-2023-20585 CVE-2023-20585 CVE-2023-31248 CVE-2023-3772 CVE-2023-3867 CVE-2023-39197 CVE-2023-4130 CVE-2023-42752 CVE-2023-42753 CVE-2023-4515 CVE-2023-4641 CVE-2023-53147 CVE-2023-53148 CVE-2023-53150 CVE-2023-53151 CVE-2023-53152 CVE-2023-53165 CVE-2023-53167 CVE-2023-53170 CVE-2023-53174 CVE-2023-53175 CVE-2023-53177 CVE-2023-53179 CVE-2023-53180 CVE-2023-53181 CVE-2023-53183 CVE-2023-53184 CVE-2023-53185 CVE-2023-53187 CVE-2023-53189 CVE-2023-53192 CVE-2023-53195 CVE-2023-53196 CVE-2023-53201 CVE-2023-53204 CVE-2023-53205 CVE-2023-53206 CVE-2023-53207 CVE-2023-53208 CVE-2023-53209 CVE-2023-53210 CVE-2023-53215 CVE-2023-53217 CVE-2023-53220 CVE-2023-53221 CVE-2023-53222 CVE-2023-53226 CVE-2023-53230 CVE-2023-53231 CVE-2023-53235 CVE-2023-53238 CVE-2023-53243 CVE-2023-53245 CVE-2023-53247 CVE-2023-53248 CVE-2023-53249 CVE-2023-53251 CVE-2023-53252 CVE-2023-53255 CVE-2023-53257 CVE-2023-53258 CVE-2023-53260 CVE-2023-53261 CVE-2023-53263 CVE-2023-53264 CVE-2023-53272 CVE-2023-53274 CVE-2023-53275 CVE-2023-53280 CVE-2023-53286 CVE-2023-53287 CVE-2023-53288 CVE-2023-53291 CVE-2023-53292 CVE-2023-53303 CVE-2023-53304 CVE-2023-53305 CVE-2023-53309 CVE-2023-53311 CVE-2023-53312 CVE-2023-53313 CVE-2023-53314 CVE-2023-53316 CVE-2023-53319 CVE-2023-53321 CVE-2023-53322 CVE-2023-53323 CVE-2023-53324 CVE-2023-53325 CVE-2023-53328 CVE-2023-53331 CVE-2023-53333 CVE-2023-53336 CVE-2023-53338 CVE-2023-53339 CVE-2023-53342 CVE-2023-53343 CVE-2023-53350 CVE-2023-53352 CVE-2023-53354 CVE-2023-53356 CVE-2023-53357 CVE-2023-53360 CVE-2023-53362 CVE-2023-53364 CVE-2023-53365 CVE-2023-53367 CVE-2023-53368 CVE-2023-53369 CVE-2023-53370 CVE-2023-53371 CVE-2023-53374 CVE-2023-53377 CVE-2023-53379 CVE-2023-53380 CVE-2023-53384 CVE-2023-53385 CVE-2023-53386 CVE-2023-53391 CVE-2023-53394 CVE-2023-53395 CVE-2023-53397 CVE-2023-53401 CVE-2023-53420 CVE-2023-53421 CVE-2023-53424 CVE-2023-53425 CVE-2023-53426 CVE-2023-53428 CVE-2023-53429 CVE-2023-53432 CVE-2023-53436 CVE-2023-53438 CVE-2023-53441 CVE-2023-53442 CVE-2023-53444 CVE-2023-53446 CVE-2023-53447 CVE-2023-53448 CVE-2023-53451 CVE-2023-53454 CVE-2023-53456 CVE-2023-53457 CVE-2023-53461 CVE-2023-53462 CVE-2023-53463 CVE-2023-53465 CVE-2023-53472 CVE-2023-53479 CVE-2023-53480 CVE-2023-53485 CVE-2023-53487 CVE-2023-53488 CVE-2023-53490 CVE-2023-53491 CVE-2023-53492 CVE-2023-53493 CVE-2023-53495 CVE-2023-53496 CVE-2023-53500 CVE-2023-53501 CVE-2023-53504 CVE-2023-53505 CVE-2023-53507 CVE-2023-53508 CVE-2023-53510 CVE-2023-53515 CVE-2023-53516 CVE-2023-53518 CVE-2023-53519 CVE-2023-53520 CVE-2023-53523 CVE-2023-53526 CVE-2023-53527 CVE-2023-53528 CVE-2023-53530 CVE-2023-53531 CVE-2023-53538 CVE-2023-53539 CVE-2023-53540 CVE-2023-53541 CVE-2023-53543 CVE-2023-53545 CVE-2023-53546 CVE-2023-53548 CVE-2023-53550 CVE-2023-53552 CVE-2023-53553 CVE-2023-53554 CVE-2023-53555 CVE-2023-53556 CVE-2023-53557 CVE-2023-53558 CVE-2023-53559 CVE-2023-53560 CVE-2023-53563 CVE-2023-53568 CVE-2023-53570 CVE-2023-53572 CVE-2023-53574 CVE-2023-53575 CVE-2023-53577 CVE-2023-53579 CVE-2023-53580 CVE-2023-53581 CVE-2023-53583 CVE-2023-53585 CVE-2023-53588 CVE-2023-53593 CVE-2023-53596 CVE-2023-53597 CVE-2023-53599 CVE-2023-53600 CVE-2023-53601 CVE-2023-53602 CVE-2023-53603 CVE-2023-53611 CVE-2023-53613 CVE-2023-53615 CVE-2023-53616 CVE-2023-53617 CVE-2023-53618 CVE-2023-53619 CVE-2023-53621 CVE-2023-53622 CVE-2023-53631 CVE-2023-53632 CVE-2023-53633 CVE-2023-53638 CVE-2023-53645 CVE-2023-53646 CVE-2023-53647 CVE-2023-53648 CVE-2023-53649 CVE-2023-53650 CVE-2023-53652 CVE-2023-53653 CVE-2023-53654 CVE-2023-53656 CVE-2023-53657 CVE-2023-53658 CVE-2023-53659 CVE-2023-53660 CVE-2023-53662 CVE-2023-53663 CVE-2023-53665 CVE-2023-53666 CVE-2023-53668 CVE-2023-53670 CVE-2023-53672 CVE-2023-53673 CVE-2023-53674 CVE-2023-53676 CVE-2023-53681 CVE-2023-53686 CVE-2023-53687 CVE-2023-53693 CVE-2023-53697 CVE-2023-53698 CVE-2023-53699 CVE-2023-53703 CVE-2023-53704 CVE-2023-53707 CVE-2023-53708 CVE-2023-53711 CVE-2023-53713 CVE-2023-53714 CVE-2023-53718 CVE-2023-53721 CVE-2023-53722 CVE-2023-53725 CVE-2023-53726 CVE-2023-53727 CVE-2023-53728 CVE-2023-53729 CVE-2023-53730 CVE-2023-53731 CVE-2023-53733 CVE-2023-53743 CVE-2023-53750 CVE-2023-53752 CVE-2023-53759 CVE-2023-53762 CVE-2023-53766 CVE-2023-53768 CVE-2023-53777 CVE-2023-53778 CVE-2023-53782 CVE-2023-53784 CVE-2023-53785 CVE-2023-53787 CVE-2023-53791 CVE-2023-53792 CVE-2023-53793 CVE-2023-53794 CVE-2023-53795 CVE-2023-53797 CVE-2023-53799 CVE-2023-53807 CVE-2023-53808 CVE-2023-53813 CVE-2023-53815 CVE-2023-53817 CVE-2023-53819 CVE-2023-53821 CVE-2023-53823 CVE-2023-53825 CVE-2023-53828 CVE-2023-53831 CVE-2023-53834 CVE-2023-53836 CVE-2023-53839 CVE-2023-53841 CVE-2023-53842 CVE-2023-53843 CVE-2023-53844 CVE-2023-53846 CVE-2023-53847 CVE-2023-53848 CVE-2023-53850 CVE-2023-53851 CVE-2023-53852 CVE-2023-53855 CVE-2023-53856 CVE-2023-53857 CVE-2023-53858 CVE-2023-53860 CVE-2023-53861 CVE-2023-53863 CVE-2023-53864 CVE-2023-53865 CVE-2023-53989 CVE-2023-53992 CVE-2023-53994 CVE-2023-53995 CVE-2023-53996 CVE-2023-53997 CVE-2023-53998 CVE-2023-53999 CVE-2023-54000 CVE-2023-54001 CVE-2023-54005 CVE-2023-54006 CVE-2023-54008 CVE-2023-54013 CVE-2023-54014 CVE-2023-54016 CVE-2023-54017 CVE-2023-54019 CVE-2023-54022 CVE-2023-54023 CVE-2023-54025 CVE-2023-54026 CVE-2023-54027 CVE-2023-54030 CVE-2023-54031 CVE-2023-54032 CVE-2023-54035 CVE-2023-54037 CVE-2023-54038 CVE-2023-54042 CVE-2023-54045 CVE-2023-54048 CVE-2023-54049 CVE-2023-54051 CVE-2023-54052 CVE-2023-54060 CVE-2023-54064 CVE-2023-54066 CVE-2023-54067 CVE-2023-54069 CVE-2023-54070 CVE-2023-54072 CVE-2023-54076 CVE-2023-54080 CVE-2023-54081 CVE-2023-54083 CVE-2023-54088 CVE-2023-54089 CVE-2023-54091 CVE-2023-54092 CVE-2023-54093 CVE-2023-54094 CVE-2023-54095 CVE-2023-54096 CVE-2023-54099 CVE-2023-54101 CVE-2023-54104 CVE-2023-54106 CVE-2023-54112 CVE-2023-54113 CVE-2023-54115 CVE-2023-54117 CVE-2023-54121 CVE-2023-54125 CVE-2023-54127 CVE-2023-54133 CVE-2023-54134 CVE-2023-54135 CVE-2023-54136 CVE-2023-54137 CVE-2023-54140 CVE-2023-54141 CVE-2023-54142 CVE-2023-54143 CVE-2023-54145 CVE-2023-54148 CVE-2023-54149 CVE-2023-54153 CVE-2023-54154 CVE-2023-54155 CVE-2023-54156 CVE-2023-54164 CVE-2023-54166 CVE-2023-54169 CVE-2023-54170 CVE-2023-54171 CVE-2023-54172 CVE-2023-54173 CVE-2023-54177 CVE-2023-54178 CVE-2023-54179 CVE-2023-54181 CVE-2023-54183 CVE-2023-54185 CVE-2023-54189 CVE-2023-54194 CVE-2023-54201 CVE-2023-54204 CVE-2023-54207 CVE-2023-54209 CVE-2023-54210 CVE-2023-54211 CVE-2023-54215 CVE-2023-54219 CVE-2023-54220 CVE-2023-54221 CVE-2023-54223 CVE-2023-54224 CVE-2023-54225 CVE-2023-54227 CVE-2023-54229 CVE-2023-54230 CVE-2023-54235 CVE-2023-54240 CVE-2023-54241 CVE-2023-54246 CVE-2023-54247 CVE-2023-54251 CVE-2023-54253 CVE-2023-54254 CVE-2023-54255 CVE-2023-54258 CVE-2023-54261 CVE-2023-54263 CVE-2023-54264 CVE-2023-54266 CVE-2023-54267 CVE-2023-54271 CVE-2023-54276 CVE-2023-54278 CVE-2023-54281 CVE-2023-54282 CVE-2023-54283 CVE-2023-54285 CVE-2023-54289 CVE-2023-54291 CVE-2023-54292 CVE-2023-54293 CVE-2023-54296 CVE-2023-54297 CVE-2023-54299 CVE-2023-54300 CVE-2023-54302 CVE-2023-54303 CVE-2023-54304 CVE-2023-54309 CVE-2023-54312 CVE-2023-54313 CVE-2023-54314 CVE-2023-54315 CVE-2023-54316 CVE-2023-54318 CVE-2023-54319 CVE-2023-54322 CVE-2023-54324 CVE-2023-54326 CVE-2023-5633 CVE-2024-10041 CVE-2024-12084 CVE-2024-12085 CVE-2024-12086 CVE-2024-12087 CVE-2024-12088 CVE-2024-12747 CVE-2024-12797 CVE-2024-13176 CVE-2024-2312 CVE-2024-26584 CVE-2024-26661 CVE-2024-26944 CVE-2024-27005 CVE-2024-36028 CVE-2024-36348 CVE-2024-36349 CVE-2024-36350 CVE-2024-36357 CVE-2024-39298 CVE-2024-42103 CVE-2024-42134 CVE-2024-44963 CVE-2024-46733 CVE-2024-49861 CVE-2024-49996 CVE-2024-53070 CVE-2024-53149 CVE-2024-56721 CVE-2024-56738 CVE-2024-56742 CVE-2024-57947 CVE-2024-58090 CVE-2024-58238 CVE-2024-58239 CVE-2024-58240 CVE-2024-58251 CVE-2024-8176 CVE-2024-9143 CVE-2025-10148 CVE-2025-10158 CVE-2025-10158 CVE-2025-10263 CVE-2025-10911 CVE-2025-11187 CVE-2025-11563 CVE-2025-12801 CVE-2025-13151 CVE-2025-1352 CVE-2025-13601 CVE-2025-1372 CVE-2025-1376 CVE-2025-1377 CVE-2025-14017 CVE-2025-14087 CVE-2025-14104 CVE-2025-14512 CVE-2025-14524 CVE-2025-14819 CVE-2025-15079 CVE-2025-15224 CVE-2025-15281 CVE-2025-15467 CVE-2025-15468 CVE-2025-15469 CVE-2025-21710 CVE-2025-21839 CVE-2025-21845 CVE-2025-21854 CVE-2025-21872 CVE-2025-22022 CVE-2025-22047 CVE-2025-22090 CVE-2025-23163 CVE-2025-24912 CVE-2025-27587 CVE-2025-28162 CVE-2025-28164 CVE-2025-3576 CVE-2025-37744 CVE-2025-37751 CVE-2025-37798 CVE-2025-37813 CVE-2025-37856 CVE-2025-37861 CVE-2025-37864 CVE-2025-37885 CVE-2025-37885 CVE-2025-37916 CVE-2025-37920 CVE-2025-37984 CVE-2025-38006 CVE-2025-38008 CVE-2025-38034 CVE-2025-38035 CVE-2025-38047 CVE-2025-38051 CVE-2025-38052 CVE-2025-38058 CVE-2025-38061 CVE-2025-38062 CVE-2025-38063 CVE-2025-38064 CVE-2025-38074 CVE-2025-38075 CVE-2025-38084 CVE-2025-38085 CVE-2025-38087 CVE-2025-38088 CVE-2025-38089 CVE-2025-38090 CVE-2025-38091 CVE-2025-38094 CVE-2025-38095 CVE-2025-38097 CVE-2025-38098 CVE-2025-38099 CVE-2025-38100 CVE-2025-38102 CVE-2025-38103 CVE-2025-38105 CVE-2025-38106 CVE-2025-38107 CVE-2025-38108 CVE-2025-38109 CVE-2025-38110 CVE-2025-38111 CVE-2025-38112 CVE-2025-38113 CVE-2025-38114 CVE-2025-38115 CVE-2025-38117 CVE-2025-38118 CVE-2025-38119 CVE-2025-38120 CVE-2025-38122 CVE-2025-38123 CVE-2025-38124 CVE-2025-38125 CVE-2025-38126 CVE-2025-38127 CVE-2025-38129 CVE-2025-38131 CVE-2025-38132 CVE-2025-38135 CVE-2025-38136 CVE-2025-38138 CVE-2025-38142 CVE-2025-38143 CVE-2025-38145 CVE-2025-38146 CVE-2025-38147 CVE-2025-38148 CVE-2025-38149 CVE-2025-38151 CVE-2025-38153 CVE-2025-38154 CVE-2025-38155 CVE-2025-38157 CVE-2025-38158 CVE-2025-38159 CVE-2025-38160 CVE-2025-38161 CVE-2025-38162 CVE-2025-38165 CVE-2025-38166 CVE-2025-38173 CVE-2025-38174 CVE-2025-38177 CVE-2025-38180 CVE-2025-38181 CVE-2025-38182 CVE-2025-38183 CVE-2025-38184 CVE-2025-38185 CVE-2025-38186 CVE-2025-38187 CVE-2025-38188 CVE-2025-38189 CVE-2025-38190 CVE-2025-38192 CVE-2025-38193 CVE-2025-38194 CVE-2025-38197 CVE-2025-38198 CVE-2025-38200 CVE-2025-38201 CVE-2025-38202 CVE-2025-38203 CVE-2025-38204 CVE-2025-38205 CVE-2025-38206 CVE-2025-38208 CVE-2025-38209 CVE-2025-38210 CVE-2025-38211 CVE-2025-38212 CVE-2025-38213 CVE-2025-38214 CVE-2025-38215 CVE-2025-38216 CVE-2025-38217 CVE-2025-38220 CVE-2025-38222 CVE-2025-38225 CVE-2025-38226 CVE-2025-38227 CVE-2025-38229 CVE-2025-38231 CVE-2025-38234 CVE-2025-38236 CVE-2025-38238 CVE-2025-38239 CVE-2025-38243 CVE-2025-38244 CVE-2025-38245 CVE-2025-38246 CVE-2025-38248 CVE-2025-38249 CVE-2025-38250 CVE-2025-38250 CVE-2025-38251 CVE-2025-38255 CVE-2025-38256 CVE-2025-38257 CVE-2025-38259 CVE-2025-38263 CVE-2025-38264 CVE-2025-38265 CVE-2025-38268 CVE-2025-38272 CVE-2025-38273 CVE-2025-38275 CVE-2025-38277 CVE-2025-38279 CVE-2025-38283 CVE-2025-38286 CVE-2025-38287 CVE-2025-38288 CVE-2025-38289 CVE-2025-38290 CVE-2025-38291 CVE-2025-38292 CVE-2025-38293 CVE-2025-38299 CVE-2025-38300 CVE-2025-38303 CVE-2025-38304 CVE-2025-38305 CVE-2025-38307 CVE-2025-38310 CVE-2025-38312 CVE-2025-38313 CVE-2025-38315 CVE-2025-38317 CVE-2025-38319 CVE-2025-38321 CVE-2025-38322 CVE-2025-38323 CVE-2025-38326 CVE-2025-38328 CVE-2025-38332 CVE-2025-38334 CVE-2025-38335 CVE-2025-38336 CVE-2025-38337 CVE-2025-38338 CVE-2025-38342 CVE-2025-38343 CVE-2025-38344 CVE-2025-38345 CVE-2025-38348 CVE-2025-38349 CVE-2025-38350 CVE-2025-38351 CVE-2025-38352 CVE-2025-38353 CVE-2025-38354 CVE-2025-38355 CVE-2025-38356 CVE-2025-38359 CVE-2025-38360 CVE-2025-38361 CVE-2025-38362 CVE-2025-38363 CVE-2025-38364 CVE-2025-38365 CVE-2025-38369 CVE-2025-38371 CVE-2025-38373 CVE-2025-38375 CVE-2025-38376 CVE-2025-38377 CVE-2025-38379 CVE-2025-38380 CVE-2025-38382 CVE-2025-38384 CVE-2025-38385 CVE-2025-38386 CVE-2025-38387 CVE-2025-38389 CVE-2025-38391 CVE-2025-38392 CVE-2025-38393 CVE-2025-38395 CVE-2025-38396 CVE-2025-38399 CVE-2025-38400 CVE-2025-38401 CVE-2025-38402 CVE-2025-38403 CVE-2025-38404 CVE-2025-38406 CVE-2025-38408 CVE-2025-38409 CVE-2025-38410 CVE-2025-38412 CVE-2025-38414 CVE-2025-38415 CVE-2025-38416 CVE-2025-38417 CVE-2025-38418 CVE-2025-38419 CVE-2025-38420 CVE-2025-38424 CVE-2025-38425 CVE-2025-38426 CVE-2025-38427 CVE-2025-38428 CVE-2025-38429 CVE-2025-38430 CVE-2025-38436 CVE-2025-38439 CVE-2025-38440 CVE-2025-38441 CVE-2025-38443 CVE-2025-38444 CVE-2025-38445 CVE-2025-38448 CVE-2025-38449 CVE-2025-38453 CVE-2025-38455 CVE-2025-38456 CVE-2025-38457 CVE-2025-38458 CVE-2025-38459 CVE-2025-38460 CVE-2025-38461 CVE-2025-38462 CVE-2025-38463 CVE-2025-38464 CVE-2025-38465 CVE-2025-38465 CVE-2025-38466 CVE-2025-38467 CVE-2025-38468 CVE-2025-38469 CVE-2025-38470 CVE-2025-38471 CVE-2025-38472 CVE-2025-38473 CVE-2025-38474 CVE-2025-38475 CVE-2025-38476 CVE-2025-38477 CVE-2025-38478 CVE-2025-38480 CVE-2025-38481 CVE-2025-38482 CVE-2025-38483 CVE-2025-38485 CVE-2025-38487 CVE-2025-38488 CVE-2025-38489 CVE-2025-38490 CVE-2025-38491 CVE-2025-38494 CVE-2025-38495 CVE-2025-38496 CVE-2025-38497 CVE-2025-38498 CVE-2025-38499 CVE-2025-38500 CVE-2025-38503 CVE-2025-38506 CVE-2025-38510 CVE-2025-38511 CVE-2025-38512 CVE-2025-38513 CVE-2025-38514 CVE-2025-38515 CVE-2025-38516 CVE-2025-38520 CVE-2025-38521 CVE-2025-38524 CVE-2025-38526 CVE-2025-38527 CVE-2025-38528 CVE-2025-38529 CVE-2025-38530 CVE-2025-38531 CVE-2025-38533 CVE-2025-38535 CVE-2025-38537 CVE-2025-38538 CVE-2025-38539 CVE-2025-38539 CVE-2025-38540 CVE-2025-38541 CVE-2025-38543 CVE-2025-38544 CVE-2025-38546 CVE-2025-38548 CVE-2025-38549 CVE-2025-38550 CVE-2025-38552 CVE-2025-38553 CVE-2025-38555 CVE-2025-38556 CVE-2025-38560 CVE-2025-38563 CVE-2025-38565 CVE-2025-38566 CVE-2025-38568 CVE-2025-38571 CVE-2025-38572 CVE-2025-38574 CVE-2025-38576 CVE-2025-38581 CVE-2025-38582 CVE-2025-38583 CVE-2025-38584 CVE-2025-38585 CVE-2025-38587 CVE-2025-38588 CVE-2025-38590 CVE-2025-38591 CVE-2025-38593 CVE-2025-38595 CVE-2025-38597 CVE-2025-38601 CVE-2025-38602 CVE-2025-38604 CVE-2025-38605 CVE-2025-38605 CVE-2025-38608 CVE-2025-38609 CVE-2025-38610 CVE-2025-38612 CVE-2025-38614 CVE-2025-38616 CVE-2025-38617 CVE-2025-38618 CVE-2025-38621 CVE-2025-38622 CVE-2025-38623 CVE-2025-38624 CVE-2025-38628 CVE-2025-38630 CVE-2025-38632 CVE-2025-38634 CVE-2025-38635 CVE-2025-38639 CVE-2025-38640 CVE-2025-38643 CVE-2025-38644 CVE-2025-38645 CVE-2025-38646 CVE-2025-38650 CVE-2025-38653 CVE-2025-38656 CVE-2025-38659 CVE-2025-38660 CVE-2025-38663 CVE-2025-38664 CVE-2025-38665 CVE-2025-38668 CVE-2025-38668 CVE-2025-38670 CVE-2025-38671 CVE-2025-38676 CVE-2025-38678 CVE-2025-38679 CVE-2025-38680 CVE-2025-38681 CVE-2025-38683 CVE-2025-38684 CVE-2025-38685 CVE-2025-38687 CVE-2025-38691 CVE-2025-38692 CVE-2025-38693 CVE-2025-38694 CVE-2025-38695 CVE-2025-38697 CVE-2025-38698 CVE-2025-38699 CVE-2025-38700 CVE-2025-38701 CVE-2025-38702 CVE-2025-38703 CVE-2025-38705 CVE-2025-38706 CVE-2025-38709 CVE-2025-38710 CVE-2025-38712 CVE-2025-38713 CVE-2025-38714 CVE-2025-38715 CVE-2025-38718 CVE-2025-38721 CVE-2025-38722 CVE-2025-38724 CVE-2025-38725 CVE-2025-38727 CVE-2025-38728 CVE-2025-38729 CVE-2025-38730 CVE-2025-38732 CVE-2025-38734 CVE-2025-38735 CVE-2025-38736 CVE-2025-39673 CVE-2025-39675 CVE-2025-39676 CVE-2025-39677 CVE-2025-39678 CVE-2025-39679 CVE-2025-39681 CVE-2025-39682 CVE-2025-39683 CVE-2025-39684 CVE-2025-39685 CVE-2025-39686 CVE-2025-39689 CVE-2025-39691 CVE-2025-39693 CVE-2025-39694 CVE-2025-39695 CVE-2025-39697 CVE-2025-39701 CVE-2025-39702 CVE-2025-39703 CVE-2025-39705 CVE-2025-39706 CVE-2025-39707 CVE-2025-39709 CVE-2025-39710 CVE-2025-39711 CVE-2025-39713 CVE-2025-39714 CVE-2025-39718 CVE-2025-39719 CVE-2025-39721 CVE-2025-39724 CVE-2025-39726 CVE-2025-39730 CVE-2025-39732 CVE-2025-39738 CVE-2025-39739 CVE-2025-39742 CVE-2025-39743 CVE-2025-39744 CVE-2025-39746 CVE-2025-39747 CVE-2025-39748 CVE-2025-39749 CVE-2025-39750 CVE-2025-39751 CVE-2025-39754 CVE-2025-39756 CVE-2025-39757 CVE-2025-39758 CVE-2025-39759 CVE-2025-39760 CVE-2025-39761 CVE-2025-39763 CVE-2025-39764 CVE-2025-39766 CVE-2025-39770 CVE-2025-39772 CVE-2025-39773 CVE-2025-39782 CVE-2025-39783 CVE-2025-39787 CVE-2025-39788 CVE-2025-39790 CVE-2025-39794 CVE-2025-39797 CVE-2025-39797 CVE-2025-39798 CVE-2025-39800 CVE-2025-39801 CVE-2025-39805 CVE-2025-39806 CVE-2025-39807 CVE-2025-39808 CVE-2025-39810 CVE-2025-39811 CVE-2025-39812 CVE-2025-39813 CVE-2025-39813 CVE-2025-39816 CVE-2025-39817 CVE-2025-39819 CVE-2025-39822 CVE-2025-39823 CVE-2025-39824 CVE-2025-39825 CVE-2025-39826 CVE-2025-39827 CVE-2025-39828 CVE-2025-39829 CVE-2025-39830 CVE-2025-39832 CVE-2025-39833 CVE-2025-39834 CVE-2025-39835 CVE-2025-39836 CVE-2025-39838 CVE-2025-39839 CVE-2025-39841 CVE-2025-39842 CVE-2025-39844 CVE-2025-39845 CVE-2025-39846 CVE-2025-39847 CVE-2025-39848 CVE-2025-39849 CVE-2025-39850 CVE-2025-39851 CVE-2025-39853 CVE-2025-39854 CVE-2025-39857 CVE-2025-39859 CVE-2025-39860 CVE-2025-39861 CVE-2025-39863 CVE-2025-39864 CVE-2025-39865 CVE-2025-39866 CVE-2025-39869 CVE-2025-39870 CVE-2025-39871 CVE-2025-39873 CVE-2025-39876 CVE-2025-39880 CVE-2025-39881 CVE-2025-39882 CVE-2025-39885 CVE-2025-39889 CVE-2025-39890 CVE-2025-39891 CVE-2025-39895 CVE-2025-39898 CVE-2025-39900 CVE-2025-39902 CVE-2025-39907 CVE-2025-39911 CVE-2025-39913 CVE-2025-39920 CVE-2025-39922 CVE-2025-39923 CVE-2025-39925 CVE-2025-39931 CVE-2025-39934 CVE-2025-39937 CVE-2025-39938 CVE-2025-39944 CVE-2025-39945 CVE-2025-39946 CVE-2025-39947 CVE-2025-39948 CVE-2025-39949 CVE-2025-39952 CVE-2025-39955 CVE-2025-39957 CVE-2025-39964 CVE-2025-39965 CVE-2025-39967 CVE-2025-39968 CVE-2025-39969 CVE-2025-39970 CVE-2025-39971 CVE-2025-39972 CVE-2025-39973 CVE-2025-39977 CVE-2025-39978 CVE-2025-39980 CVE-2025-39981 CVE-2025-39982 CVE-2025-39984 CVE-2025-39985 CVE-2025-39986 CVE-2025-39987 CVE-2025-39988 CVE-2025-39991 CVE-2025-39993 CVE-2025-39994 CVE-2025-39995 CVE-2025-39996 CVE-2025-39997 CVE-2025-39998 CVE-2025-40000 CVE-2025-40001 CVE-2025-40005 CVE-2025-40006 CVE-2025-40010 CVE-2025-40011 CVE-2025-40012 CVE-2025-40013 CVE-2025-40016 CVE-2025-40018 CVE-2025-40019 CVE-2025-40020 CVE-2025-40021 CVE-2025-40024 CVE-2025-40027 CVE-2025-40029 CVE-2025-40030 CVE-2025-40032 CVE-2025-40033 CVE-2025-40035 CVE-2025-40036 CVE-2025-40037 CVE-2025-40038 CVE-2025-40040 CVE-2025-40042 CVE-2025-40043 CVE-2025-40044 CVE-2025-40047 CVE-2025-40048 CVE-2025-40049 CVE-2025-40051 CVE-2025-40052 CVE-2025-40053 CVE-2025-40055 CVE-2025-40056 CVE-2025-40058 CVE-2025-40059 CVE-2025-40060 CVE-2025-40061 CVE-2025-40062 CVE-2025-40064 CVE-2025-40070 CVE-2025-40071 CVE-2025-40074 CVE-2025-40075 CVE-2025-40078 CVE-2025-40080 CVE-2025-40081 CVE-2025-40082 CVE-2025-40083 CVE-2025-40085 CVE-2025-40086 CVE-2025-40087 CVE-2025-40088 CVE-2025-40091 CVE-2025-40096 CVE-2025-40097 CVE-2025-40098 CVE-2025-40099 CVE-2025-40100 CVE-2025-40102 CVE-2025-40103 CVE-2025-40104 CVE-2025-40105 CVE-2025-40106 CVE-2025-40107 CVE-2025-40109 CVE-2025-40110 CVE-2025-40111 CVE-2025-40115 CVE-2025-40116 CVE-2025-40118 CVE-2025-40120 CVE-2025-40121 CVE-2025-40123 CVE-2025-40127 CVE-2025-40129 CVE-2025-40132 CVE-2025-40134 CVE-2025-40135 CVE-2025-40136 CVE-2025-40139 CVE-2025-40140 CVE-2025-40141 CVE-2025-40142 CVE-2025-40149 CVE-2025-40153 CVE-2025-40154 CVE-2025-40156 CVE-2025-40157 CVE-2025-40158 CVE-2025-40159 CVE-2025-40160 CVE-2025-40164 CVE-2025-40166 CVE-2025-40167 CVE-2025-40168 CVE-2025-40169 CVE-2025-40170 CVE-2025-40171 CVE-2025-40172 CVE-2025-40173 CVE-2025-40176 CVE-2025-40177 CVE-2025-40178 CVE-2025-40179 CVE-2025-40180 CVE-2025-40181 CVE-2025-40183 CVE-2025-40185 CVE-2025-40186 CVE-2025-40187 CVE-2025-40188 CVE-2025-40190 CVE-2025-40194 CVE-2025-40198 CVE-2025-40200 CVE-2025-40201 CVE-2025-40202 CVE-2025-40204 CVE-2025-40205 CVE-2025-40206 CVE-2025-40207 CVE-2025-40211 CVE-2025-40213 CVE-2025-40213 CVE-2025-40215 CVE-2025-40216 CVE-2025-40219 CVE-2025-40219 CVE-2025-40220 CVE-2025-40223 CVE-2025-40225 CVE-2025-40231 CVE-2025-40233 CVE-2025-40238 CVE-2025-40240 CVE-2025-40242 CVE-2025-40244 CVE-2025-40248 CVE-2025-40250 CVE-2025-40251 CVE-2025-40252 CVE-2025-40253 CVE-2025-40254 CVE-2025-40256 CVE-2025-40257 CVE-2025-40258 CVE-2025-40259 CVE-2025-40261 CVE-2025-40262 CVE-2025-40263 CVE-2025-40264 CVE-2025-40268 CVE-2025-40269 CVE-2025-40271 CVE-2025-40272 CVE-2025-40273 CVE-2025-40274 CVE-2025-40275 CVE-2025-40276 CVE-2025-40277 CVE-2025-40278 CVE-2025-40279 CVE-2025-40280 CVE-2025-40282 CVE-2025-40283 CVE-2025-40284 CVE-2025-40287 CVE-2025-40288 CVE-2025-40289 CVE-2025-40292 CVE-2025-40293 CVE-2025-40294 CVE-2025-40297 CVE-2025-40300 CVE-2025-40301 CVE-2025-40302 CVE-2025-40304 CVE-2025-40306 CVE-2025-40307 CVE-2025-40308 CVE-2025-40309 CVE-2025-40310 CVE-2025-40311 CVE-2025-40312 CVE-2025-40314 CVE-2025-40315 CVE-2025-40316 CVE-2025-40317 CVE-2025-40318 CVE-2025-40319 CVE-2025-40320 CVE-2025-40321 CVE-2025-40322 CVE-2025-40323 CVE-2025-40324 CVE-2025-40328 CVE-2025-40329 CVE-2025-40330 CVE-2025-40331 CVE-2025-40332 CVE-2025-40337 CVE-2025-40338 CVE-2025-40339 CVE-2025-40340 CVE-2025-40341 CVE-2025-40342 CVE-2025-40343 CVE-2025-40345 CVE-2025-40346 CVE-2025-40347 CVE-2025-40349 CVE-2025-40350 CVE-2025-40351 CVE-2025-40354 CVE-2025-40355 CVE-2025-40357 CVE-2025-40359 CVE-2025-40360 CVE-2025-40363 CVE-2025-45582 CVE-2025-4575 CVE-2025-48060 CVE-2025-53905 CVE-2025-53906 CVE-2025-53906 CVE-2025-54518 CVE-2025-54518 CVE-2025-54518 CVE-2025-54770 CVE-2025-54771 CVE-2025-55157 CVE-2025-55158 CVE-2025-59375 CVE-2025-61661 CVE-2025-61662 CVE-2025-61663 CVE-2025-61664 CVE-2025-61984 CVE-2025-61985 CVE-2025-64505 CVE-2025-64506 CVE-2025-64720 CVE-2025-65018 CVE-2025-66199 CVE-2025-66293 CVE-2025-68160 CVE-2025-68168 CVE-2025-68170 CVE-2025-68171 CVE-2025-68172 CVE-2025-68174 CVE-2025-68176 CVE-2025-68178 CVE-2025-68180 CVE-2025-68181 CVE-2025-68183 CVE-2025-68184 CVE-2025-68185 CVE-2025-68188 CVE-2025-68190 CVE-2025-68192 CVE-2025-68194 CVE-2025-68195 CVE-2025-68197 CVE-2025-68200 CVE-2025-68201 CVE-2025-68204 CVE-2025-68206 CVE-2025-68207 CVE-2025-68208 CVE-2025-68209 CVE-2025-68215 CVE-2025-68217 CVE-2025-68218 CVE-2025-68222 CVE-2025-68223 CVE-2025-68223 CVE-2025-68227 CVE-2025-68230 CVE-2025-68233 CVE-2025-68235 CVE-2025-68237 CVE-2025-68238 CVE-2025-68239 CVE-2025-68241 CVE-2025-68244 CVE-2025-68245 CVE-2025-68249 CVE-2025-68252 CVE-2025-68254 CVE-2025-68255 CVE-2025-68256 CVE-2025-68257 CVE-2025-68258 CVE-2025-68259 CVE-2025-68261 CVE-2025-68264 CVE-2025-68283 CVE-2025-68284 CVE-2025-68285 CVE-2025-68286 CVE-2025-68287 CVE-2025-68289 CVE-2025-68290 CVE-2025-68295 CVE-2025-68296 CVE-2025-68297 CVE-2025-68298 CVE-2025-68301 CVE-2025-68302 CVE-2025-68303 CVE-2025-68305 CVE-2025-68306 CVE-2025-68307 CVE-2025-68308 CVE-2025-68310 CVE-2025-68312 CVE-2025-68313 CVE-2025-68320 CVE-2025-68324 CVE-2025-68325 CVE-2025-68327 CVE-2025-68328 CVE-2025-68330 CVE-2025-68331 CVE-2025-68332 CVE-2025-68335 CVE-2025-68337 CVE-2025-68339 CVE-2025-68340 CVE-2025-68345 CVE-2025-68346 CVE-2025-68347 CVE-2025-68349 CVE-2025-68351 CVE-2025-68354 CVE-2025-68362 CVE-2025-68363 CVE-2025-68365 CVE-2025-68366 CVE-2025-68367 CVE-2025-68372 CVE-2025-68374 CVE-2025-68378 CVE-2025-68379 CVE-2025-68380 CVE-2025-68724 CVE-2025-68725 CVE-2025-68727 CVE-2025-68728 CVE-2025-68732 CVE-2025-68733 CVE-2025-68734 CVE-2025-68735 CVE-2025-68736 CVE-2025-68740 CVE-2025-68741 CVE-2025-68742 CVE-2025-68744 CVE-2025-68746 CVE-2025-68747 CVE-2025-68749 CVE-2025-68750 CVE-2025-68753 CVE-2025-68757 CVE-2025-68758 CVE-2025-68759 CVE-2025-68764 CVE-2025-68765 CVE-2025-68766 CVE-2025-68768 CVE-2025-68770 CVE-2025-68771 CVE-2025-68773 CVE-2025-68775 CVE-2025-68776 CVE-2025-68777 CVE-2025-68778 CVE-2025-68783 CVE-2025-68785 CVE-2025-68788 CVE-2025-68789 CVE-2025-68794 CVE-2025-68795 CVE-2025-68797 CVE-2025-68798 CVE-2025-68800 CVE-2025-68801 CVE-2025-68802 CVE-2025-68803 CVE-2025-68804 CVE-2025-68808 CVE-2025-68810 CVE-2025-68813 CVE-2025-68814 CVE-2025-68815 CVE-2025-68816 CVE-2025-68818 CVE-2025-68819 CVE-2025-68820 CVE-2025-68822 CVE-2025-68973 CVE-2025-69418 CVE-2025-69419 CVE-2025-69420 CVE-2025-69421 CVE-2025-69720 CVE-2025-7039 CVE-2025-70873 CVE-2025-71064 CVE-2025-71066 CVE-2025-71066 CVE-2025-71071 CVE-2025-71076 CVE-2025-71077 CVE-2025-71078 CVE-2025-71079 CVE-2025-71080 CVE-2025-71081 CVE-2025-71082 CVE-2025-71083 CVE-2025-71084 CVE-2025-71085 CVE-2025-71086 CVE-2025-71087 CVE-2025-71088 CVE-2025-71089 CVE-2025-71091 CVE-2025-71093 CVE-2025-71094 CVE-2025-71095 CVE-2025-71096 CVE-2025-71097 CVE-2025-71098 CVE-2025-71099 CVE-2025-71100 CVE-2025-71101 CVE-2025-71104 CVE-2025-71108 CVE-2025-71111 CVE-2025-71112 CVE-2025-71113 CVE-2025-71114 CVE-2025-71116 CVE-2025-71118 CVE-2025-71119 CVE-2025-71120 CVE-2025-71123 CVE-2025-71125 CVE-2025-71126 CVE-2025-71130 CVE-2025-71131 CVE-2025-71132 CVE-2025-71133 CVE-2025-71135 CVE-2025-71136 CVE-2025-71137 CVE-2025-71138 CVE-2025-71141 CVE-2025-71142 CVE-2025-71143 CVE-2025-71145 CVE-2025-71147 CVE-2025-71148 CVE-2025-71149 CVE-2025-71154 CVE-2025-71156 CVE-2025-71157 CVE-2025-71162 CVE-2025-71163 CVE-2025-71182 CVE-2025-71183 CVE-2025-71184 CVE-2025-71185 CVE-2025-71188 CVE-2025-71189 CVE-2025-71190 CVE-2025-71191 CVE-2025-71192 CVE-2025-71194 CVE-2025-71195 CVE-2025-71196 CVE-2025-71197 CVE-2025-71198 CVE-2025-71199 CVE-2025-71200 CVE-2025-71222 CVE-2025-71224 CVE-2025-71225 CVE-2025-71229 CVE-2025-71231 CVE-2025-71232 CVE-2025-71234 CVE-2025-71235 CVE-2025-71236 CVE-2025-71238 CVE-2025-71268 CVE-2025-71269 CVE-2025-71274 CVE-2025-71286 CVE-2025-71291 CVE-2025-71294 CVE-2025-71297 CVE-2025-71302 CVE-2025-71305 CVE-2025-71314 CVE-2025-7709 CVE-2025-7709 CVE-2025-8058 CVE-2025-8114 CVE-2025-8277 CVE-2025-8732 CVE-2025-9086 CVE-2025-9187 CVE-2025-9230 CVE-2025-9231 CVE-2025-9232 CVE-2025-9403 CVE-2025-9615 CVE-2026-0861 CVE-2026-0915 CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-0988 CVE-2026-0989 CVE-2026-0990 CVE-2026-0992 CVE-2026-10536 CVE-2026-11822 CVE-2026-11824 CVE-2026-11850 CVE-2026-11979 CVE-2026-12064 CVE-2026-12087 CVE-2026-13595 CVE-2026-1484 CVE-2026-1485 CVE-2026-1489 CVE-2026-15816 CVE-2026-16445 CVE-2026-1757 CVE-2026-1965 CVE-2026-22695 CVE-2026-22795 CVE-2026-22796 CVE-2026-22801 CVE-2026-22976 CVE-2026-22977 CVE-2026-22978 CVE-2026-22979 CVE-2026-22982 CVE-2026-22984 CVE-2026-22985 CVE-2026-22988 CVE-2026-22989 CVE-2026-22990 CVE-2026-22991 CVE-2026-22992 CVE-2026-22993 CVE-2026-22996 CVE-2026-22997 CVE-2026-22998 CVE-2026-22999 CVE-2026-23000 CVE-2026-23001 CVE-2026-23003 CVE-2026-23004 CVE-2026-23005 CVE-2026-23006 CVE-2026-23010 CVE-2026-23011 CVE-2026-23017 CVE-2026-23021 CVE-2026-23023 CVE-2026-23026 CVE-2026-23030 CVE-2026-23033 CVE-2026-23035 CVE-2026-23037 CVE-2026-23038 CVE-2026-23047 CVE-2026-23049 CVE-2026-23053 CVE-2026-23054 CVE-2026-23056 CVE-2026-23057 CVE-2026-23058 CVE-2026-23060 CVE-2026-23061 CVE-2026-23062 CVE-2026-23063 CVE-2026-23064 CVE-2026-23065 CVE-2026-23068 CVE-2026-23069 CVE-2026-23070 CVE-2026-23071 CVE-2026-23073 CVE-2026-23074 CVE-2026-23076 CVE-2026-23078 CVE-2026-23080 CVE-2026-23082 CVE-2026-23083 CVE-2026-23084 CVE-2026-23085 CVE-2026-23086 CVE-2026-23088 CVE-2026-23089 CVE-2026-23090 CVE-2026-23091 CVE-2026-23094 CVE-2026-23095 CVE-2026-23096 CVE-2026-23097 CVE-2026-23099 CVE-2026-23101 CVE-2026-23102 CVE-2026-23103 CVE-2026-23104 CVE-2026-23105 CVE-2026-23107 CVE-2026-23108 CVE-2026-23110 CVE-2026-23111 CVE-2026-23112 CVE-2026-23113 CVE-2026-23116 CVE-2026-23119 CVE-2026-23120 CVE-2026-23121 CVE-2026-23125 CVE-2026-23128 CVE-2026-23129 CVE-2026-23131 CVE-2026-23133 CVE-2026-23135 CVE-2026-23136 CVE-2026-23139 CVE-2026-23140 CVE-2026-23141 CVE-2026-23145 CVE-2026-23146 CVE-2026-23150 CVE-2026-23151 CVE-2026-23152 CVE-2026-23154 CVE-2026-23155 CVE-2026-23156 CVE-2026-23157 CVE-2026-23163 CVE-2026-23166 CVE-2026-23167 CVE-2026-23168 CVE-2026-23169 CVE-2026-23170 CVE-2026-23171 CVE-2026-23172 CVE-2026-23173 CVE-2026-23176 CVE-2026-23178 CVE-2026-23179 CVE-2026-23182 CVE-2026-23187 CVE-2026-23190 CVE-2026-23191 CVE-2026-23193 CVE-2026-23198 CVE-2026-23201 CVE-2026-23202 CVE-2026-23204 CVE-2026-23207 CVE-2026-23208 CVE-2026-23209 CVE-2026-23209 CVE-2026-23210 CVE-2026-23213 CVE-2026-23214 CVE-2026-23215 CVE-2026-23216 CVE-2026-23221 CVE-2026-23222 CVE-2026-23229 CVE-2026-23231 CVE-2026-23236 CVE-2026-23237 CVE-2026-23239 CVE-2026-23240 CVE-2026-23242 CVE-2026-23243 CVE-2026-23245 CVE-2026-23246 CVE-2026-23253 CVE-2026-23255 CVE-2026-23259 CVE-2026-23260 CVE-2026-23261 CVE-2026-23262 CVE-2026-23264 CVE-2026-23266 CVE-2026-23268 CVE-2026-23268 CVE-2026-23269 CVE-2026-23269 CVE-2026-23270 CVE-2026-23271 CVE-2026-23272 CVE-2026-23273 CVE-2026-23274 CVE-2026-23276 CVE-2026-23276 CVE-2026-23277 CVE-2026-23278 CVE-2026-23279 CVE-2026-23281 CVE-2026-23290 CVE-2026-23291 CVE-2026-23292 CVE-2026-23293 CVE-2026-23298 CVE-2026-23300 CVE-2026-23303 CVE-2026-23304 CVE-2026-23306 CVE-2026-23307 CVE-2026-23308 CVE-2026-23312 CVE-2026-23313 CVE-2026-23315 CVE-2026-23317 CVE-2026-23318 CVE-2026-23319 CVE-2026-23321 CVE-2026-23324 CVE-2026-23325 CVE-2026-23327 CVE-2026-23335 CVE-2026-23336 CVE-2026-23339 CVE-2026-23340 CVE-2026-23343 CVE-2026-23346 CVE-2026-23351 CVE-2026-23354 CVE-2026-23357 CVE-2026-23359 CVE-2026-23361 CVE-2026-23362 CVE-2026-23363 CVE-2026-23365 CVE-2026-23367 CVE-2026-23368 CVE-2026-23370 CVE-2026-23372 CVE-2026-23373 CVE-2026-23374 CVE-2026-23378 CVE-2026-23379 CVE-2026-23381 CVE-2026-23382 CVE-2026-23383 CVE-2026-23386 CVE-2026-23391 CVE-2026-23392 CVE-2026-23392 CVE-2026-23393 CVE-2026-23395 CVE-2026-23396 CVE-2026-23397 CVE-2026-23398 CVE-2026-23399 CVE-2026-23403 CVE-2026-23404 CVE-2026-23405 CVE-2026-23406 CVE-2026-23407 CVE-2026-23408 CVE-2026-23409 CVE-2026-23410 CVE-2026-23411 CVE-2026-23412 CVE-2026-23413 CVE-2026-23414 CVE-2026-23418 CVE-2026-23419 CVE-2026-23420 CVE-2026-23426 CVE-2026-23434 CVE-2026-23438 CVE-2026-23440 CVE-2026-23441 CVE-2026-23442 CVE-2026-23443 CVE-2026-23444 CVE-2026-23445 CVE-2026-23446 CVE-2026-23447 CVE-2026-23448 CVE-2026-23449 CVE-2026-23450 CVE-2026-23451 CVE-2026-23452 CVE-2026-23454 CVE-2026-23455 CVE-2026-23456 CVE-2026-23457 CVE-2026-23458 CVE-2026-23460 CVE-2026-23461 CVE-2026-23462 CVE-2026-23463 CVE-2026-23465 CVE-2026-23466 CVE-2026-23468 CVE-2026-23470 CVE-2026-23472 CVE-2026-23473 CVE-2026-23474 CVE-2026-23475 CVE-2026-24515 CVE-2026-24882 CVE-2026-25210 CVE-2026-25646 CVE-2026-25707 CVE-2026-26269 CVE-2026-2673 CVE-2026-27135 CVE-2026-27171 CVE-2026-27456 CVE-2026-27456 CVE-2026-2781 CVE-2026-28387 CVE-2026-28388 CVE-2026-28389 CVE-2026-28390 CVE-2026-28390 CVE-2026-28417 CVE-2026-29111 CVE-2026-29518 CVE-2026-31389 CVE-2026-31392 CVE-2026-31393 CVE-2026-31394 CVE-2026-31395 CVE-2026-31396 CVE-2026-31400 CVE-2026-31402 CVE-2026-31403 CVE-2026-31404 CVE-2026-31405 CVE-2026-31407 CVE-2026-31408 CVE-2026-31411 CVE-2026-31412 CVE-2026-31414 CVE-2026-31415 CVE-2026-31416 CVE-2026-31417 CVE-2026-31420 CVE-2026-31421 CVE-2026-31422 CVE-2026-31423 CVE-2026-31424 CVE-2026-31425 CVE-2026-31426 CVE-2026-31427 CVE-2026-31428 CVE-2026-31429 CVE-2026-31430 CVE-2026-31431 CVE-2026-31431 CVE-2026-31436 CVE-2026-31439 CVE-2026-31440 CVE-2026-31441 CVE-2026-31446 CVE-2026-31447 CVE-2026-31448 CVE-2026-31449 CVE-2026-31450 CVE-2026-31452 CVE-2026-31453 CVE-2026-31454 CVE-2026-31455 CVE-2026-31462 CVE-2026-31464 CVE-2026-31466 CVE-2026-31469 CVE-2026-31470 CVE-2026-31473 CVE-2026-31474 CVE-2026-31479 CVE-2026-31480 CVE-2026-31482 CVE-2026-31483 CVE-2026-31485 CVE-2026-31488 CVE-2026-31492 CVE-2026-31493 CVE-2026-31494 CVE-2026-31495 CVE-2026-31496 CVE-2026-31497 CVE-2026-31498 CVE-2026-31499 CVE-2026-31500 CVE-2026-31502 CVE-2026-31503 CVE-2026-31504 CVE-2026-31505 CVE-2026-31507 CVE-2026-31509 CVE-2026-31510 CVE-2026-31511 CVE-2026-31512 CVE-2026-31513 CVE-2026-31515 CVE-2026-31516 CVE-2026-31518 CVE-2026-31519 CVE-2026-31520 CVE-2026-31522 CVE-2026-31523 CVE-2026-31524 CVE-2026-31525 CVE-2026-31528 CVE-2026-31532 CVE-2026-31533 CVE-2026-31540 CVE-2026-31542 CVE-2026-31545 CVE-2026-31546 CVE-2026-31547 CVE-2026-31548 CVE-2026-31549 CVE-2026-31550 CVE-2026-31551 CVE-2026-31552 CVE-2026-31555 CVE-2026-31560 CVE-2026-31561 CVE-2026-31565 CVE-2026-31566 CVE-2026-31568 CVE-2026-31570 CVE-2026-31576 CVE-2026-31578 CVE-2026-31580 CVE-2026-31581 CVE-2026-31583 CVE-2026-31585 CVE-2026-31586 CVE-2026-31587 CVE-2026-31588 CVE-2026-31590 CVE-2026-31591 CVE-2026-31592 CVE-2026-31593 CVE-2026-31596 CVE-2026-31598 CVE-2026-31599 CVE-2026-31602 CVE-2026-31603 CVE-2026-31604 CVE-2026-31605 CVE-2026-31607 CVE-2026-31613 CVE-2026-31614 CVE-2026-31615 CVE-2026-31616 CVE-2026-31617 CVE-2026-31618 CVE-2026-31619 CVE-2026-31622 CVE-2026-31623 CVE-2026-31624 CVE-2026-31625 CVE-2026-31626 CVE-2026-31627 CVE-2026-31628 CVE-2026-31629 CVE-2026-31647 CVE-2026-31649 CVE-2026-31651 CVE-2026-31655 CVE-2026-31656 CVE-2026-31657 CVE-2026-31659 CVE-2026-31660 CVE-2026-31661 CVE-2026-31662 CVE-2026-31664 CVE-2026-31665 CVE-2026-31667 CVE-2026-31668 CVE-2026-31669 CVE-2026-31670 CVE-2026-31671 CVE-2026-31672 CVE-2026-31673 CVE-2026-31674 CVE-2026-31675 CVE-2026-31677 CVE-2026-31678 CVE-2026-31678 CVE-2026-31679 CVE-2026-31680 CVE-2026-31681 CVE-2026-31682 CVE-2026-31684 CVE-2026-31685 CVE-2026-31687 CVE-2026-31693 CVE-2026-31694 CVE-2026-31697 CVE-2026-31698 CVE-2026-31699 CVE-2026-31700 CVE-2026-31701 CVE-2026-31703 CVE-2026-31720 CVE-2026-31726 CVE-2026-31727 CVE-2026-31728 CVE-2026-31730 CVE-2026-31738 CVE-2026-31747 CVE-2026-31748 CVE-2026-31749 CVE-2026-31751 CVE-2026-31752 CVE-2026-31754 CVE-2026-31755 CVE-2026-31756 CVE-2026-31758 CVE-2026-31759 CVE-2026-31759 CVE-2026-31761 CVE-2026-31762 CVE-2026-31763 CVE-2026-31765 CVE-2026-31767 CVE-2026-31768 CVE-2026-31770 CVE-2026-31771 CVE-2026-31773 CVE-2026-31774 CVE-2026-31776 CVE-2026-31778 CVE-2026-31779 CVE-2026-31780 CVE-2026-31781 CVE-2026-31787 CVE-2026-31788 CVE-2026-31789 CVE-2026-31790 CVE-2026-3184 CVE-2026-32316 CVE-2026-32776 CVE-2026-32777 CVE-2026-32778 CVE-2026-33412 CVE-2026-33416 CVE-2026-33636 CVE-2026-33947 CVE-2026-33948 CVE-2026-34180 CVE-2026-34181 CVE-2026-34182 CVE-2026-34183 CVE-2026-34714 CVE-2026-34743 CVE-2026-34757 CVE-2026-3497 CVE-2026-34982 CVE-2026-35385 CVE-2026-35385 CVE-2026-35388 CVE-2026-35414 CVE-2026-35414 CVE-2026-3731 CVE-2026-3783 CVE-2026-3784 CVE-2026-3805 CVE-2026-39881 CVE-2026-39956 CVE-2026-39979 CVE-2026-40164 CVE-2026-40226 CVE-2026-40355 CVE-2026-40356 CVE-2026-4046 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-41035 CVE-2026-4105 CVE-2026-41676 CVE-2026-41989 CVE-2026-41991 CVE-2026-41992 CVE-2026-42307 CVE-2026-42764 CVE-2026-42766 CVE-2026-42767 CVE-2026-42768 CVE-2026-42769 CVE-2026-42770 CVE-2026-43007 CVE-2026-43009 CVE-2026-43009 CVE-2026-43010 CVE-2026-43011 CVE-2026-43013 CVE-2026-43016 CVE-2026-43017 CVE-2026-43018 CVE-2026-43019 CVE-2026-43020 CVE-2026-43022 CVE-2026-43023 CVE-2026-43024 CVE-2026-43025 CVE-2026-43026 CVE-2026-43027 CVE-2026-43028 CVE-2026-43030 CVE-2026-43032 CVE-2026-43033 CVE-2026-43034 CVE-2026-43035 CVE-2026-43036 CVE-2026-43037 CVE-2026-43038 CVE-2026-43040 CVE-2026-43043 CVE-2026-43044 CVE-2026-43046 CVE-2026-43047 CVE-2026-43049 CVE-2026-43050 CVE-2026-43051 CVE-2026-43052 CVE-2026-43053 CVE-2026-43054 CVE-2026-43056 CVE-2026-43057 CVE-2026-43058 CVE-2026-43059 CVE-2026-43059 CVE-2026-43060 CVE-2026-43061 CVE-2026-43062 CVE-2026-43064 CVE-2026-43065 CVE-2026-43066 CVE-2026-43068 CVE-2026-43069 CVE-2026-43072 CVE-2026-43074 CVE-2026-43077 CVE-2026-43079 CVE-2026-43080 CVE-2026-43081 CVE-2026-43083 CVE-2026-43085 CVE-2026-43086 CVE-2026-43088 CVE-2026-43089 CVE-2026-43092 CVE-2026-43093 CVE-2026-43094 CVE-2026-43098 CVE-2026-43101 CVE-2026-43104 CVE-2026-43105 CVE-2026-43107 CVE-2026-43109 CVE-2026-43109 CVE-2026-43110 CVE-2026-43111 CVE-2026-43112 CVE-2026-43113 CVE-2026-43114 CVE-2026-43117 CVE-2026-43118 CVE-2026-43119 CVE-2026-43120 CVE-2026-43123 CVE-2026-43124 CVE-2026-43126 CVE-2026-43128 CVE-2026-43129 CVE-2026-43130 CVE-2026-43133 CVE-2026-43134 CVE-2026-43135 CVE-2026-43136 CVE-2026-43137 CVE-2026-43139 CVE-2026-43140 CVE-2026-43141 CVE-2026-43143 CVE-2026-43147 CVE-2026-43149 CVE-2026-43150 CVE-2026-43152 CVE-2026-43156 CVE-2026-43157 CVE-2026-43158 CVE-2026-43159 CVE-2026-43161 CVE-2026-43162 CVE-2026-43167 CVE-2026-43168 CVE-2026-43169 CVE-2026-43170 CVE-2026-43171 CVE-2026-43172 CVE-2026-43177 CVE-2026-43180 CVE-2026-43182 CVE-2026-43183 CVE-2026-43187 CVE-2026-43189 CVE-2026-43190 CVE-2026-43191 CVE-2026-43194 CVE-2026-43196 CVE-2026-43198 CVE-2026-43199 CVE-2026-43200 CVE-2026-43202 CVE-2026-43203 CVE-2026-43204 CVE-2026-43205 CVE-2026-43206 CVE-2026-43207 CVE-2026-43211 CVE-2026-43214 CVE-2026-43215 CVE-2026-43216 CVE-2026-43218 CVE-2026-43220 CVE-2026-43221 CVE-2026-43222 CVE-2026-43223 CVE-2026-43225 CVE-2026-43226 CVE-2026-43230 CVE-2026-43231 CVE-2026-43232 CVE-2026-43233 CVE-2026-43234 CVE-2026-43236 CVE-2026-43238 CVE-2026-43239 CVE-2026-43240 CVE-2026-43241 CVE-2026-43242 CVE-2026-43243 CVE-2026-43244 CVE-2026-43246 CVE-2026-43248 CVE-2026-43249 CVE-2026-43251 CVE-2026-43252 CVE-2026-43253 CVE-2026-43255 CVE-2026-43256 CVE-2026-43257 CVE-2026-43260 CVE-2026-43261 CVE-2026-43262 CVE-2026-43264 CVE-2026-43265 CVE-2026-43266 CVE-2026-43269 CVE-2026-43270 CVE-2026-43276 CVE-2026-43277 CVE-2026-43278 CVE-2026-43279 CVE-2026-43281 CVE-2026-43284 CVE-2026-43284 CVE-2026-43284 CVE-2026-43287 CVE-2026-43291 CVE-2026-43294 CVE-2026-43295 CVE-2026-43296 CVE-2026-43300 CVE-2026-43302 CVE-2026-43303 CVE-2026-43304 CVE-2026-43308 CVE-2026-43309 CVE-2026-43312 CVE-2026-43313 CVE-2026-43314 CVE-2026-43316 CVE-2026-43318 CVE-2026-43319 CVE-2026-43320 CVE-2026-43324 CVE-2026-43325 CVE-2026-43327 CVE-2026-43328 CVE-2026-43329 CVE-2026-43330 CVE-2026-43333 CVE-2026-43334 CVE-2026-43336 CVE-2026-43337 CVE-2026-43338 CVE-2026-43339 CVE-2026-43340 CVE-2026-43341 CVE-2026-43342 CVE-2026-43343 CVE-2026-43345 CVE-2026-43346 CVE-2026-43352 CVE-2026-43353 CVE-2026-43357 CVE-2026-43359 CVE-2026-43360 CVE-2026-43361 CVE-2026-43362 CVE-2026-43365 CVE-2026-43366 CVE-2026-43370 CVE-2026-43373 CVE-2026-43380 CVE-2026-43381 CVE-2026-43382 CVE-2026-43383 CVE-2026-43387 CVE-2026-43395 CVE-2026-43397 CVE-2026-43405 CVE-2026-43406 CVE-2026-43407 CVE-2026-43411 CVE-2026-43412 CVE-2026-43413 CVE-2026-43414 CVE-2026-43419 CVE-2026-43420 CVE-2026-43425 CVE-2026-43426 CVE-2026-43427 CVE-2026-43428 CVE-2026-43429 CVE-2026-43430 CVE-2026-43432 CVE-2026-43436 CVE-2026-43437 CVE-2026-43439 CVE-2026-43440 CVE-2026-43441 CVE-2026-43443 CVE-2026-43444 CVE-2026-43445 CVE-2026-43449 CVE-2026-43450 CVE-2026-43451 CVE-2026-43452 CVE-2026-43455 CVE-2026-43456 CVE-2026-43459 CVE-2026-43465 CVE-2026-43466 CVE-2026-43467 CVE-2026-43468 CVE-2026-43469 CVE-2026-43470 CVE-2026-43472 CVE-2026-43473 CVE-2026-43475 CVE-2026-43476 CVE-2026-43480 CVE-2026-43483 CVE-2026-43488 CVE-2026-43491 CVE-2026-43492 CVE-2026-43493 CVE-2026-43494 CVE-2026-43496 CVE-2026-43497 CVE-2026-43499 CVE-2026-43501 CVE-2026-43502 CVE-2026-43503 CVE-2026-43617 CVE-2026-43618 CVE-2026-43619 CVE-2026-43620 CVE-2026-43961 CVE-2026-4437 CVE-2026-4438 CVE-2026-44605 CVE-2026-44656 CVE-2026-44932 CVE-2026-44933 CVE-2026-44941 CVE-2026-44942 CVE-2026-44943 CVE-2026-44944 CVE-2026-45130 CVE-2026-45232 CVE-2026-45445 CVE-2026-45446 CVE-2026-45447 CVE-2026-45834 CVE-2026-45835 CVE-2026-45838 CVE-2026-45839 CVE-2026-45840 CVE-2026-45841 CVE-2026-45842 CVE-2026-45843 CVE-2026-45846 CVE-2026-45848 CVE-2026-45851 CVE-2026-45852 CVE-2026-45853 CVE-2026-45856 CVE-2026-45857 CVE-2026-45858 CVE-2026-45860 CVE-2026-45862 CVE-2026-45867 CVE-2026-45868 CVE-2026-45869 CVE-2026-45870 CVE-2026-45871 CVE-2026-45873 CVE-2026-45875 CVE-2026-45877 CVE-2026-45878 CVE-2026-45879 CVE-2026-45880 CVE-2026-45881 CVE-2026-45883 CVE-2026-45885 CVE-2026-45886 CVE-2026-45891 CVE-2026-45894 CVE-2026-45898 CVE-2026-45899 CVE-2026-45902 CVE-2026-45904 CVE-2026-45905 CVE-2026-45910 CVE-2026-45911 CVE-2026-45912 CVE-2026-45913 CVE-2026-45914 CVE-2026-45915 CVE-2026-45916 CVE-2026-45917 CVE-2026-45919 CVE-2026-45920 CVE-2026-45921 CVE-2026-45922 CVE-2026-45923 CVE-2026-45928 CVE-2026-45932 CVE-2026-45936 CVE-2026-45940 CVE-2026-45941 CVE-2026-45944 CVE-2026-45946 CVE-2026-45947 CVE-2026-45948 CVE-2026-45954 CVE-2026-45958 CVE-2026-45961 CVE-2026-45963 CVE-2026-45964 CVE-2026-45965 CVE-2026-45969 CVE-2026-45970 CVE-2026-45973 CVE-2026-45974 CVE-2026-45976 CVE-2026-45981 CVE-2026-45982 CVE-2026-45983 CVE-2026-45984 CVE-2026-45985 CVE-2026-45986 CVE-2026-45987 CVE-2026-45994 CVE-2026-45996 CVE-2026-45997 CVE-2026-46003 CVE-2026-46004 CVE-2026-46005 CVE-2026-46006 CVE-2026-46009 CVE-2026-46011 CVE-2026-46015 CVE-2026-46016 CVE-2026-46018 CVE-2026-46019 CVE-2026-46021 CVE-2026-46023 CVE-2026-46024 CVE-2026-46026 CVE-2026-46027 CVE-2026-46028 CVE-2026-46033 CVE-2026-46037 CVE-2026-46038 CVE-2026-46040 CVE-2026-46043 CVE-2026-46046 CVE-2026-46048 CVE-2026-46049 CVE-2026-46050 CVE-2026-46051 CVE-2026-46052 CVE-2026-46053 CVE-2026-46056 CVE-2026-46058 CVE-2026-46059 CVE-2026-46063 CVE-2026-46064 CVE-2026-46065 CVE-2026-46068 CVE-2026-46069 CVE-2026-46071 CVE-2026-46075 CVE-2026-46076 CVE-2026-46077 CVE-2026-46079 CVE-2026-46080 CVE-2026-46082 CVE-2026-46083 CVE-2026-46084 CVE-2026-46086 CVE-2026-46088 CVE-2026-46089 CVE-2026-46090 CVE-2026-46092 CVE-2026-46094 CVE-2026-46099 CVE-2026-46101 CVE-2026-46102 CVE-2026-46103 CVE-2026-46108 CVE-2026-46109 CVE-2026-46110 CVE-2026-46111 CVE-2026-46112 CVE-2026-46113 CVE-2026-46114 CVE-2026-46116 CVE-2026-46117 CVE-2026-46119 CVE-2026-46120 CVE-2026-46122 CVE-2026-46123 CVE-2026-46124 CVE-2026-46125 CVE-2026-46126 CVE-2026-46128 CVE-2026-46131 CVE-2026-46132 CVE-2026-46133 CVE-2026-46136 CVE-2026-46137 CVE-2026-46138 CVE-2026-46140 CVE-2026-46143 CVE-2026-46144 CVE-2026-46145 CVE-2026-46146 CVE-2026-46147 CVE-2026-46150 CVE-2026-46151 CVE-2026-46152 CVE-2026-46157 CVE-2026-46158 CVE-2026-46159 CVE-2026-46160 CVE-2026-46161 CVE-2026-46162 CVE-2026-46163 CVE-2026-46165 CVE-2026-46166 CVE-2026-46167 CVE-2026-46168 CVE-2026-46170 CVE-2026-46172 CVE-2026-46173 CVE-2026-46174 CVE-2026-46176 CVE-2026-46177 CVE-2026-46178 CVE-2026-46179 CVE-2026-46180 CVE-2026-46181 CVE-2026-46184 CVE-2026-46185 CVE-2026-46186 CVE-2026-46187 CVE-2026-46189 CVE-2026-46190 CVE-2026-46191 CVE-2026-46193 CVE-2026-46197 CVE-2026-46198 CVE-2026-46199 CVE-2026-46201 CVE-2026-46204 CVE-2026-46205 CVE-2026-46206 CVE-2026-46207 CVE-2026-46209 CVE-2026-46211 CVE-2026-46212 CVE-2026-46214 CVE-2026-46216 CVE-2026-46218 CVE-2026-46219 CVE-2026-46220 CVE-2026-46225 CVE-2026-46227 CVE-2026-46229 CVE-2026-46230 CVE-2026-46231 CVE-2026-46232 CVE-2026-46233 CVE-2026-46234 CVE-2026-46235 CVE-2026-46236 CVE-2026-46238 CVE-2026-46242 CVE-2026-46243 CVE-2026-46243 CVE-2026-46244 CVE-2026-46245 CVE-2026-46247 CVE-2026-46249 CVE-2026-46252 CVE-2026-46253 CVE-2026-46254 CVE-2026-46259 CVE-2026-46261 CVE-2026-46263 CVE-2026-46265 CVE-2026-46266 CVE-2026-46267 CVE-2026-46270 CVE-2026-46273 CVE-2026-46274 CVE-2026-46275 CVE-2026-46276 CVE-2026-46285 CVE-2026-46286 CVE-2026-46289 CVE-2026-46291 CVE-2026-46292 CVE-2026-46294 CVE-2026-46300 CVE-2026-46300 CVE-2026-46306 CVE-2026-46307 CVE-2026-46312 CVE-2026-46313 CVE-2026-46314 CVE-2026-46315 CVE-2026-46319 CVE-2026-46320 CVE-2026-46321 CVE-2026-46322 CVE-2026-46323 CVE-2026-46324 CVE-2026-46328 CVE-2026-46330 CVE-2026-46330 CVE-2026-46331 CVE-2026-46333 CVE-2026-46333 CVE-2026-46483 CVE-2026-4873 CVE-2026-4878 CVE-2026-48863 CVE-2026-52904 CVE-2026-52908 CVE-2026-52909 CVE-2026-52910 CVE-2026-52914 CVE-2026-52915 CVE-2026-52916 CVE-2026-52918 CVE-2026-52919 CVE-2026-52921 CVE-2026-52922 CVE-2026-52923 CVE-2026-52924 CVE-2026-52926 CVE-2026-52927 CVE-2026-52930 CVE-2026-52931 CVE-2026-52933 CVE-2026-52936 CVE-2026-52937 CVE-2026-52941 CVE-2026-52942 CVE-2026-52943 CVE-2026-52947 CVE-2026-52948 CVE-2026-52951 CVE-2026-52953 CVE-2026-52954 CVE-2026-52955 CVE-2026-52956 CVE-2026-52957 CVE-2026-52958 CVE-2026-52961 CVE-2026-52962 CVE-2026-52963 CVE-2026-52964 CVE-2026-52967 CVE-2026-52969 CVE-2026-52970 CVE-2026-52972 CVE-2026-52974 CVE-2026-52976 CVE-2026-52981 CVE-2026-52982 CVE-2026-52984 CVE-2026-52986 CVE-2026-52988 CVE-2026-52989 CVE-2026-52991 CVE-2026-52993 CVE-2026-52995 CVE-2026-52998 CVE-2026-52999 CVE-2026-53000 CVE-2026-53002 CVE-2026-53003 CVE-2026-53004 CVE-2026-53006 CVE-2026-53009 CVE-2026-53011 CVE-2026-53012 CVE-2026-53013 CVE-2026-53016 CVE-2026-53021 CVE-2026-53022 CVE-2026-53032 CVE-2026-53035 CVE-2026-53036 CVE-2026-53037 CVE-2026-53039 CVE-2026-53040 CVE-2026-53041 CVE-2026-53045 CVE-2026-53047 CVE-2026-53049 CVE-2026-53050 CVE-2026-53052 CVE-2026-53053 CVE-2026-53056 CVE-2026-53058 CVE-2026-53060 CVE-2026-53062 CVE-2026-53063 CVE-2026-53064 CVE-2026-53065 CVE-2026-53066 CVE-2026-53068 CVE-2026-53069 CVE-2026-53070 CVE-2026-53071 CVE-2026-53072 CVE-2026-53073 CVE-2026-53074 CVE-2026-53075 CVE-2026-53078 CVE-2026-53080 CVE-2026-53083 CVE-2026-53086 CVE-2026-53088 CVE-2026-53090 CVE-2026-53093 CVE-2026-53098 CVE-2026-53106 CVE-2026-53107 CVE-2026-53112 CVE-2026-53122 CVE-2026-53123 CVE-2026-53129 CVE-2026-53131 CVE-2026-53132 CVE-2026-53133 CVE-2026-53134 CVE-2026-53135 CVE-2026-53136 CVE-2026-53137 CVE-2026-53138 CVE-2026-53139 CVE-2026-53140 CVE-2026-53143 CVE-2026-53144 CVE-2026-53146 CVE-2026-53147 CVE-2026-53148 CVE-2026-53149 CVE-2026-53150 CVE-2026-53158 CVE-2026-53159 CVE-2026-53160 CVE-2026-53161 CVE-2026-53167 CVE-2026-53168 CVE-2026-53175 CVE-2026-53176 CVE-2026-53177 CVE-2026-53178 CVE-2026-53181 CVE-2026-53182 CVE-2026-53183 CVE-2026-53184 CVE-2026-53185 CVE-2026-53186 CVE-2026-53189 CVE-2026-53190 CVE-2026-53192 CVE-2026-53194 CVE-2026-53195 CVE-2026-53196 CVE-2026-53202 CVE-2026-53203 CVE-2026-53208 CVE-2026-53209 CVE-2026-53212 CVE-2026-53213 CVE-2026-53215 CVE-2026-53216 CVE-2026-53217 CVE-2026-53218 CVE-2026-53221 CVE-2026-53224 CVE-2026-53225 CVE-2026-53227 CVE-2026-53229 CVE-2026-53230 CVE-2026-53236 CVE-2026-53237 CVE-2026-53239 CVE-2026-53241 CVE-2026-53242 CVE-2026-53245 CVE-2026-53246 CVE-2026-53249 CVE-2026-53250 CVE-2026-53252 CVE-2026-53253 CVE-2026-53254 CVE-2026-53255 CVE-2026-53256 CVE-2026-53258 CVE-2026-53262 CVE-2026-53265 CVE-2026-53266 CVE-2026-53267 CVE-2026-53268 CVE-2026-53270 CVE-2026-53272 CVE-2026-53274 CVE-2026-53275 CVE-2026-53279 CVE-2026-53281 CVE-2026-53285 CVE-2026-53287 CVE-2026-53289 CVE-2026-53291 CVE-2026-53293 CVE-2026-53297 CVE-2026-53306 CVE-2026-53313 CVE-2026-53321 CVE-2026-53324 CVE-2026-53325 CVE-2026-53329 CVE-2026-53331 CVE-2026-53332 CVE-2026-53339 CVE-2026-53345 CVE-2026-53347 CVE-2026-53350 CVE-2026-53354 CVE-2026-53355 CVE-2026-53356 CVE-2026-53357 CVE-2026-53358 CVE-2026-53359 CVE-2026-53359 CVE-2026-53360 CVE-2026-53362 CVE-2026-53362 CVE-2026-53366 CVE-2026-53369 CVE-2026-53374 CVE-2026-53375 CVE-2026-53376 CVE-2026-53379 CVE-2026-53382 CVE-2026-53385 CVE-2026-53388 CVE-2026-53391 CVE-2026-53392 CVE-2026-53393 CVE-2026-53397 CVE-2026-53398 CVE-2026-53399 CVE-2026-53402 CVE-2026-53403 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-53783 CVE-2026-53784 CVE-2026-53785 CVE-2026-53786 CVE-2026-53788 CVE-2026-53789 CVE-2026-53790 CVE-2026-53791 CVE-2026-53792 CVE-2026-53793 CVE-2026-53794 CVE-2026-53795 CVE-2026-53796 CVE-2026-53797 CVE-2026-53798 CVE-2026-53799 CVE-2026-53800 CVE-2026-53801 CVE-2026-53802 CVE-2026-53803 CVE-2026-5435 CVE-2026-54411 CVE-2026-5450 CVE-2026-5545 CVE-2026-5704 CVE-2026-57062 CVE-2026-57432 CVE-2026-5773 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-58374 CVE-2026-5928 CVE-2026-5958 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 CVE-2026-59856 CVE-2026-59857 CVE-2026-59858 CVE-2026-59995 CVE-2026-59996 CVE-2026-59997 CVE-2026-59998 CVE-2026-59999 CVE-2026-60000 CVE-2026-60001 CVE-2026-60002 CVE-2026-6238 CVE-2026-6253 CVE-2026-6276 CVE-2026-63794 CVE-2026-63795 CVE-2026-63802 CVE-2026-63806 CVE-2026-63807 CVE-2026-63809 CVE-2026-63821 CVE-2026-63822 CVE-2026-63824 CVE-2026-63826 CVE-2026-63829 CVE-2026-63836 CVE-2026-63843 CVE-2026-63844 CVE-2026-63845 CVE-2026-63846 CVE-2026-63847 CVE-2026-63848 CVE-2026-63851 CVE-2026-63852 CVE-2026-63853 CVE-2026-63854 CVE-2026-63855 CVE-2026-63856 CVE-2026-63861 CVE-2026-63862 CVE-2026-63869 CVE-2026-63882 CVE-2026-63884 CVE-2026-63892 CVE-2026-63893 CVE-2026-63895 CVE-2026-63896 CVE-2026-63897 CVE-2026-63899 CVE-2026-63900 CVE-2026-63901 CVE-2026-63902 CVE-2026-63903 CVE-2026-63904 CVE-2026-63905 CVE-2026-63908 CVE-2026-63912 CVE-2026-63915 CVE-2026-63916 CVE-2026-63917 CVE-2026-63919 CVE-2026-63921 CVE-2026-63922 CVE-2026-63924 CVE-2026-63927 CVE-2026-63928 CVE-2026-63930 CVE-2026-63931 CVE-2026-63934 CVE-2026-63938 CVE-2026-63939 CVE-2026-63940 CVE-2026-63942 CVE-2026-63943 CVE-2026-63945 CVE-2026-63946 CVE-2026-63947 CVE-2026-63948 CVE-2026-63949 CVE-2026-63952 CVE-2026-63957 CVE-2026-63958 CVE-2026-63959 CVE-2026-63960 CVE-2026-63961 CVE-2026-63962 CVE-2026-63964 CVE-2026-63967 CVE-2026-63968 CVE-2026-63971 CVE-2026-63974 CVE-2026-63975 CVE-2026-63976 CVE-2026-63984 CVE-2026-63991 CVE-2026-63994 CVE-2026-64025 CVE-2026-64089 CVE-2026-64106 CVE-2026-64174 CVE-2026-64179 CVE-2026-64182 CVE-2026-64183 CVE-2026-64187 CVE-2026-64189 CVE-2026-64191 CVE-2026-64220 CVE-2026-64221 CVE-2026-64223 CVE-2026-64231 CVE-2026-64234 CVE-2026-64242 CVE-2026-6429 CVE-2026-64298 CVE-2026-64330 CVE-2026-64336 CVE-2026-64345 CVE-2026-64347 CVE-2026-64465 CVE-2026-64530 CVE-2026-64560 CVE-2026-64561 CVE-2026-64564 CVE-2026-64600 CVE-2026-6893 CVE-2026-6893 CVE-2026-70452 CVE-2026-70453 CVE-2026-70454 CVE-2026-70455 CVE-2026-70456 CVE-2026-70457 CVE-2026-70458 CVE-2026-70459 CVE-2026-70460 CVE-2026-70461 CVE-2026-70462 CVE-2026-70463 CVE-2026-70464 CVE-2026-71401 CVE-2026-71402 CVE-2026-7168 CVE-2026-73070 CVE-2026-73071 CVE-2026-73072 CVE-2026-73074 CVE-2026-73075 CVE-2026-73076 CVE-2026-73077 CVE-2026-73078 CVE-2026-7383 CVE-2026-8286 CVE-2026-8376 CVE-2026-8458 CVE-2026-8924 CVE-2026-8926 CVE-2026-8927 CVE-2026-9076 CVE-2026-9079 CVE-2026-9080 CVE-2026-9149 CVE-2026-9150 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2018:2022-1 Released: Wed Sep 26 09:48:09 2018 Summary: Recommended update for SUSE Manager Client Tools Type: recommended Severity: moderate References: 1103388,1104120,1106523 This update fixes the following issues: hwdata: - Update to version 0.314: + Updated pci, usb and vendor ids. spacewalk-backend: - Channels to be actually un-subscribed from the assigned systems when being removed using spacewalk-remove-channel tool. (bsc#1104120) - Take only text files from /srv/salt to make spacewalk-debug smaller. (bsc#1103388) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2019:1022-1 Released: Wed Apr 24 13:46:51 2019 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: 1121410 This update for hwdata fixes the following issues: Update to version 0.320 (bsc#1121410): - Updated the pci, usb and vendor ids vendor and product databases. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2020:1261-1 Released: Tue May 12 18:40:18 2020 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: 1168806 This update for hwdata fixes the following issues: Update from version 0.320 to version 0.324 (bsc#1168806) - Updated pci, usb and vendor ids. - Replace pciutils-ids package providing compatibility symbolic link ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:421-1 Released: Wed Feb 10 12:05:23 2021 Summary: Recommended update for hwdata Type: recommended Severity: low References: 1180422,1180482 This update for hwdata fixes the following issues: - Added merge-pciids.pl to fully duplicate behavior of pciutils-ids (bsc#1180422, bsc#1180482) - Updated pci, usb and vendor ids. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:880-1 Released: Fri Mar 19 04:14:38 2021 Summary: Recommended update for hwdata Type: recommended Severity: low References: 1170160,1182482 This update for hwdata fixes the following issues: - Updated pci, usb and vendor ids (bsc#1182482, bsc#1170160, jsc#SLE-13791) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:1950-1 Released: Thu Jun 10 14:42:00 2021 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: 1170160,1182482,1185697 This update for hwdata fixes the following issues: - Update to version 0.347: + Updated pci, usb and vendor ids. (bsc#1185697) - Update to version 0.346: + Updated pci, usb and vendor ids. (bsc#1182482, jsc#SLE-13791, bsc#1170160) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:2447-1 Released: Thu Jul 22 08:26:29 2021 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: 1186749,1187948 This update for hwdata fixes the following issue: - Version 0.349: Updated pci, usb and vendor ids (bsc#1187948). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:2973-1 Released: Tue Sep 7 16:56:08 2021 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: 1190091 This update for hwdata fixes the following issue: - Update pci, usb and vendor ids (bsc#1190091) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:3832-1 Released: Wed Dec 1 14:51:19 2021 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: 1191375 This update for hwdata fixes the following issue: - Update to version 0.353 (bsc#1191375) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:100-1 Released: Tue Jan 18 05:20:03 2022 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: 1194338 This update for hwdata fixes the following issues: - Update hwdata from version 0.353 to 0.355 which includes updated pci, usb and vendor ids (bsc#1194338) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:1204-1 Released: Thu Apr 14 12:15:55 2022 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: 1196332 This update for hwdata fixes the following issues: - Updated pci, usb and vendor ids (bsc#1196332) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:1703-1 Released: Tue May 17 12:13:36 2022 Summary: Recommended update for hwdata Type: recommended Severity: important References: 1196332 This update for hwdata fixes the following issues: - Updated pci, usb and vendor ids (bsc#1196332) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:3135-1 Released: Wed Sep 7 08:39:31 2022 Summary: Recommended update for hwdata Type: recommended Severity: low References: 1200110 This update for hwdata fixes the following issue: - Update pci, usb and vendor ids to version 0.360 (bsc#1200110) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:4063-1 Released: Fri Nov 18 09:07:50 2022 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: This update for hwdata fixes the following issues: - Updated pci, usb and vendor ids ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:46-1 Released: Mon Jan 9 10:35:21 2023 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: This update for hwdata fixes the following issues: - Update pci, usb and vendor ids ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:1920-1 Released: Wed Apr 19 16:22:58 2023 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: This update for hwdata fixes the following issues: - Update pci, usb and vendor ids ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2649-1 Released: Tue Jun 27 10:01:13 2023 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: This update for hwdata fixes the following issues: - update to 0.371: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:458-1 Released: Tue Feb 13 14:34:14 2024 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: This update for hwdata fixes the following issues: - Update to version 0.378 - Update pci, usb and vendor ids ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:1176-1 Released: Tue Apr 9 10:43:33 2024 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: This update for hwdata fixes the following issues: - Update to 0.380 - Update pci, usb and vendor ids ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:4044-1 Released: Mon Nov 25 08:28:17 2024 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: This update for hwdata fixes the following issue: - Version update to v0.389: * Update pci, usb and vendor ids ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:4363-1 Released: Tue Dec 17 16:12:41 2024 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: This update for hwdata fixes the following issue: - Version update v0.390 * Update pci and vendor ids ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:1721-1 Released: Tue May 27 17:59:31 2025 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: This update for hwdata fixes the following issue: - Version update 0.394: * Update pci, usb and vendor ids * Fix usb.ids encoding and a couple of typos * Fix configure to honor --prefix ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2776-1 Released: Wed Aug 13 08:10:36 2025 Summary: Recommended update for systemd-rpm-macros Type: recommended Severity: moderate References: 1237143 This update for systemd-rpm-macros fixes the following issues: - Introduce %udev_trigger_with_reload() for packages that need to trigger events in theirs scriplets. The new macro automatically triggers a reload of the udev rule files as this step is often overlooked by packages (bsc#1237143). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2780-1 Released: Wed Aug 13 10:28:27 2025 Summary: Recommended update for gcc14 Type: recommended Severity: moderate References: 1230262,1232526,1237442,1238491,1239566,1239938,1240788,1241549,1243991,1244050 This update for gcc14 fixes the following issues: Update to GCC 14.3 release, bb24b4c804f3d95b0ba95b7496, git11799 - Fixed libqt6webengine build. - Fix build on s390x [bsc#1241549] - Make sure link editing is done against our own shared library copy rather than the installed system runtime. [bsc#1240788] - Allow GCC executables to be built PIE. [bsc#1239938] - Backport -msplit-patch-nops required for user-space livepatching on powerpc. - Also record -D_FORTIFY_SOURCE=2 in the DWARF debug info DW_AT_producer string. [bsc#1239566] - Disable profiling during build when %want_reproducible_builds is set [bsc#1238491] - Fixes reported ICE in [bsc#1237442] - Add larchintrin.h, lasxintrin.h and lsxintrin.h headers to gccXY main package in %files section - libstdc++6 fix for parsing tzdata 2024b [gcc#116657] - Fix ICE with LTO building openvino on aarch64 [bsc#1230262] - Exclude shared objects present for link editing in the GCC specific subdirectory from provides processing via __provides_exclude_from. [bsc#1244050][bsc#1243991] - Make cross-*-gcc14-bootstrap package conflict with the non-bootstrap variant conflict with the unversioned cross-*-gcc package. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2813-1 Released: Fri Aug 15 14:53:07 2025 Summary: Recommended update for grub2 Type: security Severity: moderate References: 1234959,1246157,1246231,1246237,CVE-2024-56738 This update for grub2 fixes the following issues: - CVE-2024-56738: Fixed side-channel attack due to not constant-time algorithm in grub_crypto_memcmp (bsc#1234959) Other fixes: - Fix test -f and -s do not work properly over the network files served via tftp and http (bsc#1246157, bsc#1246237) - Skip mount point in grub_find_device function (bsc#1246231) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2838-1 Released: Mon Aug 18 10:56:16 2025 Summary: Recommended update for suse-build-key Type: recommended Severity: moderate References: 1245223 This update for suse-build-key fixes the following issue: - adjust SLES16 signing key UID (name,email) with official names (bsc#1245223). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2874-1 Released: Tue Aug 19 06:07:47 2025 Summary: Recommended update for openssl-3 Type: recommended Severity: important References: 1247144,1247148 This update for openssl-3 fixes the following issues: - Increase limit for CRL download (bsc#1247148, bsc#1247144) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2887-1 Released: Tue Aug 19 09:47:06 2025 Summary: Recommended update for suse-module-tools Type: recommended Severity: moderate References: 1241038 This update for suse-module-tools fixes the following issues: - Version update 15.7.6 - Add missing util-linux requirement in the spec file (bsc#1241038). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2915-1 Released: Tue Aug 19 14:56:35 2025 Summary: Security update for jq Type: security Severity: moderate References: 1244116,CVE-2025-48060 This update for jq fixes the following issues: - CVE-2025-48060: Fixed stack-buffer-overflow in jq_fuzz_execute (bsc#1244116) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2940-1 Released: Thu Aug 21 11:22:53 2025 Summary: Recommended update for open-iscsi Type: recommended Severity: moderate References: 1240969 This update for open-iscsi fixes the following issues: - README for rpm build directory - Fix issue with IPv6 adapter interfaces (bsc#1240969) - fwparam_ppc.c: Fix the calloc-transposed-args issue - Makefile: fix 'No rule to make target 'iscsiuio/Makefile.in' issue - Fix typo in initiator.c - Fixed some issues in this changes file - One date had incorrect format from 2014 - Two separator lines were formatted incrrectly ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2964-1 Released: Fri Aug 22 14:52:39 2025 Summary: Security update for glibc Type: security Severity: moderate References: 1240058,1246965,CVE-2025-8058 This update for glibc fixes the following issues: - CVE-2025-8058: Fixed double-free after allocation failure in regcomp. (bsc#1246965) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2970-1 Released: Mon Aug 25 10:27:57 2025 Summary: Security update for pam Type: security Severity: moderate References: 1232234,1246221,CVE-2024-10041 This update for pam fixes the following issues: - Improve previous CVE-2024-10041 fix which led to CPU performance issues (bsc#1232234) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2997-1 Released: Wed Aug 27 14:04:03 2025 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1139073,1204142,1219338,1225707,1227082,1228664,1230216,1233300,1235515,1235613,1235837,1236333,1236897,1238896,1239061,1239470,1240323,1240696,1240885,1240966,1240998,1241166,1241200,1241345,1241537,1242086,1242414,1242837,1242960,1242965,1242993,1243042,1243068,1243100,1243479,1243669,1243678,1243806,1244309,1244337,1244457,1244735,1244749,1244750,1244792,1244801,1245084,1245151,1245201,1245202,1245216,1245260,1245431,1245440,1245457,1245498,1245499,1245504,1245506,1245508,1245510,1245540,1245598,1245599,1245621,1245646,1245647,1245649,1245650,1245654,1245658,1245660,1245664,1245665,1245666,1245668,1245669,1245670,1245671,1245675,1245676,1245677,1245679,1245682,1245683,1245684,1245686,1245688,1245689,1245690,1245691,1245695,1245705,1245708,1245711,1245713,1245714,1245719,1245723,1245729,1245730,1245731,1245735,1245737,1245744,1245745,1245746,1245747,1245748,1245749,1245750,1245751,1245752,1245757,1245758,1245765,1245768,1245769,1245777,1245781,1245789,1245812,1245937,1 245945,1245951,1245952,1245954,1245955,1245957,1245966,1245970,1245976,1245980,1245983,1245986,1246000,1246002,1246006,1246008,1246020,1246023,1246029,1246031,1246037,1246041,1246042,1246044,1246045,1246047,1246049,1246050,1246055,1246073,1246093,1246098,1246109,1246113,1246122,1246125,1246134,1246171,1246173,1246178,1246179,1246182,1246183,1246186,1246188,1246195,1246203,1246212,1246217,1246220,1246236,1246240,1246243,1246244,1246246,1246249,1246250,1246253,1246258,1246262,1246264,1246266,1246268,1246273,1246283,1246285,1246286,1246287,1246290,1246292,1246293,1246295,1246297,1246333,1246334,1246337,1246342,1246349,1246354,1246358,1246361,1246364,1246370,1246375,1246384,1246385,1246386,1246387,1246438,1246443,1246449,1246453,1246473,1246490,1246506,1246547,1246644,1246695,1246777,1246781,1246870,1246879,1246911,1247018,1247021,1247023,1247028,1247031,1247033,1247035,1247061,1247062,1247064,1247079,1247089,1247091,1247097,1247098,1247101,1247103,1247104,1247113,1247118,1247123,124712 5,1247128,1247132,1247138,1247141,1247143,1247145,1247146,1247147,1247149,1247150,1247151,1247152,1247153,1247154,1247156,1247160,1247164,1247169,1247170,1247171,1247172,1247174,1247176,1247177,1247178,1247181,1247209,1247210,1247227,1247233,1247234,1247236,1247238,1247241,1247251,1247252,1247253,1247255,1247265,1247271,1247273,1247274,1247276,1247277,1247278,1247279,1247282,1247284,1247285,1247288,1247289,1247293,1247308,1247311,1247314,1247317,1247347,1247348,1247349,1247374,1247437,1247450,1247712,1247831,CVE-2019-11135,CVE-2024-36028,CVE-2024-36348,CVE-2024-36349,CVE-2024-36350,CVE-2024-36357,CVE-2024-39298,CVE-2024-42134,CVE-2024-44963,CVE-2024-49861,CVE-2024-56742,CVE-2024-57947,CVE-2025-21839,CVE-2025-21854,CVE-2025-21872,CVE-2025-22090,CVE-2025-23163,CVE-2025-37798,CVE-2025-37856,CVE-2025-37864,CVE-2025-37885,CVE-2025-37920,CVE-2025-37984,CVE-2025-38034,CVE-2025-38035,CVE-2025-38047,CVE-2025-38051,CVE-2025-38052,CVE-2025-38058,CVE-2025-38061,CVE-2025-38062,CVE-2025-38063,CVE -2025-38064,CVE-2025-38074,CVE-2025-38084,CVE-2025-38085,CVE-2025-38087,CVE-2025-38088,CVE-2025-38089,CVE-2025-38090,CVE-2025-38091,CVE-2025-38094,CVE-2025-38095,CVE-2025-38097,CVE-2025-38098,CVE-2025-38099,CVE-2025-38100,CVE-2025-38102,CVE-2025-38105,CVE-2025-38106,CVE-2025-38107,CVE-2025-38108,CVE-2025-38109,CVE-2025-38110,CVE-2025-38111,CVE-2025-38112,CVE-2025-38113,CVE-2025-38114,CVE-2025-38115,CVE-2025-38117,CVE-2025-38118,CVE-2025-38120,CVE-2025-38122,CVE-2025-38123,CVE-2025-38124,CVE-2025-38126,CVE-2025-38127,CVE-2025-38129,CVE-2025-38131,CVE-2025-38132,CVE-2025-38135,CVE-2025-38136,CVE-2025-38138,CVE-2025-38142,CVE-2025-38143,CVE-2025-38145,CVE-2025-38147,CVE-2025-38148,CVE-2025-38149,CVE-2025-38151,CVE-2025-38153,CVE-2025-38154,CVE-2025-38155,CVE-2025-38157,CVE-2025-38158,CVE-2025-38159,CVE-2025-38161,CVE-2025-38162,CVE-2025-38165,CVE-2025-38166,CVE-2025-38173,CVE-2025-38174,CVE-2025-38177,CVE-2025-38180,CVE-2025-38181,CVE-2025-38182,CVE-2025-38183,CVE-2025-38186,CVE-2025-3 8187,CVE-2025-38188,CVE-2025-38189,CVE-2025-38192,CVE-2025-38193,CVE-2025-38194,CVE-2025-38197,CVE-2025-38198,CVE-2025-38200,CVE-2025-38202,CVE-2025-38203,CVE-2025-38204,CVE-2025-38206,CVE-2025-38210,CVE-2025-38211,CVE-2025-38212,CVE-2025-38213,CVE-2025-38214,CVE-2025-38215,CVE-2025-38217,CVE-2025-38220,CVE-2025-38222,CVE-2025-38225,CVE-2025-38226,CVE-2025-38227,CVE-2025-38229,CVE-2025-38231,CVE-2025-38236,CVE-2025-38238,CVE-2025-38239,CVE-2025-38244,CVE-2025-38246,CVE-2025-38248,CVE-2025-38249,CVE-2025-38250,CVE-2025-38256,CVE-2025-38257,CVE-2025-38259,CVE-2025-38264,CVE-2025-38265,CVE-2025-38268,CVE-2025-38272,CVE-2025-38273,CVE-2025-38275,CVE-2025-38277,CVE-2025-38279,CVE-2025-38283,CVE-2025-38286,CVE-2025-38287,CVE-2025-38288,CVE-2025-38289,CVE-2025-38290,CVE-2025-38291,CVE-2025-38292,CVE-2025-38293,CVE-2025-38299,CVE-2025-38300,CVE-2025-38303,CVE-2025-38304,CVE-2025-38305,CVE-2025-38307,CVE-2025-38310,CVE-2025-38312,CVE-2025-38313,CVE-2025-38315,CVE-2025-38317,CVE-2025-38319,CV E-2025-38323,CVE-2025-38326,CVE-2025-38328,CVE-2025-38332,CVE-2025-38334,CVE-2025-38335,CVE-2025-38336,CVE-2025-38337,CVE-2025-38338,CVE-2025-38342,CVE-2025-38343,CVE-2025-38344,CVE-2025-38345,CVE-2025-38348,CVE-2025-38349,CVE-2025-38350,CVE-2025-38352,CVE-2025-38353,CVE-2025-38354,CVE-2025-38355,CVE-2025-38356,CVE-2025-38361,CVE-2025-38362,CVE-2025-38363,CVE-2025-38364,CVE-2025-38365,CVE-2025-38369,CVE-2025-38371,CVE-2025-38373,CVE-2025-38375,CVE-2025-38376,CVE-2025-38377,CVE-2025-38380,CVE-2025-38382,CVE-2025-38384,CVE-2025-38385,CVE-2025-38386,CVE-2025-38387,CVE-2025-38389,CVE-2025-38391,CVE-2025-38392,CVE-2025-38393,CVE-2025-38395,CVE-2025-38396,CVE-2025-38399,CVE-2025-38400,CVE-2025-38401,CVE-2025-38403,CVE-2025-38404,CVE-2025-38406,CVE-2025-38409,CVE-2025-38410,CVE-2025-38412,CVE-2025-38414,CVE-2025-38415,CVE-2025-38416,CVE-2025-38417,CVE-2025-38420,CVE-2025-38424,CVE-2025-38425,CVE-2025-38426,CVE-2025-38427,CVE-2025-38428,CVE-2025-38429,CVE-2025-38430,CVE-2025-38436,CVE-2025- 38443,CVE-2025-38448,CVE-2025-38449,CVE-2025-38453,CVE-2025-38455,CVE-2025-38457,CVE-2025-38460,CVE-2025-38461,CVE-2025-38462,CVE-2025-38463,CVE-2025-38465,CVE-2025-38467,CVE-2025-38468,CVE-2025-38470,CVE-2025-38471,CVE-2025-38473,CVE-2025-38474,CVE-2025-38475,CVE-2025-38476,CVE-2025-38477,CVE-2025-38478,CVE-2025-38480,CVE-2025-38481,CVE-2025-38482,CVE-2025-38483,CVE-2025-38485,CVE-2025-38487,CVE-2025-38489,CVE-2025-38494,CVE-2025-38495,CVE-2025-38496,CVE-2025-38497,CVE-2025-38498 The SUSE Linux Enterprise 15 SP7 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2019-11135: enabled CONFIG_X86_INTEL_TSX_MODE_AUTO (bsc#1139073, bsc#1246695) - CVE-2024-36028: mm/hugetlb: fix DEBUG_LOCKS_WARN_ON(1) when dissolve_free_hugetlb_folio() (bsc#1225707). - CVE-2024-36348, CVE-2024-36349, CVE-2024-36350, CVE-2024-36357: x86/process: Move the buffer clearing before MONITOR (bsc#1238896). - CVE-2024-39298:mm/memory-failure: fix handling of dissolved but not taken off from buddy pages (bsc#1227082). - CVE-2024-42134: virtio-pci: Check if is_avq is NULL (bsc#1228664). - CVE-2024-44963: btrfs: do not BUG_ON() when freeing tree block after error (bsc#1230216). - CVE-2024-49861: net: clear the dst when changing skb protocol (bsc#1245954). - CVE-2024-56742: vfio/mlx5: Fix an unwind issue in mlx5vf_add_migration_pages() (bsc#1235613). - CVE-2025-21839: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop (bsc#1239061). - CVE-2025-21854: selftest/bpf: Add vsock test for sockmap rejecting unconnected (bsc#1239470). - CVE-2025-21872: efi/mokvar-table: Avoid repeated map/unmap of the same page (bsc#1240323). - CVE-2025-22090: mm: (un)track_pfn_copy() fix + doc improvements (bsc#1241537). - CVE-2025-23163: net: vlan: do not propagate flags on open (bsc#1242837). - CVE-2025-37856: btrfs: harden block_group::bg_list against list_del() races (bsc#1243068). - CVE-2025-37864: net: dsa: clean up FDB, MDB, VLAN entries on unbind (bsc#1242965). - CVE-2025-37885: KVM: x86: Reset IRTE to host control if *new* route isn't postable (bsc#1242960). - CVE-2025-37920: kABI workaround for xsk: Fix race condition in AF_XDP generic RX path (bsc#1243479). - CVE-2025-37984: crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() (bsc#1243669). - CVE-2025-38034: btrfs: correct the order of prelim_ref arguments in btrfs__prelim_ref (bsc#1244792). - CVE-2025-38035: nvmet-tcp: do not restore null sk_state_change (bsc#1244801). - CVE-2025-38047: x86/fred: Fix system hang during S4 resume with FRED enabled (bsc#1245084). - CVE-2025-38051: smb: client: Fix use-after-free in cifs_fill_dirent (bsc#1244750). - CVE-2025-38058: __legitimize_mnt(): check for MNT_SYNC_UMOUNT should be under mount_lock (bsc#1245151). - CVE-2025-38061: net: pktgen: fix access outside of user given buffer in pktgen_thread_write() (bsc#1245440). - CVE-2025-38062: kABI: restore layout of struct msi_desc (bsc#1245216). - CVE-2025-38063: dm: fix unconditional IO throttle caused by REQ_PREFLUSH (bsc#1245202). - CVE-2025-38064: virtio: break and reset virtio devices on device_shutdown() (bsc#1245201). - CVE-2025-38074: vhost-scsi: protect vq->log_used with vq->mutex (bsc#1244735). - CVE-2025-38094: net: cadence: macb: Fix a possible deadlock in macb_halt_tx (bsc#1245649). - CVE-2025-38097: kabi: restore encap_sk in struct xfrm_state (bsc#1245660). - CVE-2025-38098: drm/amd/display: Do not treat wb connector as physical in (bsc#1245654). - CVE-2025-38099: Bluetooth: btusb: Fix regression in the initialization of fake Bluetooth controllers (bsc#1245671). - CVE-2025-38100: x86/iopl: Cure TIF_IO_BITMAP inconsistencies (bsc#1245650). - CVE-2025-38105: ALSA: usb-audio: Kill timer properly at removal (bsc#1245682). - CVE-2025-38106: io_uring/sqpoll: do not put task_struct on tctx setup failure (bsc#1245664). - CVE-2025-38115: net_sched: sch_sfq: fix a potential crash on gso_skb handling (bsc#1245689). - CVE-2025-38117: hci_dev centralize extra lock (bsc#1245695). - CVE-2025-38126: net: stmmac: make sure that ptp_rate is not 0 before configuring timestamping (bsc#1245708). - CVE-2025-38131: coresight: prevent deactivate active config while enabling the config (bsc#1245677). - CVE-2025-38132: coresight: holding cscfg_csdev_lock while removing cscfg from csdev (bsc#1245679). - CVE-2025-38147: calipso: unlock rcu before returning -EAFNOSUPPORT (bsc#1245768). - CVE-2025-38158: hisi_acc_vfio_pci: fix XQE dma address error (bsc#1245750). - CVE-2025-38162: netfilter: nft_set_pipapo: prevent overflow in lookup table allocation (bsc#1245752). - CVE-2025-38166: bpf: fix ktls panic with sockmap (bsc#1245758). - CVE-2025-38180: net: atm: fix /proc/net/atm/lec handling (bsc#1245970). - CVE-2025-38182: ublk: santizize the arguments from userspace when adding a device (bsc#1245937). - CVE-2025-38183: net: lan743x: fix potential out-of-bounds write in lan743x_ptp_io_event_clock_get() (bsc#1246006). - CVE-2025-38187: drm/nouveau: fix a use-after-free in r535_gsp_rpc_push() (bsc#1245951). - CVE-2025-38188: drm/msm/a7xx: Call CP_RESET_CONTEXT_STATE (bsc#1246098). - CVE-2025-38200: i40e: fix MMIO write access to an invalid page in i40e_clear_hw (bsc#1246045). - CVE-2025-38202: bpf: Check rcu_read_lock_trace_held() in bpf_map_lookup_percpu_elem() (bsc#1245980). - CVE-2025-38203: jfs: Fix null-ptr-deref in jfs_ioc_trim (bsc#1246044). - CVE-2025-38204: jfs: fix array-index-out-of-bounds read in add_missing_indices (bsc#1245983). - CVE-2025-38206: exfat: fix double free in delayed_free (bsc#1246073). - CVE-2025-38210: configfs-tsm-report: Fix NULL dereference of tsm_ops (bsc#1246020). - CVE-2025-38212: ipc: fix to protect IPCS lookups using RCU (bsc#1246029). - CVE-2025-38220: ext4: only dirty folios when data journaling regular files (bsc#1245966). - CVE-2025-38222: ext4: inline: fix len overflow in ext4_prepare_inline_data (bsc#1245976). - CVE-2025-38236: af_unix: Disable MSG_OOB for unprivileged users (bsc#1246093). - CVE-2025-38239: scsi: megaraid_sas: Fix invalid node index (bsc#1246178). - CVE-2025-38244: smb: client: fix potential deadlock when reconnecting channels (bsc#1246183). - CVE-2025-38248: bridge: mcast: Fix use-after-free during router port configuration (bsc#1246173). - CVE-2025-38250: kABI workaround for bluetooth hci_dev changes (bsc#1246182). - CVE-2025-38256: io_uring/rsrc: fix folio unpinning (bsc#1246188). - CVE-2025-38264: llist: add interface to check if a node is on a list (bsc#1246387). - CVE-2025-38272: net: dsa: b53: do not enable EEE on bcm63xx (bsc#1246268). - CVE-2025-38279: kABI workaround for bpf: Do not include stack ptr register in precision backtracking bookkeeping (bsc#1246264). - CVE-2025-38283: hisi_acc_vfio_pci: bugfix live migration function without VF device driver (bsc#1246273). - CVE-2025-38303: Bluetooth: eir: Fix possible crashes on eir_create_adv_data (bsc#1246354). - CVE-2025-38310: seg6: Fix validation of nexthop addresses (bsc#1246361). - CVE-2025-38323: net: atm: add lec_mutex (bsc#1246473). - CVE-2025-38334: x86/sgx: Prevent attempts to reclaim poisoned pages (bsc#1246384). - CVE-2025-38335: Input: gpio-keys - fix a sleep while atomic with PREEMPT_RT (bsc#1246250). - CVE-2025-38337: jbd2: fix data-race and null-ptr-deref in jbd2_journal_dirty_metadata() (bsc#1246253). - CVE-2025-38349: eventpoll: do not decrement ep refcount while still holding the ep mutex (bsc#1246777). - CVE-2025-38350: net/sched: Always pass notifications when child class becomes empty (bsc#1246781). - CVE-2025-38352: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() (bsc#1246911). - CVE-2025-38364: maple_tree: fix MA_STATE_PREALLOC flag in mas_preallocate() (bsc#1247091). - CVE-2025-38365: btrfs: fix a race between renames and directory logging (bsc#1247023). - CVE-2025-38375: virtio-net: ensure the received length does not exceed allocated size (bsc#1247177). - CVE-2025-38382: btrfs: fix iteration of extrefs during log replay (bsc#1247031). - CVE-2025-38392: idpf: convert control queue mutex to a spinlock (bsc#1247169). - CVE-2025-38396: fs: export anon_inode_make_secure_inode() and fix secretmem LSM bypass (bsc#1247156). - CVE-2025-38399: scsi: target: Fix NULL pointer dereference in core_scsi3_decode_spec_i_port() (bsc#1247097). - CVE-2025-38403: vsock/vmci: Clear the vmci transport packet properly when initializing it (bsc#1247141). - CVE-2025-38414: wifi: ath12k: fix GCC_GCC_PCIE_HOT_RST definition for WCN7850 (bsc#1247145). - CVE-2025-38426: drm/amdgpu: Add basic validation for RAS header (bsc#1247252). - CVE-2025-38429: bus: mhi: ep: Update read pointer only after buffer is written (bsc#1247253). - CVE-2025-38453: kABI: io_uring: msg_ring ensure io_kiocb freeing is deferred (bsc#1247234). - CVE-2025-38455: KVM: SVM: Reject SEV{-ES} intra host migration if vCPU creation is in-flight (bsc#1247101). - CVE-2025-38457: net/sched: Abort __tc_modify_qdisc if parent class does not exist (bsc#1247098). - CVE-2025-38460: atm: clip: Fix potential null-ptr-deref in to_atmarpd() (bsc#1247143). - CVE-2025-38461: vsock: Fix transport_* TOCTOU (bsc#1247103). - CVE-2025-38462: vsock: Fix transport_{g2h,h2g} TOCTOU (bsc#1247104). - CVE-2025-38463: tcp: Correct signedness in skb remaining space calculation (bsc#1247113). - CVE-2025-38465: netlink: make sure we allow at least one dump skb (bsc#1247118). - CVE-2025-38470: kABI fix for net: vlan: fix VLAN 0 refcount imbalance of toggling (bsc#1247288). - CVE-2025-38471: tls: always refresh the queue when reading sock (bsc#1247450). - CVE-2025-38475: smc: Fix various oops due to inet_sock type confusion (bsc#1247308). - CVE-2025-38497: usb: gadget: configfs: Fix OOB read on empty string write (bsc#1247347). - CVE-2025-38498: do_change_type(): refuse to operate on unmounted/not ours mounts (bsc#1247374). The following non-security bugs were fixed: - accel/ivpu: Remove copy engine support (stable-fixes). - acpi: LPSS: Remove AudioDSP related ID (git-fixes). - acpi: PRM: Reduce unnecessary printing to avoid user confusion (bsc#1246122). - acpi: processor: perflib: Fix initial _PPC limit application (git-fixes). - acpica: Refuse to evaluate a method if arguments are missing (stable-fixes). - af_packet: fix the SO_SNDTIMEO constraint not effective on tpacked_snd() (git-fixes). - af_unix: Add a prompt to CONFIG_AF_UNIX_OOB (bsc#1246093). - alsa: hda/ca0132: Fix missing error handling in ca0132_alt_select_out() (git-fixes). - alsa: hda/realtek - Add mute LED support for HP Pavilion 15-eg0xxx (stable-fixes). - alsa: hda/realtek - Enable mute LED on HP Pavilion Laptop 15-eg100 (stable-fixes). - alsa: hda/realtek: Add quirk for ASUS ROG Strix G712LWS (stable-fixes). - alsa: hda/realtek: Fix mute LED mask on HP OMEN 16 laptop (git-fixes). - alsa: hda/tegra: Add Tegra264 support (stable-fixes). - alsa: hda: Add missing NVIDIA HDA codec IDs (stable-fixes). - alsa: hda: Add new pci id for AMD GPU display HD audio controller (stable-fixes). - alsa: hda: Ignore unsol events for cards being shut down (stable-fixes). - alsa: intel_hdmi: Fix off-by-one error in __hdmi_lpe_audio_probe() (git-fixes). - alsa: sb: Do not allow changing the DMA mode during operations (stable-fixes). - alsa: sb: Force to disable DMAs once when DMA mode is changed (stable-fixes). - alsa: scarlett2: Add retry on -EPROTO from scarlett2_usb_tx() (git-fixes). - amd/amdkfd: fix a kfd_process ref leak (stable-fixes). - aoe: clean device rq_list in aoedev_downdev() (git-fixes). - apple-mfi-fastcharge: protect first device name (git-fixes). - asoc: amd: yc: Add DMI quirk for Lenovo IdeaPad Slim 5 15 (stable-fixes). - asoc: amd: yc: Add quirk for MSI Bravo 17 D7VF internal mic (stable-fixes). - asoc: amd: yc: add quirk for Acer Nitro ANV15-41 internal mic (stable-fixes). - asoc: amd: yc: update quirk data for HP Victus (stable-fixes). - asoc: codec: wcd9335: Convert to GPIO descriptors (stable-fixes). - asoc: codecs: wcd9335: Fix missing free of regulator supplies (git-fixes). - asoc: codecs: wcd9335: Handle nicer probe deferral and simplify with dev_err_probe() (stable-fixes). - asoc: cs35l56: probe() should fail if the device ID is not recognized (git-fixes). - asoc: fsl_asrc: use internal measured ratio for non-ideal ratio mode (git-fixes). - asoc: fsl_sai: Force a software reset when starting in consumer mode (git-fixes). - asoc: fsl_xcvr: get channel status data when PHY is not exists (git-fixes). - asoc: mediatek: use reserved memory or enable buffer pre-allocation (git-fixes). - asoc: ops: dynamically allocate struct snd_ctl_elem_value (git-fixes). - asoc: soc-dai: tidyup return value of snd_soc_xlate_tdm_slot_mask() (git-fixes). - ata: pata_cs5536: fix build on 32-bit UML (stable-fixes). - audit,module: restore audit logging in load failure case (git-fixes). - bluetooth: Fix null-ptr-deref in l2cap_sock_resume_cb() (git-fixes). - bluetooth: HCI: Set extended advertising data synchronously (git-fixes). - bluetooth: L2CAP: Fix L2CAP MTU negotiation (stable-fixes). - bluetooth: L2CAP: Fix attempting to adjust outgoing MTU (git-fixes). - bluetooth: MGMT: Fix not generating command complete for MGMT_OP_DISCONNECT (git-fixes). - bluetooth: MGMT: mesh_send: check instances prior disabling advertising (git-fixes). - bluetooth: MGMT: set_mesh: update LE scan interval and window (git-fixes). - bluetooth: Prevent unintended pause by checking if advertising is active (git-fixes). - bluetooth: SMP: Fix using HCI_ERROR_REMOTE_USER_TERM on timeout (git-fixes). - bluetooth: SMP: If an unallowed command is received consider it a failure (git-fixes). - bluetooth: btintel: Check if controller is ISO capable on btintel_classify_pkt_type (git-fixes). - bluetooth: btusb: QCA: Fix downloading wrong NVM for WCN6855 GF variant without board ID (git-fixes). - bluetooth: hci_conn: Fix sending BT_HCI_CMD_LE_CREATE_CONN_CANCEL (git-fixes). - bluetooth: hci_core: add missing braces when using macro parameters (git-fixes). - bluetooth: hci_event: Fix not marking Broadcast Sink BIS as connected (git-fixes). - bluetooth: hci_event: Mask data status from LE ext adv reports (git-fixes). - bluetooth: hci_sync: Attempt to dequeue connection attempt (git-fixes). - bluetooth: hci_sync: Fix UAF on create_le_conn_complete (git-fixes). - bluetooth: hci_sync: Fix handling of HCI_OP_CREATE_CONN_CANCEL (git-fixes). - bluetooth: hci_sync: Fix not disabling advertising instance (git-fixes). - bluetooth: hci_sync: fix connectable extended advertising when using static random address (git-fixes). - bluetooth: hci_sync: revert some mesh modifications (git-fixes). - bnxt_en: Fix double invocation of bnxt_ulp_stop()/bnxt_ulp_start() (git-fixes). - bonding: Correctly support GSO ESP offload (git-fixes). - bpf, sockmap: Fix sk_msg_reset_curr (git-fixes). - bpf/lpm_trie: Inline longest_prefix_match for fastpath (git-fixes). - bpf/selftests: Check errno when percpu map value size exceeds (git-fixes). - bpf: Add a possibly-zero-sized read test (git-fixes). - bpf: Avoid __hidden__ attribute in static object (git-fixes). - bpf: Check percpu map value size first (git-fixes). - bpf: Disable some `attribute ignored' warnings in GCC (git-fixes). - bpf: Fix memory leak in bpf_core_apply (git-fixes). - bpf: Fix potential integer overflow in resolve_btfids (git-fixes). - bpf: Harden __bpf_kfunc tag against linker kfunc removal (git-fixes). - bpf: Make the pointer returned by iter next method valid (git-fixes). - bpf: Simplify checking size of helper accesses (git-fixes). - bpf: fix order of args in call to bpf_map_kvcalloc (git-fixes). - bpf: sockmap, updating the sg structure should also update curr (git-fixes). - bpftool: Fix missing pids during link show (git-fixes). - bpftool: Fix undefined behavior caused by shifting into the sign bit (git-fixes). - bpftool: Mount bpffs on provided dir instead of parent dir (git-fixes). - bpftool: Remove unnecessary source files from bootstrap version (git-fixes). - bpftool: Un-const bpf_func_info to fix it for llvm 17 and newer (git-fixes). - btrfs: do not ignore inode missing when replaying log tree (git-fixes). - btrfs: do not silently ignore unexpected extent type when replaying log (git-fixes). - btrfs: do not skip remaining extrefs if dir not found during log replay (git-fixes). - btrfs: explicitly ref count block_group on new_bgs list (bsc#1243068) - btrfs: fix assertion when building free space tree (git-fixes). - btrfs: fix inode lookup error handling during log replay (git-fixes). - btrfs: fix invalid inode pointer dereferences during log replay (git-fixes). - btrfs: fix log tree replay failure due to file with 0 links and extents (git-fixes). - btrfs: fix missing error handling when searching for inode refs during log replay (git-fixes). - btrfs: fix non-empty delayed iputs list on unmount due to async workers (git-fixes). - btrfs: fix ssd_spread overallocation (git-fixes). - btrfs: make btrfs_discard_workfn() block_group ref explicit (bsc#1243068) - btrfs: propagate last_unlink_trans earlier when doing a rmdir (git-fixes). - btrfs: rename err to ret in btrfs_rmdir() (git-fixes). - btrfs: return a btrfs_inode from btrfs_iget_logging() (git-fixes). - btrfs: return a btrfs_inode from read_one_inode() (git-fixes). - btrfs: tests: fix chunk map leak after failure to add it to the tree (git-fixes). - btrfs: update superblock's device bytes_used when dropping chunk (git-fixes). - btrfs: use NOFS context when getting inodes during logging and log replay (git-fixes). - btrfs: use btrfs_record_snapshot_destroy() during rmdir (git-fixes). - bus: fsl-mc: Fix potential double device reference in fsl_mc_get_endpoint() (git-fixes). - bus: mhi: host: Detect events pointing to unexpected TREs (git-fixes). - can: dev: can_restart(): move debug message and stats after successful restart (stable-fixes). - can: dev: can_restart(): reverse logic to remove need for goto (stable-fixes). - can: kvaser_pciefd: Store device channel index (git-fixes). - can: kvaser_usb: Assign netdev.dev_port based on device channel index (git-fixes). - can: m_can: m_can_handle_lost_msg(): downgrade msg lost in rx message to debug level (git-fixes). - can: netlink: can_changelink(): fix NULL pointer deref of struct can_priv::do_set_mode (git-fixes). - can: peak_usb: fix USB FD devices potential malfunction (git-fixes). - cdc-acm: fix race between initial clearing halt and open (git-fixes). - cgroup,freezer: fix incomplete freezing when attaching tasks (bsc#1245789). - cgroup/cpuset: Extend kthread_is_per_cpu() check to all PF_NO_SETAFFINITY tasks (bsc#1241166). - cifs: reconnect helper should set reconnect for the right channel (git-fixes). - clk: clk-axi-clkgen: fix fpfd_max frequency for zynq (git-fixes). - clk: davinci: Add NULL check in davinci_lpsc_clk_register() (git-fixes). - clk: sunxi-ng: v3s: Fix de clock definition (git-fixes). - clk: xilinx: vcu: unregister pll_post only if registered correctly (git-fixes). - clocksource: Scale the watchdog read retries automatically (bsc#1241345 bsc#1244457). - clocksource: Set cs_watchdog_read() checks based on .uncertainty_margin (bsc#1241345 bsc#1244457). - comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large (git-fixes). - comedi: Fix initialization of data for instructions that write to subdevice (git-fixes). - comedi: Fix some signed shift left operations (git-fixes). - comedi: Fix use of uninitialized data in insn_rw_emulate_bits() (git-fixes). - comedi: aio_iiro_16: Fix bit shift out of bounds (git-fixes). - comedi: das16m1: Fix bit shift out of bounds (git-fixes). - comedi: das6402: Fix bit shift out of bounds (git-fixes). - comedi: pcl812: Fix bit shift out of bounds (git-fixes). - compiler_types.h: Define __retain for __attribute__((__retain__)) (git-fixes). - crypto: arm/aes-neonbs - work around gcc-15 warning (git-fixes). - crypto: ccp - Fix crash when rebind ccp device for ccp.ko (git-fixes). - crypto: ccp - Fix locking on alloc failure handling (git-fixes). - crypto: hkdf - skip TVs with unapproved salt lengths in FIPS mode (bsc#1241200 bsc#1246134). - crypto: img-hash - Fix dma_unmap_sg() nents value (git-fixes). - crypto: inside-secure - Fix `dma_unmap_sg()` nents value (git-fixes). - crypto: keembay - Fix dma_unmap_sg() nents value (git-fixes). - crypto: marvell/cesa - Fix engine load inaccuracy (git-fixes). - crypto: qat - allow enabling VFs in the absence of IOMMU (git-fixes). - crypto: qat - disable ZUC-256 capability for QAT GEN5 (git-fixes). - crypto: qat - fix DMA direction for compression on GEN2 devices (git-fixes). - crypto: qat - fix seq_file position update in adf_ring_next() (git-fixes). - crypto: qat - fix state restore for banks with exceptions (git-fixes). - crypto: qat - flush misc workqueue during device shutdown (git-fixes). - crypto: qat - use unmanaged allocation for dc_data (git-fixes). - crypto: sun8i-ce - fix nents passed to dma_unmap_sg() (git-fixes). - dax: add a sysfs knob to control memmap_on_memory behavior (bsc#1235515,jsc#PED-12731). - dax: add a sysfs knob to control memmap_on_memory behavior (bsc#1235515,jsc#PED-12731). - devlink: Add support for u64 parameters (jsc#PED-12745). - devlink: Add support for u64 parameters (jsc#PED-12745). - devlink: avoid param type value translations (jsc#PED-12745). - devlink: avoid param type value translations (jsc#PED-12745). - devlink: define enum for attr types of dynamic attributes (jsc#PED-12745). - devlink: define enum for attr types of dynamic attributes (jsc#PED-12745). - devlink: introduce devlink_nl_put_u64() (jsc#PED-12745). - devlink: introduce devlink_nl_put_u64() (jsc#PED-12745). - dm-bufio: fix sched in atomic context (git-fixes). - dm-flakey: error all IOs when num_features is absent (git-fixes). - dm-flakey: make corrupting read bios work (git-fixes). - dm-mirror: fix a tiny race condition (git-fixes). - dm-raid: fix variable in journal device check (git-fixes). - dm-verity: fix a memory leak if some arguments are specified multiple times (git-fixes). - dm: do not change md if dm_table_set_restrictions() fails (git-fixes). - dm: free table mempools if not used in __bind (git-fixes). - dm: restrict dm device size to 2^63-512 bytes (git-fixes). - dma-buf: fix timeout handling in dma_resv_wait_timeout v2 (stable-fixes). - dmaengine: dw-edma: Drop unused dchan2dev() and chan2dev() (git-fixes). - dmaengine: idxd: Check availability of workqueue allocated by idxd wq driver before using (stable-fixes). - dmaengine: mv_xor: Fix missing check after DMA map and missing unmap (git-fixes). - dmaengine: nbpfaxi: Add missing check after DMA map (git-fixes). - dmaengine: nbpfaxi: Fix memory corruption in probe() (git-fixes). - dmaengine: qcom: gpi: Drop unused gpi_write_reg_field() (git-fixes). - dmaengine: xilinx_dma: Set dma_device directions (stable-fixes). - docs/ABI: Fix sysfs-kernel-address_bits path (git-fixes). - documentatiion/ABI: add ABI documentation for sys-bus-dax (bsc#1235515,jsc#PED-12731). - documentation/ABI: add ABI documentation for sys-bus-dax (bsc#1235515,jsc#PED-12731). - documentation: ACPI: Fix parent device references (git-fixes). - documentation: usb: gadget: Wrap remaining usage snippets in literal code block (git-fixes). - dpll: Add basic Microchip ZL3073x support (jsc#PED-12745). - dpll: Add basic Microchip ZL3073x support (jsc#PED-12745). - dpll: zl3073x: Add support to get/set frequency on pins (jsc#PED-12745). - dpll: zl3073x: Add support to get/set frequency on pins (jsc#PED-12745). - dpll: zl3073x: Add support to get/set priority on input pins (jsc#PED-12745). - dpll: zl3073x: Add support to get/set priority on input pins (jsc#PED-12745). - dpll: zl3073x: Fetch invariants during probe (jsc#PED-12745). - dpll: zl3073x: Fetch invariants during probe (jsc#PED-12745). - dpll: zl3073x: Implement input pin selection in manual mode (jsc#PED-12745). - dpll: zl3073x: Implement input pin selection in manual mode (jsc#PED-12745). - dpll: zl3073x: Implement input pin state setting in automatic mode (jsc#PED-12745). - dpll: zl3073x: Implement input pin state setting in automatic mode (jsc#PED-12745). - dpll: zl3073x: Read DPLL types and pin properties from system firmware (jsc#PED-12745). - dpll: zl3073x: Read DPLL types and pin properties from system firmware (jsc#PED-12745). - dpll: zl3073x: Register DPLL devices and pins (jsc#PED-12745). - dpll: zl3073x: Register DPLL devices and pins (jsc#PED-12745). - drm/amd/display: Check dce_hwseq before dereferencing it (stable-fixes). - drm/amd/display: Correct non-OLED pre_T11_delay (stable-fixes). - drm/amd/display: Disable CRTC degamma LUT for DCN401 (stable-fixes). - drm/amd/display: Do not overwrite dce60_clk_mgr (git-fixes). - drm/amd/display: Fix RMCM programming seq errors (stable-fixes). - drm/amd/display: Fix mpv playback corruption on weston (stable-fixes). - drm/amd/display: Free memory allocation (stable-fixes). - drm/amd/display: fix initial backlight brightness calculation (git-fixes). - drm/amd/pm/powerplay/hwmgr/smu_helper: fix order of mask and value (git-fixes). - drm/amdgpu/discovery: use specific ip_discovery.bin for legacy asics (stable-fixes). - drm/amdgpu/gfx10: fix kiq locking in KCQ reset (git-fixes). - drm/amdgpu/gfx8: reset compute ring wptr on the GPU on resume (git-fixes). - drm/amdgpu/gfx9.4.3: fix kiq locking in KCQ reset (git-fixes). - drm/amdgpu/gfx9: fix kiq locking in KCQ reset (git-fixes). - drm/amdgpu/ip_discovery: add missing ip_discovery fw (stable-fixes). - drm/amdgpu: Add kicker device detection (stable-fixes). - drm/amdgpu: Fix SDMA UTC_L1 handling during start/stop sequences (stable-fixes). - drm/amdgpu: Increase reset counter only on success (stable-fixes). - drm/amdgpu: Initialize data to NULL in imu_v12_0_program_rlc_ram() (git-fixes). - drm/amdgpu: Remove nbiov7.9 replay count reporting (git-fixes). - drm/amdgpu: Reset the clear flag in buddy during resume (git-fixes). - drm/amdgpu: amdgpu_vram_mgr_new(): Clamp lpfn to total vram (stable-fixes). - drm/amdgpu: seq64 memory unmap uses uninterruptible lock (stable-fixes). - drm/amdkfd: Do not call mmput from MMU notifier callback (git-fixes). - drm/amdkfd: Fix instruction hazard in gfx12 trap handler (stable-fixes). - drm/amdkfd: Fix race in GWS queue scheduling (stable-fixes). - drm/amdkfd: remove gfx 12 trap handler page size cap (stable-fixes). - drm/bridge: aux-hpd-bridge: fix assignment of the of_node (git-fixes). - drm/bridge: panel: move prepare_prev_first handling to drm_panel_bridge_add_typed (git-fixes). - drm/bridge: ti-sn65dsi86: Add HPD for DisplayPort connector type (git-fixes). - drm/bridge: ti-sn65dsi86: Remove extra semicolon in ti_sn_bridge_probe() (git-fixes). - drm/bridge: ti-sn65dsi86: make use of debugfs_init callback (stable-fixes). - drm/connector: hdmi: Evaluate limited range after computing format (git-fixes). - drm/exynos: exynos7_drm_decon: add vblank check in IRQ handling (git-fixes). - drm/exynos: fimd: Guard display clock control with runtime PM calls (git-fixes). - drm/framebuffer: Acquire internal references on GEM handles (git-fixes). - drm/gem: Acquire references on GEM handles for framebuffers (stable-fixes). - drm/gem: Fix race in drm_gem_handle_create_tail() (stable-fixes). - drm/i915/display: Fix dma_fence_wait_timeout() return value handling (git-fixes). - drm/i915/dsi: Fix off by one in BXT_MIPI_TRANS_VTOTAL (stable-fixes). - drm/i915/gsc: mei interrupt top half should be in irq disabled context (git-fixes). - drm/i915/gt: Fix timeline left held on VMA alloc error (git-fixes). - drm/i915/selftests: Change mock_request() to return error pointers (git-fixes). - drm/imagination: Fix kernel crash when hard resetting the GPU (git-fixes). - drm/mediatek: Add wait_event_timeout when disabling plane (git-fixes). - drm/mediatek: only announce AFBC if really supported (git-fixes). - drm/msm/dpu: Fill in min_prefill_lines for SC8180X (git-fixes). - drm/msm: Fix a fence leak in submit error path (stable-fixes). - drm/msm: Fix another leak in the submit error path (stable-fixes). - drm/nouveau: check ioctl command codes better (git-fixes). - drm/panfrost: Fix panfrost device variable name in devfreq (git-fixes). - drm/panthor: Add missing explicit padding in drm_panthor_gpu_info (git-fixes). - drm/rockchip: cleanup fb when drm_gem_fb_afbc_init failed (git-fixes). - drm/sched: Increment job count before swapping tail spsc queue (git-fixes). - drm/sched: Remove optimization that causes hang when killing dependent jobs (git-fixes). - drm/scheduler: signal scheduled fence when kill job (stable-fixes). - drm/tegra: nvdec: Fix dma_alloc_coherent error check (git-fixes). - drm/ttm: fix error handling in ttm_buffer_object_transfer (git-fixes). - drm/v3d: Disable interrupts before resetting the GPU (git-fixes). - drm/vmwgfx: Fix Host-Backed userspace on Guest-Backed kernel (git-fixes). - drm/xe/bmg: fix compressed VRAM handling (git-fixes). - drm/xe/guc: Dead CT helper (stable-fixes). - drm/xe/guc: Explicitly exit CT safe mode on unwind (git-fixes). - drm/xe/guc_submit: add back fix (git-fixes). - drm/xe/mocs: Initialize MOCS index early (stable-fixes). - drm/xe/pf: Clear all LMTT pages on alloc (git-fixes). - drm/xe/pf: Move VFs reprovisioning to worker (stable-fixes). - drm/xe/pf: Prepare to stop SR-IOV support prior GT reset (git-fixes). - drm/xe/pf: Sanitize VF scratch registers on FLR (stable-fixes). - drm/xe/pm: Correct comment of xe_pm_set_vram_threshold() (git-fixes). - drm/xe/uapi: Correct sync type definition in comments (git-fixes). - drm/xe/vf: Disable CSC support on VF (git-fixes). - drm/xe: Allocate PF queue size on pow2 boundary (git-fixes). - drm/xe: Allow bo mapping on multiple ggtts (stable-fixes). - drm/xe: Fix DSB buffer coherency (stable-fixes). - drm/xe: Fix build without debugfs (git-fixes). - drm/xe: Fix early wedge on GuC load failure (git-fixes). - drm/xe: Fix taking invalid lock on wedge (stable-fixes). - drm/xe: Move DSB l2 flush to a more sensible place (git-fixes). - drm/xe: Replace double space with single space after comma (stable-fixes). - drm/xe: add interface to request physical alignment for buffer objects (stable-fixes). - drm/xe: move DPT l2 flush to a more sensible place (git-fixes). - dt-bindings: dpll: Add DPLL device and pin (jsc#PED-12745). - dt-bindings: dpll: Add DPLL device and pin (jsc#PED-12745). - dt-bindings: dpll: Add support for Microchip Azurite chip family (jsc#PED-12745). - dt-bindings: dpll: Add support for Microchip Azurite chip family (jsc#PED-12745). - e1000: Move cancel_work_sync to avoid deadlock (git-fixes). - enable SMC_LO (a.k.a SMC-D) (jsc#PED-13248). - exfat: fdatasync flag should be same like generic_write_sync() (git-fixes). - fbcon: Fix outdated registered_fb reference in comment (git-fixes). - fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref (git-fixes). - firewire: ohci: correct code comments about bus_reset tasklet (git-fixes). - fix dma_unmap_sg() nents value (git-fixes) - fs/jfs: consolidate sanity checking in dbMount (git-fixes). - fs/orangefs: Allow 2 more characters in do_c_string() (git-fixes). - gpio: mlxbf2: use platform_get_irq_optional() (git-fixes). - gpio: pca953x: log an error when failing to get the reset GPIO (git-fixes). - gpio: sim: include a missing header (git-fixes). - gpio: vf610: add locking to gpio direction functions (git-fixes). - gpio: virtio: Fix config space reading (git-fixes). - gpiolib: Fix debug messaging in gpiod_find_and_request() (git-fixes). - gpiolib: Handle no pin_ranges in gpiochip_generic_config() (git-fixes). - gpiolib: acpi: Do not use GPIO chip fwnode in acpi_gpiochip_find() (bsc#1233300). - gpiolib: acpi: Fix failed in acpi_gpiochip_find() by adding parent node match (bsc#1233300). - gpiolib: cdev: Ignore reconfiguration without direction (git-fixes). - gpiolib: of: Add polarity quirk for s5m8767 (stable-fixes). - hfs: make splice write available again (git-fixes). - hfsplus: make splice write available again (git-fixes). - hfsplus: remove mutex_lock check in hfsplus_free_extents (git-fixes). - hid: Add IGNORE quirk for SMARTLINKTECHNOLOGY (stable-fixes). - hid: core: do not bypass hid_hw_raw_request (stable-fixes). - hid: core: ensure __hid_request reserves the report ID as the first byte (git-fixes). - hid: core: ensure the allocated report buffer can contain the reserved report ID (stable-fixes). - hid: lenovo: Add support for ThinkPad X1 Tablet Thin Keyboard Gen2 (stable-fixes). - hid: quirks: Add quirk for 2 Chicony Electronics HP 5MP Cameras (stable-fixes). - hv_netvsc: Use VF's tso_max_size value when data path is VF (bsc#1246203). - hwmon: (corsair-cpro) Validate the size of the received input buffer (git-fixes). - hwmon: (gsc-hwmon) fix fan pwm setpoint show functions (git-fixes). - hwmon: (pmbus/max34440) Fix support for max34451 (stable-fixes). - hwrng: mtk - handle devm_pm_runtime_enable errors (git-fixes). - i2c/designware: Fix an initialization issue (git-fixes). - i2c: qup: jump out of the loop in case of timeout (git-fixes). - i2c: stm32: fix the device used for the DMA map (git-fixes). - i2c: tegra: Fix reset error handling with ACPI (git-fixes). - i2c: virtio: Avoid hang by using interruptible completion wait (git-fixes). - i3c: fix module_i3c_i2c_driver() with I3C=n (git-fixes). - ib/mlx5: Fix potential deadlock in MR deregistration (git-fixes) - ice, irdma: fix an off by one in error handling code (bsc#1247712). - ice, irdma: move interrupts code to irdma (bsc#1247712). - ice: Fix signedness bug in ice_init_interrupt_scheme() (bsc#1247712). - ice: count combined queues using Rx/Tx count (bsc#1247712). - ice: devlink PF MSI-X max and min parameter (bsc#1247712). - ice: enable_rdma devlink param (bsc#1247712). - ice: fix eswitch code memory leak in reset scenario (git-fixes). - ice: get rid of num_lan_msix field (bsc#1247712). - ice: init flow director before RDMA (bsc#1247712). - ice: remove splitting MSI-X between features (bsc#1247712). - ice: simplify VF MSI-X managing (bsc#1247712). - ice: treat dyn_allowed only as suggestion (bsc#1247712). - iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush (git-fixes). - iio: adc: ad7949: use spi_is_bpw_supported() (git-fixes). - iio: adc: ad_sigma_delta: Fix use of uninitialized status_pos (stable-fixes). - iio: adc: ad_sigma_delta: change to buffer predisable (git-fixes). - iio: adc: max1363: Fix MAX1363_4X_CHANS/MAX1363_8X_CHANS[] (stable-fixes). - iio: adc: max1363: Reorder mode_list[] entries (stable-fixes). - iio: adc: stm32-adc: Fix race in installing chained IRQ handler (git-fixes). - iio: imu: bno055: fix OOB access of hw_xlate array (git-fixes). - iio: pressure: zpa2326: Use aligned_s64 for the timestamp (stable-fixes). - input: iqs7222 - explicitly define number of external channels (git-fixes). - input: xpad - adjust error handling for disconnect (git-fixes). - input: xpad - set correct controller type for Acer NGR200 (git-fixes). - input: xpad - support Acer NGR 200 Controller (stable-fixes). - io_uring/timeout: fix multishot updates (bsc#1247021). - io_uring: fix potential page leak in io_sqe_buffer_register() (git-fixes). - iommu/amd: Fix geometry.aperture_end for V2 tables (git-fixes). - iommu/amd: Set the pgsize_bitmap correctly (git-fixes). - iommu/arm-smmu-qcom: Add SM6115 MDSS compatible (git-fixes). - iommu/tegra241-cmdqv: Read SMMU IDR1.CMDQS instead of hardcoding (git-fixes). - iommu/vt-d: Fix possible circular locking dependency (git-fixes). - iommu/vt-d: Fix system hang on reboot -f (git-fixes). - ipv6: fix possible infinite loop in fib6_info_uses_dev() (git-fixes). - ipv6: mcast: Delay put pmc->idev in mld_del_delrec() (git-fixes). - ipv6: prevent infinite loop in rt6_nlmsg_size() (git-fixes). - ipv6: reject malicious packets in ipv6_gso_segment() (git-fixes). - irdma: free iwdev->rf after removing MSI-X (bsc#1247712). - iwlwifi: Add missing check for alloc_ordered_workqueue (git-fixes). - jfs: fix metapage reference count leak in dbAllocCtl (git-fixes). - kABI fix after KVM: SVM: Fix SNP AP destroy race with VMRUN (git-fixes). - kABI fixes for struct memory_block changes (bsc#1235515,jsc#PED-12731). - kABI fixes for struct memory_block changes (bsc#1235515,jsc#PED-12731). - kABI workaround for fw_attributes_class_get() (stable-fixes). - kABI workaround for struct drm_framebuffer changes (git-fixes). - kABI: Fix the module::name type in audit_context (git-fixes). - kabi/severities: ignore two unused/dropped symbols from MEI - kabi: Hide adding of u64 to devlink_param_type (jsc#PED-12745). - kabi: Hide adding of u64 to devlink_param_type (jsc#PED-12745). - kasan: remove kasan_find_vm_area() to prevent possible deadlock (git-fixes). - kernel-obs-qa: Do not depend on srchash when qemu emulation is used In this case the dependency is never fulfilled Fixes: 485ae1da2b88 ('kernel-obs-qa: Use srchash for dependency as well') - kernel-syms.spec: Drop old rpm release number hack (bsc#1247172). - kvm: SVM: Fix SNP AP destroy race with VMRUN (git-fixes). - leds: multicolor: Fix intensity setting while SW blinking (stable-fixes). - lib/group_cpus.c: avoid acquiring cpu hotplug lock in group_cpus_evenly (bsc#1236897). - lib/group_cpus: fix NULL pointer dereference from group_cpus_evenly() (bsc#1236897). - logitech C-270 even more broken (stable-fixes). - maple_tree: fix mt_destroy_walk() on root leaf node (git-fixes). - md/md-bitmap: fix dm-raid max_write_behind setting (git-fixes). - media: gspca: Add bounds checking to firmware parser (git-fixes). - media: hi556: correct the test pattern configuration (git-fixes). - media: imx: fix a potential memory leak in imx_media_csc_scaler_device_init() (git-fixes). - media: ipu6: isys: Use correct pads for xlate_streams() (git-fixes). - media: ivsc: Fix crash at shutdown due to missing mei_cldev_disable() calls (git-fixes). - media: ov2659: Fix memory leaks in ov2659_probe() (git-fixes). - media: rainshadow-cec: fix TOCTOU race condition in rain_interrupt() (git-fixes). - media: usbtv: Lock resolution while streaming (git-fixes). - media: uvcvideo: Do not mark valid metadata as invalid (git-fixes). - media: uvcvideo: Fix 1-byte out-of-bounds read in uvc_parse_format() (git-fixes). - media: v4l2-ctrls: Do not reset handler's error in v4l2_ctrl_handler_free() (git-fixes). - media: v4l2-ctrls: Fix H264 SEPARATE_COLOUR_PLANE check (git-fixes). - media: venus: Add a check for packet size after reading from shared memory (git-fixes). - media: venus: hfi: explicitly release IRQ during teardown (git-fixes). - media: venus: protect against spurious interrupts during probe (git-fixes). - media: venus: vdec: Clamp param smaller than 1fps and bigger than 240 (git-fixes). - media: venus: venc: Clamp param smaller than 1fps and bigger than 240 (git-fixes). - media: verisilicon: Fix AV1 decoder clock frequency (git-fixes). - media: vivid: fix wrong pixel_array control size (git-fixes). - mei: vsc: Destroy mutex after freeing the IRQ (git-fixes). - mei: vsc: Do not re-init VSC from mei_vsc_hw_reset() on stop (git-fixes). - mei: vsc: Drop unused vsc_tp_request_irq() and vsc_tp_free_irq() (stable-fixes). - mei: vsc: Event notifier fixes (git-fixes). - mei: vsc: Fix 'BUG: Invalid wait context' lockdep error (git-fixes). - mei: vsc: Run event callback from a workqueue (git-fixes). - mei: vsc: Unset the event callback on remove and probe errors (git-fixes). - memstick: core: Zero initialize id_reg in h_memstick_read_dev_id() (git-fixes). - mfd: max14577: Fix wakeup source leaks on device unbind (stable-fixes). - misc: rtsx: usb: Ensure mmc child device is active when card is present (git-fixes). - mm/memory_hotplug: allow architecture to override memmap on memory support check (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: allow architecture to override memmap on memory support check (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: allow memmap on memory hotplug request to fallback (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: allow memmap on memory hotplug request to fallback (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: embed vmem_altmap details in memory block (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: embed vmem_altmap details in memory block (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: export mhp_supports_memmap_on_memory() (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: export mhp_supports_memmap_on_memory() (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: fix memmap_on_memory sysfs value retrieval (git-fixes). - mm/memory_hotplug: replace an open-coded kmemdup() in (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: replace an open-coded kmemdup() in (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: simplify ARCH_MHP_MEMMAP_ON_MEMORY_ENABLE kconfig (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: simplify ARCH_MHP_MEMMAP_ON_MEMORY_ENABLE kconfig (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: split memmap_on_memory requests across memblocks (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: split memmap_on_memory requests across memblocks (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: support memmap_on_memory when memmap is not aligned to pageblocks (bsc#1235515,jsc#PED-12731). - mm/memory_hotplug: support memmap_on_memory when memmap is not aligned to pageblocks (bsc#1235515,jsc#PED-12731). - mmc: bcm2835: Fix dma_unmap_sg() nents value (git-fixes). - mmc: core: sd: Apply BROKEN_SD_DISCARD quirk earlier (git-fixes). - mmc: sdhci-pci: Quirk for broken command queuing on Intel GLK-based Positivo models (git-fixes). - mmc: sdhci: Add a helper function for dump register in dynamic debug mode (stable-fixes). - mmc: sdhci_am654: Workaround for Errata i2312 (git-fixes). - module: Fix memory deallocation on error path in move_module() (git-fixes). - module: Remove unnecessary +1 from last_unloaded_module::name size (git-fixes). - module: Restore the moduleparam prefix length check (git-fixes). - mtd: fix possible integer overflow in erase_xfer() (git-fixes). - mtd: rawnand: atmel: Fix dma_mapping_error() address (git-fixes). - mtd: rawnand: atmel: set pmecc data setup time (git-fixes). - mtd: rawnand: fsmc: Add missing check after DMA map (git-fixes). - mtd: rawnand: renesas: Add missing check after DMA map (git-fixes). - mtd: rawnand: rockchip: Add missing check after DMA map (git-fixes). - mtd: spi-nor: Fix spi_nor_try_unlock_all() (git-fixes). - mtd: spinand: fix memory leak of ECC engine conf (stable-fixes). - mtd: spinand: propagate spinand_wait() errors from spinand_write_page() (git-fixes). - mtk-sd: Fix a pagefault in dma_unmap_sg() for not prepared data (git-fixes). - mtk-sd: Prevent memory corruption from DMA map failure (git-fixes). - mtk-sd: reset host->mrq on prepare_data() error (git-fixes). - mwl8k: Add missing check after DMA map (git-fixes). - nbd: fix uaf in nbd_genl_connect() error path (git-fixes). - net/mlx5: HWS, fix missing ip_version handling in definer (git-fixes). - net/packet: fix a race in packet_set_ring() and packet_notifier() (git-fixes). - net/sched: Restrict conditions for adding duplicating netems to qdisc tree (git-fixes). - net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree (git-fixes). - net/sched: mqprio: fix stack out-of-bounds write in tc entry parsing (git-fixes). - net/sched: sch_qfq: Avoid triggering might_sleep in atomic context in qfq_delete_class (git-fixes). - net/sched: sch_qfq: Fix race condition on qfq_aggregate (git-fixes). - net/sched: taprio: enforce minimum value for picos_per_byte (git-fixes). - net/smc: Fix lookup of netdev by using ib_device_get_netdev() (git-fixes bsc#1246217). - net: mana: Add debug logs in MANA network driver (bsc#1246212). - net: mana: Add handler for hardware servicing events (bsc#1245730). - net: mana: Allocate MSI-X vectors dynamically (bsc#1245457). - net: mana: Allow irq_setup() to skip cpus for affinity (bsc#1245457). - net: mana: Allow tso_max_size to go up-to GSO_MAX_SIZE (bsc#1246203). - net: mana: Expose additional hardware counters for drop and TC via ethtool (bsc#1245729). - net: mana: Set tx_packets to post gso processing packet count (bsc#1245731). - net: mana: explain irq_setup() algorithm (bsc#1245457). - net: phy: Do not register LEDs for genphy (git-fixes). - net: phy: micrel: fix KSZ8081/KSZ8091 cable test (git-fixes). - net: phy: microchip: limit 100M workaround to link-down events on LAN88xx (git-fixes). - net: phy: smsc: Fix Auto-MDIX configuration when disabled by strap (git-fixes). - net: phy: smsc: Fix link failure in forced mode with Auto-MDIX (git-fixes). - net: usb: lan78xx: fix WARN in __netif_napi_del_locked on disconnect (git-fixes). - net: usb: qmi_wwan: add SIMCom 8230C composition (stable-fixes). - net: usbnet: Avoid potential RCU stall on LINK_CHANGE event (git-fixes). - net: usbnet: Fix the wrong netif_carrier_on() call (git-fixes). - netlink: fix policy dump for int with validation callback (jsc#PED-12745). - netlink: fix policy dump for int with validation callback (jsc#PED-12745). - netlink: specs: devlink: replace underscores with dashes in names (jsc#PED-12745). - netlink: specs: devlink: replace underscores with dashes in names (jsc#PED-12745). - netlink: specs: nfsd: replace underscores with dashes in names (git-fixes). - netlink: specs: tc: replace underscores with dashes in names (git-fixes). - netpoll: prevent hanging NAPI when netcons gets enabled (git-fixes). - nfs: Clean up /proc/net/rpc/nfs when nfs_fs_proc_net_init() fails (git-fixes). - nfs: Fix filehandle bounds checking in nfs_fh_to_dentry() (git-fixes). - nfs: Fix the setting of capabilities when automounting a new filesystem (git-fixes). - nfs: Fix wakeup of __nfs_lookup_revalidate() in unblock_revalidate() (git-fixes). - nfs: Fixup allocation flags for nfsiod's __GFP_NORETRY (git-fixes). - nfsd: detect mismatch of file handle and delegation stateid in OPEN op (git-fixes). - nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() (git-fixes). - nfsv4.2: another fix for listxattr (git-fixes). - nfsv4.2: fix listxattr to return selinux security label (git-fixes). - nfsv4/pNFS: Fix a race to wake on NFS_LAYOUT_DRAIN (git-fixes). - nfsv4: Always set NLINK even if the server does not support it (git-fixes). - nfsv4: xattr handlers should check for absent nfs filehandles (git-fixes). - nilfs2: reject invalid file types when reading inodes (git-fixes). - nvme-pci: refresh visible attrs after being checked (git-fixes). - nvme: Fix incorrect cdw15 value in passthru error logging (git-fixes). - nvme: fix endianness of command word prints in nvme_log_err_passthru() (git-fixes). - nvme: fix inconsistent RCU list manipulation in nvme_ns_add_to_ctrl_list() (git-fixes). - nvme: fix misaccounting of nvme-mpath inflight I/O (git-fixes). - nvmet-tcp: fix callback lock for TLS handshake (git-fixes). - objtool: Fix INSN_CONTEXT_SWITCH handling in validate_unret() (git-fixes). - objtool: Fix UNWIND_HINT_{SAVE,RESTORE} across basic blocks (git-fixes). - objtool: Fix _THIS_IP_ detection for cold functions (git-fixes). - objtool: Fix error handling inconsistencies in check() (git-fixes). - objtool: Ignore dangling jump table entries (git-fixes). - objtool: Ignore end-of-section jumps for KCOV/GCOV (git-fixes). - objtool: Properly disable uaccess validation (git-fixes). - objtool: Silence more KCOV warnings (git-fixes). - objtool: Silence more KCOV warnings, part 2 (git-fixes). - objtool: Stop UNRET validation on UD2 (git-fixes). - pNFS/flexfiles: do not attempt pnfs on fatal DS errors (git-fixes). - pch_uart: Fix dma_sync_sg_for_device() nents value (git-fixes). - pci/msi: Export pci_msix_prepare_desc() for dynamic MSI-X allocations (bsc#1245457). - pci: dwc: Make link training more robust by setting PORT_LOGIC_LINK_WIDTH to one lane (stable-fixes). - pci: endpoint: Fix configfs group list head handling (git-fixes). - pci: endpoint: Fix configfs group removal on driver teardown (git-fixes). - pci: endpoint: pci-epf-vntb: Fix the incorrect usage of __iomem attribute (git-fixes). - pci: endpoint: pci-epf-vntb: Return -ENOENT if pci_epc_get_next_free_bar() fails (git-fixes). - pci: hv: Allow dynamic MSI-X vector allocation (bsc#1245457). - pci: rockchip-host: Fix 'Unexpected Completion' log message (git-fixes). - perf: Fix sample vs do_exit() (bsc#1246547). - phy: tegra: xusb: Fix unbalanced regulator disable in UTMI PHY mode (git-fixes). - pinctrl: amd: Clear GPIO debounce for suspend (git-fixes). - pinctrl: qcom: msm: mark certain pins as invalid for interrupts (git-fixes). - pinctrl: sunxi: Fix memory leak on krealloc failure (git-fixes). - pinmux: fix race causing mux_owner NULL with active mux_usecount (git-fixes). - platform/chrome: cros_ec: Unregister notifier in cros_ec_unregister() (git-fixes). - platform/mellanox: mlxbf-pmc: Fix duplicate event ID for CACHE_DATA1 (git-fixes). - platform/mellanox: mlxbf-tmfifo: fix vring_desc.len assignment (git-fixes). - platform/mellanox: mlxreg-lc: Fix logic error in power state check (git-fixes). - platform/mellanox: nvsw-sn2201: Fix bus number in adapter error message (git-fixes). - platform/x86/amd/pmc: Add PCSpecialist Lafite Pro V 14M to 8042 quirks list (stable-fixes). - platform/x86: Fix initialization order for firmware_attributes_class (git-fixes). - platform/x86: dell-sysman: Directly use firmware_attributes_class (stable-fixes). - platform/x86: dell-wmi-sysman: Fix WMI data block retrieval in sysfs callbacks (git-fixes). - platform/x86: dell-wmi-sysman: Fix class device unregistration (git-fixes). - platform/x86: firmware_attributes_class: Move include linux/device/class.h (stable-fixes). - platform/x86: firmware_attributes_class: Simplify API (stable-fixes). - platform/x86: hp-bioscfg: Directly use firmware_attributes_class (stable-fixes). - platform/x86: hp-bioscfg: Fix class device unregistration (git-fixes). - platform/x86: ideapad-laptop: Fix kbd backlight not remembered among boots (git-fixes). - platform/x86: make fw_attr_class constant (stable-fixes). - platform/x86: think-lmi: Create ksets consecutively (stable-fixes). - platform/x86: think-lmi: Directly use firmware_attributes_class (stable-fixes). - platform/x86: think-lmi: Fix class device unregistration (git-fixes). - platform/x86: think-lmi: Fix kobject cleanup (git-fixes). - platform/x86: think-lmi: Fix sysfs group cleanup (git-fixes). - pm / devfreq: Check governor before using governor->name (git-fixes). - power: supply: cpcap-charger: Fix null check for power_supply_get_by_name (git-fixes). - power: supply: max14577: Handle NULL pdata when CONFIG_OF is not set (git-fixes). - powercap: call put_device() on an error path in powercap_register_control_type() (stable-fixes). - powercap: dtpm_cpu: Fix NULL pointer dereference in get_pd_power_uw() (git-fixes). - powercap: intel_rapl: Do not change CLAMPING bit if ENABLE bit cannot be changed (git-fixes). - powerpc/bpf: enforce full ordering for ATOMIC operations with BPF_FETCH (git-fixes). - powerpc/pseries/dlpar: Search DRC index from ibm,drc-indexes for IO add (bsc#1243042 ltc#212167). - ptp: fix breakage after ptp_vclock_in_use() rework (bsc#1246506). - pwm: imx-tpm: Reset counter if CMOD is 0 (git-fixes). - pwm: mediatek: Ensure to disable clocks in error path (git-fixes). - pwm: rockchip: Round period/duty down on apply, up on get (git-fixes). - rdma/core: Rate limit GID cache warning messages (git-fixes) - rdma/counter: Check CAP_NET_RAW check in user namespace for RDMA counters (git-fixes) - rdma/hns: Drop GFP_NOWARN (git-fixes) - rdma/hns: Fix -Wframe-larger-than issue (git-fixes) - rdma/hns: Fix HW configurations not cleared in error flow (git-fixes) - rdma/hns: Fix accessing uninitialized resources (git-fixes) - rdma/hns: Fix double destruction of rsv_qp (git-fixes) - rdma/hns: Get message length of ack_req from FW (git-fixes) - rdma/mlx5: Check CAP_NET_RAW in user namespace for anchor create (git-fixes) - rdma/mlx5: Check CAP_NET_RAW in user namespace for devx create (git-fixes) - rdma/mlx5: Check CAP_NET_RAW in user namespace for flow create (git-fixes) - rdma/mlx5: Fix CC counters query for MPV (git-fixes) - rdma/mlx5: Fix HW counters query for non-representor devices (git-fixes) - rdma/mlx5: Fix UMR modifying of mkey page size (git-fixes) - rdma/mlx5: Fix compilation warning when USER_ACCESS isn't set (git-fixes) - rdma/mlx5: Fix vport loopback for MPV device (git-fixes) - rdma/mlx5: Initialize obj_event->obj_sub_list before xa_insert (git-fixes) - rdma/mlx5: reduce stack usage in mlx5_ib_ufile_hw_cleanup (git-fixes) - rdma/nldev: Check CAP_NET_RAW in user namespace for QP modify (git-fixes) - rdma/siw: Fix the sendmsg byte count in siw_tcp_sendpages (git-fixes) - rdma/uverbs: Add empty rdma_uattrs_has_raw_cap() declaration (git-fixes) - rdma/uverbs: Check CAP_NET_RAW in user namespace for QP create (git-fixes) - rdma/uverbs: Check CAP_NET_RAW in user namespace for RAW QP create (git-fixes) - rdma/uverbs: Check CAP_NET_RAW in user namespace for flow create (git-fixes) - re-enable qmi_wwan for arm64 (bsc#1246113) - reapply 'wifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()' (git-fixes). - regmap: fix potential memory leak of regmap_bus (git-fixes). - regulator: core: fix NULL dereference on unbind due to stale coupling data (stable-fixes). - regulator: fan53555: add enable_time support and soft-start times (stable-fixes). - regulator: gpio: Fix the out-of-bounds access to drvdata::gpiods (git-fixes). - regulator: pwm-regulator: Calculate the output voltage for disabled PWMs (stable-fixes). - resource: fix false warning in __request_region() (git-fixes). - restore UCSI_CONNECTOR_RESET_HARD definition (git-fixes). - revert 'ACPI: battery: negate current when discharging' (stable-fixes). - revert 'cgroup_freezer: cgroup_freezing: Check if not frozen' (bsc#1219338). - revert 'drm/i915/gem: Allow EXEC_CAPTURE on recoverable contexts on DG1' (stable-fixes). - revert 'drm/nouveau: check ioctl command codes better' (git-fixes). - revert 'drm/xe/xe2: Enable Indirect Ring State support for Xe2' (git-fixes). - revert 'mmc: sdhci: Disable SD card clock before changing parameters' (git-fixes). - revert 'usb: xhci: Implement xhci_handshake_check_state() helper' (git-fixes). - revert 'vgacon: Add check for vc_origin address range in vgacon_scroll()' (stable-fixes). - ring-buffer: Do not allow events in NMI with generic atomic64 cmpxchg() (git-fixes). - rose: fix dangling neighbour pointers in rose_rt_device_down() (git-fixes). - rpl: Fix use-after-free in rpl_do_srh_inline() (git-fixes). - rpm/kernel-subpackage-spec: Skip brp-strip-debug to avoid file truncation (bsc#1246879) Put the same workaround to avoid file truncation of vmlinux and co in kernel-default-base package, too. - rpm/mkspec: Fix missing kernel-syms-rt creation (bsc#1244337) - rtc: ds1307: fix incorrect maximum clock rate handling (git-fixes). - rtc: hym8563: fix incorrect maximum clock rate handling (git-fixes). - rtc: nct3018y: fix incorrect maximum clock rate handling (git-fixes). - rtc: pcf85063: fix incorrect maximum clock rate handling (git-fixes). - rtc: pcf8563: fix incorrect maximum clock rate handling (git-fixes). - rtc: rv3028: fix incorrect maximum clock rate handling (git-fixes). - s390/bpf: Fix bpf_arch_text_poke() with new_addr == NULL again (git-fixes bsc#1246870). - s390/entry: Fix last breaking event handling in case of stack corruption (git-fixes bsc#1243806). - s390/pci: Do not try re-enabling load/store if device is disabled (git-fixes bsc#1245646). - s390/pci: Fix stale function handles in error handling (git-fixes bsc#1245647). - s390/pkey: Prevent overflow in size calculation for memdup_user() (git-fixes bsc#1245598). - s390: Add z17 elf platform (LTC#214086 bsc#1245540). - samples: mei: Fix building on musl libc (git-fixes). - sched,freezer: Remove unnecessary warning in __thaw_task (bsc#1219338). - sched: Add test_and_clear_wake_up_bit() and atomic_dec_and_wake_up() (git-fixes). - scsi: core: Enforce unlimited max_segment_size when virt_boundary_mask is set (git-fixes). - scsi: fnic: Add and improve logs in FDMI and FDMI ABTS paths (bsc#1246644). - scsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times out (git-fixes). - scsi: fnic: Fix missing DMA mapping error in fnic_send_frame() (git-fixes). - scsi: fnic: Set appropriate logging level for log message (bsc#1246644). - scsi: fnic: Turn off FDMI ACTIVE flags on link down (git-fixes). - scsi: lpfc: Check for hdwq null ptr when cleaning up lpfc_vport structure (bsc#1245260 bsc#1243100 bsc#1246125). - scsi: lpfc: Early return out of FDMI cmpl for locally rejected statuses (bsc#1245260 bsc#1243100 bsc#1246125). - scsi: lpfc: Ensure HBA_SETUP flag is used only for SLI4 in dev_loss_tmo_callbk (bsc#1245260 bsc#1243100 bsc#1246125). - scsi: lpfc: Modify end-of-life adapters' model descriptions (bsc#1245260 bsc#1243100 bsc#1246125 bsc#1204142). - scsi: lpfc: Move clearing of HBA_SETUP flag to before lpfc_sli4_queue_unset (bsc#1245260 bsc#1243100 bsc#1246125). - scsi: lpfc: Relocate clearing initial phba flags from link up to link down hdlr (bsc#1245260 bsc#1243100 bsc#1246125). - scsi: lpfc: Revise CQ_CREATE_SET mailbox bitfield definitions (bsc#1245260 bsc#1243100 bsc#1246125). - scsi: lpfc: Revise logging format for failed CT MIB requests (bsc#1245260 bsc#1243100 bsc#1246125). - scsi: lpfc: Simplify error handling for failed lpfc_get_sli4_parameters cmd (bsc#1245260 bsc#1243100 bsc#1246125). - scsi: lpfc: Skip RSCN processing when FC_UNLOADING flag is set (bsc#1245260 bsc#1243100 bsc#1246125). - scsi: lpfc: Update debugfs trace ring initialization messages (bsc#1245260 bsc#1243100 bsc#1246125). - scsi: lpfc: Update lpfc version to 14.4.0.10 (bsc#1245260 bsc#1243100 bsc#1246125). - scsi: megaraid_sas: Fix invalid node index (git-fixes). - scsi: qla2xxx: Fix DMA mapping test in qla24xx_get_port_database() (git-fixes). - scsi: qla4xxx: Fix missing DMA mapping error in qla4xxx_alloc_pdu() (git-fixes). - scsi: s390: zfcp: Ensure synchronous unit_add (git-fixes bsc#1245599). - selftests/bpf: Add CFLAGS per source file and runner (git-fixes). - selftests/bpf: Add tests for iter next method returning valid pointer (git-fixes). - selftests/bpf: Change functions definitions to support GCC (git-fixes). - selftests/bpf: Fix a few tests for GCC related warnings (git-fixes). - selftests/bpf: Fix pointer arithmetic in test_xdp_do_redirect (git-fixes). - selftests/bpf: Fix prog numbers in test_sockmap (git-fixes). - smb3: move server check earlier when setting channel sequence number (git-fixes). - smb3: rename macro CIFS_SERVER_IS_CHAN to avoid confusion (git-fixes). - smb3: send channel sequence number in SMB3 requests after reconnects (git-fixes). - soc/tegra: cbb: Clear ERR_FORCE register with ERR_STATUS (git-fixes). - soc: aspeed: lpc-snoop: Cleanup resources in stack-order (git-fixes). - soc: aspeed: lpc-snoop: Do not disable channels that are not enabled (git-fixes). - soc: qcom: QMI encoding/decoding for big endian (git-fixes). - soc: qcom: fix endianness for QMI header (git-fixes). - soc: qcom: pmic_glink: fix OF node leak (git-fixes). - soundwire: amd: fix for clearing command status register (git-fixes). - soundwire: stream: restore params when prepare ports fail (git-fixes). - spi: spi-fsl-dspi: Clear completion counter before initiating transfer (git-fixes). - sprintf.h requires stdarg.h (git-fixes). - sprintf.h: mask additional include (git-fixes). - staging: axis-fifo: remove sysfs interface (git-fixes). - staging: fbtft: fix potential memory leak in fbtft_framebuffer_alloc() (git-fixes). - staging: nvec: Fix incorrect null termination of battery manufacturer (git-fixes). - staging: vchiq_arm: Make vchiq_shutdown never fail (git-fixes). - struct cdns: move new member to the end (git-fixes). - struct ucsi_operations: use padding for new operation (git-fixes). - sunrpc: do not immediately retransmit on seqno miss (git-fixes). - sunrpc: fix client side handling of tls alerts (git-fixes). - supported.conf: Mark ZL3073X modules supported - supported.conf: add missing entries for armv7hl - supported.conf: move nvme-apple to optional again - supported.conf: sort entries again - tcp: call tcp_measure_rcv_mss() for ooo packets (git-fixes). - thermal: trip: Use READ_ONCE() for lockless access to trip properties (git-fixes). - thermal: trip: Use common set of trip type names (git-fixes). - thunderbolt: Fix bit masking in tb_dp_port_set_hops() (git-fixes). - thunderbolt: Fix copy+paste error in match_service_id() (git-fixes). - thunderbolt: Fix wake on connect at runtime (git-fixes). - tracing/kprobe: Make trace_kprobe's module callback called after jump_label update (git-fixes). - tracing/kprobes: Fix to free objects when failed to copy a symbol (git-fixes). - types: Complement the aligned types with signed 64-bit one (stable-fixes). - ucount: fix atomic_long_inc_below() argument type (git-fixes). - ucsi-glink: adapt to kABI consistency (git-fixes). - ucsi_ccg: Refine the UCSI Interrupt handling (git-fixes). - ucsi_operations: add stubs for all operations (git-fixes). - ucsi_ops: adapt update_connector to kABI consistency (git-fixes). - update config files (bsc#1243678) - usb: Add checks for snprintf() calls in usb_alloc_dev() (stable-fixes). - usb: atm: cxacru: Merge cxacru_upload_firmware() into cxacru_heavy_init() (git-fixes). - usb: cdc-wdm: avoid setting WDM_READ for ZLP-s (stable-fixes). - usb: cdnsp: Fix issue with CV Bad Descriptor test (git-fixes). - usb: cdnsp: Fix issue with resuming from L1 (git-fixes). - usb: cdnsp: Replace snprintf() with the safer scnprintf() variant (stable-fixes). - usb: cdnsp: do not disable slot for disabled slot (git-fixes). - usb: chipidea: udc: disconnect/reconnect from host when do suspend/resume (git-fixes). - usb: common: usb-conn-gpio: use a unique name for usb connector device (stable-fixes). - usb: dwc2: also exit clock_gating when stopping udc while suspended (stable-fixes). - usb: dwc3: Abort suspend on soft disconnect failure (git-fixes). - usb: dwc3: meson-g12a: fix device leaks at unbind (git-fixes). - usb: early: xhci-dbc: Fix early_ioremap leak (git-fixes). - usb: gadget : fix use-after-free in composite_dev_cleanup() (git-fixes). - usb: gadget: u_serial: Fix race condition in TTY wakeup (git-fixes). - usb: gadget: udc: renesas_usb3: fix device leak at unbind (git-fixes). - usb: host: xhci-plat: fix incorrect type for of_match variable in xhci_plat_probe() (git-fixes). - usb: hub: Do not try to recover devices lost during warm reset (git-fixes). - usb: misc: apple-mfi-fastcharge: Make power supply names unique (git-fixes). - usb: musb: fix gadget state on disconnect (git-fixes). - usb: musb: omap2430: fix device leak at unbind (git-fixes). - usb: net: sierra: check for no status endpoint (git-fixes). - usb: potential integer overflow in usbg_make_tpg() (stable-fixes). - usb: serial: ftdi_sio: add support for NDI EMGUIDE GEMINI (stable-fixes). - usb: serial: option: add Foxconn T99W640 (stable-fixes). - usb: serial: option: add Telit Cinterion FE910C04 (ECM) composition (stable-fixes). - usb: typec: Update sysfs when setting ops (git-fixes). - usb: typec: altmodes/displayport: do not index invalid pin_assignments (git-fixes). - usb: typec: displayport: Fix potential deadlock (git-fixes). - usb: typec: displayport: Receive DP Status Update NAK request exit dp altmode (stable-fixes). - usb: typec: mux: do not return on EOPNOTSUPP in {mux, switch}_set (stable-fixes). - usb: typec: tcpm: allow switching to mode accessory to mux properly (stable-fixes). - usb: typec: tcpm: allow to use sink in accessory mode (stable-fixes). - usb: typec: tcpm: apply vbus before data bringup in tcpm_src_attach (git-fixes). - usb: typec: ucsi: Add DATA_RESET option of Connector Reset command (git-fixes). - usb: typec: ucsi: Add qcm6490-pmic-glink as needing PDOS quirk (git-fixes). - usb: typec: ucsi: Delay alternate mode discovery (git-fixes). - usb: typec: ucsi: Fix busy loop on ASUS VivoBooks (git-fixes). - usb: typec: ucsi: Fix the partner PD revision (git-fixes). - usb: typec: ucsi: Get PD revision for partner (git-fixes). - usb: typec: ucsi: Set orientation as none when connector is unplugged (git-fixes). - usb: typec: ucsi: Update power_supply on power role change (git-fixes). - usb: typec: ucsi: add callback for connector status updates (git-fixes). - usb: typec: ucsi: add update_connector callback (git-fixes). - usb: typec: ucsi: do not retrieve PDOs if not supported (git-fixes). - usb: typec: ucsi: extract code to read PD caps (git-fixes). - usb: typec: ucsi: fix UCSI on SM8550 & SM8650 Qualcomm devices (git-fixes). - usb: typec: ucsi: glink: fix off-by-one in connector_status (git-fixes). - usb: typec: ucsi: glink: increase max ports for x1e80100 (git-fixes). - usb: typec: ucsi: glink: move GPIO reading into connector_status callback (git-fixes). - usb: typec: ucsi: glink: use typec_set_orientation (git-fixes). - usb: typec: ucsi: move ucsi_acknowledge() from ucsi_read_error() (git-fixes). - usb: typec: ucsi: properly register partner's PD device (git-fixes). - usb: typec: ucsi: support delaying GET_PDOS for device (git-fixes). - usb: typec: ucsi_acpi: Add LG Gram quirk (git-fixes). - usb: typec: ucsi_glink: drop NO_PARTNER_PDOS quirk for sm8550 / sm8650 (git-fixes). - usb: typec: ucsi_glink: enable the UCSI_DELAY_DEVICE_PDOS quirk (git-fixes). - usb: typec: ucsi_glink: enable the UCSI_DELAY_DEVICE_PDOS quirk on qcm6490 (git-fixes). - usb: typec: ucsi_glink: rework quirks implementation (git-fixes). - usb: xhci: Skip xhci_reset in xhci_resume if xhci is being removed (git-fixes). - usb: xhci: quirk for data loss in ISOC transfers (stable-fixes). - usb:cdnsp: remove TRB_FLUSH_ENDPOINT command (stable-fixes). - virtgpu: do not reset on shutdown (git-fixes). - vmci: Prevent the dispatching of uninitialized payloads (git-fixes). - vt: add missing notification when switching back to text mode (stable-fixes). - vt: defkeymap: Map keycodes above 127 to K_HOLE (git-fixes). - vt: keyboard: Do not process Unicode characters in K_OFF mode (git-fixes). - watchdog: ziirave_wdt: check record length in ziirave_firm_verify() (git-fixes). - wifi: ath11k: clear initialized flag for deinit-ed srng lists (git-fixes). - wifi: ath11k: fix dest ring-buffer corruption (git-fixes). - wifi: ath11k: fix dest ring-buffer corruption when ring is full (git-fixes). - wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask() (git-fixes). - wifi: ath11k: fix source ring-buffer corruption (git-fixes). - wifi: ath11k: fix suspend use-after-free after probe failure (git-fixes). - wifi: ath12k: Pass ab pointer directly to ath12k_dp_tx_get_encap_type() (git-fixes). - wifi: ath12k: fix dest ring-buffer corruption (git-fixes). - wifi: ath12k: fix dest ring-buffer corruption when ring is full (git-fixes). - wifi: ath12k: fix endianness handling while accessing wmi service bit (git-fixes). - wifi: ath12k: fix source ring-buffer corruption (git-fixes). - wifi: ath6kl: remove WARN on bad firmware input (stable-fixes). - wifi: brcmfmac: fix P2P discovery failure in P2P peer due to missing P2P IE (git-fixes). - wifi: brcmsmac: Remove const from tbl_ptr parameter in wlc_lcnphy_common_read_table() (git-fixes). - wifi: cfg80211/mac80211: correctly parse S1G beacon optional elements (git-fixes). - wifi: cfg80211: fix S1G beacon head validation in nl80211 (git-fixes). - wifi: cfg80211: remove scan request n_channels counted_by (git-fixes). - wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_start() (git-fixes). - wifi: iwlwifi: Fix memory leak in iwl_mvm_init() (git-fixes). - wifi: iwlwifi: return ERR_PTR from opmode start() (stable-fixes). - wifi: mac80211: Add link iteration macro for link data (stable-fixes). - wifi: mac80211: Check 802.11 encaps offloading in ieee80211_tx_h_select_key() (git-fixes). - wifi: mac80211: Create separate links for VLAN interfaces (stable-fixes). - wifi: mac80211: Do not call fq_flow_idx() for management frames (git-fixes). - wifi: mac80211: Do not schedule stopped TXQs (git-fixes). - wifi: mac80211: Write cnt before copying in ieee80211_copy_rnr_beacon() (git-fixes). - wifi: mac80211: chan: chandef is non-NULL for reserved (stable-fixes). - wifi: mac80211: drop invalid source address OCB frames (stable-fixes). - wifi: mac80211: finish link init before RCU publish (git-fixes). - wifi: mac80211: fix non-transmitted BSSID profile search (git-fixes). - wifi: mac80211: reject TDLS operations when station is not associated (git-fixes). - wifi: mt76: mt7925: Fix null-ptr-deref in mt7925_thermal_init() (git-fixes). - wifi: mt76: mt7925: fix invalid array index in ssid assignment during hw scan (git-fixes). - wifi: mt76: mt7925: fix the wrong config for tx interrupt (git-fixes). - wifi: nl80211: Set num_sub_specs before looping through sub_specs (git-fixes). - wifi: plfxlc: Fix error handling in usb driver probe (git-fixes). - wifi: prevent A-MSDU attacks in mesh networks (stable-fixes). - wifi: rt2x00: fix remove callback type mismatch (git-fixes). - wifi: rtl818x: Kill URBs before clearing tx status queue (git-fixes). - wifi: rtw89: avoid NULL dereference when RX problematic packet on unsupported 6 GHz band (git-fixes). - wifi: zd1211rw: Fix potential NULL pointer dereference in zd_mac_tx_to_dev() (git-fixes). - x86/CPU/AMD: Add more models to X86_FEATURE_ZEN5 (bsc#1246449). - x86/CPU/AMD: Improve the erratum 1386 workaround (git-fixes). - x86/CPU/AMD: Terminate the erratum_1386_microcode array (git-fixes). - x86/cpu/amd: Fix workaround for erratum 1054 (git-fixes). - x86/cpu: Avoid running off the end of an AMD erratum table (git-fixes). - x86/cpu: Expose only stepping min/max interface (git-fixes). - x86/cpu: Introduce new microcode matching helper (git-fixes). - x86/cpu: Move AMD erratum 1386 table over to 'x86_cpu_id' (git-fixes). - x86/cpu: Replace PEBS use of 'x86_cpu_desc' use with 'x86_cpu_id' (git-fixes). - x86/mce/amd: Add default names for MCA banks and blocks (git-fixes). - x86/mce/amd: Fix threshold limit reset (git-fixes). - x86/mce: Do not remove sysfs if thresholding sysfs init fails (git-fixes). - x86/mce: Make sure CMCI banks are cleared during shutdown on Intel (git-fixes). - x86/mtrr: Rename mtrr_overwrite_state() to guest_force_mtrr_state() (git-fixes). - x86/tdx: Fix __noreturn build warning around __tdx_hypercall_failed() (git-fixes). - x86/traps: Initialize DR6 by writing its architectural reset value (git-fixes). - x86/virt/tdx: Avoid indirect calls to TDX assembly functions (git-fixes). - x86: UV RTC: Add parameter to disable RTC clocksource (bsc#1241345). - xfs: fix off-by-one error in fsmap's end_daddr usage (bsc#1235837). - xfs: only create event xfs_file_compat_ioctl when CONFIG_COMPAT is configure (git-fixes). - xfs: remove unused event xfs_alloc_near_error (git-fixes). - xfs: remove unused event xfs_alloc_near_nominleft (git-fixes). - xfs: remove unused event xfs_attr_node_removename (git-fixes). - xfs: remove unused event xfs_ioctl_clone (git-fixes). - xfs: remove unused event xfs_pagecache_inval (git-fixes). - xfs: remove unused event xlog_iclog_want_sync (git-fixes). - xfs: remove unused trace event xfs_attr_remove_iter_return (git-fixes). - xfs: remove unused trace event xfs_attr_rmtval_set (git-fixes). - xfs: remove unused trace event xfs_reflink_cow_enospc (git-fixes). - xfs: remove unused xfs_attr events (git-fixes). - xfs: remove unused xfs_reflink_compare_extents events (git-fixes). - xfs: remove usused xfs_end_io_direct events (git-fixes). - xhci: Disable stream for xHC controller with XHCI_BROKEN_STREAMS (git-fixes). - xhci: dbc: Flush queued requests before stopping dbc (git-fixes). - xhci: dbctty: disable ECHO flag by default (git-fixes). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3066-1 Released: Thu Sep 4 08:37:17 2025 Summary: Recommended update for systemd-presets-branding-SLE Type: recommended Severity: moderate References: 1244553,1246835 This update for systemd-presets-branding-SLE fixes the following issues: - Enable sysstat_collect.timer and sysstat_summary.timer (bsc#1244553, bsc#1246835). - Modified default SLE presets. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3072-1 Released: Thu Sep 4 09:20:43 2025 Summary: Recommended update for sysstat Type: recommended Severity: moderate References: 1244553,1246835,1246852 This update for sysstat fixes the following issues: - Renaming services to allow preset in systemd-presets-branding-SLE to work (bsc#1244553, bsc#1246835). - Fix argument order of find (bsc#1246852). - Fix systemd timers that are not enabled after upgrade (bsc#1244553). - deleted 90-sysstat.preset file, not needed anymore. ----------------------------------------------------------------- Advisory ID: SUSE-OU-2025:3094-1 Released: Mon Sep 8 11:46:41 2025 Summary: Optional update for NetworkManager Type: optional Severity: low References: 1246113 This update for NetworkManager fixes the following issue - Add NetworkManager-wwan to SLE-Module-Desktop-Applications_15-SP7 (bsc#1246113) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3228-1 Released: Mon Sep 15 14:51:02 2025 Summary: Recommended update for console-setup, kbd Type: recommended Severity: important References: 1246522 This update for console-setup and kbd fixes the following issues: console-setup: - Fix unicode check (bsc#1246522) kbd: - Improve error message on unsupported unicode value ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3239-1 Released: Tue Sep 16 19:04:00 2025 Summary: Security update for expat Type: security Severity: important References: 1239618,CVE-2024-8176 This update for expat fixes the following issues: expat was updated to version 2.7.1: - Bug fixes: - Restore event pointer behavior from Expat 2.6.4 (that the fix to CVE-2024-8176 changed in 2.7.0); affected API functions are: - XML_GetCurrentByteCount - XML_GetCurrentByteIndex - XML_GetCurrentColumnNumber - XML_GetCurrentLineNumber - XML_GetInputContext - Other changes: - Fix printf format specifiers for 32bit Emscripten - docs: Promote OpenSSF Best Practices self-certification - tests/benchmark: Resolve mistaken double close - Address compiler warnings - Version info bumped from 11:1:10 (libexpat*.so.1.10.1) to 11:2:10 (libexpat*.so.1.10.2); see https://verbump.de/ for what these numbers do Version update to 2.7.0 (CVE-2024-8176, bsc#1239618, jsc#PED-12507) * Security fixes: - CVE-2024-8176 -- Fix crash from chaining a large number of entities caused by stack overflow by resolving use of recursion, for all three uses of entities: - general entities in character data ('&g1;') - general entities in attribute values ('') - parameter entities ('%p1;') Known impact is (reliable and easy) denial of service: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:H/RL:O/RC:C (Base Score: 7.5, Temporal Score: 7.2) Please note that a layer of compression around XML can significantly reduce the minimum attack payload size. * Other changes: - docs: Add missing documentation of error code XML_ERROR_NOT_STARTED that was introduced with 2.6.4 - docs: Document need for C++11 compiler for use from C++ - Address Cppcheck warnings - Mass-migrate links from http:// to https:// - Document changes since the previous release - Version info bumped from 11:0:10 (libexpat*.so.1.10.0) to 11:1:10 (libexpat*.so.1.10.1); see https://verbump.de/ for what these numbers do ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3268-1 Released: Thu Sep 18 13:08:10 2025 Summary: Security update for curl Type: security Severity: important References: 1246197,1249191,1249348,1249367,CVE-2025-10148,CVE-2025-9086 This update for curl fixes the following issues: Security issues fixed: - CVE-2025-9086: bug in patch comparison logic when processing cookies can lead to out-of-bounds read in heap buffer (bsc#1249191). - CVE-2025-10148: predictable websocket mask can lead to proxy cache poisoning by malicious server (bsc#1249348). Other issues fixed: - Fix the --ftp-pasv option in curl v8.14.1 (bsc#1246197). * tool_getparam: fix --ftp-pasv [5f805ee] - Update to version 8.14.1 (jsc#PED-13055, jsc#PED-13056). * TLS: add CURLOPT_SSL_SIGNATURE_ALGORITHMS and --sigalgs. * websocket: add option to disable auto-pong reply. * huge number of bugfixes. Please see https://curl.se/ch/ for full changelogs. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3290-1 Released: Mon Sep 22 14:34:03 2025 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1012628,1170284,1213545,1215199,1221858,1222323,1230557,1230708,1232089,1233120,1240708,1240890,1241353,1242034,1242754,1242960,1244734,1244930,1245410,1245663,1245710,1245767,1245780,1245815,1245956,1245973,1245977,1246005,1246012,1246181,1246193,1247057,1247078,1247112,1247116,1247119,1247155,1247162,1247167,1247229,1247243,1247280,1247290,1247313,1247712,1247976,1248088,1248108,1248164,1248166,1248175,1248178,1248179,1248180,1248183,1248186,1248194,1248196,1248198,1248205,1248206,1248208,1248209,1248212,1248213,1248214,1248216,1248217,1248223,1248227,1248228,1248229,1248232,1248240,1248255,1248297,1248306,1248312,1248333,1248334,1248337,1248338,1248340,1248341,1248345,1248349,1248350,1248354,1248355,1248361,1248363,1248368,1248370,1248374,1248377,1248386,1248390,1248395,1248399,1248401,1248511,1248573,1248575,1248577,1248609,1248614,1248617,1248621,1248636,1248643,1248647,1248648,1248652,1248655,1248666,1248669,1248746,1248748,1249022,1249346,CVE-2023-3867,CVE-2023-41 30,CVE-2023-4515,CVE-2024-26661,CVE-2024-46733,CVE-2024-49996,CVE-2024-58238,CVE-2024-58239,CVE-2025-37885,CVE-2025-38006,CVE-2025-38075,CVE-2025-38103,CVE-2025-38125,CVE-2025-38146,CVE-2025-38160,CVE-2025-38184,CVE-2025-38185,CVE-2025-38190,CVE-2025-38201,CVE-2025-38205,CVE-2025-38208,CVE-2025-38245,CVE-2025-38251,CVE-2025-38360,CVE-2025-38439,CVE-2025-38440,CVE-2025-38441,CVE-2025-38444,CVE-2025-38445,CVE-2025-38458,CVE-2025-38459,CVE-2025-38464,CVE-2025-38472,CVE-2025-38490,CVE-2025-38491,CVE-2025-38499,CVE-2025-38500,CVE-2025-38503,CVE-2025-38506,CVE-2025-38510,CVE-2025-38511,CVE-2025-38512,CVE-2025-38513,CVE-2025-38515,CVE-2025-38516,CVE-2025-38520,CVE-2025-38521,CVE-2025-38524,CVE-2025-38528,CVE-2025-38529,CVE-2025-38530,CVE-2025-38531,CVE-2025-38535,CVE-2025-38537,CVE-2025-38538,CVE-2025-38540,CVE-2025-38541,CVE-2025-38543,CVE-2025-38546,CVE-2025-38548,CVE-2025-38550,CVE-2025-38553,CVE-2025-38555,CVE-2025-38560,CVE-2025-38563,CVE-2025-38565,CVE-2025-38566,CVE-2025-38568,CVE-2 025-38571,CVE-2025-38572,CVE-2025-38576,CVE-2025-38581,CVE-2025-38582,CVE-2025-38583,CVE-2025-38585,CVE-2025-38587,CVE-2025-38588,CVE-2025-38591,CVE-2025-38601,CVE-2025-38602,CVE-2025-38604,CVE-2025-38605,CVE-2025-38608,CVE-2025-38609,CVE-2025-38610,CVE-2025-38612,CVE-2025-38617,CVE-2025-38618,CVE-2025-38621,CVE-2025-38624,CVE-2025-38630,CVE-2025-38632,CVE-2025-38634,CVE-2025-38635,CVE-2025-38644,CVE-2025-38646,CVE-2025-38650,CVE-2025-38656,CVE-2025-38663,CVE-2025-38665,CVE-2025-38668,CVE-2025-38670,CVE-2025-38671 The SUSE Linux Enterprise 15 SP7 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2024-46733: btrfs: fix qgroup reserve leaks in cow_file_range (bsc#1230708). - CVE-2024-49996: cifs: Fix buffer overflow when parsing NFS reparse points (bsc#1232089). - CVE-2025-37885: KVM: x86: Reset IRTE to host control if *new* route isn't postable (bsc#1242960). - CVE-2025-38006: net: mctp: Do not access ifa_index when missing (bsc#1244930). - CVE-2025-38075: scsi: target: iscsi: Fix timeout on deleted connection (bsc#1244734). - CVE-2025-38103: HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse() (bsc#1245663). - CVE-2025-38125: net: stmmac: make sure that ptp_rate is not 0 before configuring EST (bsc#1245710). - CVE-2025-38146: net: openvswitch: Fix the dead loop of MPLS parse (bsc#1245767). - CVE-2025-38160: clk: bcm: rpi: Add NULL check in raspberrypi_clk_register() (bsc#1245780). - CVE-2025-38184: tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer (bsc#1245956). - CVE-2025-38185: atm: atmtcp: Free invalid length skb in atmtcp_c_send() (bsc#1246012). - CVE-2025-38190: atm: Revert atm_account_tx() if copy_from_iter_full() fails (bsc#1245973). - CVE-2025-38201: netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX (bsc#1245977). - CVE-2025-38205: drm/amd/display: Avoid divide by zero by initializing dummy pitch to 1 (bsc#1246005). - CVE-2025-38208: smb: client: add NULL check in automount_fullpath (bsc#1245815). - CVE-2025-38245: atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister() (bsc#1246193). - CVE-2025-38251: atm: clip: prevent NULL deref in clip_push() (bsc#1246181). - CVE-2025-38360: drm/amd/display: Add more checks for DSC / HUBP ONO guarantees (bsc#1247078). - CVE-2025-38439: bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT (bsc#1247155). - CVE-2025-38440: net/mlx5e: Fix race between DIM disable and net_dim() (bsc#1247290). - CVE-2025-38441: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() (bsc#1247167). - CVE-2025-38444: raid10: cleanup memleak at raid10_make_request (bsc#1247162). - CVE-2025-38445: md/raid1: Fix stack memory use after return in raid1_reshape (bsc#1247229). - CVE-2025-38458: atm: clip: Fix NULL pointer dereference in vcc_sendmsg() (bsc#1247116). - CVE-2025-38459: atm: clip: Fix infinite recursive call of clip_push() (bsc#1247119). - CVE-2025-38464: tipc: Fix use-after-free in tipc_conn_close() (bsc#1247112). - CVE-2025-38472: netfilter: nf_conntrack: fix crash due to removal of uninitialised entry (bsc#1247313). - CVE-2025-38490: net: libwx: remove duplicate page_pool_put_full_page() (bsc#1247243). - CVE-2025-38491: mptcp: make fallback action and fallback decision atomic (bsc#1247280). - CVE-2025-38499: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (bsc#1247976). - CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248088). - CVE-2025-38506: KVM: Allow CPU to reschedule while setting per-page memory attributes (bsc#1248186). - CVE-2025-38520: drm/amdkfd: Do not call mmput from MMU notifier callback (bsc#1248217). - CVE-2025-38524: rxrpc: Fix recv-recv race of completed call (bsc#1248194). - CVE-2025-38528: bpf: Reject %p% format string in bprintf-like helpers (bsc#1248198). - CVE-2025-38531: iio: common: st_sensors: Fix use of uninitialize device structs (bsc#1248205). - CVE-2025-38546: atm: clip: Fix memory leak of struct clip_vcc (bsc#1248223). - CVE-2025-38560: x86/sev: Evict cache lines during SNP memory validation (bsc#1248312). - CVE-2025-38563: perf/core: Prevent VMA split of buffer mappings (bsc#1248306). - CVE-2025-38585: staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int() (bsc#1248355). - CVE-2025-38591: bpf: Reject narrower access to pointer ctx fields (bsc#1248363). - CVE-2025-38608: bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls (bsc#1248338). - CVE-2025-38618: vsock: Do not allow binding to VMADDR_PORT_ANY (bsc#1248511). The following non-security bugs were fixed: - ACPI: APEI: send SIGBUS to current task if synchronous memory error not recovered (stable-fixes). - ACPI: pfr_update: Fix the driver update version check (git-fixes). - ACPI: processor: fix acpi_object initialization (stable-fixes). - ACPI: processor: perflib: Move problematic pr->performance check (git-fixes). - ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control (stable-fixes). - ALSA: hda/realtek: Add Framework Laptop 13 (AMD Ryzen AI 300) to quirks (stable-fixes). - ALSA: hda/realtek: Add support for HP EliteBook x360 830 G6 and EliteBook 830 G6 (stable-fixes). - ALSA: hda/realtek: Audio disappears on HP 15-fc000 after warm boot again (git-fixes). - ALSA: hda/realtek: Fix headset mic on ASUS Zenbook 14 (git-fixes). - ALSA: hda/realtek: Fix headset mic on HONOR BRB-X (stable-fixes). - ALSA: hda: Disable jack polling at shutdown (stable-fixes). - ALSA: hda: Handle the jack polling always via a work (stable-fixes). - ALSA: intel8x0: Fix incorrect codec index usage in mixer for ICH4 (stable-fixes). - ALSA: pcm: Rewrite recalculate_boundary() to avoid costly loop (stable-fixes). - ALSA: scarlett2: Add retry on -EPROTO from scarlett2_usb_tx() (git-fixes). - ALSA: usb-audio: Avoid precedence issues in mixer_quirks macros (stable-fixes). - ALSA: usb-audio: Fix size validation in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Use correct sub-type for UAC3 feature unit validation (git-fixes). - ALSA: usb-audio: Validate UAC3 cluster segment descriptors (git-fixes). - ALSA: usb-audio: Validate UAC3 power domain descriptors, too (git-fixes). - ASoC: Intel: avs: Fix uninitialized pointer error in probe() (stable-fixes). - ASoC: Intel: fix SND_SOC_SOF dependencies (stable-fixes). - ASoC: SOF: amd: acp-loader: Use GFP_KERNEL for DMA allocations in resume context (git-fixes). - ASoC: amd: yc: Add DMI entries to support HP 15-fb1xxx (stable-fixes). - ASoC: amd: yc: Add DMI quirk for HP Laptop 17 cp-2033dx (stable-fixes). - ASoC: amd: yc: add DMI quirk for ASUS M6501RM (stable-fixes). - ASoC: codecs: rt5640: Retry DEVICE_ID verification (stable-fixes). - ASoC: core: Check for rtd == NULL in snd_soc_remove_pcm_runtime() (stable-fixes). - ASoC: fsl_sai: replace regmap_write with regmap_update_bits (git-fixes). - ASoC: hdac_hdmi: Rate limit logging on connection and disconnection (stable-fixes). - ASoC: qcom: use drvdata instead of component to keep id (stable-fixes). - ASoC: soc-dapm: set bias_level if snd_soc_dapm_set_bias_level() was successed (stable-fixes). - ASoC: tas2781: Fix the wrong step for TLV on tas2781 (git-fixes). - Bluetooth: btmtk: Fix wait_on_bit_timeout interruption during shutdown (git-fixes). - Bluetooth: btusb: Add USB ID 3625:010b for TP-LINK Archer TX10UB Nano (stable-fixes). - Bluetooth: hci_conn: do return error from hci_enhanced_setup_sync() (git-fixes). - Bluetooth: hci_core: Fix using {cis,bis}_capable for current settings (git-fixes). - Bluetooth: hci_event: Detect if HCI_EV_NUM_COMP_PKTS is unbalanced (git-fixes). - Bluetooth: hci_event: Mark connection as closed during suspend disconnect (git-fixes). - Bluetooth: hci_event: Treat UNKNOWN_CONN_ID on disconnect as success (git-fixes). - Bluetooth: hci_event: fix MTU for BN == 0 in CIS Established (git-fixes). - Bluetooth: hci_sock: Reset cookie to zero in hci_sock_free_cookie() (stable-fixes). - Bluetooth: hci_sync: fix set_local_name race condition (git-fixes). - Fix 'drm/amdgpu: read back register after written for VCN v4.0.5' (bsc#1248370). - HID: asus: fix UAF via HID_CLAIMED_INPUT validation (git-fixes). - HID: multitouch: fix slab out-of-bounds access in mt_report_fixup() (git-fixes). - PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug Capable ports (git-fixes). - PCI/portdrv: Use is_pciehp instead of is_hotplug_bridge (git-fixes). - PCI: Add ACS quirk for Loongson PCIe (git-fixes). - PCI: Support Immediate Readiness on devices without PM capabilities (git-fixes). - PCI: apple: Fix missing OF node reference in apple_pcie_setup_port (git-fixes). - PCI: imx6: Add IMX8MM_EP and IMX8MP_EP fixed 256-byte BAR 4 in epc_features (git-fixes). - PCI: imx6: Delay link start until configfs 'start' written (git-fixes). - PCI: imx6: Remove apps_reset toggling from imx_pcie_{assert/deassert}_core_reset (git-fixes). - PCI: pnv_php: Clean up allocated IRQs on unplug (bsc#1215199). - PCI: pnv_php: Work around switches with broken presence detection (bsc#1215199). - PCI: rockchip: Set Target Link Speed to 5.0 GT/s before retraining (git-fixes). - PCI: rockchip: Use standard PCIe definitions (git-fixes). - PM / devfreq: governor: Replace sscanf() with kstrtoul() in set_freq_store() (stable-fixes). - PM: runtime: Clear power.needs_force_resume in pm_runtime_reinit() (stable-fixes). - PM: sleep: console: Fix the black screen issue (stable-fixes). - RAS/AMD/ATL: Include row bit in row retirement (bsc#1242034). - RAS/AMD/FMPM: Get masked address (bsc#1242034). - RAS/AMD/FMPM: Use atl internal.h for INVALID_SPA (bsc#1242034). - RDMA/bnxt_re: Fix a possible memory leak in the driver (git-fixes). - RDMA/bnxt_re: Fix to do SRQ armena by default (git-fixes). - RDMA/bnxt_re: Fix to initialize the PBL array (git-fixes). - RDMA/bnxt_re: Fix to remove workload check in SRQ limit path (git-fixes). - RDMA/core: reduce stack using in nldev_stat_get_doit() (git-fixes). - RDMA/erdma: Fix ignored return value of init_kernel_qp (git-fixes). - RDMA/hns: Fix dip entries leak on devices newer than hip09 (git-fixes). - RDMA/hns: Fix querying wrong SCC context for DIP algorithm (git-fixes). - RDMA/rxe: Flush delayed SKBs while releasing RXE resources (git-fixes). - RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() (git-fixes). - Revert 'gpio: mlxbf3: only get IRQ for device instance 0' (git-fixes). - USB: serial: option: add Foxconn T99W709 (stable-fixes). - USB: storage: Add unusual-devs entry for Novatek NTK96550-based camera (stable-fixes). - USB: storage: Ignore driver CD mode for Realtek multi-mode Wi-Fi dongles (stable-fixes). - accel/habanalabs/gaudi2: Use kvfree() for memory allocated with kvcalloc() (git-fixes). - amdgpu/amdgpu_discovery: increase timeout limit for IFWI init (stable-fixes). - aoe: defer rexmit timer downdev work to workqueue (git-fixes). - arch/powerpc: Remove .interp section in vmlinux (bsc#1215199). - arm64/cpufeatures/kvm: Add ARMv8.9 FEAT_ECBHB bits in ID_AA64MMFR1 (git-fixes). - arm64/entry: Mask DAIF in cpu_switch_to(), call_on_irq_stack() (git-fixes). - arm64/mm: Check PUD_TYPE_TABLE in pud_bad() (git-fixes). - arm64: Add support for HIP09 Spectre-BHB mitigation (git-fixes). - arm64: Filter out SME hwcaps when FEAT_SME isn't implemented (git-fixes). - arm64: Restrict pagetable teardown to avoid false warning (git-fixes). - arm64: dts: apple: t8103: Fix PCIe BCM4377 nodename (git-fixes). - arm64: dts: freescale: imx8mm-verdin: Keep LDO5 always on (git-fixes). - arm64: dts: imx8mm-beacon: Fix HS400 USDHC clock speed (git-fixes). - arm64: dts: imx8mm-beacon: Fix RTC capacitive load (git-fixes). - arm64: dts: imx8mm-venice-gw700x: Increase HS400 USDHC clock speed (git-fixes). - arm64: dts: imx8mm-venice-gw7901: Increase HS400 USDHC clock speed (git-fixes). - arm64: dts: imx8mm-venice-gw7902: Increase HS400 USDHC clock speed (git-fixes). - arm64: dts: imx8mm-venice-gw7903: Increase HS400 USDHC clock speed (git-fixes). - arm64: dts: imx8mm-venice-gw7904: Increase HS400 USDHC clock speed (git-fixes). - arm64: dts: imx8mn-beacon: Fix HS400 USDHC clock speed (git-fixes). - arm64: dts: imx8mn-beacon: Fix RTC capacitive load (git-fixes). - arm64: dts: imx8mn-venice-gw7902: Increase HS400 USDHC clock speed (git-fixes). - arm64: dts: imx8mp-beacon: Fix RTC capacitive load (git-fixes). - arm64: dts: rockchip: Update eMMC for NanoPi R5 series (git-fixes). - arm64: dts: rockchip: fix endpoint dtc warning for PX30 ISP (git-fixes). - arm64: tegra: Drop remaining serial clock-names and reset-names (git-fixes). - arm64: tegra: p2597: Fix gpio for vdd-1v8-dis regulator (git-fixes). - arm64: zynqmp: add clock-output-names property in clock nodes (git-fixes). - ata: libata-scsi: Fix CDL control (git-fixes). - block: fix kobject leak in blk_unregister_queue (git-fixes). - block: mtip32xx: Fix usage of dma_map_sg() (git-fixes). - bpf: fix kfunc btf caching for modules (git-fixes). - bpf: use kvzmalloc to allocate BPF verifier environment (git-fixes). - btrfs: convert BUG_ON in btrfs_reloc_cow_block() to proper error handling (git-fixes). - btrfs: correctly escape subvol in btrfs_show_options() (git-fixes). - btrfs: fix adding block group to a reclaim list and the unused list during reclaim (git-fixes). - btrfs: fix bitmap leak when loading free space cache on duplicate entry (git-fixes). - btrfs: fix data race when accessing the inode's disk_i_size at btrfs_drop_extents() (git-fixes). - btrfs: fix the length of reserved qgroup to free (bsc#1240708). - btrfs: retry block group reclaim without infinite loop (git-fixes). - btrfs: return accurate error code on open failure in open_fs_devices() (bsc#1233120). - btrfs: run delayed iputs when flushing delalloc (git-fixes). - btrfs: update target inode's ctime on unlink (git-fixes). - cdx: Fix off-by-one error in cdx_rpmsg_probe() (git-fixes). - char: misc: Fix improper and inaccurate error code returned by misc_init() (stable-fixes). - comedi: Fix use of uninitialized memory in do_insn_ioctl() and do_insnlist_ioctl() (git-fixes). - comedi: Make insn_rw_emulate_bits() do insn->n samples (git-fixes). - comedi: fix race between polling and detaching (git-fixes). - comedi: pcl726: Prevent invalid irq number (git-fixes). - crypto: hisilicon/hpre - fix dma unmap sequence (stable-fixes). - crypto: jitter - fix intermediary handling (stable-fixes). - crypto: octeontx2 - add timeout for load_fvc completion poll (stable-fixes). - crypto: qat - lower priority for skcipher and aead algorithms (stable-fixes). - devlink: add value check to devlink_info_version_put() (bsc#1245410 jsc#PED-12320). - devlink: let driver opt out of automatic phys_port_name generation (git-fixes). - drm/amd/display: Add null pointer check in mod_hdcp_hdcp1_create_session() (git-fixes). - drm/amd/display: Add primary plane to commits for correct VRR handling (stable-fixes). - drm/amd/display: Adjust DCE 8-10 clock, do not overclock by 15% (git-fixes). - drm/amd/display: Allow DCN301 to clear update flags (git-fixes). - drm/amd/display: Avoid a NULL pointer dereference (stable-fixes). - drm/amd/display: Avoid configuring PSR granularity if PSR-SU not supported (stable-fixes). - drm/amd/display: Avoid trying AUX transactions on disconnected ports (stable-fixes). - drm/amd/display: Disable dsc_power_gate for dcn314 by default (stable-fixes). - drm/amd/display: Do not overclock DCE 6 by 15% (git-fixes). - drm/amd/display: Do not print errors for nonexistent connectors (git-fixes). - drm/amd/display: Fill display clock and vblank time in dce110_fill_display_configs (stable-fixes). - drm/amd/display: Find first CRTC and its line time in dce110_fill_display_configs (stable-fixes). - drm/amd/display: Fix 'failed to blank crtc!' (stable-fixes). - drm/amd/display: Fix DP audio DTO1 clock source on DCE 6 (stable-fixes). - drm/amd/display: Fix Xorg desktop unresponsive on Replay panel (stable-fixes). - drm/amd/display: Fix fractional fb divider in set_pixel_clock_v3 (git-fixes). - drm/amd/display: Initialize mode_select to 0 (stable-fixes). - drm/amd/display: Only finalize atomic_obj if it was initialized (stable-fixes). - drm/amd/display: Separate set_gsl from set_gsl_source_select (stable-fixes). - drm/amd/display: Update DMCUB loading sequence for DCN3.5 (stable-fixes). - drm/amd/display: fix a Null pointer dereference vulnerability (stable-fixes). - drm/amd/display: limit clear_update_flags to dcn32 and above (stable-fixes). - drm/amd/pm: fix null pointer access (stable-fixes). - drm/amd: Allow printing VanGogh OD SCLK levels without setting dpm to manual (stable-fixes). - drm/amd: Restore cached power limit during resume (stable-fixes). - drm/amdgpu/swm14: Update power limit logic (stable-fixes). - drm/amdgpu: Avoid extra evict-restore process (stable-fixes). - drm/amdgpu: Update external revid for GC v9.5.0 (stable-fixes). - drm/amdgpu: check if hubbub is NULL in debugfs/amdgpu_dm_capabilities (stable-fixes). - drm/amdgpu: fix incorrect vm flags to map bo (git-fixes). - drm/amdgpu: fix task hang from failed job submission during process kill (git-fixes). - drm/amdgpu: fix vram reservation issue (git-fixes). - drm/amdgpu: update mmhub 3.0.1 client id mappings (stable-fixes). - drm/amdgpu: update mmhub 4.1.0 client id mappings (stable-fixes). - drm/amdkfd: Destroy KFD debugfs after destroy KFD wq (stable-fixes). - drm/bridge: fix OF node leak (git-fixes). - drm/dp: Change AUX DPCD probe address from DPCD_REV to LANE0_1_STATUS (stable-fixes). - drm/format-helper: Add conversion from XRGB8888 to BGR888 (stable-fixes). - drm/hisilicon/hibmc: fix the hibmc loaded failed bug (git-fixes). - drm/hisilicon/hibmc: fix the i2c device resource leak when vdac init failed (git-fixes). - drm/hisilicon/hibmc: refactored struct hibmc_drm_private (stable-fixes). - drm/i915/ddi: change intel_ddi_init_{dp, hdmi}_connector() return type (stable-fixes). - drm/i915/ddi: gracefully handle errors from intel_ddi_init_hdmi_connector() (stable-fixes). - drm/i915/ddi: only call shutdown hooks for valid encoders (stable-fixes). - drm/i915/display: add intel_encoder_is_hdmi() (stable-fixes). - drm/i915/hdmi: add error handling in g4x_hdmi_init() (stable-fixes). - drm/i915/hdmi: propagate errors from intel_hdmi_init_connector() (stable-fixes). - drm/imagination: Clear runtime PM errors while resetting the GPU (stable-fixes). - drm/mediatek: Add error handling for old state CRTC in atomic_disable (git-fixes). - drm/mediatek: Fix device/node reference count leaks in mtk_drm_get_all_drm_priv (git-fixes). - drm/msm/kms: move snapshot init earlier in KMS init (git-fixes). - drm/msm: Add error handling for krealloc in metadata setup (stable-fixes). - drm/msm: Defer fd_install in SUBMIT ioctl (git-fixes). - drm/msm: update the high bitfield of certain DSI registers (git-fixes). - drm/msm: use trylock for debugfs (stable-fixes). - drm/nouveau/disp: Always accept linear modifier (git-fixes). - drm/nouveau/nvif: Fix potential memory leak in nvif_vmm_ctor() (git-fixes). - drm/nouveau: fix error path in nvkm_gsp_fwsec_v2 (git-fixes). - drm/nouveau: fix typos in comments (git-fixes). - drm/nouveau: remove unused increment in gm200_flcn_pio_imem_wr (git-fixes). - drm/nouveau: remove unused memory target test (git-fixes). - drm/tests: Fix endian warning (git-fixes). - drm/ttm: Respect the shrinker core free target (stable-fixes). - drm/ttm: Should to return the evict error (stable-fixes). - drm/xe/vm: Clear the scratch_pt pointer on error (git-fixes). - drm/xe/xe_query: Use separate iterator while filling GT list (stable-fixes). - drm/xe/xe_sync: avoid race during ufence signaling (git-fixes). - drm/xe: Do not trigger rebind on initial dma-buf validation (git-fixes). - drm/xe: Make dma-fences compliant with the safe access rules (stable-fixes). - drm: renesas: rz-du: mipi_dsi: Add min check for VCLK range (stable-fixes). - et131x: Add missing check after DMA map (stable-fixes). - exfat: add cluster chain loop check for dir (git-fixes). - fbdev: Fix vmalloc out-of-bounds write in fast_imageblit (stable-fixes). - fbdev: fix potential buffer overflow in do_register_framebuffer() (stable-fixes). - fs/mnt_idmapping.c: Return -EINVAL when no map is written (bsc#1233120) - fs/orangefs: use snprintf() instead of sprintf() (git-fixes). - gpio: mlxbf3: use platform_get_irq_optional() (git-fixes). - gpio: tps65912: check the return value of regmap_update_bits() (stable-fixes). - gpio: wcd934x: check the return value of regmap_update_bits() (stable-fixes). - hfs: fix not erasing deleted b-tree node issue (git-fixes). - hfs: fix slab-out-of-bounds in hfs_bnode_read() (git-fixes). - hfsplus: do not use BUG_ON() in hfsplus_create_attributes_file() (git-fixes). - hfsplus: fix slab-out-of-bounds in hfsplus_bnode_read() (git-fixes). - hfsplus: fix slab-out-of-bounds read in hfsplus_uni2asc() (git-fixes). - hwmon: (emc2305) Set initial PWM minimum value during probe based on thermal state (stable-fixes). - i2c: Force DLL0945 touchpad i2c freq to 100khz (stable-fixes). - i3c: do not fail if GETHDRCAP is unsupported (stable-fixes). - i3c: master: Initialize ret in i3c_i2c_notifier_call() (stable-fixes). - ice, irdma: fix an off by one in error handling code (bsc#1247712). - ice, irdma: move interrupts code to irdma (bsc#1247712). - ice: Fix signedness bug in ice_init_interrupt_scheme() (bsc#1247712). - ice: count combined queues using Rx/Tx count (bsc#1247712). - ice: devlink PF MSI-X max and min parameter (bsc#1247712). - ice: enable_rdma devlink param (bsc#1247712). - ice: get rid of num_lan_msix field (bsc#1247712). - ice: init flow director before RDMA (bsc#1247712). - ice: remove splitting MSI-X between features (bsc#1247712). - ice: simplify VF MSI-X managing (bsc#1247712). - ice: treat dyn_allowed only as suggestion (bsc#1247712). - iio: adc: ad7768-1: Ensure SYNC_IN pulse minimum timing requirement (stable-fixes). - iio: adc: ad_sigma_delta: do not overallocate scan buffer (stable-fixes). - iio: imu: inv_icm42600: switch timestamp type from int64_t __aligned(8) to aligned_s64 (stable-fixes). - iio: imu: inv_icm42600: use = { } instead of memset() (stable-fixes). - iio: pressure: bmp280: Use IS_ERR() in bmp280_common_probe() (git-fixes). - iio: proximity: isl29501: fix buffered read on big-endian systems (git-fixes). - integrity/platform_certs: Allow loading of keys in the static key management mode (jsc#PED-13345 jsc#PED-13343). - iosys-map: Fix undefined behavior in iosys_map_clear() (git-fixes). - ipmi: Fix strcpy source and destination the same (stable-fixes). - ipmi: Use dev_warn_ratelimited() for incorrect message warnings (stable-fixes). - irdma: free iwdev->rf after removing MSI-X (bsc#1247712). - ixgbe: add .info_get extension specific for E610 devices (bsc#1245410 jsc#PED-12320). - ixgbe: add E610 functions for acquiring flash data (bsc#1245410 jsc#PED-12320). - ixgbe: add E610 functions getting PBA and FW ver info (bsc#1245410 jsc#PED-12320). - ixgbe: add E610 implementation of FW recovery mode (bsc#1245410 jsc#PED-12320). - ixgbe: add FW API version check (bsc#1245410 jsc#PED-12320). - ixgbe: add device flash update via devlink (bsc#1245410 jsc#PED-12320). - ixgbe: add handler for devlink .info_get() (bsc#1245410 jsc#PED-12320). - ixgbe: add initial devlink support (bsc#1245410 jsc#PED-12320). - ixgbe: add support for FW rollback mode (bsc#1245410 jsc#PED-12320). - ixgbe: add support for devlink reload (bsc#1245410 jsc#PED-12320). - ixgbe: extend .info_get() with stored versions (bsc#1245410 jsc#PED-12320). - ixgbe: fix ixgbe_orom_civd_info struct layout (bsc#1245410). - ixgbe: prevent from unwanted interface name changes (git-fixes). - ixgbe: read the OROM version information (bsc#1245410 jsc#PED-12320). - ixgbe: read the netlist version information (bsc#1245410 jsc#PED-12320). - ixgbe: wrap netdev_priv() usage (bsc#1245410 jsc#PED-12320). - jfs: Regular file corruption check (git-fixes). - jfs: truncate good inode pages when hard link is 0 (git-fixes). - jfs: upper bound check of tree index in dbAllocAG (git-fixes). - kABI: PCI/ACPI: Fix runtime PM ref imbalance on Hot-Plug Capable ports (git-fixes). - kABI: fix for struct devlink_port_attrs: move new member to the end (git-fixes). - kselftest/arm64: Fix check for setting new VLs in sve-ptrace (git-fixes). - kselftest/runner.sh: add netns support. - kselftests: Sort the collections list to avoid duplicate tests. - leds: leds-lp50xx: Handle reg to get correct multi_index (stable-fixes). - livepatch: Add 'replace' sysfs attribute (poo#187320). - livepatch: Add stack_order sysfs attribute (poo#187320). - livepatch: Replace snprintf() with sysfs_emit() (poo#187320). - loop: use kiocb helpers to fix lockdep warning (git-fixes). - mISDN: hfcpci: Fix warning when deleting uninitialized timer (git-fixes). - md/md-cluster: handle REMOVE message earlier (bsc#1247057). - md/raid1,raid10: strip REQ_NOWAIT from member bios (git-fixes). - md: allow removing faulty rdev during resync (git-fixes). - md: make rdev_addable usable for rcu mode (git-fixes). - media: dvb-frontends: dib7090p: fix null-ptr-deref in dib7090p_rw_on_apb() (stable-fixes). - media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar (stable-fixes). - media: tc358743: Check I2C succeeded during probe (stable-fixes). - media: tc358743: Increase FIFO trigger level to 374 (stable-fixes). - media: tc358743: Return an appropriate colorspace from tc358743_set_fmt (stable-fixes). - media: usb: hdpvr: disable zero-length read messages (stable-fixes). - media: uvcvideo: Fix bandwidth issue for Alcor camera (stable-fixes). - media: v4l2-common: Reduce warnings about missing V4L2_CID_LINK_FREQ control (stable-fixes). - mei: bus: Check for still connected devices in mei_cl_bus_dev_release() (stable-fixes). - memstick: Fix deadlock by moving removing flag earlier (git-fixes). - mm/ptdump: take the memory hotplug lock inside ptdump_walk_pgd() (git-fixes) - mmc: rtsx_usb_sdmmc: Fix error-path in sd_set_power_mode() (stable-fixes). - mmc: sdhci-msm: Ensure SD card power isn't ON when card removed (stable-fixes). - mmc: sdhci-pci-gli: GL9763e: Rename the gli_set_gl9763e() for consistency (git-fixes). - most: core: Drop device reference after usage in get_channel() (git-fixes). - mptcp: fallback when MPTCP opts are dropped after 1st data (git-fixes). - mptcp: reset when MPTCP opts are dropped after join (git-fixes). - net: phy: micrel: Add ksz9131_resume() (stable-fixes). - net: phy: smsc: add proper reset flags for LAN8710A (stable-fixes). - net: thunderbolt: Enable end-to-end flow control also in transmit (stable-fixes). - net: thunderbolt: Fix the parameter passing of tb_xdomain_enable_paths()/tb_xdomain_disable_paths() (stable-fixes). - net: usb: asix_devices: Fix PHY address mask in MDIO bus initialization (git-fixes). - net: usb: asix_devices: add phy_mask for ax88772 mdio bus (git-fixes). - pNFS: Fix disk addr range check in block/scsi layout (git-fixes). - pNFS: Fix stripe mapping in block/scsi layout (git-fixes). - pNFS: Fix uninited ptr deref in block/scsi layout (git-fixes). - pNFS: Handle RPC size limit for layoutcommits (git-fixes). - phy: mscc: Fix parsing of unicast frames (git-fixes). - phy: rockchip-pcie: Properly disable TEST_WRITE strobe signal (stable-fixes). - pinctrl: STMFX: add missing HAS_IOMEM dependency (git-fixes). - pinctrl: stm32: Manage irq affinity settings (stable-fixes). - platform/chrome: cros_ec_typec: Defer probe on missing EC parent (stable-fixes). - platform/x86/amd/hsmp: Ensure sock->metric_tbl_addr is non-NULL (git-fixes). - platform/x86/amd: pmc: Add Lenovo Yoga 6 13ALC6 to pmc quirk list (stable-fixes). - platform/x86/intel-uncore-freq: Check write blocked for ELC (git-fixes). - pm: cpupower: Fix the snapshot-order of tsc,mperf, clock in mperf_stop() (stable-fixes). - power: supply: qcom_battmgr: Add lithium-polymer entry (stable-fixes). - powerpc/eeh: Export eeh_unfreeze_pe() (bsc#1215199). - powerpc/eeh: Make EEH driver device hotplug safe (bsc#1215199). - powerpc/eeh: Rely on dev->link_active_reporting (bsc#1215199). - powerpc/kernel: Fix ppc_save_regs inclusion in build (bsc#1215199). - powerpc/pseries: Correct secvar format representation for static key management (jsc#PED-13345 jsc#PED-13343). - powerpc/secvar: Expose secvars relevant to the key management mode (jsc#PED-13345 jsc#PED-13343). - powerpc: do not build ppc_save_regs.o always (bsc#1215199). - pwm: mediatek: Fix duty and period setting (git-fixes). - pwm: mediatek: Handle hardware enable and clock enable separately (stable-fixes). - Revert 'scsi: iscsi: Fix HW conn removal use after free' (git-fixes). - reset: brcmstb: Enable reset drivers for ARCH_BCM2835 (stable-fixes). - rtc: ds1307: handle oscillator stop flag (OSF) for ds1341 (stable-fixes). - rtc: ds1307: remove clear of oscillator stop flag (OSF) in probe (stable-fixes). - samples/bpf: Fix compilation errors with cf-protection option (git-fixes). - scsi: core: Fix kernel doc for scsi_track_queue_full() (git-fixes). - scsi: elx: efct: Fix dma_unmap_sg() nents value (git-fixes). - scsi: ibmvscsi_tgt: Fix dma_unmap_sg() nents value (git-fixes). - scsi: isci: Fix dma_unmap_sg() nents value (git-fixes). - scsi: mpi3mr: Fix kernel-doc issues in mpi3mr_app.c (git-fixes). - scsi: mpi3mr: Fix race between config read submit and interrupt completion (git-fixes). - scsi: mpi3mr: Serialize admin queue BAR writes on 32-bit systems (git-fixes). - scsi: mpt3sas: Fix a fw_event memory leak (git-fixes). - scsi: mvsas: Fix dma_unmap_sg() nents value (git-fixes). - scsi: sd: Make sd shutdown issue START STOP UNIT appropriately (git-fixes). - selftest/livepatch: Only run test-kprobe with CONFIG_KPROBES_ON_FTRACE. - selftests/bpf: fexit_sleep: Fix stack allocation for arm64 (git-fixes). - selftests/livepatch: Add selftests for 'replace' sysfs attribute. - selftests/livepatch: Ignore NO_SUPPORT line in dmesg (poo#187320). - selftests/livepatch: Replace hardcoded module name. - selftests/livepatch: define max test-syscall processes. - selftests/livepatch: fix and refactor new dmesg message code. - selftests/livepatch: wait for atomic replace to occur. - selftests/run_kselftest.sh: Fix help string for --per-test-log. - selftests/run_kselftest.sh: Use readlink if realpath is not available. - selftests/tracing: Fix false failure of subsystem event test (git-fixes). - selftests: Fix errno checking in syscall_user_dispatch test (git-fixes). - selftests: allow runners to override the timeout. - selftests: livepatch: Avoid running the tests for certain kernel-devel situations. - selftests: livepatch: Test atomic replace against multiple modules. - selftests: livepatch: Test livepatching a heavily called syscall. - selftests: livepatch: add new ftrace helpers functions. - selftests: livepatch: add test cases of stack_order sysfs interface. - selftests: livepatch: handle PRINTK_CALLER in check_result(). - selftests: livepatch: rename KLP_SYSFS_DIR to SYSFS_KLP_DIR. - selftests: livepatch: save and restore kprobe state. - selftests: livepatch: test if ftrace can trace a livepatched function. - selftests: livepatch: test livepatching a kprobed function. - selftests: rtnetlink.sh: remove esp4_offload after test (git-fixes). - serial: 8250: fix panic due to PSLVERR (git-fixes). - serial: core: fix OF node leak (git-fixes). - slab: Decouple slab_debug and no_hash_pointers (bsc#1249022). - smb: client: fix parsing of device numbers (git-fixes). - soc/tegra: pmc: Ensure power-domains are in a known state (git-fixes). - soundwire: Move handle_nested_irq outside of sdw_dev_lock (stable-fixes). - soundwire: amd: serialize amd manager resume sequence during pm_prepare (stable-fixes). - squashfs: fix memory leak in squashfs_fill_super (git-fixes). - sunrpc: fix handling of server side tls alerts (git-fixes). - sunvdc: Balance device refcount in vdc_port_mpgroup_check (git-fixes). - thermal/drivers/qcom-spmi-temp-alarm: Enable stage 2 shutdown when required (stable-fixes). - thermal: sysfs: Return ENODATA instead of EAGAIN for reads (stable-fixes). - ublk: sanity check add_dev input for underflow (git-fixes). - ublk: use vmalloc for ublk_device's __queues (git-fixes). - usb: core: config: Prevent OOB read in SS endpoint companion parsing (stable-fixes). - usb: core: hcd: fix accessing unmapped memory in SINGLE_STEP_SET_FEATURE test (git-fixes). - usb: core: usb_submit_urb: downgrade type check (stable-fixes). - usb: dwc3: Ignore late xferNotReady event to prevent halt timeout (git-fixes). - usb: dwc3: Remove WARN_ON for device endpoint command timeouts (stable-fixes). - usb: dwc3: core: Fix system suspend on TI AM62 platforms (git-fixes). - usb: dwc3: fix fault at system suspend if device was already runtime suspended (git-fixes). - usb: dwc3: pci: add support for the Intel Wildcat Lake (stable-fixes). - usb: quirks: Add DELAY_INIT quick for another SanDisk 3.2Gen1 Flash Drive (stable-fixes). - usb: renesas-xhci: Fix External ROM access timeouts (git-fixes). - usb: storage: realtek_cr: Use correct byte order for bcs->Residue (git-fixes). - usb: typec: intel_pmc_mux: Defer probe if SCU IPC isn't present (stable-fixes). - usb: typec: ucsi: psy: Set current max to 100mA for BC 1.2 and Default (stable-fixes). - usb: xhci: Avoid showing errors during surprise removal (stable-fixes). - usb: xhci: Avoid showing warnings for dying controller (stable-fixes). - usb: xhci: Fix slot_id resource race conflict (git-fixes). - usb: xhci: Set avg_trb_len = 8 for EP0 during Address Device Command (stable-fixes). - usb: xhci: print xhci->xhc_state when queue_command failed (stable-fixes). - vfs: Add a sysctl for automated deletion of dentry (bsc#1240890). - watchdog: dw_wdt: Fix default timeout (stable-fixes). - watchdog: iTCO_wdt: Report error if timeout configuration fails (stable-fixes). - watchdog: sbsa: Adjust keepalive timeout to avoid MediaTek WS0 race condition (stable-fixes). - wifi: ath10k: shutdown driver when hardware is unreliable (stable-fixes). - wifi: ath12k: Add memset and update default rate value in wmi tx completion (stable-fixes). - wifi: ath12k: Correct tid cleanup when tid setup fails (stable-fixes). - wifi: ath12k: Decrement TID on RX peer frag setup error handling (stable-fixes). - wifi: ath12k: Enable REO queue lookup table feature on QCN9274 hw2.0 (stable-fixes). - wifi: ath12k: Fix station association with MBSSID Non-TX BSS (stable-fixes). - wifi: cfg80211: Fix interface type validation (stable-fixes). - wifi: cfg80211: reject HTC bit for management frames (stable-fixes). - wifi: iwlegacy: Check rate_idx range after addition (stable-fixes). - wifi: iwlwifi: dvm: fix potential overflow in rs_fill_link_cmd() (stable-fixes). - wifi: iwlwifi: fw: Fix possible memory leak in iwl_fw_dbg_collect (stable-fixes). - wifi: iwlwifi: mvm: avoid outdated reorder buffer head_sn (stable-fixes). - wifi: iwlwifi: mvm: fix scan request validation (stable-fixes). - wifi: iwlwifi: mvm: set gtk id also in older FWs (stable-fixes). - wifi: mac80211: avoid weird state in error path (stable-fixes). - wifi: mac80211: do not complete management TX on SAE commit (stable-fixes). - wifi: mac80211: do not unreserve never reserved chanctx (stable-fixes). - wifi: mac80211: fix rx link assignment for non-MLO stations (stable-fixes). - wifi: mac80211: update radar_required in channel context after channel switch (stable-fixes). - wifi: mt76: mt7915: mcu: re-init MCU before loading FW patch (stable-fixes). - wifi: rtlwifi: fix possible skb memory leak in _rtl_pci_init_one_rxdesc() (stable-fixes). - wifi: rtlwifi: fix possible skb memory leak in `_rtl_pci_rx_interrupt()` (stable-fixes). - wifi: rtw89: Disable deep power saving for USB/SDIO (stable-fixes). - wifi: rtw89: Fix rtw89_mac_power_switch() for USB (stable-fixes). - wifi: rtw89: Lower the timeout in rtw89_fw_read_c2h_reg() for USB (stable-fixes). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3300-1 Released: Tue Sep 23 11:03:41 2025 Summary: Security update for vim Type: security Severity: moderate References: 1246602,1246604,1247938,1247939,CVE-2025-53905,CVE-2025-53906,CVE-2025-55157,CVE-2025-55158 This update for vim fixes the following issues: Updated to 9.1.1629: - CVE-2025-53905: Fixed malicious tar archive may causing a path traversal in Vim???s tar.vim plugin (bsc#1246604) - CVE-2025-53906: Fixed malicious zip archive may causing a path traversal in Vim???s zip (bsc#1246602) - CVE-2025-55157: Fixed use-after-free in internal tuple reference management (bsc#1247938) - CVE-2025-55158: Fixed double-free in internal typed value (typval_T) management (bsc#1247939) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3305-1 Released: Tue Sep 23 11:10:37 2025 Summary: Recommended update for dracut Type: recommended Severity: moderate References: 1247819 This update for dracut fixes the following issues: - fix (dracut-util): crash if CMDLINE ends with quotation mark (bsc#1247819) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3369-1 Released: Fri Sep 26 12:54:43 2025 Summary: Security update for libssh Type: security Severity: moderate References: 1246974,1249375,CVE-2025-8114,CVE-2025-8277 This update for libssh fixes the following issues: - CVE-2025-8277: memory exhaustion leading to client-side DoS due to improper memory management when KEX process is repeated with incorrect guesses (bsc#1249375). - CVE-2025-8114: NULL pointer dereference when an allocation error happens during the calculation of the KEX session ID (bsc#1246974). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3371-1 Released: Fri Sep 26 13:41:03 2025 Summary: Recommended update for sysconfig Type: recommended Severity: important References: 1237595 This update for sysconfig fixes the following issues: - Update to version 0.85.10 - codespell run for all repository files and changes file - spec: define permissions for ghost file attrs to avoid rpm --restore resets them to 0 (bsc#1237595). - spec: fix name-repeated-in-summary rpmlint warning ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3372-1 Released: Fri Sep 26 13:42:10 2025 Summary: Recommended update for iproute2 Type: recommended Severity: important References: 1243005,1248660 This update for iproute2 fixes the following issues: - add post-6.4 follow-up fixes (bsc#1243005) - sync UAPI header copies with SLE15-SP6 kernel - devlink: support ipsec_crypto and ipsec_packet cap (bsc#1248660) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3421-1 Released: Mon Sep 29 08:01:46 2025 Summary: Recommended update for sysstat Type: recommended Severity: important References: 1244553 This update for sysstat fixes the following issues: - removal of broken symlinks during the post-install phase (bsc#1244553). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3486-1 Released: Wed Oct 8 08:16:56 2025 Summary: Recommended update for grub2 Type: recommended Severity: important References: 1249088 This update for grub2 fixes the following issues: - Fix boot hangs in setting up serial console when ACPI SPCR table is present and redirection is disabled (bsc#1249088) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3489-1 Released: Wed Oct 8 08:23:53 2025 Summary: Recommended update for libsolv, libzypp, zypper Type: recommended Severity: important References: 1230267,1246912,1250343 This update for libsolv, libzypp, zypper fixes the following issues: - fixed rare crash in the handling of allowuninstall in combination with forcebest updates - new pool_satisfieddep_map feature to test if a set of packages satisfies a dependency - runposttrans: strip root prefix from tmppath (bsc#1250343) - fixup! Make ld.so ignore the subarch packages during install (bsc#1246912) - Make ld.so ignore the subarch packages during install (bsc#1246912) - Fixed `bash-completion`: `zypper refresh` now ignores repository priority lines. - Changes to support building against restructured libzypp in stack build (bsc#1230267) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3508-1 Released: Thu Oct 9 10:32:56 2025 Summary: Security update for expat Type: security Severity: important References: 1249584,CVE-2025-59375 This update for expat fixes the following issues: - CVE-2025-59375: memory amplification vulnerability allows attackers to trigger excessive dynamic memory allocations by submitting crafted XML input (bsc#1249584). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3546-1 Released: Sat Oct 11 03:21:33 2025 Summary: Security update for openssl-3 Type: security Severity: important References: 1250232,CVE-2025-9230 This update for openssl-3 fixes the following issues: - CVE-2025-9230: Fixed out-of-bounds read & write in RFC 3211 KEK unwrap (bsc#1250232). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3596-1 Released: Wed Oct 15 09:51:21 2025 Summary: Recommended update for curl Type: recommended Severity: moderate References: 1251264 This update for curl fixes the following issue: - rebuilds it against a newer nghttp2 to fix handling 2 or more whitespaces in headers. (bsc#1251264) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3601-1 Released: Wed Oct 15 14:56:34 2025 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1212533,1216527,1218644,1227555,1230062,1236897,1237449,1237776,1238782,1240324,1241166,1241292,1241866,1243112,1245538,1245700,1245963,1246057,1246190,1246248,1246298,1246509,1246782,1247099,1247126,1247136,1247137,1247223,1247239,1247262,1247442,1247483,1247963,1248111,1248121,1248192,1248199,1248200,1248202,1248225,1248296,1248334,1248343,1248357,1248360,1248365,1248378,1248380,1248392,1248512,1248610,1248616,1248619,1248622,1248626,1248628,1248634,1248639,1248647,1248674,1248681,1248733,1248734,1248735,1248775,1249122,1249123,1249124,1249125,1249126,1249143,1249156,1249163,1249172,1249176,1249183,1249186,1249193,1249199,1249201,1249202,1249206,1249258,1249262,1249274,1249284,1249290,1249295,1249300,1249303,1249305,1249306,1249315,1249333,1249334,1249374,1249481,1249482,1249488,1249494,1249504,1249508,1249510,1249513,1249516,1249524,1249526,1249533,1249540,1249545,1249566,1249604,1249608,1249770,1249887,1249906,1249915,1249974,1250002,1250021,1250025,1250057,1250179,1 250251,1250267,1250294,1250334,1250336,1250344,1250365,1250407,1250522,1250530,1250574,1250655,1250722,1250952,CVE-2023-53261,CVE-2023-5633,CVE-2024-58090,CVE-2025-22022,CVE-2025-38119,CVE-2025-38216,CVE-2025-38234,CVE-2025-38255,CVE-2025-38263,CVE-2025-38351,CVE-2025-38402,CVE-2025-38408,CVE-2025-38418,CVE-2025-38419,CVE-2025-38456,CVE-2025-38466,CVE-2025-38488,CVE-2025-38514,CVE-2025-38526,CVE-2025-38527,CVE-2025-38533,CVE-2025-38544,CVE-2025-38556,CVE-2025-38574,CVE-2025-38584,CVE-2025-38590,CVE-2025-38593,CVE-2025-38595,CVE-2025-38597,CVE-2025-38605,CVE-2025-38614,CVE-2025-38616,CVE-2025-38622,CVE-2025-38623,CVE-2025-38628,CVE-2025-38639,CVE-2025-38640,CVE-2025-38643,CVE-2025-38645,CVE-2025-38659,CVE-2025-38660,CVE-2025-38664,CVE-2025-38668,CVE-2025-38676,CVE-2025-38678,CVE-2025-38679,CVE-2025-38684,CVE-2025-38701,CVE-2025-38703,CVE-2025-38705,CVE-2025-38709,CVE-2025-38710,CVE-2025-38721,CVE-2025-38722,CVE-2025-38730,CVE-2025-38732,CVE-2025-39677,CVE-2025-39678,CVE-2025-39681,CV E-2025-39682,CVE-2025-39691,CVE-2025-39695,CVE-2025-39703,CVE-2025-39705,CVE-2025-39707,CVE-2025-39711,CVE-2025-39718,CVE-2025-39738,CVE-2025-39744,CVE-2025-39746,CVE-2025-39747,CVE-2025-39749,CVE-2025-39754,CVE-2025-39764,CVE-2025-39766,CVE-2025-39770,CVE-2025-39773,CVE-2025-39782,CVE-2025-39787,CVE-2025-39797,CVE-2025-39807,CVE-2025-39811,CVE-2025-39816,CVE-2025-39823,CVE-2025-39825,CVE-2025-39830,CVE-2025-39834,CVE-2025-39835,CVE-2025-39838,CVE-2025-39842,CVE-2025-39857,CVE-2025-39865,CVE-2025-39885,CVE-2025-39890,CVE-2025-39922,CVE-2025-40300 The SUSE Linux Enterprise 15 SP7 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2023-53261: coresight: Fix memory leak in acpi_buffer->pointer (bsc#1249770). - CVE-2024-58090: sched/core: Prevent rescheduling when interrupts are disabled (bsc#1240324). - CVE-2025-22022: usb: xhci: Apply the link chain quirk on NEC isoc endpoints (bsc#1241292). - CVE-2025-38119: scsi: core: ufs: Fix a hang in the error handler (bsc#1245700). - CVE-2025-38216: iommu/vt-d: Restore context entry setup order for aliased devices (bsc#1245963). - CVE-2025-38234: sched/rt: Fix race in push_rt_task (bsc#1246057). - CVE-2025-38263: bcache: fix NULL pointer in cache_set_flush() (bsc#1246248). - CVE-2025-38351: KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush (bsc#1246782). - CVE-2025-38402: idpf: return 0 size for RSS key if not supported (bsc#1247262). - CVE-2025-38408: genirq/irq_sim: Initialize work context pointers properly (bsc#1247126). - CVE-2025-38418: remoteproc: core: Release rproc->clean_table after rproc_attach() fails (bsc#1247137). - CVE-2025-38419: remoteproc: core: Cleanup acquired resources when rproc_handle_resources() fails in rproc_attach() (bsc#1247136). - CVE-2025-38456: ipmi:msghandler: Fix potential memory corruption in ipmi_create_user() (bsc#1247099). - CVE-2025-38466: perf: Revert to requiring CAP_SYS_ADMIN for uprobes (bsc#1247442). - CVE-2025-38488: smb: client: fix use-after-free in crypt_message when using async crypto (bsc#1247239). - CVE-2025-38514: rxrpc: Fix oops due to non-existence of prealloc backlog struct (bsc#1248202). - CVE-2025-38526: ice: add NULL check in eswitch lag check (bsc#1248192). - CVE-2025-38527: smb: client: fix use-after-free in cifs_oplock_break (bsc#1248199). - CVE-2025-38533: net: libwx: fix the using of Rx buffer DMA (bsc#1248200). - CVE-2025-38544: rxrpc: Fix bug due to prealloc collision (bsc#1248225). - CVE-2025-38556: HID: core: Harden s32ton() against conversion to 0 bits (bsc#1248296). - CVE-2025-38574: pptp: ensure minimal skb length in pptp_xmit() (bsc#1248365). - CVE-2025-38584: padata: Fix pd UAF once and for all (bsc1248343). - CVE-2025-38590: net/mlx5e: Remove skb secpath if xfrm state is not found (bsc#1248360). - CVE-2025-38593: kABI workaround for bluetooth discovery_state change (bsc#1248357). - CVE-2025-38595: xen: fix UAF in dmabuf_exp_from_pages() (bsc#1248380). - CVE-2025-38597: drm/rockchip: vop2: fail cleanly if missing a primary plane for a video-port (bsc#1248378). - CVE-2025-38605: wifi: ath12k: Pass ab pointer directly to ath12k_dp_tx_get_encap_type() (bsc#1248334). - CVE-2025-38614: eventpoll: Fix semi-unbounded recursion (bsc#1248392). - CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1248512). - CVE-2025-38622: net: drop UFO packets in udp_rcv_segment() (bsc#1248619). - CVE-2025-38623: PCI: pnv_php: Fix surprise plug detection and recovery (bsc#1248610). - CVE-2025-38628: vdpa/mlx5: Fix release of uninitialized resources on error path (bsc#1248616). - CVE-2025-38639: netfilter: xt_nfacct: do not assume acct name is null-terminated (bsc#1248674). - CVE-2025-38640: bpf: Disable migration in nf_hook_run_bpf() (bsc#1248622). - CVE-2025-38643: wifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac() (bsc#1248681). - CVE-2025-38645: net/mlx5: Check device memory pointer before usage (bsc#1248626). - CVE-2025-38659: gfs2: No more self recovery (bsc#1248639). - CVE-2025-38660: [ceph] parse_longname(): strrchr() expects NUL-terminated string (bsc#1248634). - CVE-2025-38664: ice: Fix a null pointer dereference in ice_copy_and_init_pkg() (bsc#1248628). - CVE-2025-38668: regulator: core: fix NULL dereference on unbind due to stale coupling data (bsc#1248647). - CVE-2025-38676: iommu/amd: Avoid stack buffer overflow from kernel cmdline (bsc#1248775). - CVE-2025-38678: netfilter: nf_tables: reject duplicate device on updates (bsc#1249126). - CVE-2025-38679: media: venus: Fix OOB read due to missing payload bound check (bsc#1249202). - CVE-2025-38684: net/sched: ets: use old 'nbands' while purging unused classes (bsc#1249156). - CVE-2025-38701: ext4: do not BUG when INLINE_DATA_FL lacks system.data xattr (bsc#1249258). - CVE-2025-38705: drm/amd/pm: fix null pointer access (bsc#1249334). - CVE-2025-38709: loop: Avoid updating block size under exclusive owner (bsc#1249199). - CVE-2025-38710: gfs2: Validate i_depth for exhash directories (bsc#1249201). - CVE-2025-38721: netfilter: ctnetlink: fix refcount leak on table dump (bsc#1249176). - CVE-2025-38722: habanalabs: fix UAF in export_dmabuf() (bsc#1249163). - CVE-2025-38730: io_uring/net: commit partial buffers on retry (bsc#1249172). - CVE-2025-38732: netfilter: nf_reject: do not leak dst refcount for loopback packets (bsc#1249262). - CVE-2025-39677: net/sched: Fix backlog accounting in qdisc_dequeue_internal (bsc#1249300). - CVE-2025-39678: platform/x86/amd/hsmp: Ensure sock->metric_tbl_addr is non-NULL (bsc#1249290). - CVE-2025-39681: x86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init helper (bsc#1249303). - CVE-2025-39682: tls: fix handling of zero-length records on the rx_list (bsc#1249284). - CVE-2025-39691: fs/buffer: fix use-after-free when call bh_read() helper (bsc#1249374). - CVE-2025-39703: net, hsr: reject HSR frame if skb can't hold tag (bsc#1249315). - CVE-2025-39705: drm/amd/display: fix a Null pointer dereference vulnerability (bsc#1249295). - CVE-2025-39718: vsock/virtio: Validate length in packet header before skb_put() (bsc#1249305). - CVE-2025-39738: btrfs: do not allow relocation of partially dropped subvolumes (bsc#1249540). - CVE-2025-39744: rcu: Fix rcu_read_unlock() deadloop due to IRQ work (bsc#1249494). - CVE-2025-39746: wifi: ath10k: shutdown driver when hardware is unreliable (bsc#1249516). - CVE-2025-39749: rcu: Protect ->defer_qs_iw_pending from data race (bsc#1249533). - CVE-2025-39754: mm/smaps: fix race between smaps_hugetlb_range and migration (bsc#1249524). - CVE-2025-39764: netfilter: ctnetlink: remove refcounting in expectation dumpers (bsc#1249513). - CVE-2025-39766: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit (bsc#1249510). - CVE-2025-39770: net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM (bsc#1249508). - CVE-2025-39773: net: bridge: fix soft lockup in br_multicast_query_expired() (bsc#1249504). - CVE-2025-39782: jbd2: prevent softlockup in jbd2_log_do_checkpoint() (bsc#1249526). - CVE-2025-39787: soc: qcom: mdt_loader: Deal with zero e_shentsize (bsc#1249545). - CVE-2025-39797: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI (bsc#1249608). - CVE-2025-39816: io_uring/kbuf: always use READ_ONCE() to read ring provided buffer lengths (bsc#1249906). - CVE-2025-39823: KVM: x86: use array_index_nospec with indices that come from guest (bsc#1250002). - CVE-2025-39825: smb: client: fix race with concurrent opens in rename(2) (bsc#1250179). - CVE-2025-39830: net/mlx5: HWS, Fix memory leak in hws_pool_buddy_init error path (bsc#1249974). - CVE-2025-39834: net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic error flow (bsc#1250021). - CVE-2025-39835: xfs: do not propagate ENODATA disk errors into xattr code (bsc#1250025). - CVE-2025-39838: cifs: prevent NULL pointer dereference in UTF16 conversion (bsc#1250365). - CVE-2025-39842: ocfs2: prevent release journal inode after journal shutdown (bsc#1250267). - CVE-2025-39857: net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync() (bsc#1250251). - CVE-2025-39865: tee: fix NULL pointer dereference in tee_shm_put (bsc#1250294). - CVE-2025-39885: ocfs2: fix recursive semaphore deadlock in fiemap call (bsc#1250407). - CVE-2025-39922: ixgbe: fix incorrect map used in eee linkmode (bsc#1250722). - CVE-2025-40300: x86/vmscape: Warn when STIBP is disabled with SMT (bsc#1247483). The following non-security bugs were fixed: - !CONFIG & reference -> this is bug, immediate fail - 9p/xen: fix init sequence (git-fixes). - ACPI/IORT: Fix memory leak in iort_rmr_alloc_sids() (git-fixes). - ACPI: EC: Add device to acpi_ec_no_wakeup[] qurik list (stable-fixes). - ACPI: TAD: Add missing sysfs_remove_group() for ACPI_TAD_RT (git-fixes). - ACPI: debug: fix signedness issues in read/write helpers (git-fixes). - ACPI: processor: idle: Fix memory leak when register cpuidle device failed (git-fixes). - ACPI: property: Fix buffer properties extraction for subnodes (git-fixes). - ACPICA: Fix largest possible resource descriptor index (git-fixes). - ALSA: firewire-motu: drop EPOLLOUT from poll return values as write is not supported (stable-fixes). - ALSA: hda/hdmi: Add pin fix for another HP EliteDesk 800 G4 model (stable-fixes). - ALSA: hda/realtek - Add new HP ZBook laptop with micmute led fixup (stable-fixes). - ALSA: hda/realtek: Add ALC295 Dell TAS2781 I2C fixup (git-fixes). - ALSA: hda/realtek: Add support for HP Agusta using CS35L41 HDA (stable-fixes). - ALSA: hda/realtek: Fix headset mic for TongFang X6[AF]R5xxY (stable-fixes). - ALSA: hda/realtek: Fix mute led for HP Laptop 15-dw4xx (stable-fixes). - ALSA: hda: intel-dsp-config: Prevent SEGFAULT if ACPI_HANDLE() is NULL (git-fixes). - ALSA: lx_core: use int type to store negative error codes (git-fixes). - ALSA: pcm: Disable bottom softirqs as part of spin_lock_irq() on PREEMPT_RT (git-fixes). - ALSA: usb-audio: Add DSD support for Comtrue USB Audio device (stable-fixes). - ALSA: usb-audio: Add mixer quirk for Sony DualSense PS5 (stable-fixes). - ALSA: usb-audio: Add mute TLV for playback volumes on more devices (stable-fixes). - ALSA: usb-audio: Add mute TLV for playback volumes on some devices (stable-fixes). - ALSA: usb-audio: Avoid multiple assignments in mixer_quirks (stable-fixes). - ALSA: usb-audio: Convert comma to semicolon (git-fixes). - ALSA: usb-audio: Drop unnecessary parentheses in mixer_quirks (stable-fixes). - ALSA: usb-audio: Fix block comments in mixer_quirks (stable-fixes). - ALSA: usb-audio: Fix build with CONFIG_INPUT=n (git-fixes). - ALSA: usb-audio: Remove unneeded wmb() in mixer_quirks (stable-fixes). - ALSA: usb-audio: Simplify NULL comparison in mixer_quirks (stable-fixes). - ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free (git-fixes). - ALSA: usb-audio: move mixer_quirks' min_mute into common quirk (stable-fixes). - ASoC: Intel: bytcht_es8316: Fix invalid quirk input mapping (git-fixes). - ASoC: Intel: bytcr_rt5640: Fix invalid quirk input mapping (git-fixes). - ASoC: Intel: bytcr_rt5651: Fix invalid quirk input mapping (git-fixes). - ASoC: Intel: catpt: Expose correct bit depth to userspace (git-fixes). - ASoC: Intel: sof_sdw: Prevent jump to NULL add_sidecar callback (git-fixes). - ASoC: SOF: Intel: hda-stream: Fix incorrect variable used in error message (git-fixes). - ASoC: codecs: tx-macro: correct tx_macro_component_drv name (stable-fixes). - ASoC: imx-hdmi: remove cpu_pdev related code (git-fixes). - ASoC: qcom: audioreach: Fix lpaif_type configuration for the I2S interface (git-fixes). - ASoC: qcom: audioreach: fix potential null pointer dereference (git-fixes). - ASoC: qcom: q6apm-lpass-dais: Fix NULL pointer dereference if source graph failed (git-fixes). - ASoC: qcom: q6apm-lpass-dais: Fix missing set_fmt DAI op for I2S (git-fixes). - ASoC: wcd934x: fix error handling in wcd934x_codec_parse_data() (git-fixes). - ASoC: wm8940: Correct PLL rate rounding (git-fixes). - ASoC: wm8940: Correct typo in control name (git-fixes). - ASoC: wm8974: Correct PLL rate rounding (git-fixes). - Add alt-commit to drm v3d patch - Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() (git-fixes). - Bluetooth: ISO: Fix possible UAF on iso_conn_free (git-fixes). - Bluetooth: ISO: do not leak skb in ISO_CONT RX (git-fixes). - Bluetooth: ISO: free rx_skb if not consumed (git-fixes). - Bluetooth: MGMT: Fix not exposing debug UUID on MGMT_OP_READ_EXP_FEATURES_INFO (git-fixes). - Bluetooth: MGMT: Fix possible UAFs (git-fixes). - Bluetooth: compute LE flow credits based on recvbuf space (git-fixes). - Bluetooth: hci_event: Fix UAF in hci_acl_create_conn_sync (git-fixes). - Bluetooth: hci_sync: Avoid adding default advertising on startup (stable-fixes). - Bluetooth: hci_sync: Fix hci_resume_advertising_sync (git-fixes). - Bluetooth: hci_sync: Fix using random address for BIG/PA advertisements (git-fixes). - Bluetooth: qca: fix invalid device address check (git-fixes). - Bluetooth: qca: fix wcn3991 device address check (git-fixes). - Bluetooth: vhci: Prevent use-after-free by removing debugfs files early (git-fixes). - CONFIG & no reference -> OK temporarily, must be resolved eventually - Do not self obsolete older kernel variants - Drivers: hv: Always select CONFIG_SYSFB for Hyper-V guests (git-fixes). - Drivers: hv: Select CONFIG_SYSFB only if EFI is enabled (git-fixes). - Drop PCI patches that broke kdump capture boot (bsc#1246509) - Drop arm64 patches that may lead to module load failure (bsc#1250057) - Drop ath12k patch that was reverted in the upstream (git-fixes) - wrt: Regression fix for wrt s2idle on AMD laptops (bsc#1243112). - Fix source string __assign_string() (bsc#1238782) - HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() (stable-fixes). - HID: input: rename hidinput_set_battery_charge_status() (stable-fixes). - HID: input: report battery status changes immediately (git-fixes). - HID: intel-ish-ipc: Remove redundant ready check after timeout function (git-fixes). - HID: mcp2221: Do not set bus speed on every transfer (stable-fixes). - HID: mcp2221: Handle reads greater than 60 bytes (stable-fixes). - HID: quirks: add support for Legion Go dual dinput modes (stable-fixes). - HID: wacom: Add a new Art Pen 2 (stable-fixes). - IB/mlx5: Fix obj_type mismatch for SRQ event subscriptions (git-fixes) - Input: i8042 - add TUXEDO InfinityBook Pro Gen10 AMD to i8042 quirk table (stable-fixes). - Input: iqs7222 - avoid enabling unused interrupts (stable-fixes). - KVM: SVM: Clear current_vmcb during vCPU free for all *possible* CPUs (git-fixes). - KVM: SVM: Disable interception of SPEC_CTRL iff the MSR exists for the guest (git-fixes). - KVM: SVM: Sync TPR from LAPIC into VMCB::V_TPR even if AVIC is active (git-fixes). - KVM: VMX: Extract checking of guest's DEBUGCTL into helper (git-fixes). - KVM: VMX: Flush shadow VMCS on emergency reboot (git-fixes). - KVM: VMX: Handle KVM-induced preemption timer exits in fastpath for L2 (git-fixes). - KVM: VMX: Handle forced exit due to preemption timer in fastpath (git-fixes). - KVM: VMX: Re-enter guest in fastpath for 'spurious' preemption timer exits (git-fixes). - KVM: arm64: vgic: fix incorrect spinlock API usage (git-fixes). - KVM: s390: Fix incorrect usage of mmu_notifier_register() (git-fixes bsc#1250336). - KVM: x86/xen: Allow 'out of range' event channel ports in IRQ routing table (git-fixes). - KVM: x86: Drop pending_smi vs. INIT_RECEIVED check when setting MP_STATE (git-fixes). - KVM: x86: Fully defer to vendor code to decide how to force immediate exit (git-fixes). - KVM: x86: Move handling of is_guest_mode() into fastpath exit handlers (git-fixes). - KVM: x86: Plumb 'force_immediate_exit' into kvm_entry() tracepoint (git-fixes). - KVM: x86: avoid underflow when scaling TSC frequency (git-fixes). - Kconfig.suse: Add KABI checkiness macro (config) (bsc#1249186) - Limit patch filenames to 100 characters (bsc#1249604). - NFSv4/flexfiles: Fix layout merge mirror check (git-fixes). - NFSv4: Clear the NFS_CAP_FS_LOCATIONS flag if it is not set (git-fixes). - NFSv4: Clear the NFS_CAP_XATTR flag if not supported by the server (git-fixes). - NFSv4: Do not clear capabilities that won't be reset (git-fixes). - PCI: Extend isolated function probing to LoongArch (git-fixes). - PM / devfreq: mtk-cci: Fix potential error pointer dereference in probe() (git-fixes). - PM: sleep: core: Clear power.must_resume in noirq suspend error path (git-fixes). - RDMA/mana_ib: Fix DSCP value in modify QP (git-fixes). - Revert 'SUNRPC: Do not allow waiting for exiting tasks' (git-fixes). - Revert 'drm/amdgpu: fix incorrect vm flags to map bo' (stable-fixes). - Revert 'usb: xhci: Avoid Stop Endpoint retry loop if the endpoint seems Running' (git-fixes). - SUNRPC: call xs_sock_process_cmsg for all cmsg (git-fixes). - Squashfs: add additional inode sanity checking (git-fixes). - Squashfs: fix uninit-value in squashfs_get_parent (git-fixes). - Squashfs: reject negative file sizes in squashfs_read_inode() (git-fixes). - USB: gadget: dummy-hcd: Fix locking bug in RT-enabled kernels (git-fixes). - USB: serial: option: add Telit Cinterion FN990A w/audio compositions (stable-fixes). - USB: serial: option: add Telit Cinterion LE910C4-WWX new compositions (stable-fixes). - Update config files. (bsc#1249186) Plain run_oldconfig after Kconfig update. - afs: Fix potential null pointer dereference in afs_put_server (git-fixes). - arm64: Handle KCOV __init vs inline mismatches (git-fixes) - arm64: Mark kernel as tainted on SAE and SError panic (git-fixes) - arm64: dts: imx8mp-tqma8mpql: fix LDO5 power off (git-fixes) - arm64: dts: imx8mp: Fix missing microSD slot vqmmc on DH electronics (git-fixes) - arm64: dts: imx8mp: Fix missing microSD slot vqmmc on Data Modul (git-fixes) - arm64: dts: rockchip: Add vcc-supply to SPI flash on (git-fixes) - arm64: dts: rockchip: disable unrouted USB controllers and PHY on (git-fixes) - arm64: dts: rockchip: disable unrouted USB controllers and PHY on RK3399 Puma with Haikou (git-fixes). - arm64: dts: rockchip: fix internal USB hub instability on RK3399 Puma (git-fixes) - arm64: dts: rockchip: use cs-gpios for spi1 on ringneck (git-fixes) - arm64: ftrace: fix unreachable PLT for ftrace_caller in init_module (git-fixes) - ax25: properly unshare skbs in ax25_kiss_rcv() (git-fixes). - batman-adv: fix OOB read/write in network-coding decode (git-fixes). - bpf, bpftool: Fix incorrect disasm pc (git-fixes). - bpf/selftests: Fix test_tcpnotify_user (poo#189822). - bpf: Adjust free target to avoid global starvation of LRU map (git-fixes). - bpf: Fix iter/task tid filtering (git-fixes). - bpf: Fix link info netfilter flags to populate defrag flag (git-fixes). - bpf: Make reg_not_null() true for CONST_PTR_TO_MAP (git-fixes). - bpf: Properly test iter/task tid filtering (git-fixes). - bpf: bpftool: Setting error code in do_loader() (git-fixes). - bpf: handle implicit declaration of function gettid in bpf_iter.c - bpf: skip non exist keys in generic_map_lookup_batch (git-fixes). - bpftool: Fix JSON writer resource leak in version command (git-fixes). - bpftool: Fix memory leak in dump_xx_nlmsg on realloc failure (git-fixes). - bpftool: Fix readlink usage in get_fd_type (git-fixes). - bpftool: Mount bpffs when pinmaps path not under the bpffs (git-fixes). - bpftool: fix potential NULL pointer dereferencing in prog_dump() (git-fixes). - btrfs: abort transaction during log replay if walk_log_tree() failed (git-fixes). - btrfs: abort transaction on unexpected eb generation at btrfs_copy_root() (git-fixes). - btrfs: add cancellation points to trim loops (git-fixes). - btrfs: always abort transaction on failure to add block group to free space tree (git-fixes). - btrfs: always update fstrim_range on failure in FITRIM ioctl (git-fixes). - btrfs: avoid load/store tearing races when checking if an inode was logged (git-fixes). - btrfs: fix data overwriting bug during buffered write when block size < page size (git-fixes). - btrfs: fix invalid extref key setup when replaying dentry (git-fixes). - btrfs: fix race between logging inode and checking if it was logged before (git-fixes). - btrfs: fix race between setting last_dir_index_offset and inode logging (git-fixes). - btrfs: make found_logical_ret parameter mandatory for function queue_scrub_stripe() (git-fixes). - btrfs: move transaction aborts to the error site in add_block_group_free_space() (git-fixes). - btrfs: qgroup: fix race between quota disable and quota rescan ioctl (git-fixes). - btrfs: scrub: avoid unnecessary csum tree search preparing stripes (git-fixes). - btrfs: scrub: avoid unnecessary extent tree search preparing stripes (git-fixes). - btrfs: scrub: fix grouping of read IO (git-fixes). - btrfs: scrub: remove scrub_ctx::csum_list member (git-fixes). - btrfs: split remaining space to discard in chunks (git-fixes). - btrfs: tree-checker: fix the incorrect inode ref size check (git-fixes). - btrfs: use SECTOR_SHIFT to convert physical offset to LBA (git-fixes). - build_bug.h: Add KABI assert (bsc#1249186). - bus: fsl-mc: Check return value of platform_get_resource() (git-fixes). - bus: mhi: host: Do not use uninitialized 'dev' pointer in mhi_init_irq_setup() (git-fixes). - can: etas_es58x: populate ndo_change_mtu() to prevent buffer overflow (git-fixes). - can: hi311x: populate ndo_change_mtu() to prevent buffer overflow (git-fixes). - can: j1939: implement NETDEV_UNREGISTER notification handler (git-fixes). - can: j1939: j1939_local_ecu_get(): undo increment when j1939_local_ecu_get() fails (git-fixes). - can: j1939: j1939_sk_bind(): call j1939_priv_put() immediately when j1939_local_ecu_get() failed (git-fixes). - can: mcba_usb: populate ndo_change_mtu() to prevent buffer overflow (git-fixes). - can: peak_usb: fix shift-out-of-bounds issue (git-fixes). - can: rcar_can: rcar_can_resume(): fix s2ram with PSCI (stable-fixes). - can: sun4i_can: populate ndo_change_mtu() to prevent buffer overflow (git-fixes). - can: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB (git-fixes). - cdc_ncm: Flag Intel OEM version of Fibocom L850-GL as WWAN (stable-fixes). - ceph: fix possible integer overflow in ceph_zero_objects() (git-fixes). - ceph: validate snapdirname option length when mounting (git-fixes). - cgroup/cpuset: Fix a partition error with CPU hotplug (bsc#1241166). - cgroup/cpuset: Use static_branch_enable_cpuslocked() on cpusets_insane_config_key (bsc#1241166). - cgroup/rstat: Optimize cgroup_rstat_updated_list() (bsc#1247963). - cgroup/rstat: Reduce cpu_lock hold time in cgroup_rstat_flush_locked() (bsc#1247963). - cgroup: llist: avoid memory tears for llist_node (bsc#1247963). - cgroup: make css_rstat_updated nmi safe (bsc#1247963). - cgroup: remove cgroup_rstat_flush_atomic() (bsc#1247963). - cgroup: remove per-cpu per-subsystem locks (bsc#1247963). - cgroup: support to enable nmi-safe css_rstat_updated (bsc#1247963). - compiler-clang.h: define __SANITIZE_*__ macros only when undefined (stable-fixes). - compiler: remove __ADDRESSABLE_ASM{_STR,}() again (git-fixes). - cpufreq: CPPC: Mark driver with NEED_UPDATE_LIMITS flag (stable-fixes). - cpufreq: Exit governor when failed to start old governor (stable-fixes). - cpufreq: Init policy->rwsem before it may be possibly used (git-fixes). - cpufreq: Initialize cpufreq-based frequency-invariance later (git-fixes). - cpufreq: Initialize cpufreq-based invariance before subsys (git-fixes). - cpufreq: Use the fixed and coherent frequency for scaling capacity (stable-fixes). - cpufreq: cppc: Fix invalid return value in .get() callback (git-fixes). - cpufreq: governor: Fix negative 'idle_time' handling in dbs_update() (git-fixes). - cpufreq: intel_pstate: Always use HWP_DESIRED_PERF in passive mode (git-fixes). - cpufreq: intel_pstate: Unchecked MSR aceess in legacy mode (git-fixes). - cpufreq: scpi: compare kHz instead of Hz (git-fixes). - cpufreq: tegra186: Share policy per cluster (stable-fixes). - cpupower: Fix a bug where the -t option of the set subcommand was not working (stable-fixes). - crypto: af_alg - Set merge to zero early in af_alg_sendmsg (git-fixes). - crypto: aspeed - Fix dma_unmap_sg() direction (git-fixes). - crypto: atmel - Fix dma_unmap_sg() direction (git-fixes). - crypto: hisilicon - re-enable address prefetch after device resuming (git-fixes). - crypto: hisilicon/qm - check whether the input function and PF are on the same device (git-fixes). - crypto: hisilicon/qm - request reserved interrupt for virtual function (git-fixes). - crypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs (git-fixes). - crypto: hisilicon/zip - remove unnecessary validation for high-performance mode configurations (git-fixes). - crypto: keembay - Add missing check after sg_nents_for_len() (git-fixes). - crypto: qat - add shutdown handler to qat_c3xxx (git-fixes). - crypto: qat - add shutdown handler to qat_c62x (git-fixes). - crypto: qat - add shutdown handler to qat_dh895xcc (git-fixes). - dma/pool: Ensure DMA_DIRECT_REMAP allocations are decrypted (stable-fixes). - dmaengine: dw: dmamux: Fix device reference leak in rzn1_dmamux_route_allocate (git-fixes). - dmaengine: idxd: Fix double free in idxd_setup_wqs() (git-fixes). - dmaengine: idxd: Fix refcount underflow on module unload (git-fixes). - dmaengine: idxd: Remove improper idxd_free (git-fixes). - dmaengine: mediatek: Fix a flag reuse error in mtk_cqdma_tx_status() (git-fixes). - dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees (git-fixes). - dmaengine: ti: edma: Fix memory allocation size for queue_priority_map (git-fixes). - docs: admin-guide: update to current minimum pipe size default (git-fixes). - drivers/base/node: fix double free in register_one_node() (git-fixes). - drivers/base/node: handle error properly in register_one_node() (git-fixes). - drivers/base/node: optimize memory block registration to reduce boot time (bsc#1241866). - drivers/base/node: remove register_mem_block_under_node_early() (bsc#1241866). - drivers/base/node: remove register_memory_blocks_under_node() function call from register_one_node (bsc#1241866). - drivers/base/node: rename __register_one_node() to register_one_node() (bsc#1241866). - drivers/base/node: rename register_memory_blocks_under_node() and remove context argument (bsc#1241866). - drm/amd/amdgpu: Fix missing error return on kzalloc failure (git-fixes). - drm/amd/amdgpu: disable hwmon power1_cap* for gfx 11.0.3 on vf mode (stable-fixes). - drm/amd/display: Allow RX6xxx & RX7700 to invoke amdgpu_irq_get/put (git-fixes). - drm/amd/display: Clear the CUR_ENABLE register on DCN314 w/out DPP PG (stable-fixes). - drm/amd/display: Default IPS to RCG_IN_ACTIVE_IPS2_IN_OFF (git-fixes). - drm/amd/display: Disable DPCD Probe Quirk (bsc#1248121). - drm/amd/display: Do not warn when missing DCE encoder caps (stable-fixes). - drm/amd/display: Fix mismatch type comparison (stable-fixes). - drm/amd/display: Fix unnecessary cast warnings from checkpatch (stable-fixes). - drm/amd/display: Reduce accessing remote DPCD overhead (git-fixes). - drm/amd/display: Remove redundant semicolons (git-fixes). - drm/amd/display: use udelay rather than fsleep (git-fixes). - drm/amd/pm: Adjust si_upload_smc_data register programming (v3) (git-fixes). - drm/amd/pm: Disable MCLK switching with non-DC at 120 Hz+ (v2) (git-fixes). - drm/amd/pm: Disable SCLK switching on Oland with high pixel clocks (v3) (git-fixes). - drm/amd/pm: Disable ULV even if unsupported (v3) (git-fixes). - drm/amd/pm: Fix si_upload_smc_data (v3) (git-fixes). - drm/amd/pm: Treat zero vblank time as too short in si_dpm (v3) (git-fixes). - drm/amdgpu/discovery: fix fw based ip discovery (git-fixes). - drm/amdgpu/discovery: optionally use fw based ip discovery (stable-fixes). - drm/amdgpu/mes: add missing locking in helper functions (stable-fixes). - drm/amdgpu/vcn4: Fix IB parsing with multiple engine info packages (stable-fixes). - drm/amdgpu/vcn: Allow limiting ctx to instance 0 for AV1 at any time (stable-fixes). - drm/amdgpu: Fix Circular Locking Dependency in AMDGPU GFX Isolation (git-fixes). - drm/amdgpu: Power up UVD 3 for FW validation (v2) (git-fixes). - drm/amdgpu: VCN v5_0_1 to prevent FW checking RB during DPG pause (stable-fixes). - drm/amdgpu: add kicker fws loading for gfx11/smu13/psp13 (stable-fixes). - drm/amdgpu: drop hw access in non-DC audio fini (stable-fixes). - drm/amdgpu: fix a memory leak in fence cleanup when unloading (git-fixes). - drm/amdgpu: fix incorrect MALL size for GFX1151 (stable-fixes). - drm/amdgpu: remove the redeclaration of variable i (git-fixes). - drm/amdkfd: Fix error code sign for EINVAL in svm_ioctl() (git-fixes). - drm/ast: Use msleep instead of mdelay for edid read (bsc#1250530). - drm/ast: Use msleep instead of mdelay for edid read (git-fixes). - drm/bridge: it6505: select REGMAP_I2C (git-fixes). - drm/bridge: ti-sn65dsi86: fix REFCLK setting (git-fixes). - drm/cirrus-qemu: Fix pitch programming (git-fixes). - drm/dp: Add an EDID quirk for the DPCD register access probe (bsc#1248121). - drm/dp: Change AUX DPCD probe address from LANE0_1_STATUS to TRAINING_PATTERN_SET (bsc#1248121). - drm/edid: Add support for quirks visible to DRM core and drivers (bsc#1248121). - drm/edid: Define the quirks in an enum list (bsc#1248121). - drm/gma500: Fix null dereference in hdmi teardown (git-fixes). - drm/i915/backlight: Return immediately when scale() finds invalid parameters (stable-fixes). - drm/i915/dp: Fix 2.7 Gbps DP_LINK_BW value on g4x (git-fixes). - drm/i915/icl+/tc: Cache the max lane count value (stable-fixes). - drm/i915/icl+/tc: Convert AUX powered WARN to a debug message (stable-fixes). - drm/i915/power: fix size for for_each_set_bit() in abox iteration (git-fixes). - drm/mediatek: fix potential OF node use-after-free (git-fixes). - drm/msm/dp: account for widebus and yuv420 during mode validation (git-fixes). - drm/msm/dpu: fix incorrect type for ret (git-fixes). - drm/nouveau/gsp: fix potential leak of memory used during acpi init (git-fixes). - drm/nouveau: select FW caching (git-fixes). - drm/panel: novatek-nt35560: Fix invalid return value (git-fixes). - drm/panthor: Defer scheduler entitiy destruction to queue release (git-fixes). - drm/panthor: Fix memory leak in panthor_ioctl_group_create() (git-fixes). - drm/panthor: validate group queue count (git-fixes). - drm/radeon/r600_cs: clean up of dead code in r600_cs (git-fixes). - drm/rcar-du: dsi: Fix 1/2/3 lane support (git-fixes). - drm/simpledrm: Do not upcast in release helpers (git-fixes). - drm/xe/bmg: Add new PCI IDs (stable-fixes). - drm/xe/bmg: Update Wa_22019338487 (git-fixes). - drm/xe/gsc: do not flush the GSC worker from the reset path (git-fixes). - drm/xe/tile: Release kobject for the failure path (git-fixes). - drm/xe: Allow dropping kunit dependency as built-in (git-fixes). - drm/xe: Attempt to bring bos back to VRAM after eviction (git-fixes). - drm/xe: Carve out wopcm portion from the stolen memory (git-fixes). - drm/xe: Ensure fixed_slice_mode gets set after ccs_mode change (git-fixes). - drm/xe: Fix a NULL vs IS_ERR() in xe_vm_add_compute_exec_queue() (git-fixes). - drm/xe: Fix and re-enable xe_print_blob_ascii85() (git-fixes). - drm/xe: Move page fault init after topology init (git-fixes). - drm: bridge: anx7625: Fix NULL pointer dereference with early IRQ (git-fixes). - drm: bridge: cdns-mhdp8546: Fix missing mutex unlock on error path (git-fixes). - erofs: fix atomic context detection when !CONFIG_DEBUG_LOCK_ALLOC (git-fixes). - ext4: remove writable userspace mappings before truncating page cache (bsc#1247223). - fbcon: Fix OOB access in font allocation (git-fixes). - fbcon: fix integer overflow in fbcon_do_set_font (git-fixes). - firewire: core: fix overlooked update of subsystem ABI version (git-fixes). - firmware: meson_sm: fix device leak at probe (git-fixes). - flexfiles/pNFS: fix NULL checks on result of ff_layout_choose_ds_for_read (git-fixes). - fs/nfs/io: make nfs_start_io_*() killable (git-fixes). - hv_netvsc: Fix panic during namespace deletion with VF (bsc#1248111). - hv_netvsc: Set VF priv_flags to IFF_NO_ADDRCONF before open to prevent IPv6 addrconf (git-fixes). - hwmon: (mlxreg-fan) Separate methods of fan setting coming from different subsystems (git-fixes). - hwmon: mlxreg-fan: Prevent fans from getting stuck at 0 RPM (git-fixes). - hwrng: ks-sa - fix division by zero in ks_sa_rng_init (git-fixes). - hwrng: nomadik - add ARM_AMBA dependency (git-fixes). - hypfs_create_cpu_files(): add missing check for hypfs_mkdir() failure (git-fixes bsc#1249122). - i2c: designware: Add disabling clocks when probe fails (git-fixes). - i2c: i801: Hide Intel Birch Stream SoC TCO WDT (git-fixes). - i2c: mediatek: fix potential incorrect use of I2C_MASTER_WRRD (git-fixes). - i2c: riic: Allow setting frequencies lower than 50KHz (git-fixes). - i2c: tegra: Use internal reset when reset property is not available (bsc#1249143) - i3c: Fix default I2C adapter timeout value (git-fixes). - i3c: master: svc: Recycle unused IBI slot (git-fixes). - i3c: master: svc: Use manual response for IBI events (git-fixes). - iio: consumers: Fix offset handling in iio_convert_raw_to_processed() (git-fixes). - iio: dac: ad5360: use int type to store negative error codes (git-fixes). - iio: dac: ad5421: use int type to store negative error codes (git-fixes). - iio: frequency: adf4350: Fix ADF4350_REG3_12BIT_CLKDIV_MODE (git-fixes). - iio: frequency: adf4350: Fix prescaler usage (git-fixes). - iio: imu: inv_icm42600: Drop redundant pm_runtime reinitialization in resume (git-fixes). - iio: xilinx-ams: Fix AMS_ALARM_THR_DIRECT_MASK (git-fixes). - iio: xilinx-ams: Unmask interrupts after updating alarms (git-fixes). - iommu/vt-d: Fix __domain_mapping()'s usage of switch_to_super_page() (git-fixes). - isolcpus: add missing hunk back (bsc#1236897 bsc#1249206). - kABI fix after vsock/virtio: fix `rx_bytes` accounting for stream sockets (git-fixes). - kABI fix for 'netfilter: nf_tables: Audit log rule reset' (git-fixes). - kABI workaround for 'drm/dp: Add an EDID quirk for the DPCD register access probe' (bsc#1248121). - kABI workaround for RCU tasks exit tracking (bsc#1246298). - kABI: adjust new field on ip_ct_sctp struct (git-fixes). - kABI: arm64: ftrace: Restore struct mod_arch_specific layout (git-fixes). - kABI: make nft_trans_gc_catchall() public again (git-fixes). - kABI: netfilter flowtable move gc operation to bottom (git-fixes). - kabi: Restore layout of parallel_data (bsc1248343). - kabi: add struct cgroup_extra (bsc#1247963). - kabi: restore layout of struct cgroup_rstat_cpu (bsc#1247963). - kbuild/modpost: Continue processing all unresolved symbols when KLP_SYM_RELA is found (bsc#1218644, bsc#1250655). - kernel-source: Do not list mkspec and its inputs as sources (bsc#1250522). - mISDN: Fix memory leak in dsp_hwec_enable() (git-fixes). - maple_tree: fix MAPLE_PARENT_RANGE32 and parent pointer docs (git-fixes). - media: b2c2: Fix use-after-free causing by irq_check_work in flexcop_pci_remove (git-fixes). - media: chips-media: wave5: Fix gray color on screen (git-fixes). - media: cx18: Add missing check after DMA map (git-fixes). - media: i2c: mt9v111: fix incorrect type for ret (git-fixes). - media: lirc: Fix error handling in lirc_register() (git-fixes). - media: mc: Fix MUST_CONNECT handling for pads with no links (git-fixes). - media: pci: ivtv: Add missing check after DMA map (git-fixes). - media: rj54n1cb0c: Fix memleak in rj54n1_probe() (git-fixes). - media: st-delta: avoid excessive stack usage (git-fixes). - media: tuner: xc5000: Fix use-after-free in xc5000_release (git-fixes). - media: uvcvideo: Mark invalid entities with id UVC_INVALID_ENTITY_ID (git-fixes). - media: v4l2-subdev: Fix alloc failure check in v4l2_subdev_call_state_try() (git-fixes). - media: zoran: Remove zoran_fh structure (git-fixes). - memory: samsung: exynos-srom: Fix of_iomap leak in exynos_srom_probe (git-fixes). - mfd: rz-mtu3: Fix MTU5 NFCR register offset (git-fixes). - mfd: vexpress-sysreg: Check the return value of devm_gpiochip_add_data() (git-fixes). - misc: genwqe: Fix incorrect cmd field being reported in error (git-fixes). - mm/hwpoison: do not send SIGBUS to processes with recovered clean pages (git-fixes). - mm/memory-failure: fix infinite UCE for VM_PFNMAP pfn (git-fixes). - mm: introduce and use {pgd,p4d}_populate_kernel() (git-fixes). - mm: move page table sync declarations to linux/pgtable.h (git-fixes). - mmc: core: Use GFP_NOIO in ACMD22 (git-fixes). - mmc: mvsdio: Fix dma_unmap_sg() nents value (git-fixes). - mmc: sdhci-cadence: add Mobileye eyeQ support (stable-fixes). - mtd: nand: raw: atmel: Fix comment in timings preparation (stable-fixes). - mtd: nand: raw: atmel: Respect tAR, tCLR in read setup timing (git-fixes). - mtd: rawnand: omap2: fix device leak on probe failure (git-fixes). - mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer (git-fixes). - mtd: rawnand: stm32_fmc2: fix ECC overwrite (git-fixes). - net: hv_netvsc: fix loss of early receive events from host during channel open (git-fixes). - net: nfc: nci: Add parameter validation for packet data (git-fixes). - net: phy: fix phy_uses_state_machine() (git-fixes). - net: rfkill: gpio: Fix crash due to dereferencering uninitialized pointer (git-fixes). - net: rose: convert 'use' field to refcount_t (git-fixes). - net: rose: fix a typo in rose_clear_routes() (git-fixes). - net: rose: include node references in rose_neigh refcount (git-fixes). - net: rose: split remove and free operations in rose_remove_neigh() (stable-fixes). - net: usb: Remove disruptive netif_wake_queue in rtl8150_set_multicast (git-fixes). - net: usb: cdc-ncm: check for filtering capability (git-fixes). - net: usb: qmi_wwan: add Telit Cinterion LE910C4-WWX new compositions (git-fixes). - netfilter: conntrack: fix extension size table (git-fixes). - netfilter: flowtable: GC pushes back packets to classic path (git-fixes). - netfilter: handle the connecting collision properly in nf_conntrack_proto_sctp (git-fixes). - netfilter: nat: fix ipv6 nat redirect with mapped and scoped addresses (git-fixes). - netfilter: nf_conntrack_bridge: initialize err to 0 (git-fixes). - netfilter: nf_tables: A better name for nft_obj_filter (git-fixes). - netfilter: nf_tables: Audit log rule reset (git-fixes). - netfilter: nf_tables: Carry reset boolean in nft_obj_dump_ctx (git-fixes). - netfilter: nf_tables: Carry s_idx in nft_obj_dump_ctx (git-fixes). - netfilter: nf_tables: Deduplicate nft_register_obj audit logs (git-fixes). - netfilter: nf_tables: Drop pointless memset in nf_tables_dump_obj (git-fixes). - netfilter: nf_tables: Drop pointless memset when dumping rules (git-fixes). - netfilter: nf_tables: Fix entries val in rule reset audit log (git-fixes). - netfilter: nf_tables: Introduce nf_tables_getrule_single() (git-fixes). - netfilter: nf_tables: Open-code audit log call in nf_tables_getrule() (git-fixes). - netfilter: nf_tables: Unbreak audit log reset (git-fixes). - netfilter: nf_tables: Unconditionally allocate nft_obj_filter (git-fixes). - netfilter: nf_tables: audit log object reset once per table (git-fixes). - netfilter: nf_tables: bogus ENOENT when destroying element which does not exist (git-fixes). - netfilter: nf_tables: disallow element removal on anonymous sets (git-fixes). - netfilter: nf_tables: do not remove elements if set backend implements .abort (git-fixes). - netfilter: nf_tables: nft_obj_filter fits into cb->ctx (git-fixes). - netfilter: nf_tables: remove catchall element in GC sync path (git-fixes). - netfilter: nf_tables: revert do not remove elements if set backend implements .abort (git-fixes). - netfilter: nf_tables: split async and sync catchall in two functions (git-fixes). - netfilter: nfnetlink_log: silence bogus compiler warning (git-fixes). - netfilter: nft_payload: fix wrong mac header matching (git-fixes). - netfilter: nft_set_hash: try later when GC hits EAGAIN on iteration (git-fixes). - netfilter: nft_set_pipapo: call nft_trans_gc_queue_sync() in catchall GC (git-fixes). - netfilter: nft_set_pipapo: stop GC iteration if GC transaction allocation fails (git-fixes). - netfilter: nft_set_rbtree: prefer sync gc to async worker (git-fixes). - netfilter: nft_set_rbtree: rename gc deactivate+erase function (git-fixes). - netfilter: xt_recent: fix (increase) ipv6 literal buffer length (git-fixes). - nilfs2: fix CFI failure when accessing /sys/fs/nilfs2/features/* (git-fixes). - nouveau: fix disabling the nonstall irq due to storm code (git-fixes). - nvme-auth: do not re-authenticate queues with no prior authentication (bsc#1227555). - nvme-pci: try function level reset on init failure (git-fixes). - nvme-tcp: remove tag set when second admin queue config fails (git-fixes). - nvmet-auth: always free derived key data (git-fixes). - nvmet-auth: authenticate on admin queue only (bsc#1227555). - nvmet: auth: use NULL to clear a pointer in (git-fixes). - pcmcia: Add error handling for add_interval() in do_validate_mem() (git-fixes). - pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() (git-fixes). - pcmcia: omap: Add missing check for platform_get_resource (git-fixes). - phy: tegra: xusb: fix device and OF node leak at probe (git-fixes). - phy: ti-pipe3: fix device leak at unbind (git-fixes). - pinctrl: equilibrium: Remove redundant semicolons (git-fixes). - pinctrl: meson-gxl: add missing i2c_d pinmux (git-fixes). - pinctrl: renesas: Use int type to store negative error codes (git-fixes). - pinctrl: samsung: Drop unused S3C24xx driver data (git-fixes). - platform/mellanox: mlxbf-pmc: Remove newline char from event name input (git-fixes). - platform/mellanox: mlxbf-pmc: Validate event/enable input (git-fixes). - platform/x86/amd/pmc: Add TUXEDO IB Pro Gen10 AMD to spurious 8042 quirks list (stable-fixes). - platform/x86/intel: power-domains: Use topology_logical_package_id() for package ID (git-fixes). - platform/x86: dell-wmi-sysman: Fix class device unregistration (git-fixes). - platform/x86: think-lmi: Fix class device unregistration (git-fixes). - platform/x86: thinkpad_acpi: Handle KCOV __init vs inline mismatches (git-fixes). - power: supply: bq27xxx: fix error return in case of no bq27000 hdq battery (git-fixes). - power: supply: bq27xxx: restrict no-battery detection to bq27000 (git-fixes). - power: supply: cw2015: Fix a alignment coding style issue (git-fixes). - power: supply: max77976_charger: fix constant current reporting (git-fixes). - pptp: fix pptp_xmit() error path (git-fixes). - pwm: berlin: Fix wrong register in suspend/resume (git-fixes). - pwm: tiehrpwm: Fix corner case in clock divisor calculation (git-fixes). - pwm: tiehrpwm: Make code comment in .free() more useful (git-fixes). - rcu-tasks: Add data to eliminate RCU-tasks/do_exit() (bsc#1246298) - rcu-tasks: Eliminate deadlocks involving do_exit() and RCU (bsc#1246298) - rcu-tasks: Initialize callback lists at rcu_init() time (bsc#1246298) - rcu-tasks: Initialize data to eliminate RCU-tasks/do_exit() (bsc#1246298) - rcu-tasks: Maintain lists to eliminate RCU-tasks/do_exit() (bsc#1246298) - rcu-tasks: Maintain real-time response in (bsc#1246298) - rcu/exp: Fix RCU expedited parallel grace period kworker (git-fixes) - rcu/exp: Handle RCU expedited grace period kworker allocation (git-fixes) - rcu: Fix racy re-initialization of irq_work causing hangs (git-fixes) - regmap: Remove superfluous check for !config in __regmap_init() (git-fixes). - regulator: scmi: Use int type to store negative error codes (git-fixes). - regulator: sy7636a: fix lifecycle of power good gpio (git-fixes). - rpm: Configure KABI checkingness macro (bsc#1249186). - rpm: Drop support for kabi/arch/ignore-flavor (bsc#1249186). - rpm: Link arch-symbols script from scripts directory. - rpm: Link guards script from scripts directory. - s390/ap: Unmask SLCF bit in card and queue ap functions sysfs (git-fixes bsc#1249183). - s390/cpum_cf: Deny all sampling events by counter PMU (git-fixes bsc#1249481). - s390/debug: Add a reverse mode for debug_dump() (git-fixes jsc#PED-13260). - s390/debug: Add debug_dump() to write debug view to a string buffer (git-fixes jsc#PED-13260). - s390/debug: Simplify and document debug_next_entry() logic (git-fixes jsc#PED-13260). - s390/debug: Split private data alloc/free out of file operations (git-fixes jsc#PED-13260). - s390/hypfs: Avoid unnecessary ioctl registration in debugfs (git-fixes bsc#1248733 LTC#214881). - s390/hypfs: Enable limited access during lockdown (git-fixes bsc#1248733 LTC#214881). - s390/ism: fix concurrency management in ism_cmd() (git-fixes bsc#1248735). - s390/pai: Deny all events not handled by this PMU (git-fixes bsc#1249482). - s390/pci: Add pci_msg debug view to PCI report (git-fixes jsc#PED-13260). - s390/pci: Allow automatic recovery with minimal driver support (git-fixes bsc#1248734 LTC#214880). - s390/pci: Report PCI error recovery results via SCLP (git-fixes jsc#PED-13260). - s390/sclp: Fix SCCB present check (git-fixes bsc#1249123). - s390/stp: Remove udelay from stp_sync_clock() (git-fixes bsc#1249124). - s390/time: Use monotonic clock in get_cycles() (git-fixes bsc#1249125). - s390/vfio-ap: Fix no AP queue sharing allowed message written to kernel log (git-fixes bsc#1249488). - sched/deadline: Collect sched_dl_entity initialization (git-fixes) - sched/fair: Remove unused parameter from sched_asym() (git-fixes) - sched/fair: Take the scheduling domain into account in (git-fixes) - sched/isolation: Fix boot crash when maxcpus < first (git-fixes) - sched/numa, mm: do not try to migrate memory to memoryless (git-fixes) - seccomp: Fix a race with WAIT_KILLABLE_RECV if the tracer replies too fast (git-fixes). - selftests/bpf: Add asserts for netfilter link info (git-fixes). - selftests/bpf: Add cmp_map_pointer_with_const test (git-fixes). - selftests/bpf: Add test cases with CONST_PTR_TO_MAP null checks (git-fixes). - selftests/bpf: adapt one more case in test_lru_map to the new target_free (git-fixes). - selftests/cpufreq: Fix cpufreq basic read and update testcases (bsc#1250344). - selftests: bpf: test batch lookup on array of maps with holes (git-fixes). - serial: max310x: Add error checking in probe() (git-fixes). - serial: sc16is7xx: fix bug in flow control levels init (git-fixes). - soc: qcom: rpmh-rsc: Unconditionally clear _TRIGGER bit for TCS (git-fixes). - spi: bcm2835: Remove redundant semicolons (git-fixes). - spi: cadence-quadspi: Flush posted register writes before DAC access (git-fixes). - spi: cadence-quadspi: Flush posted register writes before INDAC access (git-fixes). - spi: mtk-snfi: Remove redundant semicolons (git-fixes). - spi: spi-fsl-lpspi: Fix transmissions when using CONT (git-fixes). - spi: spi-fsl-lpspi: Reset FIFO and disable module on transfer abort (git-fixes). - spi: spi-fsl-lpspi: Set correct chip-select polarity bit (git-fixes). - struct cdc_ncm_ctx: hide new member filtering_supported (git-fixes). - struct l2cap_chan: shift new member rx_avail to end (git-fixes). - supported.conf: mark hyperv_drm as external - thermal/drivers/qcom/lmh: Add missing IRQ includes (git-fixes). - thunderbolt: Compare HMAC values in constant time (git-fixes). - tty: hvc_console: Call hvc_kick in hvc_write unconditionally (bsc#1230062). - tty: n_gsm: Do not block input queue by waiting MSC (git-fixes). - uio: uio_pdrv_genirq: Remove MODULE_DEVICE_TABLE (git-fixes). - usb: cdns3: cdnsp-pci: remove redundant pci_disable_device() call (git-fixes). - usb: core: Add 0x prefix to quirks debug output (stable-fixes). - usb: dwc3: imx8mp: fix device leak at unbind (git-fixes). - usb: dwc3: qcom: Do not leave BCR asserted (git-fixes). - usb: gadget: configfs: Correctly set use_os_string at bind (git-fixes). - usb: host: max3421-hcd: Fix error pointer dereference in probe cleanup (git-fixes). - usb: misc: qcom_eud: Access EUD_MODE_MANAGER2 through secure calls (git-fixes). - usb: phy: twl6030: Fix incorrect type for ret (git-fixes). - usb: typec: fusb302: cache PD RX state (git-fixes). - usb: typec: maxim_contaminant: disable low power mode when reading comparator values (git-fixes). - usb: typec: maxim_contaminant: re-enable cc toggle if cc is open and port is clean (git-fixes). - usb: typec: tcpci: use GENMASK() for TCPC_ROLE_CTRL_CC[12] (git-fixes). - usb: typec: tcpm/tcpci_maxim: fix non-contaminant CC handling (git-fixes). - usb: typec: tcpm/tcpci_maxim: use GENMASK() for TCPC_VENDOR_CC_CTRL2 register (git-fixes). - usb: typec: tcpm: properly deliver cable vdms to altmode drivers (git-fixes). - usb: typec: tipd: Clear interrupts first (git-fixes). - usb: vhci-hcd: Prevent suspending virtually attached devices (git-fixes). - usb: xhci: Fix invalid pointer dereference in Etron workaround (git-fixes). - use uniform permission checks for all mount propagation changes (git-fixes). - vhost-scsi: Fix log flooding with target does not exist errors (git-fixes). - vhost-scsi: Return queue full for page alloc failures during copy (git-fixes). - vhost/net: Protect ubufs with rcu read lock in vhost_net_ubuf_put() (git-fixes). - vhost/vsock: Avoid allocating arbitrarily-sized SKBs (git-fixes). - vhost: fail early when __vhost_add_used() fails (git-fixes). - vsock/virtio: Resize receive buffers so that each SKB fits in a 4K page (git-fixes). - vsock/virtio: fix `rx_bytes` accounting for stream sockets (git-fixes). - vsock: Allow retrying on connect() failure (git-fixes). - vsock: Fix IOCTL_VM_SOCKETS_GET_LOCAL_CID to check also `transport_local` (git-fixes). - vsock: avoid timeout during connect() if the socket is closing (git-fixes). - wifi: ath10k: avoid unnecessary wait for service ready message (git-fixes). - wifi: ath11k: Fix DMA buffer allocation to resolve SWIOTLB issues (stable-fixes). - wifi: ath11k: HAL SRNG: do not deinitialize and re-initialize again (git-fixes). - wifi: ath11k: Use dma_alloc_noncoherent for rx_tid buffer allocation (stable-fixes). - wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load() (git-fixes). - wifi: ath11k: fix group data packet drops during rekey (git-fixes). - wifi: ath12k: Add MODULE_FIRMWARE() entries (bsc#1250952). - wifi: ath12k: fix memory leak in ath12k_pci_remove() (stable-fixes). - wifi: ath12k: fix memory leak in ath12k_service_ready_ext_event (git-fixes). - wifi: ath12k: fix the fetching of combined rssi (git-fixes). - wifi: ath12k: fix wrong handling of CCMP256 and GCMP ciphers (git-fixes). - wifi: ath12k: fix wrong logging ID used for CE (git-fixes). - wifi: brcmfmac: fix use-after-free when rescheduling brcmf_btcoex_info work (git-fixes). - wifi: cfg80211: fix use-after-free in cmp_bss() (git-fixes). - wifi: cfg80211: remove cfg80211_inform_single_bss_frame_data() (git-fixes). - wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() (git-fixes). - wifi: cw1200: cap SSID length in cw1200_do_join() (git-fixes). - wifi: iwlwifi: Remove redundant header files (git-fixes). - wifi: iwlwifi: uefi: check DSM item validity (git-fixes). - wifi: libertas: cap SSID len in lbs_associate() (git-fixes). - wifi: mac80211: fix Rx packet handling when pubsta information is not available (git-fixes). - wifi: mac80211: fix incorrect type for ret (stable-fixes). - wifi: mac80211: increase scan_ies_len for S1G (stable-fixes). - wifi: mt76: fix potential memory leak in mt76_wmac_probe() (git-fixes). - wifi: mt76: mt7996: Initialize hdr before passing to skb_put_data() (git-fixes). - wifi: mwifiex: Initialize the chan_stats array to zero (git-fixes). - wifi: mwifiex: send world regulatory domain to driver (git-fixes). - wifi: rtw89: avoid circular locking dependency in ser_state_run() (git-fixes). - wifi: virt_wifi: Fix page fault on connect (stable-fixes). - wifi: wilc1000: avoid buffer overflow in WID string configuration (stable-fixes). - wireless: purelifi: plfxlc: fix memory leak in plfxlc_usb_wreq_asyn() (git-fixes). - writeback: Avoid contention on wb->list_lock when switching inodes (bsc#1237776). - writeback: Avoid contention on wb->list_lock when switching inodes (kABI fixup) (bsc#1237776). - writeback: Avoid excessively long inode switching times (bsc#1237776). - writeback: Avoid softlockup when switching many inodes (bsc#1237776). - x86/CPU/AMD: WARN when setting EFER.AUTOIBRS if and only if the WRMSR fails (git-fixes). - x86/Kconfig: Always enable ARCH_SPARSEMEM_ENABLE (git-fixes). - x86/amd_nb: Restrict init function to AMD-based systems (git-fixes). - x86/cpu: Add model number for Intel Clearwater Forest processor (git-fixes). - x86/fpu: Delay instruction pointer fixup until after warning (git-fixes). - x86/kvm: Force legacy PCI hole to UC when overriding MTRRs for TDX/SNP (bsc#1245538). - x86/microcode/AMD: Handle the case of no BIOS microcode (git-fixes). - x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() (git-fixes). - x86/rdrand: Disable RDSEED on AMD Cyan Skillfish (git-fixes). - xen/gntdev: remove struct gntdev_copy_batch from stack (git-fixes). - xen/netfront: Fix TX response spurious interrupts (git-fixes). - xen: Add support for XenServer 6.1 platform device (git-fixes). - xenbus: Allow PVH dom0 a non-local xenstore (git-fixes). - xfs: rearrange code in xfs_inode_item_precommit (bsc#1237449). - xfs: rework datasync tracking and execution (bsc#1237449). - xhci: Fix control transfer error on Etron xHCI host (git-fixes). - xhci: dbc: Fix full DbC transfer ring after several reconnects (git-fixes). - xhci: dbc: decouple endpoint allocation from initialization (git-fixes). - xhci: fix memory leak regression when freeing xhci vdev devices depth first (git-fixes). - xirc2ps_cs: fix register access when enabling FullDuplex (git-fixes). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3699-1 Released: Tue Oct 21 12:07:47 2025 Summary: Security update for krb5 Type: security Severity: moderate References: 1241219,CVE-2025-3576 This update for krb5 fixes the following issues: - CVE-2025-3576: weakness in the MD5 checksum design allows for spoofing of GSSAPI-protected messages that are using RC4-HMAC-MD5 (bsc#1241219). Krb5 as very old protocol supported quite a number of ciphers that are not longer up to current cryptographic standards. To avoid problems with those, SUSE has by default now disabled those alorithms. The following algorithms have been removed from valid krb5 enctypes: - des3-cbc-sha1 - arcfour-hmac-md5 To reenable those algorithms, you can use allow options in krb5.conf: [libdefaults] allow_des3 = true allow_rc4 = true to reenable them. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3804-1 Released: Mon Oct 27 12:35:04 2025 Summary: Security update for mozilla-nss Type: security Severity: important References: 1251263,CVE-2025-9187 This update for mozilla-nss fixes the following issues: - Move NSS DB password hash away from SHA-1 Update to NSS 3.112.2: * Prevent leaks during pkcs12 decoding. * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates Update to NSS 3.112.1: * restore support for finding certificates by decoded serial number. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3836-1 Released: Tue Oct 28 11:38:00 2025 Summary: Recommended update for bash Type: recommended Severity: important References: 1245199 This update for bash fixes the following issues: - Fix histfile missing timestamp for the oldest record (bsc#1245199) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3847-1 Released: Wed Oct 29 06:06:00 2025 Summary: Recommended update for python-kiwi Type: recommended Severity: critical References: 1243381,1245190,1250754 This update for python-kiwi, appx-util, python-docopt, python-xmltodict, libsolv fixes the following issues: python-kiwi: - Switch to Python 3.11 based python-kiwi (jsc#PED-13168) - Fixed system booting to Emergency Mode on first reboot using qcow2 (bsc#1250754) - Fixed get_partition_node_name (bsc#1245190) - Added new eficsm type attribute (bsc#1243381) - Included support for older schemas - New binary packages: * kiwi-bash-completion * kiwi-systemdeps-containers-wsl appx-util: - Implementation as dependency required by kiwi-systemdeps-containers-wsl python-docopt, python-xmltodict, libsolv: - Implementation of Python 3.11 flavours required by python311-kiwi (no source changes) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3851-1 Released: Wed Oct 29 15:04:32 2025 Summary: Recommended update for vim Type: recommended Severity: moderate References: 1229750,1250593 This update for vim fixes the following issues: - Fix regression in vim: xxd -a shows no output (bsc#1250593). Backported from 9.1.1683 (xxd: Avoid null dereference in autoskip colorless). - Fix vim compatible mode is not switched off earlier (bsc#1229750). Nocompatible must be set before the syntax highlighting is turned on. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3877-1 Released: Fri Oct 31 05:29:41 2025 Summary: Recommended update for libselinux Type: recommended Severity: important References: 1252160 This update for libselinux fixes the following issues: - Ship license file (bsc#1252160) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3930-1 Released: Tue Nov 4 09:26:22 2025 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1232526,1238491,1239566,1239938,1240788,1243794,1243991,1244050 This update for gcc15 fixes the following issues: This update ships the GNU Compiler Collection GCC 15.2. (jsc#PED-12029) The compiler runtime libraries are provided for all SUSE Linux Enterprise 15 versions and replace the same named GCC 14 ones. The new compilers for C, C++, and Fortran are provided for SUSE Linux Enterprise 15 SP6 and SP7, and provided in the 'Development Tools' module. The Go, D, Ada and Modula 2 language compiler parts are available unsupported via the PackageHub repositories. To use gcc15 compilers use: - install 'gcc15' or 'gcc15-c++' or one of the other 'gcc15-COMPILER' frontend packages. - override your Makefile to use CC=gcc15, CXX=g++15 and similar overrides for the other languages. For a full changelog with all new GCC15 features, check out https://gcc.gnu.org/gcc-15/changes.html Update to GCC 15.2 release: * the GCC 15.2 release contains regression fixes accumulated since the GCC 15.1 release - Prune the use of update-alternatives from openSUSE Factory and SLFO. - Adjust crosses to conflict consistently where they did not already and make them use unsuffixed binaries. - Tune for power10 for SLES 16. [jsc#PED-12029] - Tune for z15 for SLES 16. [jsc#PED-253] - Fix PR120827, ICE due to splitter emitting constant loads directly - Exclude shared objects present for link editing in the GCC specific subdirectory from provides processing via __provides_exclude_from. [bsc#1244050][bsc#1243991] - Make cross-*-gcc15-bootstrap package conflict with the non-bootstrap variant conflict with the unversioned cross-*-gcc package. - Enable C++ for offload compilers. [bsc#1243794] - Add libgcobol and libquadmath-devel dependence to the cobol frontend package. Update to GCC 15 branch head, 15.1.1+git9595 * includes GCC 15.1 release - Enable gfx9-generic, gfx10-3-generic and gfx11-generic multilibs for the AMD GCN offload compiler when llvm is new enough. - Make sure link editing is done against our own shared library copy rather than the installed system runtime. [bsc#1240788] - Fix newlib libm miscompilation for GCN offloading. Update to GCC trunk head, 15.0.1+git9001 * includes -msplit-patch-nops required for user-space livepatching on powerpc * includes fix for Ada build with --enable-host-pie - Build GCC executables PIE on SLE. [bsc#1239938] - Includes change to also record -D_FORTIFY_SOURCE=2 in the DWARF debug info DW_AT_producer string. [bsc#1239566] - Package GCC COBOL compiler for openSUSE Factory for supported targets which are x86_64, aarch64 and ppc64le. - Disable profiling during build when %want_reproducible_builds is set [bsc#1238491] - Includes fix for emacs JIT use - Bumps libgo SONAME to libgo24 which should fix go1.9 build - Adjust cross compiler requirements to use %requires_ge - For cross compilers require the same or newer binutils, newlib or cross-glibc that was used at build time. [bsc#1232526] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3934-1 Released: Tue Nov 4 12:23:11 2025 Summary: Recommended update for cyrus-sasl Type: recommended Severity: moderate References: 1247498 This update for cyrus-sasl fixes the following issue: - Replace insecure MD5 with ephemeral HMAC-SHA256 (bsc#1247498). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3968-1 Released: Thu Nov 6 11:58:36 2025 Summary: Recommended update for libaio Type: recommended Severity: moderate References: 1082318,1133233,1181869,1243195 This update for libaio fixes the following issues: libaio was updated to 0.3.113 (jsc#PED-13433): * Fix struct io_iocb_vector padding for 32bit architectures * struct io_iocb_sockaddr padding for 32bit architectures * Verify structure padding is correct at build time * harness: add test for aio poll missed events * Various patches for architectures/etc ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4057-1 Released: Tue Nov 11 19:35:57 2025 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1012628,1194869,1213061,1213666,1214073,1214928,1214953,1214954,1215143,1215150,1215199,1215696,1216396,1216436,1216976,1220186,1220419,1229165,1239206,1243100,1243112,1244939,1245193,1245260,1246125,1247118,1247222,1247500,1247683,1248111,1248211,1248230,1248517,1248630,1248735,1248754,1248847,1248886,1249123,1249159,1249161,1249164,1249166,1249169,1249170,1249177,1249182,1249190,1249194,1249195,1249196,1249200,1249203,1249204,1249215,1249220,1249221,1249224,1249254,1249255,1249257,1249260,1249263,1249265,1249266,1249271,1249272,1249273,1249278,1249279,1249281,1249282,1249285,1249286,1249288,1249292,1249296,1249299,1249302,1249304,1249308,1249312,1249317,1249318,1249319,1249320,1249321,1249323,1249324,1249338,1249397,1249413,1249479,1249486,1249489,1249490,1249506,1249512,1249515,1249522,1249523,1249538,1249542,1249548,1249554,1249595,1249598,1249608,1249615,1249640,1249641,1249642,1249658,1249662,1249672,1249673,1249677,1249678,1249679,1249682,1249687,1249698,1249707,1 249712,1249730,1249735,1249756,1249758,1249761,1249762,1249768,1249774,1249779,1249780,1249785,1249787,1249795,1249815,1249820,1249823,1249824,1249825,1249826,1249833,1249842,1249845,1249849,1249850,1249853,1249856,1249861,1249863,1249864,1249865,1249866,1249869,1249870,1249880,1249883,1249888,1249894,1249896,1249897,1249901,1249911,1249917,1249919,1249923,1249926,1249938,1249949,1249950,1249952,1249975,1249979,1249984,1249988,1249990,1249993,1249994,1249997,1250004,1250006,1250007,1250012,1250022,1250024,1250028,1250029,1250032,1250035,1250049,1250055,1250058,1250062,1250063,1250065,1250066,1250067,1250069,1250070,1250073,1250074,1250088,1250089,1250106,1250112,1250117,1250119,1250120,1250125,1250127,1250128,1250145,1250150,1250156,1250157,1250161,1250163,1250166,1250167,1250169,1250171,1250177,1250180,1250186,1250196,1250198,1250199,1250201,1250202,1250203,1250204,1250205,1250206,1250208,1250237,1250241,1250242,1250243,1250247,1250249,1250262,1250263,1250266,1250268,1250274,125027 5,1250276,1250281,1250290,1250291,1250292,1250296,1250297,1250298,1250313,1250319,1250323,1250325,1250329,1250337,1250358,1250371,1250377,1250379,1250384,1250389,1250395,1250397,1250400,1250402,1250406,1250426,1250450,1250455,1250459,1250491,1250519,1250650,1250702,1250704,1250712,1250713,1250721,1250732,1250736,1250741,1250742,1250758,1250759,1250763,1250765,1250807,1250808,1250809,1250812,1250813,1250815,1250816,1250820,1250823,1250825,1250827,1250830,1250831,1250837,1250841,1250861,1250863,1250867,1250872,1250873,1250878,1250905,1250907,1250917,1250918,1250923,1250926,1250928,1250929,1250930,1250931,1250941,1250942,1250946,1250949,1250957,1250964,1251024,1251027,1251028,1251031,1251035,1251038,1251043,1251045,1251052,1251053,1251054,1251056,1251057,1251059,1251060,1251065,1251066,1251067,1251068,1251071,1251076,1251079,1251081,1251083,1251084,1251100,1251105,1251106,1251108,1251113,1251114,1251119,1251123,1251126,1251132,1251134,1251143,1251146,1251150,1251152,1251153,1251159,125 1161,1251170,1251177,1251180,1251206,1251215,1251216,1251222,1251230,1251232,1251233,1251247,1251268,1251269,1251270,1251282,1251283,1251286,1251290,1251319,1251321,1251323,1251328,1251529,1251721,1251732,1251742,1251743,1251746,1251748,1251749,1251750,1251754,1251755,1251756,1251758,1251759,1251760,1251762,1251763,1251764,1251769,1251771,1251772,1251777,1251780,1251804,1251810,1251930,1251967,1252033,1252035,1252039,1252044,1252047,1252051,1252052,1252056,1252060,1252062,1252064,1252065,1252069,1252070,1252072,1252074,1252075,1252078,1252079,1252081,1252082,1252083,1252236,1252253,1252265,1252330,1252332,1252336,1252346,1252348,1252349,1252364,1252469,1252479,1252481,1252489,1252490,1252492,1252495,1252496,1252499,1252534,1252536,1252537,1252550,1252553,1252559,1252561,1252564,1252565,1252566,1252632,1252668,1252678,1252679,1252685,1252688,1252734,1252735,1252772,1252775,1252785,1252787,1252789,1252797,1252819,1252822,1252826,1252841,1252848,1252849,1252850,1252851,1252854,1252858, 1252865,1252866,1252873,1252902,1252904,1252909,1252915,1252918,1252921,1252939,CVE-2023-31248,CVE-2023-3772,CVE-2023-39197,CVE-2023-42753,CVE-2023-53147,CVE-2023-53148,CVE-2023-53150,CVE-2023-53151,CVE-2023-53152,CVE-2023-53165,CVE-2023-53167,CVE-2023-53170,CVE-2023-53174,CVE-2023-53175,CVE-2023-53177,CVE-2023-53179,CVE-2023-53180,CVE-2023-53181,CVE-2023-53183,CVE-2023-53184,CVE-2023-53185,CVE-2023-53187,CVE-2023-53189,CVE-2023-53192,CVE-2023-53195,CVE-2023-53196,CVE-2023-53201,CVE-2023-53204,CVE-2023-53205,CVE-2023-53206,CVE-2023-53207,CVE-2023-53208,CVE-2023-53209,CVE-2023-53210,CVE-2023-53215,CVE-2023-53217,CVE-2023-53220,CVE-2023-53221,CVE-2023-53222,CVE-2023-53226,CVE-2023-53230,CVE-2023-53231,CVE-2023-53235,CVE-2023-53238,CVE-2023-53243,CVE-2023-53245,CVE-2023-53247,CVE-2023-53248,CVE-2023-53249,CVE-2023-53251,CVE-2023-53252,CVE-2023-53255,CVE-2023-53257,CVE-2023-53258,CVE-2023-53260,CVE-2023-53263,CVE-2023-53264,CVE-2023-53272,CVE-2023-53274,CVE-2023-53275,CVE-2023-53280,CVE -2023-53286,CVE-2023-53287,CVE-2023-53288,CVE-2023-53291,CVE-2023-53292,CVE-2023-53303,CVE-2023-53304,CVE-2023-53305,CVE-2023-53309,CVE-2023-53311,CVE-2023-53312,CVE-2023-53313,CVE-2023-53314,CVE-2023-53316,CVE-2023-53319,CVE-2023-53321,CVE-2023-53322,CVE-2023-53323,CVE-2023-53324,CVE-2023-53325,CVE-2023-53328,CVE-2023-53331,CVE-2023-53333,CVE-2023-53336,CVE-2023-53338,CVE-2023-53339,CVE-2023-53342,CVE-2023-53343,CVE-2023-53350,CVE-2023-53352,CVE-2023-53354,CVE-2023-53356,CVE-2023-53357,CVE-2023-53360,CVE-2023-53362,CVE-2023-53364,CVE-2023-53365,CVE-2023-53367,CVE-2023-53368,CVE-2023-53369,CVE-2023-53370,CVE-2023-53371,CVE-2023-53374,CVE-2023-53377,CVE-2023-53379,CVE-2023-53380,CVE-2023-53384,CVE-2023-53385,CVE-2023-53386,CVE-2023-53391,CVE-2023-53394,CVE-2023-53395,CVE-2023-53397,CVE-2023-53401,CVE-2023-53420,CVE-2023-53421,CVE-2023-53424,CVE-2023-53425,CVE-2023-53426,CVE-2023-53428,CVE-2023-53429,CVE-2023-53432,CVE-2023-53436,CVE-2023-53438,CVE-2023-53441,CVE-2023-53442,CVE-2023-5 3444,CVE-2023-53446,CVE-2023-53447,CVE-2023-53448,CVE-2023-53451,CVE-2023-53454,CVE-2023-53456,CVE-2023-53457,CVE-2023-53461,CVE-2023-53462,CVE-2023-53463,CVE-2023-53465,CVE-2023-53472,CVE-2023-53479,CVE-2023-53480,CVE-2023-53485,CVE-2023-53487,CVE-2023-53488,CVE-2023-53490,CVE-2023-53491,CVE-2023-53492,CVE-2023-53493,CVE-2023-53495,CVE-2023-53496,CVE-2023-53500,CVE-2023-53501,CVE-2023-53504,CVE-2023-53505,CVE-2023-53507,CVE-2023-53508,CVE-2023-53510,CVE-2023-53515,CVE-2023-53516,CVE-2023-53518,CVE-2023-53519,CVE-2023-53520,CVE-2023-53523,CVE-2023-53526,CVE-2023-53527,CVE-2023-53528,CVE-2023-53530,CVE-2023-53531,CVE-2023-53538,CVE-2023-53539,CVE-2023-53540,CVE-2023-53541,CVE-2023-53543,CVE-2023-53545,CVE-2023-53546,CVE-2023-53548,CVE-2023-53550,CVE-2023-53552,CVE-2023-53553,CVE-2023-53554,CVE-2023-53555,CVE-2023-53556,CVE-2023-53557,CVE-2023-53558,CVE-2023-53559,CVE-2023-53560,CVE-2023-53563,CVE-2023-53568,CVE-2023-53570,CVE-2023-53572,CVE-2023-53574,CVE-2023-53575,CVE-2023-53577,CV E-2023-53579,CVE-2023-53580,CVE-2023-53581,CVE-2023-53583,CVE-2023-53585,CVE-2023-53588,CVE-2023-53593,CVE-2023-53596,CVE-2023-53597,CVE-2023-53599,CVE-2023-53600,CVE-2023-53601,CVE-2023-53602,CVE-2023-53603,CVE-2023-53611,CVE-2023-53613,CVE-2023-53615,CVE-2023-53616,CVE-2023-53617,CVE-2023-53618,CVE-2023-53619,CVE-2023-53621,CVE-2023-53622,CVE-2023-53631,CVE-2023-53632,CVE-2023-53633,CVE-2023-53638,CVE-2023-53645,CVE-2023-53646,CVE-2023-53647,CVE-2023-53648,CVE-2023-53649,CVE-2023-53650,CVE-2023-53652,CVE-2023-53653,CVE-2023-53654,CVE-2023-53656,CVE-2023-53657,CVE-2023-53658,CVE-2023-53659,CVE-2023-53660,CVE-2023-53662,CVE-2023-53663,CVE-2023-53665,CVE-2023-53666,CVE-2023-53668,CVE-2023-53670,CVE-2023-53672,CVE-2023-53673,CVE-2023-53674,CVE-2023-53681,CVE-2023-53686,CVE-2023-53687,CVE-2023-53693,CVE-2023-53697,CVE-2023-53698,CVE-2023-53699,CVE-2023-53703,CVE-2023-53704,CVE-2023-53707,CVE-2023-53708,CVE-2023-53711,CVE-2023-53713,CVE-2023-53718,CVE-2023-53721,CVE-2023-53722,CVE-2023- 53725,CVE-2023-53726,CVE-2023-53727,CVE-2023-53728,CVE-2023-53729,CVE-2023-53730,CVE-2023-53731,CVE-2023-53733,CVE-2024-26584,CVE-2024-58240,CVE-2025-38008,CVE-2025-38465,CVE-2025-38539,CVE-2025-38552,CVE-2025-38653,CVE-2025-38680,CVE-2025-38681,CVE-2025-38683,CVE-2025-38685,CVE-2025-38687,CVE-2025-38691,CVE-2025-38692,CVE-2025-38693,CVE-2025-38694,CVE-2025-38695,CVE-2025-38697,CVE-2025-38698,CVE-2025-38699,CVE-2025-38700,CVE-2025-38702,CVE-2025-38706,CVE-2025-38712,CVE-2025-38713,CVE-2025-38714,CVE-2025-38715,CVE-2025-38718,CVE-2025-38724,CVE-2025-38725,CVE-2025-38727,CVE-2025-38729,CVE-2025-38734,CVE-2025-38735,CVE-2025-38736,CVE-2025-39673,CVE-2025-39675,CVE-2025-39676,CVE-2025-39679,CVE-2025-39683,CVE-2025-39684,CVE-2025-39685,CVE-2025-39686,CVE-2025-39693,CVE-2025-39694,CVE-2025-39697,CVE-2025-39701,CVE-2025-39702,CVE-2025-39706,CVE-2025-39709,CVE-2025-39710,CVE-2025-39713,CVE-2025-39714,CVE-2025-39719,CVE-2025-39721,CVE-2025-39724,CVE-2025-39726,CVE-2025-39730,CVE-2025-39732,C VE-2025-39739,CVE-2025-39742,CVE-2025-39743,CVE-2025-39750,CVE-2025-39751,CVE-2025-39756,CVE-2025-39757,CVE-2025-39758,CVE-2025-39759,CVE-2025-39760,CVE-2025-39761,CVE-2025-39763,CVE-2025-39772,CVE-2025-39783,CVE-2025-39790,CVE-2025-39794,CVE-2025-39797,CVE-2025-39798,CVE-2025-39800,CVE-2025-39801,CVE-2025-39806,CVE-2025-39808,CVE-2025-39810,CVE-2025-39812,CVE-2025-39813,CVE-2025-39824,CVE-2025-39826,CVE-2025-39827,CVE-2025-39828,CVE-2025-39832,CVE-2025-39833,CVE-2025-39839,CVE-2025-39841,CVE-2025-39844,CVE-2025-39845,CVE-2025-39846,CVE-2025-39847,CVE-2025-39848,CVE-2025-39849,CVE-2025-39850,CVE-2025-39851,CVE-2025-39853,CVE-2025-39854,CVE-2025-39860,CVE-2025-39861,CVE-2025-39863,CVE-2025-39864,CVE-2025-39866,CVE-2025-39869,CVE-2025-39870,CVE-2025-39871,CVE-2025-39873,CVE-2025-39876,CVE-2025-39881,CVE-2025-39882,CVE-2025-39889,CVE-2025-39891,CVE-2025-39895,CVE-2025-39898,CVE-2025-39900,CVE-2025-39902,CVE-2025-39907,CVE-2025-39911,CVE-2025-39920,CVE-2025-39923,CVE-2025-39925,CVE-2025 -39931,CVE-2025-39934,CVE-2025-39937,CVE-2025-39938,CVE-2025-39945,CVE-2025-39946,CVE-2025-39947,CVE-2025-39948,CVE-2025-39949,CVE-2025-39952,CVE-2025-39955,CVE-2025-39957,CVE-2025-39965,CVE-2025-39967,CVE-2025-39968,CVE-2025-39969,CVE-2025-39970,CVE-2025-39971,CVE-2025-39972,CVE-2025-39973,CVE-2025-39978,CVE-2025-39981,CVE-2025-39982,CVE-2025-39984,CVE-2025-39985,CVE-2025-39986,CVE-2025-39987,CVE-2025-39988,CVE-2025-39991,CVE-2025-39993,CVE-2025-39994,CVE-2025-39995,CVE-2025-39996,CVE-2025-39997,CVE-2025-40000,CVE-2025-40005,CVE-2025-40010,CVE-2025-40011,CVE-2025-40012,CVE-2025-40013,CVE-2025-40016,CVE-2025-40018,CVE-2025-40019,CVE-2025-40020,CVE-2025-40029,CVE-2025-40032,CVE-2025-40035,CVE-2025-40036,CVE-2025-40037,CVE-2025-40043,CVE-2025-40044,CVE-2025-40049,CVE-2025-40051,CVE-2025-40052,CVE-2025-40056,CVE-2025-40058,CVE-2025-40060,CVE-2025-40061,CVE-2025-40062,CVE-2025-40071,CVE-2025-40078,CVE-2025-40082,CVE-2025-40085,CVE-2025-40087,CVE-2025-40088,CVE-2025-40091,CVE-2025-40096, CVE-2025-40100,CVE-2025-40104 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-38008: mm/page_alloc: fix race condition in unaccepted memory handling (bsc#1244939). - CVE-2025-38539: trace/fgraph: Fix the warning caused by missing unregister notifier (bsc#1248211). - CVE-2025-38552: mptcp: plug races between subflow fail and subflow creation (bsc#1248230). - CVE-2025-38653: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (bsc#1248630). - CVE-2025-38699: scsi: bfa: Double-free fix (bsc#1249224). - CVE-2025-38700: scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated (bsc#1249182). - CVE-2025-38718: sctp: linearize cloned gso packets in sctp_rcv (bsc#1249161). - CVE-2025-38734: net/smc: fix UAF on smcsk after smc_listen_out() (bsc#1249324). - CVE-2025-38735: gve: prevent ethtool ops after shutdown (bsc#1249288). - CVE-2025-39673: ppp: fix race conditions in ppp_fill_forward_path (bsc#1249320). - CVE-2025-39676: scsi: qla4xxx: Prevent a potential error pointer dereference (bsc#1249302). - CVE-2025-39683: tracing: Limit access to parser->buffer when trace_get_user failed (bsc#1249286). - CVE-2025-39697: nfs: remove dead code for the old swap over NFS implementation (bsc#1249319). - CVE-2025-39702: ipv6: sr: Fix MAC comparison to be constant-time (bsc#1249317). - CVE-2025-39756: fs: Prevent file descriptor table allocations exceeding INT_MAX (bsc#1249512). - CVE-2025-39794: ARM: tegra: Use I/O memcpy to write to IRAM (bsc#1249595). - CVE-2025-39810: bnxt_en: Fix memory corruption when FW resources change during ifdown (bsc#1249975). - CVE-2025-39812: sctp: initialize more fields in sctp_v6_from_sk() (bsc#1250202). - CVE-2025-39813: ftrace: Fix potential warning in trace_printk_seq during ftrace_dump (bsc#1250032). - CVE-2025-39828: atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control() (bsc#1250205). - CVE-2025-39832: net/mlx5: Add sync reset drop mode support (bsc#1249901). - CVE-2025-39847: ppp: fix memory leak in pad_compress_skb (bsc#1250292). - CVE-2025-39850: vxlan: Fix NPD in {arp,neigh}_reduce() when using nexthop objects (bsc#1250276). - CVE-2025-39851: vxlan: Fix NPD when refreshing an FDB entry with a nexthop object (bsc#1250296). - CVE-2025-39853: i40e: Fix potential invalid access when MAC list is empty (bsc#1250275). - CVE-2025-39854: ice: fix NULL access of tx->in_use in ice_ll_ts_intr (bsc#1250297). - CVE-2025-39866: fs: writeback: fix use-after-free in __mark_inode_dirty() (bsc#1250455). - CVE-2025-39876: net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() (bsc#1250400). - CVE-2025-39881: kernfs: Fix UAF in polling when open file is released (bsc#1250379). - CVE-2025-39895: sched: Fix sched_numa_find_nth_cpu() if mask offline (bsc#1250721). - CVE-2025-39898: e1000e: fix heap overflow in e1000_set_eeprom (bsc#1250742). - CVE-2025-39900: net_sched: gen_estimator: fix est_timer() vs CONFIG_PREEMPT_RT=y (bsc#1250758). - CVE-2025-39902: mm/slub: avoid accessing metadata when pointer is invalid in object_err() (bsc#1250702). - CVE-2025-39911: i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path (bsc#1250704). - CVE-2025-39945: cnic: Fix use-after-free bugs in cnic_delete_task (bsc#1251230). - CVE-2025-39946: tls: make sure to abort the stream if headers are bogus (bsc#1251114). - CVE-2025-39947: net/mlx5e: Harden uplink netdev access against device unbind (bsc#1251232). - CVE-2025-39948: ice: fix Rx page leak on multi-buffer frames (bsc#1251233). - CVE-2025-39949: qed: Don't collect too many protection override GRC elements (bsc#1251177). - CVE-2025-39955: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect() (bsc#1251804). - CVE-2025-39968: i40e: add max boundary check for VF filters (bsc#1252047). - CVE-2025-39969: i40e: fix validation of VF state in get resources (bsc#1252044). - CVE-2025-39970: i40e: fix input validation logic for action_meta (bsc#1252051). - CVE-2025-39971: i40e: fix idx validation in config queues msg (bsc#1252052). - CVE-2025-39972: i40e: fix idx validation in i40e_validate_queue_map (bsc#1252039). - CVE-2025-39973: i40e: add validation for ring_len param (bsc#1252035). - CVE-2025-39978: octeontx2-pf: Fix potential use after free in otx2_tc_add_flow() (bsc#1252069). - CVE-2025-39984: net: tun: Update napi->skb after XDP process (bsc#1252081). - CVE-2025-40000: wifi: rtw89: fix use-after-free in rtw89_core_tx_kick_off_and_wait() (bsc#1252062). - CVE-2025-40005: spi: cadence-quadspi: Implement refcount to handle unbind during busy (bsc#1252349). - CVE-2025-40012: net/smc: fix warning in smc_rx_splice() when calling get_page() (bsc#1252330). - CVE-2025-40018: ipvs: Defer ip_vs_ftp unregister during netns cleanup (bsc#1252688). - CVE-2025-40051: vhost: vringh: Modify the return value check (bsc#1252858). - CVE-2025-40056: vhost: vringh: Fix copy_to_iter return value check (bsc#1252826). - CVE-2025-40060: coresight: trbe: Return NULL pointer for allocation failures (bsc#1252848). - CVE-2025-40078: bpf: Explicitly check accesses to bpf_sock_addr (bsc#1252789). - CVE-2025-40100: btrfs: do not assert we found block group item when creating free space tree (bsc#1252918). The following non security issues were fixed: - ACPI/processor_idle: Add FFH state handling (jsc#PED-13815). - ACPI/processor_idle: Export acpi_processor_ffh_play_dead() (jsc#PED-13815). - ACPI: battery: Add synchronization between interface updates (git-fixes). - ACPI: processor: Rescan 'dead' SMT siblings during initialization (jsc#PED-13815). - KVM: PPC: Fix misleading interrupts comment in kvmppc_prepare_to_enter() (bsc#1215199). - KVM: x86: Plumb in the vCPU to kvm_x86_ops.hwapic_isr_update() (git-fixes). - KVM: x86: Process 'guest stopped request' once per guest time update (git-fixes). - PM: hibernate: Add pm_hibernation_mode_is_suspend() (bsc#1243112). - PM: hibernate: Add stub for pm_hibernate_is_recovering() (bsc#1243112). - PM: hibernate: Fix pm_hibernation_mode_is_suspend() build breakage (bsc#1243112). - PM: hibernate: add new api pm_hibernate_is_recovering() (bsc#1243112). - bpf: Allow helper bpf_get_[ns_]current_pid_tgid() for all prog types (bsc#1252364). - cpufreq: intel_pstate: Fix object lifecycle issue in update_qos_request() (stable-fixes git-fixes). - cpuidle: Do not return from cpuidle_play_dead() on callback failures (jsc#PED-13815). - dpll: Make ZL3073X invisible (bsc#1252253). - dpll: zl3073x: Add firmware loading functionality (bsc#1252253). - dpll: zl3073x: Add functions to access hardware registers (bsc#1252253). - dpll: zl3073x: Add low-level flash functions (bsc#1252253). - dpll: zl3073x: Add support to get fractional frequency offset (bsc#1252253). - dpll: zl3073x: Add support to get phase offset on connected input pin (bsc#1252253). - dpll: zl3073x: Add support to get/set esync on pins (bsc#1252253). - dpll: zl3073x: Fix build failure (bsc#1252253). - dpll: zl3073x: Fix double free in zl3073x_devlink_flash_update() (bsc#1252253). - dpll: zl3073x: Handle missing or corrupted flash configuration (bsc#1252253). - dpll: zl3073x: Implement devlink flash callback (bsc#1252253). - dpll: zl3073x: Increase maximum size of flash utility (bsc#1252253). - dpll: zl3073x: Refactor DPLL initialization (bsc#1252253). - dpll: zl3073x: ZL3073X_I2C and ZL3073X_SPI should depend on NET (bsc#1252253). - drm/amd : Update MES API header file for v11 & v12 (stable-fixes). - drm/amd/amdgpu: Implement MES suspend/resume gang functionality for v12 (bsc#1243112). - drm/amd/display: Add NULL check for stream before dereference in 'dm_vupdate_high_irq' (bsc#1243112). - drm/amd/display: Enable Dynamic DTBCLK Switch (bsc#1243112). - drm/amd/display: Fix vupdate_offload_work doc (bsc#1243112). - drm/amd/display: fix dmub access race condition (bsc#1243112). - drm/amd/display: more liberal vmin/vmax update for freesync (bsc#1243112). - drm/amd/include : MES v11 and v12 API header update (stable-fixes). - drm/amd/include : Update MES v12 API for fence update (stable-fixes). - drm/amd/pm: fix smu table id bound check issue in smu_cmn_update_table() (git-fixes). - drm/amd: Avoid evicting resources at S5 (bsc#1243112). - drm/amd: Check whether secure display TA loaded successfully (bsc#1243112). - drm/amd: Fix hybrid sleep (bsc#1243112). - drm/amd: Only restore cached manual clock settings in restore if OD enabled (bsc#1243112). - drm/amd: Restore cached manual clock settings during resume (bsc#1243112). - drm/amdgpu/mes11: implement detect and reset callback (bsc#1243112). - drm/amdgpu/mes12: implement detect and reset callback (bsc#1243112). - drm/amdgpu/mes: add front end for detect and reset hung queue (bsc#1243112). - drm/amdgpu/vpe: cancel delayed work in hw_fini (bsc#1243112). - drm/amdgpu: Avoid rma causes GPU duplicate reset (bsc#1243112). - drm/amdgpu: Fix for GPU reset being blocked by KIQ I/O (bsc#1243112). - drm/amdgpu: Report individual reset error (bsc#1243112). - drm/amdgpu: do not resume device in thaw for normal hibernation (bsc#1243112). - drm/amdgpu: fix link error for !PM_SLEEP (bsc#1243112). - drm/amdkfd: Fix mmap write lock not release (bsc#1243112). - drm/xe/guc: Prepare GuC register list and update ADS size for error capture (stable-fixes). - ext4: fix checks for orphan inodes (bsc#1250119). - hfsplus: fix KMSAN uninit-value issue in hfsplus_delete_cat() (git-fixes). - intel_idle: Provide the default enter_dead() handler (jsc#PED-13815). - intel_idle: Rescan 'dead' SMT siblings during initialization (jsc#PED-13815). - intel_idle: Use subsys_initcall_sync() for initialization (jsc#PED-13815). - ixgbe: handle IXGBE_VF_FEATURES_NEGOTIATE mbox cmd (bsc#1247222). - ixgbe: handle IXGBE_VF_GET_PF_LINK_STATE mailbox operation (bsc#1247222). - ixgbevf: fix getting link speed data for E610 devices (bsc#1247222). - ixgbevf: fix mailbox API compatibility by negotiating supported features (bsc#1247222). - kdb: Replace deprecated strcpy() with memmove() in vkdb_printf() (bsc#1252939). - net: mana: Use page pool fragments for RX buffers instead of full pages to improve memory efficiency (bsc#1248754). - netfilter: nft_objref: validate objref and objrefmap expressions (bsc#1250237). - nvme-auth: update bi_directional flag (git-fixes bsc#1249735). - nvme-auth: update sc_c in host response (git-fixes bsc#1249397). - nvme-fc: use lock accessing port_state and rport state (bsc#1245193 bsc#1247500). - nvme-tcp: send only permitted commands for secure concat (git-fixes bsc#1247683). - nvmet-fc: avoid scheduling association deletion twice (bsc#1245193 bsc#1247500). - nvmet-fc: move lsop put work to nvmet_fc_ls_req_op (bsc#1245193 bsc#1247500). - nvmet-fcloop: call done callback even when remote port is gone (bsc#1245193 bsc#1247500). - perf/x86/intel: Allow to update user space GPRs from PEBS records (git-fixes). - perf/x86/intel: Fix crash in icl_update_topdown_event() (git-fixes). - phy: cadence: cdns-dphy: Update calibration wait time for startup state machine (git-fixes). - platform/x86/amd/pmc: Add 1Ah family series to STB support list (bsc#1243112). - platform/x86/amd/pmc: Add MECHREVO Yilong15Pro to spurious_8042 list (bsc#1243112). - platform/x86/amd/pmc: Add Stellaris Slim Gen6 AMD to spurious 8042 quirks list (bsc#1243112). - platform/x86/amd/pmc: Add VPE information for AMDI000A platform (bsc#1243112). - platform/x86/amd/pmc: Add idlemask support for 1Ah family (bsc#1243112). - platform/x86/amd/pmc: Extend support for PMC features on new AMD platform (bsc#1243112). - platform/x86/amd/pmc: Fix SMU command submission path on new AMD platform (bsc#1243112). - platform/x86/amd/pmc: Modify SMU message port for latest AMD platform (bsc#1243112). - platform/x86/amd/pmc: Notify user when platform does not support s0ix transition (bsc#1243112). - platform/x86/amd/pmc: Remove unnecessary line breaks (bsc#1243112). - platform/x86/amd/pmc: Send OS_HINT command for AMDI000A platform (bsc#1243112). - platform/x86/amd/pmc: Send OS_HINT command for new AMD platform (bsc#1243112). - platform/x86/amd/pmc: Update IP information structure for newer SoCs (bsc#1243112). - platform/x86/amd/pmc: Use ARRAY_SIZE() to fill num_ips information (bsc#1243112). - platform/x86/amd/pmc: call amd_pmc_get_ip_info() during driver probe (bsc#1243112). - platform/x86/amd: pmc: Add new ACPI ID AMDI000B (bsc#1243112). - platform/x86/amd: pmc: Drop SMU F/W match for Cezanne (bsc#1243112). - platform/x86/amd: pmc: Use guard(mutex) (bsc#1243112). - powerpc/boot: Fix build with gcc 15 (bsc#1215199). - powerpc/fadump: skip parameter area allocation when fadump is disabled (jsc#PED-9891 git-fixes). - powerpc/kvm: Fix ifdef to remove build warning (bsc#1215199). - powerpc/powernv/pci: Fix underflow and leak issue (bsc#1215199). - powerpc/pseries/msi: Fix potential underflow and leak issue (bsc#1215199). - powerpc: floppy: Add missing checks after DMA map (bsc#1215199). - proc: fix missing pde_set_flags() for net proc files (bsc#1248630) - proc: fix type confusion in pde_set_flags() (bsc#1248630) - sched/idle: Conditionally handle tick broadcast in default_idle_call() (bsc#1248517). - scsi: fc: Avoid -Wflex-array-member-not-at-end warnings (bsc#1250519). - scsi: lpfc: Abort outstanding ELS WQEs regardless of if rmmod is in progress (bsc#1250519). - scsi: lpfc: Check return status of lpfc_reset_flush_io_context during TGT_RESET (bsc#1250519). - scsi: lpfc: Clean up allocated queues when queue setup mbox commands fail (bsc#1250519). - scsi: lpfc: Copyright updates for 14.4.0.11 patches (bsc#1250519). - scsi: lpfc: Decrement ndlp kref after FDISC retries exhausted (bsc#1250519). - scsi: lpfc: Ensure PLOGI_ACC is sent prior to PRLI in Point to Point topology (bsc#1250519). - scsi: lpfc: Fix buffer free/clear order in deferred receive path (bsc#1250519). - scsi: lpfc: Fix wrong function reference in a comment (bsc#1250519). - scsi: lpfc: Remove ndlp kref decrement clause for F_Port_Ctrl in lpfc_cleanup (bsc#1250519). - scsi: lpfc: Remove redundant assignment to avoid memory leak (bsc#1250519). - scsi: lpfc: Remove unused member variables in struct lpfc_hba and lpfc_vport (bsc#1250519). - scsi: lpfc: Update lpfc version to 14.4.0.11 (bsc#1250519). - scsi: lpfc: Use int type to store negative error codes (bsc#1250519). - scsi: lpfc: use min() to improve code (bsc#1250519). - serial: sc16is7xx: rename Kconfig CONFIG_SERIAL_SC16IS7XX_CORE (bsc#1252469) Re-enable CONFIG_SERIAL_SC16IS7X for aarch64 and x86_64 default configurations, but keep it disabled for kvmsmall configurations. For ppc64 and s390x drivers was not enabled, so keep it that way. Add sc16is7xx_spi and sc16is7xx_i2c drivers to supported list. - skmsg: Return copied bytes in sk_msg_memcopy_from_iter (bsc#1250650). - smb: client: fix crypto buffers in non-linear memory (bsc#1250491, bsc#1239206). - smb: client: fix potential cfid UAF in smb2_query_info_compound (bsc#1248886). - tcp_bpf: Fix copied value in tcp_bpf_sendmsg (bsc#1250650). - tracing: Remove unneeded goto out logic (bsc#1249286). - x86/idle: Sanitize X86_BUG_AMD_E400 handling (bsc#1248517). - x86/resctrl: Fix miscount of bandwidth event when reactivating previously unavailable RMID (bsc#1252734). - x86/resctrl: Refactor resctrl_arch_rmid_read() (bsc#1252734). - x86/smp: Allow calling mwait_play_dead with an arbitrary hint (jsc#PED-13815). - x86/smp: Fix mwait_play_dead() and acpi_processor_ffh_play_dead() noreturn behavior (jsc#PED-13815). - x86/smp: PM/hibernate: Split arch_resume_nosmt() (jsc#PED-13815). - x86/topology: Implement topology_is_core_online() to address SMT regression (jsc#PED-13815). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4067-1 Released: Wed Nov 12 09:03:26 2025 Summary: Security update for openssh Type: security Severity: moderate References: 1251198,1251199,CVE-2025-61984,CVE-2025-61985 This update for openssh fixes the following issues: - CVE-2025-61984: Fixed code execution via control characters in usernames when a ProxyCommand is used (bsc#1251198) - CVE-2025-61985: Fixed code execution via '\0' character in ssh:// URI when a ProxyCommand is used (bsc#1251199) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4083-1 Released: Wed Nov 12 14:20:28 2025 Summary: Recommended update for dracut Type: recommended Severity: moderate References: 1253029 This update for dracut fixes the following issues: - Fix (kernel-modules-extra): * Remove the stray backslash (\) before the forward slash (/). (bsc#1253029) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4118-1 Released: Mon Nov 17 09:06:55 2025 Summary: Recommended update for freetype2 Type: recommended Severity: important References: 1252148 This update for freetype2 fixes the following issues: - Fix the %licence tag (bsc#1252148) * package FTL.TXT and GPLv2.TXT as %license ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4138-1 Released: Wed Nov 19 11:15:12 2025 Summary: Recommended update for systemd Type: recommended Severity: moderate References: 1224386,1248501 This update for systemd fixes the following issues: - systemd.spec: use %sysusers_generate_pre so that some systemd users are already available in %pre. This is important because D-Bus automatically reloads its configuration whenever new configuration files are installed, i.e. between %pre and %post. (bsc#1248501) No needs for systemd and udev packages as they are always installed during the initial installation. - Split systemd-network into two new sub-packages: systemd-networkd and systemd-resolved (bsc#1224386 jsc#PED-12669) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4151-1 Released: Fri Nov 21 07:53:12 2025 Summary: Recommended update for multipath-tools Type: recommended Severity: moderate References: 1253260 This update for multipath-tools fixes the following issues: - _service: switched to tar_scm for git LFS - Fixes from upstream 0.10.5 (bsc#1253260): * Improved the communication with **udev** and **systemd** by triggering uevents when path devices are added to or removed from multipath maps, or when `multipathd reconfigure` is executed after changing blacklist directives in `multipath.conf`. * Failed paths should be checked every `polling_interval`. In certain cases, this wouldn't happen, because the check interval wasn't reset by multipathd. * It could happen that multipathd would accidentally release a SCSI persistent reservation held by another node. * After manually failing some paths and then reinstating them, sometimes the reinstated paths were immediately failed again by multipathd. * Various minor fixes reported by coverity. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4155-1 Released: Fri Nov 21 15:09:44 2025 Summary: Recommended update for cyrus-sasl Type: recommended Severity: moderate References: 1233529 This update for cyrus-sasl fixes the following issues: - Python3 error log upon importing pycurl (bsc#1233529) * Remove senceless log message. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4179-1 Released: Mon Nov 24 08:27:54 2025 Summary: Recommended update for mozilla-nspr Type: recommended Severity: moderate References: This update for mozilla-nspr fixes the following issues: - update to NSPR 4.36.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.36.1 - update to NSPR 4.36.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4092-1 Released: Mon Nov 24 10:08:22 2025 Summary: Security update for elfutils Type: security Severity: moderate References: 1237236,1237240,1237241,1237242,CVE-2025-1352,CVE-2025-1372,CVE-2025-1376,CVE-2025-1377 This update for elfutils fixes the following issues: - Fixing build/testsuite for more recent glibc and kernels. - Fixing denial of service and general buffer overflow errors (bsc#1237236, bsc#1237240, bsc#1237241, bsc#1237242): - CVE-2025-1376: Fixed denial of service in function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip - CVE-2025-1377: Fixed denial of service in function gelf_getsymshndx of the file strip.c of the component eu-strip - CVE-2025-1372: Fixed buffer overflow in function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf - CVE-2025-1352: Fixed SEGV (illegal read access) in function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf - Fixing testsuite race conditions in run-debuginfod-find.sh. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4293-1 Released: Fri Nov 28 10:10:49 2025 Summary: Recommended update for gpgme Type: recommended Severity: important References: 1231055,1252425 This update for gpgme fixes the following issues: - Treat empty DISPLAY variable as unset (bsc#1252425, bsc#1231055) * To avoid gpgme constructing an invalid gpg command line when the DISPLAY variable is empty it can be treated as unset. * Reported upstream: dev.gnupg.org/T7919 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4300-1 Released: Fri Nov 28 13:57:41 2025 Summary: Security update for curl Type: security Severity: moderate References: 1253757,CVE-2025-11563 This update for curl fixes the following issues: - CVE-2025-11563: Fixed wcurl path traversal with percent-encoded slashes (bsc#1253757) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4303-1 Released: Fri Nov 28 14:11:38 2025 Summary: Recommended update for kmod Type: recommended Severity: important References: 1253741 This update for kmod fixes the following issues: - Fix modprobe.d confusion on man page (bsc#1253741): * document the config file order handling ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4305-1 Released: Fri Nov 28 14:33:33 2025 Summary: Security update for grub2 Type: security Severity: moderate References: 1245953,1252930,1252931,1252932,1252933,1252934,1252935,CVE-2025-54770,CVE-2025-54771,CVE-2025-61661,CVE-2025-61662,CVE-2025-61663,CVE-2025-61664 This update for grub2 fixes the following issues: - CVE-2025-54771: Fixed rub_file_close() does not properly controls the fs refcount (bsc#1252931) - CVE-2025-54770: Fixed missing unregister call for net_set_vlan command may lead to use-after-free (bsc#1252930) - CVE-2025-61662: Fixed missing unregister call for gettext command may lead to use-after-free (bsc#1252933) - CVE-2025-61663: Fixed missing unregister call for normal commands may lead to use-after-free (bsc#1252934) - CVE-2025-61664: Fixed missing unregister call for normal_exit command may lead to use-after-free (bsc#1252935) - CVE-2025-61661: Fixed out-of-bounds write in grub_usb_get_string() function (bsc#1252932) Other fixes: - Bump upstream SBAT generation to 6 - Fixed timeout when loading initrd via http after PPC CAS reboot (bsc#1245953) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4308-1 Released: Fri Nov 28 16:38:46 2025 Summary: Security update for glib2 Type: security Severity: moderate References: 1249055,CVE-2025-7039 This update for glib2 fixes the following issues: - CVE-2025-7039: Fixed buffer under-read on glib through glib/gfileutils.c via get_tmp_file() (bsc#1249055) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4321-1 Released: Fri Dec 5 08:07:53 2025 Summary: Recommended update for pciutils Type: recommended Severity: moderate References: 1001888,1006827,1029961,1098094,1098228,1170554,1192862,1206798,1224138,529469,837347 This update for pciutils fixes the following issues: pciutils was updated from version 3.5.6 to 3.13.0 (jsc#PED-8402, jsc#PED-8393, bsc#1224138): - Highlights of issues fixed: * Fixed LnkCap speed recognition in `lspci` for multi PCIe ports such as the ML110 Gen11 (bsc#1192862) * Included several non-standard extensions to VPD decoder (bsc#1170554, bsc#1098228) * Fixed the display of the gen4 speed for GEN 4 cards like Mellanox CX5 (bsc#1098094) * Replaced dependency on pciutil-ids with hwdata * Potentially disruptive change of PCI IDs Cache: + The local cache of PCI IDs (.pci-ids) was moved to the XDG standard location: `$XDG_CACHE_HOME/pci-ids` (v3.11.0) This could be a disruptive change if users or scripts are relying on the old path. - Key New Features and Utilities: * New `pcilmr` Utility: A new tool, `pcilmr`, was added for 'PCIe lane margining,' which is a low-level diagnostic feature (v3.11.0) * New `lspci` Path Flag: You can now use `lspci -P` (or -PP) to see the path of bridges leading to a specific device (v3.6.2) * ECAM Support: Added support for the ECAM (Enhanced Configuration Access Mechanism), a standard way to access PCIe configuration space (v3.10.0) * IOMMU Group Display: lspci can now display IOMMU groups on Linux (v3.7.0) - New Hardware and Protocol Decoding: * Added support for decoding CXL capabilities (v3.9.0) * Decoding for Advanced Error Reporting (AER) (v3.13.0) * Decoding for IDE (Integrity and Data Encryption) and TEE-IO extended capabilities (v3.12.0) * Decoding for Data Object Exchange (DOE) (v3.8.0) * Decoding for standard and VF (Virtual Function) Resizable BARs (v3.7.0) * Decoding for Multicast capabilities (v3.6.3) - Improved Output Clarity: * PCIe link speeds running below their maximum are now clearly marked as 'downgraded' (v3.6.0) * BARs (Base Address Registers) reported by the OS but not actually set on the device are marked as '[virtual]' (v3.6.0) - Command Behavior and System Changes: * `lspci` Tree View (-t): + Can now be combined with `-s` to show only a specific sub-tree (v3.6.3) + Improved filtering options (v3.9.0) + Improved support of multi-domain systems (v3.10.0) * `setpci`: + Can now check if a named register exists for that device's header type (v3.9.0) * `update-pciids`: + Now supports XZ compression when downloading new ID lists (v3.11.0) * Database Update: + The pci.ids device database was continuously updated across all versions. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4362-1 Released: Thu Dec 11 11:08:27 2025 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1253043 This update for gcc15 fixes the following issues: - Enable the use of _dl_find_object even when not available at build time. [bsc#1253043] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4374-1 Released: Fri Dec 12 10:19:34 2025 Summary: Recommended update for suse-module-tools Type: recommended Severity: moderate References: 1250655,1250664 This update for suse-module-tools fixes the following issues: - Version update 15.7.8. - Fixing spec file (bsc#1250664). - Fixing compile problems on livepatch dir when checking for unresolved symbols (bsc#1250655). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4376-1 Released: Fri Dec 12 10:36:45 2025 Summary: Recommended update for lvm2 Type: recommended Severity: moderate References: 1246691,510058 This update for lvm2 fixes the following issues: - Maintenance update attempt seems to be stuck at mkinitrd (bsc#510058). - systemd fails to start lvmlockd with sanlock running (bsc#1246691). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4393-1 Released: Mon Dec 15 12:08:54 2025 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1235463,1236743,1237888,1241166,1243474,1245193,1247076,1247500,1247509,1247683,1249547,1249912,1249982,1250034,1250176,1250237,1250252,1250705,1251120,1251786,1252063,1252267,1252269,1252303,1252352,1252353,1252365,1252366,1252368,1252370,1252681,1252763,1252773,1252774,1252780,1252790,1252794,1252795,1252809,1252817,1252821,1252836,1252845,1252862,1252912,1252917,1252923,1252928,1253018,1253176,1253275,1253318,1253324,1253349,1253352,1253355,1253360,1253362,1253363,1253367,1253369,1253393,1253394,1253395,1253403,1253407,1253409,1253412,1253416,1253421,1253423,1253424,1253425,1253427,1253428,1253431,1253436,1253438,1253440,1253441,1253445,1253448,1253449,1253453,1253456,1253472,1253648,1253779,1254181,1254221,1254235,CVE-2022-50253,CVE-2023-53676,CVE-2025-21710,CVE-2025-37916,CVE-2025-38359,CVE-2025-39788,CVE-2025-39805,CVE-2025-39819,CVE-2025-39822,CVE-2025-39859,CVE-2025-39944,CVE-2025-39980,CVE-2025-40001,CVE-2025-40021,CVE-2025-40027,CVE-2025-40030,CVE-2025-40038,CV E-2025-40040,CVE-2025-40047,CVE-2025-40048,CVE-2025-40055,CVE-2025-40059,CVE-2025-40064,CVE-2025-40070,CVE-2025-40074,CVE-2025-40075,CVE-2025-40080,CVE-2025-40083,CVE-2025-40086,CVE-2025-40098,CVE-2025-40105,CVE-2025-40107,CVE-2025-40109,CVE-2025-40110,CVE-2025-40111,CVE-2025-40115,CVE-2025-40116,CVE-2025-40118,CVE-2025-40120,CVE-2025-40121,CVE-2025-40127,CVE-2025-40129,CVE-2025-40139,CVE-2025-40140,CVE-2025-40141,CVE-2025-40149,CVE-2025-40154,CVE-2025-40156,CVE-2025-40157,CVE-2025-40159,CVE-2025-40164,CVE-2025-40168,CVE-2025-40169,CVE-2025-40171,CVE-2025-40172,CVE-2025-40173,CVE-2025-40176,CVE-2025-40180,CVE-2025-40183,CVE-2025-40185,CVE-2025-40186,CVE-2025-40188,CVE-2025-40194,CVE-2025-40198,CVE-2025-40200,CVE-2025-40204,CVE-2025-40205,CVE-2025-40206,CVE-2025-40207 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2022-50253: bpf: make sure skb->len != 0 when redirecting to a tunneling device (bsc#1249912). - CVE-2023-53676: scsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show() (bsc#1251786). - CVE-2025-21710: tcp: correct handling of extreme memory squeeze (bsc#1237888). - CVE-2025-37916: pds_core: remove write-after-free of client_id (bsc#1243474). - CVE-2025-38359: s390/mm: Fix in_atomic() handling in do_secure_storage_access() (bsc#1247076). - CVE-2025-39788: scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE (bsc#1249547). - CVE-2025-39805: net: macb: fix unregister_netdev call order in macb_remove() (bsc#1249982). - CVE-2025-39819: fs/smb: Fix inconsistent refcnt update (bsc#1250176). - CVE-2025-39822: io_uring/kbuf: fix signedness in this_len calculation (bsc#1250034). - CVE-2025-39859: ptp: ocp: fix use-after-free bugs causing by ptp_ocp_watchdog (bsc#1250252). - CVE-2025-39944: octeontx2-pf: Fix use-after-free bugs in otx2_sync_tstamp() (bsc#1251120). - CVE-2025-39980: nexthop: Forbid FDB status change while nexthop is in a group (bsc#1252063). - CVE-2025-40001: scsi: mvsas: Fix use-after-free bugs in mvs_work_queue (bsc#1252303). - CVE-2025-40021: tracing: dynevent: Add a missing lockdown check on dynevent (bsc#1252681). - CVE-2025-40027: net/9p: fix double req put in p9_fd_cancelled (bsc#1252763). - CVE-2025-40030: pinctrl: check the return value of pinmux_ops::get_function_name() (bsc#1252773). - CVE-2025-40038: KVM: SVM: Skip fastpath emulation on VM-Exit if next RIP isn't valid (bsc#1252817). - CVE-2025-40040: mm/ksm: fix flag-dropping behavior in ksm_madvise (bsc#1252780). - CVE-2025-40047: io_uring/waitid: always prune wait queue entry in io_waitid_wait() (bsc#1252790). - CVE-2025-40048: uio_hv_generic: Let userspace take care of interrupt mask (bsc#1252862). - CVE-2025-40055: ocfs2: fix double free in user_cluster_connect() (bsc#1252821). - CVE-2025-40059: coresight: Fix incorrect handling for return value of devm_kzalloc (bsc#1252809). - CVE-2025-40064: smc: Fix use-after-free in __pnet_find_base_ndev() (bsc#1252845). - CVE-2025-40070: pps: fix warning in pps_register_cdev when register device fail (bsc#1252836). - CVE-2025-40074: ipv4: start using dst_dev_rcu() (bsc#1252794). - CVE-2025-40075: tcp_metrics: use dst_dev_net_rcu() (bsc#1252795). - CVE-2025-40080: nbd: restrict sockets to TCP and UDP (bsc#1252774). - CVE-2025-40083: net/sched: sch_qfq: Fix null-deref in agg_dequeue (bsc#1252912). - CVE-2025-40086: drm/xe: Don't allow evicting of BOs in same VM in array of VM binds (bsc#1252923). - CVE-2025-40098: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state() (bsc#1252917). - CVE-2025-40105: vfs: Don't leak disconnected dentries on umount (bsc#1252928). - CVE-2025-40139: smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set() (bsc#1253409). - CVE-2025-40149: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() (bsc#1253355). - CVE-2025-40159: xsk: Harden userspace-supplied xdp_desc validation (bsc#1253403). - CVE-2025-40168: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match() (bsc#1253427). - CVE-2025-40169: bpf: Reject negative offsets for ALU ops (bsc#1253416). - CVE-2025-40173: net/ip6_tunnel: Prevent perpetual tunnel growth (bsc#1253421). - CVE-2025-40176: tls: wait for pending async decryptions if tls_strp_msg_hold fails (bsc#1253425). - CVE-2025-40185: ice: ice_adapter: release xa entry on adapter allocation failure (bsc#1253394). - CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253436). The following non security issues were fixed: - ACPI: CPPC: Check _CPC validity for only the online CPUs (git-fixes). - ACPI: CPPC: Limit perf ctrs in PCC check only to online CPUs (git-fixes). - ACPI: CPPC: Perform fast check switch only for online CPUs (git-fixes). - ACPI: PRM: Skip handlers with NULL handler_address or NULL VA (stable-fixes). - ACPI: SBS: Fix present test in acpi_battery_read() (git-fixes). - ACPI: property: Return present device nodes only on fwnode interface (stable-fixes). - ACPI: scan: Add Intel CVS ACPI HIDs to acpi_ignore_dep_ids (stable-fixes). - ACPICA: Update dsmethod.c to get rid of unused variable warning (stable-fixes). - ACPICA: dispatcher: Use acpi_ds_clear_operands() in acpi_ds_call_control_method() (stable-fixes). - ALSA: hda: Fix missing pointer check in hda_component_manager_init function (git-fixes). - ALSA: serial-generic: remove shared static buffer (stable-fixes). - ALSA: usb-audio: Add validation of UAC2/UAC3 effect units (stable-fixes). - ALSA: usb-audio: Fix NULL pointer dereference in snd_usb_mixer_controls_badd (git-fixes). - ALSA: usb-audio: Fix potential overflow of PCM transfer buffer (stable-fixes). - ALSA: usb-audio: add mono main switch to Presonus S1824c (stable-fixes). - ALSA: usb-audio: apply quirk for MOONDROP Quark2 (stable-fixes). - ALSA: usb-audio: don't log messages meant for 1810c when initializing 1824c (git-fixes). - ASoC: codecs: va-macro: fix resource leak in probe error path (git-fixes). - ASoC: cs4271: Fix regulator leak on probe failure (git-fixes). - ASoC: max98090/91: fixed max98091 ALSA widget powering up/down (stable-fixes). - ASoC: meson: aiu-encoder-i2s: fix bit clock polarity (stable-fixes). - ASoC: qcom: sc8280xp: explicitly set S16LE format in sc8280xp_be_hw_params_fixup() (stable-fixes). - ASoC: stm32: sai: manage context in set_sysclk callback (stable-fixes). - ASoC: tas2781: fix getting the wrong device number (git-fixes). - ASoC: tlv320aic3x: Fix class-D initialization for tlv320aic3007 (stable-fixes). - Bluetooth: 6lowpan: Don't hold spin lock over sleeping functions (git-fixes). - Bluetooth: 6lowpan: add missing l2cap_chan_lock() (git-fixes). - Bluetooth: 6lowpan: fix BDADDR_LE vs ADDR_LE_DEV address type confusion (git-fixes). - Bluetooth: 6lowpan: reset link-local header on ipv6 recv path (git-fixes). - Bluetooth: L2CAP: export l2cap_chan_hold for modules (stable-fixes). - Bluetooth: MGMT: Fix OOB access in parse_adv_monitor_pattern() (git-fixes). - Bluetooth: MGMT: cancel mesh send timer when hdev removed (git-fixes). - Bluetooth: SCO: Fix UAF on sco_conn_free (stable-fixes). - Bluetooth: bcsp: receive data only if registered (stable-fixes). - Bluetooth: btrtl: Fix memory leak in rtlbt_parse_firmware_v2() (git-fixes). - Bluetooth: btusb: Check for unexpected bytes when defragmenting HCI frames (stable-fixes). - Bluetooth: btusb: reorder cleanup in btusb_disconnect to avoid UAF (git-fixes). - Bluetooth: hci_event: validate skb length for unknown CC opcode (git-fixes). - Drivers: hv: vmbus: Add utility function for querying ring size (git-fixes). - HID: amd_sfh: Stop sensor before starting (git-fixes). - HID: hid-ntrig: Prevent memory leak in ntrig_report_version() (git-fixes). - HID: quirks: avoid Cooler Master MM712 dongle wakeup bug (stable-fixes). - HID: quirks: work around VID/PID conflict for 0x4c4a/0x4155 (git-fixes). - HID: uclogic: Fix potential memory leak in error path (git-fixes). - Input: atmel_mxt_ts - allow reset GPIO to sleep (stable-fixes). - Input: imx_sc_key - fix memory corruption on unload (git-fixes). - Input: pegasus-notetaker - fix potential out-of-bounds access (git-fixes). - KVM: Pass new routing entries and irqfd when updating IRTEs (git-fixes). - KVM: SEV: Enforce minimum GHCB version requirement for SEV-SNP guests (git-fixes). - KVM: SVM: Delete IRTE link from previous vCPU before setting new IRTE (git-fixes). - KVM: SVM: Delete IRTE link from previous vCPU irrespective of new routing (git-fixes). - KVM: SVM: Emulate PERF_CNTR_GLOBAL_STATUS_SET for PerfMonV2 (git-fixes). - KVM: SVM: Mark VMCB_LBR dirty when MSR_IA32_DEBUGCTLMSR is updated (git-fixes). - KVM: SVM: Re-load current, not host, TSC_AUX on #VMEXIT from SEV-ES guest (git-fixes). - KVM: SVM: Track per-vCPU IRTEs using kvm_kernel_irqfd structure (git-fixes). - KVM: SVM: WARN if an invalid posted interrupt IRTE entry is added (git-fixes). - KVM: VMX: Allow guest to set DEBUGCTL.RTM_DEBUG if RTM is supported (git-fixes). - KVM: VMX: Apply MMIO Stale Data mitigation if KVM maps MMIO into the guest (git-fixes). - KVM: VMX: Fix check for valid GVA on an EPT violation (git-fixes). - KVM: VMX: Preserve host's DEBUGCTLMSR_FREEZE_IN_SMM while running the guest (git-fixes). - KVM: VMX: Wrap all accesses to IA32_DEBUGCTL with getter/setter APIs (git-fixes). - KVM: nVMX: Check vmcs12->guest_ia32_debugctl on nested VM-Enter (git-fixes). - KVM: s390: improve interrupt cpu for wakeup (bsc#1235463). - KVM: s390: kABI backport for 'last_sleep_cpu' (bsc#1252352). - KVM: x86/mmu: Locally cache whether a PFN is host MMIO when making a SPTE (git-fixes). - KVM: x86: Add helper to retrieve current value of user return MSR (git-fixes). - KVM: x86: Convert vcpu_run()'s immediate exit param into a generic bitmap (git-fixes). - KVM: x86: Don't treat ENTER and LEAVE as branches, because they aren't (git-fixes). - KVM: x86: Drop kvm_x86_ops.set_dr6() in favor of a new KVM_RUN flag (git-fixes). - KVM: x86: Have all vendor neutral sub-configs depend on KVM_X86, not just KVM (git-fixes). - NFS4: Fix state renewals missing after boot (git-fixes). - NFS: check if suid/sgid was cleared after a write as needed (git-fixes). - NFSD: Never cache a COMPOUND when the SEQUENCE operation fails (git-fixes). - NFSD: Skip close replay processing if XDR encoding fails (git-fixes). - NFSD: free copynotify stateid in nfs4_free_ol_stateid() (git-fixes). - NFSv4.1: fix mount hang after CREATE_SESSION failure (git-fixes). - NFSv4: handle ERR_GRACE on delegation recalls (git-fixes). - PCI/P2PDMA: Fix incorrect pointer usage in devm_kfree() call (stable-fixes). - PCI/PM: Skip resuming to D0 if device is disconnected (stable-fixes). - PCI: Disable MSI on RDC PCI to PCIe bridges (stable-fixes). - PCI: cadence: Check for the existence of cdns_pcie::ops before using it (stable-fixes). - PCI: dwc: Verify the single eDMA IRQ in dw_pcie_edma_irq_verify() (stable-fixes). - PCI: j721e: Fix incorrect error message in probe() (git-fixes). - PCI: rcar-host: Convert struct rcar_msi mask_lock into raw spinlock (git-fixes). - PCI: tegra194: Reset BARs when running in PCIe endpoint mode (git-fixes). - RDMA/bnxt_re: Don't fail destroy QP and cleanup debugfs earlier (git-fixes). - RDMA/bnxt_re: Fix a potential memory leak in destroy_gsi_sqp (git-fixes). - RDMA/hns: Fix recv CQ and QP cache affinity (git-fixes). - RDMA/hns: Fix the modification of max_send_sge (git-fixes). - RDMA/hns: Fix wrong WQE data when QP wraps around (git-fixes). - RDMA/irdma: Fix SD index calculation (git-fixes). - RDMA/irdma: Set irdma_cq cq_num field during CQ create (git-fixes). - accel/habanalabs/gaudi2: fix BMON disable configuration (stable-fixes). - accel/habanalabs/gaudi2: read preboot status after recovering from dirty state (stable-fixes). - accel/habanalabs: return ENOMEM if less than requested pages were pinned (stable-fixes). - accel/habanalabs: support mapping cb with vmalloc-backed coherent memory (stable-fixes). - acpi,srat: Fix incorrect device handle check for Generic Initiator (git-fixes). - acpi/hmat: Fix lockdep warning for hmem_register_resource() (git-fixes). - amd/amdkfd: resolve a race in amdgpu_amdkfd_device_fini_sw (stable-fixes). - ata: libata-scsi: Add missing scsi_device_put() in ata_scsi_dev_rescan() (git-fixes). - block: avoid possible overflow for chunk_sectors check in blk_stack_limits() (git-fixes). - block: fix kobject double initialization in add_disk (git-fixes). - bpf: Fix test verif_scale_strobemeta_subprogs failure due to llvm19 (bsc#1252368). - bpf: improve error message for unsupported helper (bsc#1252370). - btrfs: abort transaction on failure to add link to inode (git-fixes). - btrfs: avoid page_lockend underflow in btrfs_punch_hole_lock_range() (git-fix). - btrfs: avoid using fixed char array size for tree names (git-fix). - btrfs: do not update last_log_commit when logging inode due to a new name (git-fixes). - btrfs: fix COW handling in run_delalloc_nocow() (git-fix). - btrfs: fix inode leak on failure to add link to inode (git-fixes). - btrfs: make btrfs_clear_delalloc_extent() free delalloc reserve (git-fix). - btrfs: mark dirty extent range for out of bound prealloc extents (git-fixes). - btrfs: qgroup: correctly model root qgroup rsv in convert (git-fix). - btrfs: rename err to ret in btrfs_link() (git-fixes). - btrfs: run btrfs_error_commit_super() early (git-fix). - btrfs: scrub: put bio after errors in scrub_raid56_parity_stripe() (git-fix). - btrfs: scrub: put bio after errors in scrub_raid56_parity_stripe() (git-fixes). - btrfs: send: fix duplicated rmdir operations when using extrefs (git-fixes). - btrfs: set inode flag BTRFS_INODE_COPY_EVERYTHING when logging new name (git-fixes). - btrfs: simplify error handling logic for btrfs_link() (git-fixes). - btrfs: tree-checker: add dev extent item checks (git-fix). - btrfs: tree-checker: add type and sequence check for inline backrefs (git-fix). - btrfs: tree-checker: fix the wrong output of data backref objectid (git-fix). - btrfs: tree-checker: reject BTRFS_FT_UNKNOWN dir type (git-fix). - btrfs: tree-checker: validate dref root and objectid (git-fix). - btrfs: use smp_mb__after_atomic() when forcing COW in create_pending_snapshot() (git-fixes). - cgroup/cpuset: Remove remote_partition_check() & make update_cpumasks_hier() handle remote partition (bsc#1241166). - char: misc: Does not request module for miscdevice with dynamic minor (stable-fixes). - char: misc: Make misc_register() reentry for miscdevice who wants dynamic minor (stable-fixes). - char: misc: restrict the dynamic range to exclude reserved minors (stable-fixes). - cpuset: Use new excpus for nocpu error check when enabling root partition (bsc#1241166). - cpuset: fix failure to enable isolated partition when containing isolcpus (bsc#1241166). - cramfs: Verify inode mode when loading from disk (git-fixes). - crypto: aspeed - fix double free caused by devm (git-fixes). - crypto: aspeed-acry - Convert to platform remove callback returning void (stable-fixes). - crypto: hisilicon/qm - Fix device reference leak in qm_get_qos_value (git-fixes). - crypto: iaa - Do not clobber req->base.data (git-fixes). - crypto: qat - use kcalloc() in qat_uclo_map_objs_from_mof() (stable-fixes). - dmaengine: dw-edma: Set status for callback_result (stable-fixes). - dmaengine: mv_xor: match alloc_wc and free_wc (stable-fixes). - drm/amd/amdgpu: Release xcp drm memory after unplug (stable-fixes). - drm/amd/display/dml2: Guard dml21_map_dc_state_into_dml_display_cfg with DC_FP_START (stable-fixes). - drm/amd/display: Add AVI infoframe copy in copy_stream_update_to_stream (stable-fixes). - drm/amd/display: Add fallback path for YCBCR422 (stable-fixes). - drm/amd/display: Allow VRR params change if unsynced with the stream (git-fixes). - drm/amd/display: Disable VRR on DCE 6 (stable-fixes). - drm/amd/display: Enable mst when it's detected but yet to be initialized (git-fixes). - drm/amd/display: Fix DVI-D/HDMI adapters (stable-fixes). - drm/amd/display: Fix NULL deref in debugfs odm_combine_segments (git-fixes). - drm/amd/display: Fix black screen with HDMI outputs (git-fixes). - drm/amd/display: Fix for test crash due to power gating (stable-fixes). - drm/amd/display: Fix incorrect return of vblank enable on unconfigured crtc (stable-fixes). - drm/amd/display: Fix pbn_div Calculation Error (stable-fixes). - drm/amd/display: Increase AUX Intra-Hop Done Max Wait Duration (stable-fixes). - drm/amd/display: Increase minimum clock for TMDS 420 with pipe splitting (stable-fixes). - drm/amd/display: Init dispclk from bootup clock for DCN314 (stable-fixes). - drm/amd/display: Move setup_stream_attribute (stable-fixes). - drm/amd/display: Reject modes with too high pixel clock on DCE6-10 (git-fixes). - drm/amd/display: Reset apply_eamless_boot_optimization when dpms_off (stable-fixes). - drm/amd/display: Set up pixel encoding for YCBCR422 (stable-fixes). - drm/amd/display: Support HW cursor 180 rot for any number of pipe splits (stable-fixes). - drm/amd/display: Wait until OTG enable state is cleared (stable-fixes). - drm/amd/display: add more cyan skillfish devices (stable-fixes). - drm/amd/display: change dc stream color settings only in atomic commit (stable-fixes). - drm/amd/display: ensure committing streams is seamless (stable-fixes). - drm/amd/display: fix condition for setting timing_adjust_pending (stable-fixes). - drm/amd/display: fix dml ms order of operations (stable-fixes). - drm/amd/display: incorrect conditions for failing dto calculations (stable-fixes). - drm/amd/display: update color on atomic commit time (stable-fixes). - drm/amd/display: update dpp/disp clock from smu clock table (stable-fixes). - drm/amd/pm: Disable MCLK switching on SI at high pixel clocks (stable-fixes). - drm/amd/pm: Use cached metrics data on aldebaran (stable-fixes). - drm/amd/pm: Use cached metrics data on arcturus (stable-fixes). - drm/amd: Avoid evicting resources at S5 (stable-fixes). - drm/amd: Check that VPE has reached DPM0 in idle handler (stable-fixes). - drm/amd: Fix suspend failure with secure display TA (git-fixes). - drm/amd: add more cyan skillfish PCI ids (stable-fixes). - drm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked() (stable-fixes). - drm/amdgpu/jpeg: Hold pg_lock before jpeg poweroff (stable-fixes). - drm/amdgpu/smu: Handle S0ix for vangogh (stable-fixes). - drm/amdgpu: Allow kfd CRIU with no buffer objects (stable-fixes). - drm/amdgpu: Check vcn sram load return value (stable-fixes). - drm/amdgpu: Correct the counts of nr_banks and nr_errors (stable-fixes). - drm/amdgpu: Fix NULL pointer dereference in VRAM logic for APU devices (stable-fixes). - drm/amdgpu: Fix function header names in amdgpu_connectors.c (git-fixes). - drm/amdgpu: Fix unintended error log in VCN5_0_0 (git-fixes). - drm/amdgpu: Respect max pixel clock for HDMI and DVI-D (v2) (stable-fixes). - drm/amdgpu: Skip poison aca bank from UE channel (stable-fixes). - drm/amdgpu: Use memdup_array_user in amdgpu_cs_wait_fences_ioctl (stable-fixes). - drm/amdgpu: add range check for RAS bad page address (stable-fixes). - drm/amdgpu: add support for cyan skillfish gpu_info (stable-fixes). - drm/amdgpu: disable peer-to-peer access for DCC-enabled GC12 VRAM surfaces (stable-fixes). - drm/amdgpu: don't enable SMU on cyan skillfish (stable-fixes). - drm/amdgpu: fix nullptr err of vm_handle_moved (stable-fixes). - drm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM (stable-fixes). - drm/amdgpu: reject gang submissions under SRIOV (stable-fixes). - drm/amdgpu: remove two invalid BUG_ON()s (stable-fixes). - drm/amdkfd: Handle lack of READ permissions in SVM mapping (stable-fixes). - drm/amdkfd: Tie UNMAP_LATENCY to queue_preemption (stable-fixes). - drm/amdkfd: fix vram allocation failure for a special case (stable-fixes). - drm/amdkfd: relax checks for over allocation of save area (stable-fixes). - drm/amdkfd: return -ENOTTY for unsupported IOCTLs (stable-fixes). - drm/ast: Blank with VGACR17 sync enable, always clear VGACRB6 sync off (git-fixes). - drm/bridge: cdns-dsi: Don't fail on MIPI_DSI_MODE_VIDEO_BURST (stable-fixes). - drm/bridge: cdns-dsi: Fix REG_WAKEUP_TIME value (stable-fixes). - drm/bridge: display-connector: don't set OP_DETECT for DisplayPorts (stable-fixes). - drm/exynos: exynos7_drm_decon: remove ctx->suspended (git-fixes). - drm/i915/dp_mst: Work around Thunderbolt sink disconnect after SINK_COUNT_ESI read (stable-fixes). - drm/i915: Avoid lock inversion when pinning to GGTT on CHV/BXT+VTD (git-fixes). - drm/i915: Fix conversion between clock ticks and nanoseconds (git-fixes). - drm/mediatek: Add pm_runtime support for GCE power control (git-fixes). - drm/mediatek: Disable AFBC support on Mediatek DRM driver (git-fixes). - drm/msm/a6xx: Fix PDC sleep sequence (git-fixes). - drm/msm/dsi/phy: Toggle back buffer resync after preparing PLL (stable-fixes). - drm/msm/dsi/phy_7nm: Fix missing initial VCO rate (stable-fixes). - drm/msm/registers: Generate _HI/LO builders for reg64 (stable-fixes). - drm/msm: make sure to not queue up recovery more than once (stable-fixes). - drm/nouveau: replace snprintf() with scnprintf() in nvkm_snprintbf() (stable-fixes). - drm/panthor: Serialize GPU cache flush operations (stable-fixes). - drm/panthor: check bo offset alignment in vm bind (stable-fixes). - drm/sched: Fix deadlock in drm_sched_entity_kill_jobs_cb (git-fixes). - drm/sched: Optimise drm_sched_entity_push_job (stable-fixes). - drm/sched: avoid killing parent entity on child SIGKILL (stable-fixes). - drm/tegra: Add call to put_pid() (git-fixes). - drm/tegra: dc: Fix reference leak in tegra_dc_couple() (git-fixes). - drm/tidss: Set crtc modesetting parameters with adjusted mode (stable-fixes). - drm/tidss: Use the crtc_* timings when programming the HW (stable-fixes). - drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE (git-fixes). - drm/xe/guc: Add more GuC load error status codes (stable-fixes). - drm/xe/guc: Increase GuC crash dump buffer size (stable-fixes). - drm/xe/guc: Return an error code if the GuC load fails (stable-fixes). - drm/xe/guc: Set upper limit of H2G retries over CTB (stable-fixes). - drm/xe/guc: Synchronize Dead CT worker with unbind (git-fixes). - drm/xe: Do clean shutdown also when using flr (git-fixes). - drm/xe: Do not wake device during a GT reset (git-fixes). - drm/xe: Fix oops in xe_gem_fault when running core_hotunplug test (stable-fixes). - drm/xe: Move declarations under conditional branch (stable-fixes). - drm/xe: Remove duplicate DRM_EXEC selection from Kconfig (git-fixes). - drm: panel-backlight-quirks: Make EDID match optional (stable-fixes). - exfat: limit log print for IO error (git-fixes). - extcon: adc-jack: Cleanup wakeup source only if it was enabled (git-fixes). - extcon: adc-jack: Fix wakeup source leaks on device unbind (stable-fixes). - fbcon: Set fb_display[i]->mode to NULL when the mode is released (stable-fixes). - fbdev: Add bounds checking in bit_putcs to fix vmalloc-out-of-bounds (stable-fixes). - fbdev: bitblit: bound-check glyph index in bit_putcs* (stable-fixes). - fbdev: pvr2fb: Fix leftover reference to ONCHIP_NR_DMA_CHANNELS (stable-fixes). - hwmon: (asus-ec-sensors) increase timeout for locking ACPI mutex (stable-fixes). - hwmon: (dell-smm) Add support for Dell OptiPlex 7040 (stable-fixes). - hwmon: (k10temp) Add device ID for Strix Halo (stable-fixes). - hwmon: (k10temp) Add thermal support for AMD Family 1Ah-based models (stable-fixes). - hwmon: (sbtsi_temp) AMD CPU extended temperature range support (stable-fixes). - hwmon: sy7636a: add alias (stable-fixes). - hyperv: Remove the spurious null directive line (git-fixes). - iio: adc: imx93_adc: load calibrated values even calibration failed (stable-fixes). - iio: adc: spear_adc: mask SPEAR_ADC_STATUS channel and avg sample before setting register (stable-fixes). - ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (stable-fixes). - iommu/amd: Return an error if vCPU affinity is set for non-vCPU IRTE (git-fixes). - isdn: mISDN: hfcsusb: fix memory leak in hfcsusb_probe() (git-fixes). - ixgbe: fix memory leak and use-after-free in ixgbe_recovery_probe() (git-fixes). - jfs: Verify inode mode when loading from disk (git-fixes). - jfs: fix uninitialized waitqueue in transaction manager (git-fixes). - lib/crypto: curve25519-hacl64: Fix older clang KASAN workaround for GCC (git-fixes). - md/raid1: fix data lost for writemostly rdev (git-fixes). - md: fix mssing blktrace bio split events (git-fixes). - media: adv7180: Add missing lock in suspend callback (stable-fixes). - media: adv7180: Do not write format to device in set_fmt (stable-fixes). - media: adv7180: Only validate format in querystd (stable-fixes). - media: amphion: Delete v4l2_fh synchronously in .release() (stable-fixes). - media: fix uninitialized symbol warnings (stable-fixes). - media: i2c: Kconfig: Ensure a dependency on HAVE_CLK for VIDEO_CAMERA_SENSOR (stable-fixes). - media: i2c: og01a1b: Specify monochrome media bus format instead of Bayer (stable-fixes). - media: imon: make send_packet() more robust (stable-fixes). - media: ov08x40: Fix the horizontal flip control (stable-fixes). - media: redrat3: use int type to store negative error codes (stable-fixes). - media: uvcvideo: Use heuristic to find stream entity (git-fixes). - media: videobuf2: forbid remove_bufs when legacy fileio is active (git-fixes). - memstick: Add timeout to prevent indefinite waiting (stable-fixes). - mfd: da9063: Split chip variant reading in two bus transactions (stable-fixes). - mfd: madera: Work around false-positive -Wininitialized warning (stable-fixes). - mfd: stmpe-i2c: Add missing MODULE_LICENSE (stable-fixes). - mfd: stmpe: Remove IRQ domain upon removal (stable-fixes). - minixfs: Verify inode mode when loading from disk (git-fixes). - mm/mm_init: fix hash table order logging in alloc_large_system_hash() (git-fixes). - mm/secretmem: fix use-after-free race in fault handler (git-fixes). - mmc: host: renesas_sdhi: Fix the actual clock (stable-fixes). - mmc: sdhci-msm: Enable tuning for SDR50 mode for SD card (stable-fixes). - mmc: sdhci-of-dwcmshc: Change DLL_STRBIN_TAPNUM_DEFAULT to 0x4 (git-fixes). - mtd: onenand: Pass correct pointer to IRQ handler (git-fixes). - mtd: rawnand: cadence: fix DMA device NULL pointer dereference (git-fixes). - mtdchar: fix integer overflow in read/write ioctls (git-fixes). - net/mana: fix warning in the writer of client oob (git-fixes). - net/smc: Remove validation of reserved bits in CLC Decline message (bsc#1253779). - net: nfc: nci: Increase NCI_DATA_TIMEOUT to 3000 ms (stable-fixes). - net: phy: clear link parameters on admin link down (stable-fixes). - net: phy: fixed_phy: let fixed_phy_unregister free the phy_device (stable-fixes). - net: phy: marvell: Fix 88e1510 downshift counter errata (stable-fixes). - net: tcp: send zero-window ACK when no memory (bsc#1253779). - net: usb: qmi_wwan: initialize MAC header offset in qmimux_rx_fixup (git-fixes). - nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing (git-fixes). - nouveau/firmware: Add missing kfree() of nvkm_falcon_fw::boot (git-fixes). - nvme-auth: add hkdf_expand_label() (bsc#1247683). - nvme-auth: use hkdf_expand_label() (bsc#1247683). - phy: cadence: cdns-dphy: Enable lower resolutions in dphy (stable-fixes). - phy: renesas: r8a779f0-ether-serdes: add new step added to latest datasheet (stable-fixes). - phy: rockchip: phy-rockchip-inno-csidphy: allow writes to grf register 0 (stable-fixes). - pinctrl: s32cc: fix uninitialized memory in s32_pinctrl_desc (git-fixes). - pinctrl: s32cc: initialize gpio_pin_config::list after kmalloc() (git-fixes). - pinctrl: single: fix bias pull up/down handling in pin_config_set (stable-fixes). - platform/x86/intel/speed_select_if: Convert PCIBIOS_* return codes to errnos (git-fixes). - power: supply: qcom_battmgr: add OOI chemistry (stable-fixes). - power: supply: qcom_battmgr: handle charging state change notifications (stable-fixes). - power: supply: sbs-charger: Support multiple devices (stable-fixes). - powerpc: export MIN RMA size (bsc#1236743 ltc#211409). - powerpc: increase MIN RMA size for CAS negotiation (bsc#1236743 ltc#211409 bsc#1252269 ltc#215957). - regulator: fixed: fix GPIO descriptor leak on register failure (git-fixes). - rtc: rx8025: fix incorrect register reference (git-fixes). - s390/mm,fault: simplify kfence fault handling (bsc#1247076). - scsi: Fix sas_user_scan() to handle wildcard and multi-channel scans (git-fixes). - scsi: aacraid: Stop using PCI_IRQ_AFFINITY (git-fixes). - scsi: core: sysfs: Correct sysfs attributes access rights (git-fixes). - scsi: hpsa: Fix potential memory leak in hpsa_big_passthru_ioctl() (git-fixes). - scsi: libfc: Prevent integer overflow in fc_fcp_recv_data() (git-fixes). - scsi: mpi3mr: Correctly handle ATA device errors (git-fixes). - scsi: mpi3mr: Drop unnecessary volatile from __iomem pointers (git-fixes). - scsi: mpt3sas: Correctly handle ATA device errors (git-fixes). - scsi: mpt3sas: Fix crash in transport port remove by using ioc_info() (git-fixes). - scsi: pm80xx: Fix array-index-out-of-of-bounds on rmmod (git-fixes). - scsi: storvsc: Prefer returning channel with the same CPU as on the I/O issuing CPU (bsc#1252267). - selftests/bpf: Check for timeout in perf_link test (bsc#1253648). - selftests/bpf: Close fd in error path in drop_on_reuseport (git-fixes). - selftests/bpf: Close obj in error path in xdp_adjust_tail (git-fixes). - selftests/bpf: Fix missing ARRAY_SIZE() definition in bench.c (git-fixes). - selftests/bpf: Fix missing BUILD_BUG_ON() declaration (git-fixes). - selftests/bpf: Fix missing UINT_MAX definitions in benchmarks (git-fixes). - selftests/bpf: Fix string read in strncmp benchmark (git-fixes). - selftests/bpf: Mitigate sockmap_ktls disconnect_after_delete failure (git-fixes). - selftests/bpf: Remove sockmap_ktls disconnect_after_delete test (bsc#1252365). - selftests/bpf: Remove tests for zeroed-array kptr (bsc#1252366). - selftests/bpf: Use pid_t consistently in test_progs.c (git-fixes). - selftests/bpf: fix signedness bug in redir_partial() (git-fixes). - selftests/net/forwarding: add slowwait functions (bsc#1254235). - selftests/net/lib: no need to record ns name if it already exist (bsc#1254235). - selftests/net/lib: update busywait timeout value (bsc#1254235). - selftests/net: add lib.sh (bsc#1254235). - selftests/net: add variable NS_LIST for lib.sh (bsc#1254235). - selftests/net: use tc rule to filter the na packet (bsc#1254235). - selftests/run_kselftest.sh: Add `--skip` argument option (bsc#1254221). - selftests: forwarding.config.sample: Move overrides to lib.sh (bsc#1254235). - selftests: forwarding: Add a test for testing lib.sh functionality (bsc#1254235). - selftests: forwarding: Avoid failures to source net/lib.sh (bsc#1254235). - selftests: forwarding: Change inappropriate log_test_skip() calls (bsc#1254235). - selftests: forwarding: Convert log_test() to recognize RET values (bsc#1254235). - selftests: forwarding: Have RET track kselftest framework constants (bsc#1254235). - selftests: forwarding: Parametrize mausezahn delay (bsc#1254235). - selftests: forwarding: Redefine relative_path variable (bsc#1254235). - selftests: forwarding: Remove duplicated lib.sh content (bsc#1254235). - selftests: forwarding: Support for performance sensitive tests (bsc#1254235). - selftests: lib: Define more kselftest exit codes (bsc#1254235). - selftests: lib: tc_rule_stats_get(): Move default to argument definition (bsc#1254235). - selftests: net: List helper scripts in TEST_FILES Makefile variable (bsc#1254235). - selftests: net: Unify code of busywait() and slowwait() (bsc#1254235). - selftests: net: add helper for checking if nettest is available (bsc#1254235). - selftests: net: lib: Do not overwrite error messages (bsc#1254235). - selftests: net: lib: Move logging from forwarding/lib.sh here (bsc#1254235). - selftests: net: lib: avoid error removing empty netns name (bsc#1254235). - selftests: net: lib: do not set ns var as readonly (bsc#1254235). - selftests: net: lib: fix shift count out of range (bsc#1254235). - selftests: net: lib: ignore possible errors (bsc#1254235). - selftests: net: lib: kill PIDs before del netns (bsc#1254235). - selftests: net: lib: remove 'ns' var in setup_ns (bsc#1254235). - selftests: net: lib: remove ns from list after clean-up (bsc#1254235). - selftests: net: lib: set 'i' as local (bsc#1254235). - selftests: net: lib: support errexit with busywait (bsc#1254235). - selftests: net: libs: Change variable fallback syntax (bsc#1254235). - serial: 8250_exar: add support for Advantech 2 port card with Device ID 0x0018 (git-fixes). - serial: 8250_mtk: Enable baud clock and manage in runtime PM (git-fixes). - soc/tegra: fuse: Add Tegra114 nvmem cells and fuse lookups (stable-fixes). - soc: aspeed: socinfo: Add AST27xx silicon IDs (stable-fixes). - soc: qcom: smem: Fix endian-unaware access of num_entries (stable-fixes). - spi: Try to get ACPI GPIO IRQ earlier (git-fixes). - spi: loopback-test: Don't use %pK through printk (stable-fixes). - spi: rpc-if: Add resume support for RZ/G3E (stable-fixes). - strparser: Fix signed/unsigned mismatch bug (git-fixes). - tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork (bsc#1250705). - thunderbolt: Use is_pciehp instead of is_hotplug_bridge (stable-fixes). - tools/cpupower: Fix incorrect size in cpuidle_state_disable() (stable-fixes). - tools/cpupower: fix error return value in cpupower_write_sysfs() (stable-fixes). - tools/hv: fcopy: Fix incorrect file path conversion (git-fixes). - tools/power x86_energy_perf_policy: Enhance HWP enable (stable-fixes). - tools/power x86_energy_perf_policy: Fix incorrect fopen mode usage (stable-fixes). - tools/power x86_energy_perf_policy: Prefer driver HWP limits (stable-fixes). - tools: lib: thermal: don't preserve owner in install (stable-fixes). - tools: lib: thermal: use pkg-config to locate libnl3 (stable-fixes). - uio_hv_generic: Query the ringbuffer size for device (git-fixes). - usb/core/quirks: Add Huawei ME906S to wakeup quirk (git-fixes). - usb: cdns3: gadget: Use-after-free during failed initialization and exit of cdnsp gadget (stable-fixes). - usb: gadget: f_fs: Fix epfile null pointer access after ep enable (stable-fixes). - usb: gadget: f_hid: Fix zero length packet transfer (stable-fixes). - usb: gadget: f_ncm: Fix MAC assignment NCM ethernet (stable-fixes). - usb: mon: Increase BUFF_MAX to 64 MiB to support multi-MB URBs (stable-fixes). - usb: xhci: plat: Facilitate using autosuspend for xhci plat devices (stable-fixes). - video: backlight: lp855x_bl: Set correct EPROM start for LP8556 (stable-fixes). - watchdog: s3c2410_wdt: Fix max_timeout being calculated larger (stable-fixes). - wifi: ath10k: Fix connection after GTK rekeying (stable-fixes). - wifi: ath11k: Add quirk entries for Thinkpad T14s Gen3 AMD (bsc#1254181). - wifi: ath11k: zero init info->status in wmi_process_mgmt_tx_comp() (git-fixes). - wifi: ath12k: Increase DP_REO_CMD_RING_SIZE to 256 (stable-fixes). - wifi: iwlwifi: fw: Add ASUS to PPAG and TAS list (stable-fixes). - wifi: mac80211: Fix 6 GHz Band capabilities element advertisement in lower bands (stable-fixes). - wifi: mac80211: Fix HE capabilities element check (stable-fixes). - wifi: mac80211: Track NAN interface start/stop (stable-fixes). - wifi: mac80211: don't mark keys for inactive links as uploaded (stable-fixes). - wifi: mac80211: fix key tailroom accounting leak (git-fixes). - wifi: mac80211: reject address change while connecting (git-fixes). - wifi: mac80211: skip rate verification for not captured PSDUs (git-fixes). - wifi: mac80211_hwsim: Limit destroy_on_close radio removal to netgroup (git-fixes). - wifi: mt76: mt7921: Add 160MHz beamformee capability for mt7922 device (stable-fixes). - wifi: mt76: mt7996: Temporarily disable EPCS (stable-fixes). - wifi: mt76: mt7996: fix memory leak on mt7996_mcu_sta_key_tlv error (stable-fixes). - wifi: mwl8k: inject DSSS Parameter Set element into beacons if missing (git-fixes). - wifi: rtw88: sdio: use indirect IO for device registers before power-on (stable-fixes). - wifi: rtw89: print just once for unknown C2H events (stable-fixes). - wifi: zd1211rw: fix potential memory leak in __zd_usb_enable_rx() (git-fixes). - x86/CPU/AMD: Add RDSEED fix for Zen5 (git-fixes). - x86/CPU/AMD: Add additional fixed RDSEED microcode revisions (git-fixes). - x86/CPU/AMD: Add missing terminator for zen5_rdseed_microcode (git-fixes). - x86/CPU/AMD: Do the common init on future Zens too (git-fixes). - x86/amd_nb: Add new PCI IDs for AMD family 0x1a (stable-fixes). - x86/bugs: Fix reporting of LFENCE retpoline (git-fixes). - x86/bugs: Report correct retbleed mitigation status (git-fixes). - x86/vmscape: Add old Intel CPUs to affected list (git-fixes). - xe/oa: Fix query mode of operation for OAR/OAC (git-fixes). - xhci: dbc: Allow users to modify DbC poll interval via sysfs (stable-fixes). - xhci: dbc: Avoid event polling busyloop if pending rx transfers are inactive (git-fixes). - xhci: dbc: Improve performance by removing delay in transfer event polling (stable-fixes). - xhci: dbc: fix bogus 1024 byte prefix if ttyDBC read races with stall event (git-fixes). - xhci: dbc: poll at different rate depending on data transfer activity (stable-fixes). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4431-1 Released: Wed Dec 17 13:03:59 2025 Summary: Recommended update for mdadm Type: recommended Severity: moderate References: 1207266,1229997,1233265,1243443,1246806,1248097,1253060 This update for mdadm fixes the following issues: - Version update 4.4+29.gf8bb524b. - Fixing race conditions between mdcheck_start and mdcheck_continue services (bsc#1243443, bsc#1248097). - Fixing broken monitoring for mdadm in Leap 15.6 (bsc#1229997). - Split off the Software RAID HOWTO into a -doc package. - Upstream bug fixes since 4.4 (bsc#1253060). - _service: switch to tar_scm for better interoperabity with SLFO. - _service: pull from github.com/openSUSE/mdadm, patches now managed in git. - New versioning scheme: add tag offset and git commit from openSUSE/mdadm repo. - Fix systemd unit file handling in spec file (bsc#1207266). - Fix mdraid activation issues (bsc#1233265). - Stop emitting %release into program binaries (bsc#1246806). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4494-1 Released: Fri Dec 19 14:14:12 2025 Summary: Security update for libpng16 Type: security Severity: important References: 1254157,1254158,1254159,1254160,1254480,CVE-2025-64505,CVE-2025-64506,CVE-2025-64720,CVE-2025-65018,CVE-2025-66293 This update for libpng16 fixes the following issues: - CVE-2025-65018: Fixed heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read` (bsc#1254160) - CVE-2025-66293: Fixed LIBPNG out-of-bounds read in `png_image_read_composite` (bsc#1254480) - CVE-2025-64506: Fixed heap buffer over-read in `png_write_image_8bit` with 8-bit input and `convert_to_8bit` enabled (bsc#1254158) - CVE-2025-64720: Fixed buffer overflow in `png_image_read_composite` via incorrect palette premultiplication (bsc#1254159) - CVE-2025-64505: Fixed heap buffer over-read in `png_do_quantize` via malformed palette index (bsc#1254157) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4511-1 Released: Tue Dec 23 13:14:27 2025 Summary: Security update for rsync Type: security Severity: moderate References: 1254441,CVE-2025-10158 This update for rsync fixes the following issues: - CVE-2025-10158: Fixed out-of-bounds array access via negative index (bsc#1254441) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4529-1 Released: Sat Dec 27 11:50:28 2025 Summary: Recommended update for lsscsi Type: recommended Severity: moderate References: 1008935,1047884,977572 This update for lsscsi fixes the following issues: Update to release 0.32 (jsc#PED-13948): * improve NVMe device parsing (e.g. /dev/nvme0c1n2) * print nr_hw_queues when available for SCSI hosts * make WWN printing for NVMe more consistent with output from SCSI devices (e.g. with -u and -t) * logic to select best SCSI id (--scsi_id) to output * fix issue where host managed ZBC devices don't output their size. [Fix also for RBC and CD/DVD.] * exclude NVMe listings when --classic given * supply '-' for generic NVMe device one line output so 'lsscsi -gb' output is consistent [jsc Update to version 0.30: * add support for NVMe devices and controllers - to build without: ./configure --disable-nvme-supp - deselect at runtime: lsscsi --no-nvme - deselect SCSI devices at runtime: lsscsi N * add --brief for tuple + device_name(s) only * add --pdt (-D) for device type in hex * extend --size (-s) so when given three times the size as a logical block count is output * add --sz-lbs (-S) that is equivalent to '-sss' when used twice adds comma then logical block size * '-w' now decodes 128 bit WWN without truncation * /dev/disk/by-id/wwn- is not guaranteed to be persistent (or stable); instead use /dev/disk/by-id/scsi- * '-t' on a FC host was not printing the comma separator resulting in garbled output, fix - Lookup WWN using /dev/disk/by-id/scsi-* (bsc#1008935) - fixup display of 'lsscsi -t' (bsc#1047884) Update to new upstream release 0.29 (bsc#977572): * '-u' now decodes locally assigned UUIDs (spc5r08) * as last try use T10 Vendor ID for lu name * if no lu name found, print 'none' * change '-uuu' to output the full lu name followed by the normal fields (which were skipped before) * add 'U' option, same action as '-uuu' * '-UU' prefixes lu names with 'eui.', 'naa.', etc * if '-s' given twice, lu size is base 2 related * if very long [h:c:t:l] then append space * print_enclosure_device() for FCP may be useless, comment out while checking ... * with '-t' print 0x0000000000000000 for non-SAS device in SAS domain Update to new upstream release 0.28: * fix handling of scsi_level 0 (no compliance) * add SRP transport identifier * add --unit option for LU identifier (>= lk 3.15) * add (S)ATA transport identifier (>= lk 3.15) * make USB transport ids more consistent * fix FC transport id missing comma * add pdt strings for security manager and zbc ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:18-1 Released: Mon Jan 5 11:52:25 2026 Summary: Security update for glib2 Type: security Severity: important References: 1254297,1254662,1254878,CVE-2025-13601,CVE-2025-14087,CVE-2025-14512 This update for glib2 fixes the following issues: - CVE-2025-14512: integer overflow in the GIO `escape_byte_string()` function when processing malicious files or remote filesystem attribute values can lead to denial-of-service (bsc#1254878). - CVE-2025-14087: buffer underflow in the GVariant parser `bytestring_parse()` and `string_parse()`functions when processing attacker-influenced data may lead to crash or code execution (bsc#1254662). - CVE-2025-13601: heap-based buffer overflow in the `g_escape_uri_string()` function when processing strings with a large number of unacceptable characters may lead to crash or code execution (bsc#1254297). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:48-1 Released: Wed Jan 7 09:08:18 2026 Summary: Recommended update for pciutils Type: recommended Severity: moderate References: 1252338 This update for pciutils fixes the following issues: - Add a strict dependency to libpci to prevent possible segfault (bsc#1252338) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:52-1 Released: Wed Jan 7 10:28:34 2026 Summary: Security update for curl Type: security Severity: moderate References: 1255731,1255732,1255733,1255734,CVE-2025-14524,CVE-2025-14819,CVE-2025-15079,CVE-2025-15224 This update for curl fixes the following issues: - CVE-2025-14524: bearer token leak on cross-protocol redirect (bsc#1255731). - CVE-2025-14819: libssh global knownhost override (bsc#1255732). - CVE-2025-15079: libssh key passphrase bypass without agent set (bsc#1255733). - CVE-2025-15224: OpenSSL partial chain store policy bypass (bsc#1255734). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:215-1 Released: Thu Jan 22 13:10:16 2026 Summary: Security update for gpg2 Type: security Severity: important References: 1255715,1256243,1256244,1256246,1256390,CVE-2025-68973 This update for gpg2 fixes the following issues: - CVE-2025-68973: Fix possible memory corruption in the armor parser (gpg.fail/memcpy)(bsc#1255715). - Avoid potential downgrade to SHA1 in 3rd party key signatures (gpg.fail/sha1) (bsc#1256246). - Error out on unverified output for non-detached signatures (gpg.fail/detached) (bsc#1256244). - Fix a memory leak in gpg2 agent (bsc#1256243). - Fix Cleartext Signature Forgery in the NotDashEscaped header implementation in GnuPG (gpg.fail/notdash) (bsc#1256390). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:221-1 Released: Thu Jan 22 13:15:35 2026 Summary: Security update for curl Type: security Severity: moderate References: 1256105,CVE-2025-14017 This update for curl fixes the following issues: - CVE-2025-14017: Fixed broken TLS options for threaded LDAPS (bsc#1256105). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:224-1 Released: Thu Jan 22 13:18:20 2026 Summary: Security update for libtasn1 Type: security Severity: moderate References: 1256341,CVE-2025-13151 This update for libtasn1 fixes the following issues: - CVE-2025-13151: stack-based buffer overflow in `asn1_expend_octet_string` (bsc#1256341). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:230-1 Released: Thu Jan 22 13:22:31 2026 Summary: Security update for util-linux Type: security Severity: moderate References: 1254666,CVE-2025-14104 This update for util-linux fixes the following issues: - CVE-2025-14104: Fixed heap buffer overread in setpwnam() when processing 256-byte usernames (bsc#1254666). - lscpu: Add support for NVIDIA Olympus arm64 core (jsc#PED-13682). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:234-1 Released: Thu Jan 22 13:24:43 2026 Summary: Security update for libpng16 Type: security Severity: moderate References: 1256525,1256526,CVE-2026-22695,CVE-2026-22801 This update for libpng16 fixes the following issues: - CVE-2026-22695: Fixed heap buffer over-read in png_image_finish_read (bsc#1256525) - CVE-2026-22801: Fixed integer truncation causing heap buffer over-read in png_image_write_* (bsc#1256526). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:286-1 Released: Sat Jan 24 00:35:35 2026 Summary: Security update for glib2 Type: security Severity: low References: 1257049,CVE-2026-0988 This update for glib2 fixes the following issues: - CVE-2026-0988: Fixed a potential integer overflow in g_buffered_input_stream_peek (bsc#1257049). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:309-1 Released: Wed Jan 28 10:36:32 2026 Summary: Security update for openssl-3 Type: security Severity: critical References: 1256830,1256834,1256835,1256836,1256837,1256838,1256839,1256840,CVE-2025-15467,CVE-2025-68160,CVE-2025-69418,CVE-2025-69419,CVE-2025-69420,CVE-2025-69421,CVE-2026-22795,CVE-2026-22796 This update for openssl-3 fixes the following issues: - CVE-2025-15467: Stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256830). - CVE-2025-68160: Heap out-of-bounds write in BIO_f_linebuffer on short writes (bsc#1256834). - CVE-2025-69418: Unauthenticated/unencrypted trailing bytes with low-level OCB function calls (bsc#1256835). - CVE-2025-69419: Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversion (bsc#1256836). - CVE-2025-69420: Missing ASN1_TYPE validation in TS_RESP_verify_response() function (bsc#1256837). - CVE-2025-69421: NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function (bsc#1256838). - CVE-2026-22795: Missing ASN1_TYPE validation in PKCS#12 parsing (bsc#1256839). - CVE-2026-22796: ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function (bsc#1256840). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:315-1 Released: Wed Jan 28 15:34:15 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1012628,1065729,1194869,1205462,1214285,1214635,1214847,1215146,1215211,1215344,1216062,1216436,1219165,1220419,1223731,1232223,1234163,1243112,1245193,1245449,1246328,1247500,1248886,1249256,1251752,1252046,1252342,1252686,1252776,1252808,1252824,1252861,1252919,1252973,1253155,1253262,1253342,1253365,1253386,1253400,1253402,1253408,1253413,1253442,1253458,1253463,1253623,1253647,1253674,1253739,1254119,1254126,1254235,1254244,1254363,1254373,1254378,1254477,1254518,1254520,1254599,1254606,1254611,1254613,1254615,1254616,1254621,1254623,1254626,1254648,1254649,1254653,1254655,1254657,1254660,1254661,1254663,1254669,1254677,1254678,1254688,1254690,1254691,1254693,1254695,1254698,1254701,1254704,1254705,1254707,1254712,1254715,1254717,1254723,1254724,1254732,1254733,1254737,1254739,1254742,1254743,1254749,1254750,1254753,1254754,1254758,1254761,1254762,1254765,1254782,1254791,1254793,1254794,1254795,1254796,1254797,1254798,1254813,1254815,1254824,1254825,1254827,1254828,1 254829,1254830,1254832,1254840,1254843,1254846,1254847,1254849,1254850,1254851,1254854,1254856,1254858,1254860,1254864,1254869,1254894,1254918,1254957,1254959,1254983,1254996,1255005,1255009,1255025,1255026,1255030,1255033,1255034,1255035,1255039,1255041,1255042,1255046,1255057,1255062,1255064,1255065,1255068,1255071,1255072,1255075,1255077,1255081,1255082,1255083,1255085,1255087,1255092,1255094,1255095,1255097,1255100,1255101,1255116,1255121,1255122,1255124,1255131,1255134,1255135,1255136,1255142,1255145,1255146,1255149,1255152,1255154,1255155,1255163,1255167,1255169,1255171,1255175,1255179,1255181,1255182,1255187,1255190,1255193,1255196,1255197,1255199,1255202,1255203,1255206,1255209,1255218,1255220,1255221,1255224,1255227,1255230,1255233,1255234,1255242,1255245,1255246,1255247,1255251,1255252,1255253,1255256,1255259,1255262,1255272,1255273,1255274,1255276,1255279,1255280,1255281,1255297,1255316,1255318,1255325,1255329,1255346,1255349,1255351,1255357,1255380,1255395,1255415,125542 8,1255433,1255434,1255463,1255480,1255483,1255489,1255493,1255495,1255505,1255507,1255538,1255540,1255545,1255549,1255550,1255553,1255557,1255558,1255563,1255564,1255567,1255570,1255578,1255579,1255580,1255583,1255591,1255601,1255603,1255605,1255611,1255614,1255616,1255617,1255618,1255621,1255628,1255629,1255630,1255632,1255636,1255688,1255691,1255702,1255704,1255706,1255707,1255709,1255722,1255723,1255724,1255758,1255759,1255760,1255763,1255769,1255770,1255772,1255774,1255775,1255776,1255780,1255785,1255786,1255789,1255790,1255792,1255793,1255795,1255798,1255800,1255801,1255806,1255807,1255809,1255810,1255812,1255814,1255820,1255838,1255842,1255843,1255872,1255875,1255879,1255883,1255884,1255886,1255888,1255890,1255891,1255892,1255899,1255902,1255907,1255911,1255915,1255918,1255921,1255924,1255925,1255931,1255932,1255934,1255943,1255944,1255949,1255951,1255952,1255955,1255957,1255961,1255963,1255964,1255967,1255974,1255978,1255984,1255988,1255990,1255992,1255993,1255994,1255996,125 6033,1256034,1256045,1256050,1256058,1256071,1256074,1256081,1256082,1256083,1256084,1256085,1256090,1256093,1256094,1256095,1256096,1256099,1256100,1256104,1256106,1256107,1256117,1256119,1256121,1256145,1256153,1256178,1256197,1256231,1256233,1256234,1256238,1256263,1256267,1256268,1256271,1256273,1256274,1256279,1256285,1256291,1256292,1256300,1256301,1256302,1256335,1256348,1256351,1256354,1256358,1256361,1256364,1256366,1256367,1256368,1256369,1256370,1256371,1256373,1256375,1256379,1256387,1256394,1256395,1256396,1256528,CVE-2023-42752,CVE-2023-53743,CVE-2023-53750,CVE-2023-53752,CVE-2023-53759,CVE-2023-53762,CVE-2023-53766,CVE-2023-53768,CVE-2023-53777,CVE-2023-53778,CVE-2023-53782,CVE-2023-53784,CVE-2023-53785,CVE-2023-53787,CVE-2023-53791,CVE-2023-53792,CVE-2023-53793,CVE-2023-53794,CVE-2023-53795,CVE-2023-53797,CVE-2023-53799,CVE-2023-53807,CVE-2023-53808,CVE-2023-53813,CVE-2023-53815,CVE-2023-53819,CVE-2023-53821,CVE-2023-53823,CVE-2023-53825,CVE-2023-53828,CVE-2023-53831 ,CVE-2023-53834,CVE-2023-53836,CVE-2023-53839,CVE-2023-53841,CVE-2023-53842,CVE-2023-53843,CVE-2023-53844,CVE-2023-53846,CVE-2023-53847,CVE-2023-53848,CVE-2023-53850,CVE-2023-53851,CVE-2023-53852,CVE-2023-53855,CVE-2023-53856,CVE-2023-53857,CVE-2023-53858,CVE-2023-53860,CVE-2023-53861,CVE-2023-53863,CVE-2023-53864,CVE-2023-53865,CVE-2023-53989,CVE-2023-53992,CVE-2023-53994,CVE-2023-53995,CVE-2023-53996,CVE-2023-53997,CVE-2023-53998,CVE-2023-53999,CVE-2023-54000,CVE-2023-54001,CVE-2023-54005,CVE-2023-54006,CVE-2023-54008,CVE-2023-54014,CVE-2023-54016,CVE-2023-54017,CVE-2023-54019,CVE-2023-54022,CVE-2023-54023,CVE-2023-54025,CVE-2023-54026,CVE-2023-54027,CVE-2023-54030,CVE-2023-54031,CVE-2023-54032,CVE-2023-54035,CVE-2023-54037,CVE-2023-54038,CVE-2023-54042,CVE-2023-54045,CVE-2023-54048,CVE-2023-54049,CVE-2023-54051,CVE-2023-54052,CVE-2023-54060,CVE-2023-54064,CVE-2023-54066,CVE-2023-54067,CVE-2023-54069,CVE-2023-54070,CVE-2023-54072,CVE-2023-54076,CVE-2023-54080,CVE-2023-54081,CVE-20 23-54083,CVE-2023-54088,CVE-2023-54089,CVE-2023-54091,CVE-2023-54092,CVE-2023-54093,CVE-2023-54094,CVE-2023-54095,CVE-2023-54096,CVE-2023-54099,CVE-2023-54101,CVE-2023-54104,CVE-2023-54106,CVE-2023-54112,CVE-2023-54113,CVE-2023-54115,CVE-2023-54117,CVE-2023-54121,CVE-2023-54125,CVE-2023-54127,CVE-2023-54133,CVE-2023-54134,CVE-2023-54135,CVE-2023-54136,CVE-2023-54137,CVE-2023-54140,CVE-2023-54141,CVE-2023-54142,CVE-2023-54143,CVE-2023-54145,CVE-2023-54148,CVE-2023-54149,CVE-2023-54153,CVE-2023-54154,CVE-2023-54155,CVE-2023-54156,CVE-2023-54164,CVE-2023-54166,CVE-2023-54169,CVE-2023-54170,CVE-2023-54171,CVE-2023-54172,CVE-2023-54173,CVE-2023-54177,CVE-2023-54178,CVE-2023-54179,CVE-2023-54181,CVE-2023-54183,CVE-2023-54185,CVE-2023-54189,CVE-2023-54194,CVE-2023-54201,CVE-2023-54204,CVE-2023-54207,CVE-2023-54209,CVE-2023-54210,CVE-2023-54211,CVE-2023-54215,CVE-2023-54219,CVE-2023-54220,CVE-2023-54221,CVE-2023-54223,CVE-2023-54224,CVE-2023-54225,CVE-2023-54227,CVE-2023-54229,CVE-2023-5423 0,CVE-2023-54235,CVE-2023-54240,CVE-2023-54241,CVE-2023-54246,CVE-2023-54247,CVE-2023-54251,CVE-2023-54253,CVE-2023-54254,CVE-2023-54255,CVE-2023-54258,CVE-2023-54261,CVE-2023-54263,CVE-2023-54264,CVE-2023-54266,CVE-2023-54267,CVE-2023-54271,CVE-2023-54276,CVE-2023-54278,CVE-2023-54281,CVE-2023-54282,CVE-2023-54283,CVE-2023-54285,CVE-2023-54289,CVE-2023-54291,CVE-2023-54292,CVE-2023-54293,CVE-2023-54296,CVE-2023-54297,CVE-2023-54299,CVE-2023-54300,CVE-2023-54302,CVE-2023-54303,CVE-2023-54304,CVE-2023-54309,CVE-2023-54312,CVE-2023-54313,CVE-2023-54314,CVE-2023-54315,CVE-2023-54316,CVE-2023-54318,CVE-2023-54319,CVE-2023-54322,CVE-2023-54324,CVE-2023-54326,CVE-2024-26944,CVE-2025-38321,CVE-2025-38728,CVE-2025-39977,CVE-2025-40006,CVE-2025-40024,CVE-2025-40033,CVE-2025-40042,CVE-2025-40053,CVE-2025-40081,CVE-2025-40102,CVE-2025-40123,CVE-2025-40134,CVE-2025-40135,CVE-2025-40153,CVE-2025-40158,CVE-2025-40160,CVE-2025-40167,CVE-2025-40170,CVE-2025-40178,CVE-2025-40179,CVE-2025-40187,CVE-2 025-40190,CVE-2025-40211,CVE-2025-40213,CVE-2025-40215,CVE-2025-40219,CVE-2025-40220,CVE-2025-40223,CVE-2025-40225,CVE-2025-40231,CVE-2025-40233,CVE-2025-40240,CVE-2025-40242,CVE-2025-40244,CVE-2025-40248,CVE-2025-40250,CVE-2025-40251,CVE-2025-40252,CVE-2025-40256,CVE-2025-40258,CVE-2025-40262,CVE-2025-40263,CVE-2025-40268,CVE-2025-40269,CVE-2025-40271,CVE-2025-40272,CVE-2025-40273,CVE-2025-40274,CVE-2025-40275,CVE-2025-40276,CVE-2025-40277,CVE-2025-40278,CVE-2025-40279,CVE-2025-40280,CVE-2025-40282,CVE-2025-40283,CVE-2025-40284,CVE-2025-40287,CVE-2025-40288,CVE-2025-40289,CVE-2025-40292,CVE-2025-40293,CVE-2025-40294,CVE-2025-40297,CVE-2025-40301,CVE-2025-40302,CVE-2025-40304,CVE-2025-40306,CVE-2025-40307,CVE-2025-40308,CVE-2025-40309,CVE-2025-40310,CVE-2025-40311,CVE-2025-40312,CVE-2025-40314,CVE-2025-40315,CVE-2025-40316,CVE-2025-40317,CVE-2025-40318,CVE-2025-40319,CVE-2025-40320,CVE-2025-40321,CVE-2025-40322,CVE-2025-40323,CVE-2025-40324,CVE-2025-40329,CVE-2025-40330,CVE-2025-403 31,CVE-2025-40332,CVE-2025-40337,CVE-2025-40338,CVE-2025-40339,CVE-2025-40340,CVE-2025-40342,CVE-2025-40343,CVE-2025-40345,CVE-2025-40346,CVE-2025-40347,CVE-2025-40349,CVE-2025-40351,CVE-2025-40354,CVE-2025-40357,CVE-2025-40359,CVE-2025-40360,CVE-2025-68168,CVE-2025-68170,CVE-2025-68172,CVE-2025-68176,CVE-2025-68180,CVE-2025-68181,CVE-2025-68183,CVE-2025-68184,CVE-2025-68185,CVE-2025-68190,CVE-2025-68192,CVE-2025-68194,CVE-2025-68195,CVE-2025-68197,CVE-2025-68201,CVE-2025-68204,CVE-2025-68206,CVE-2025-68207,CVE-2025-68208,CVE-2025-68209,CVE-2025-68217,CVE-2025-68218,CVE-2025-68222,CVE-2025-68223,CVE-2025-68230,CVE-2025-68233,CVE-2025-68235,CVE-2025-68237,CVE-2025-68238,CVE-2025-68239,CVE-2025-68244,CVE-2025-68249,CVE-2025-68252,CVE-2025-68255,CVE-2025-68257,CVE-2025-68258,CVE-2025-68259,CVE-2025-68264,CVE-2025-68286,CVE-2025-68287,CVE-2025-68289,CVE-2025-68290,CVE-2025-68298,CVE-2025-68302,CVE-2025-68303,CVE-2025-68305,CVE-2025-68306,CVE-2025-68307,CVE-2025-68308,CVE-2025-68312,CVE- 2025-68313,CVE-2025-68328,CVE-2025-68330,CVE-2025-68331,CVE-2025-68332,CVE-2025-68335,CVE-2025-68339,CVE-2025-68340,CVE-2025-68345,CVE-2025-68346,CVE-2025-68347,CVE-2025-68351,CVE-2025-68354,CVE-2025-68362,CVE-2025-68378,CVE-2025-68380,CVE-2025-68724,CVE-2025-68732,CVE-2025-68734,CVE-2025-68740,CVE-2025-68742,CVE-2025-68744,CVE-2025-68746,CVE-2025-68747,CVE-2025-68749,CVE-2025-68750,CVE-2025-68753,CVE-2025-68757,CVE-2025-68758,CVE-2025-68759,CVE-2025-68765,CVE-2025-68766 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-38321: smb: Log an error when close_all_cached_dirs fails (bsc#1246328). - CVE-2025-38728: smb3: fix for slab out of bounds on mount to ksmbd (bsc#1249256). - CVE-2025-39977: futex: Prevent use-after-free during requeue-PI (bsc#1252046). - CVE-2025-40006: mm/hugetlb: fix folio is still mapped when deleted (bsc#1252342). - CVE-2025-40024: vhost: Take a reference on the task in struct vhost_task (bsc#1252686). - CVE-2025-40033: remoteproc: pru: Fix potential NULL pointer dereference in pru_rproc_set_ctable() (bsc#1252824). - CVE-2025-40042: tracing: Fix race condition in kprobe initialization causing NULL pointer dereference (bsc#1252861). - CVE-2025-40053: net: dlink: handle copy_thresh allocation failure (bsc#1252808). - CVE-2025-40081: perf: arm_spe: Prevent overflow in PERF_IDX2OFF() (bsc#1252776). - CVE-2025-40102: KVM: arm64: Prevent access to vCPU events before init (bsc#1252919). - CVE-2025-40134: dm: fix NULL pointer dereference in __dm_suspend() (bsc#1253386). - CVE-2025-40135: ipv6: use RCU in ip6_xmit() (bsc#1253342). - CVE-2025-40153: mm: hugetlb: avoid soft lockup when mprotect to large memory area (bsc#1253408). - CVE-2025-40158: ipv6: use RCU in ip6_output() (bsc#1253402). - CVE-2025-40160: xen/events: Cleanup find_virq() return codes (bsc#1253400). - CVE-2025-40167: ext4: detect invalid INLINE_DATA + EXTENTS flag combination (bsc#1253458). - CVE-2025-40170: net: use dst_dev_rcu() in sk_setup_caps() (bsc#1253413). - CVE-2025-40178: pid: Add a judgment for ns null in pid_nr_ns (bsc#1253463). - CVE-2025-40179: ext4: verify orphan file size is not too big (bsc#1253442). - CVE-2025-40187: net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() (bsc#1253647). - CVE-2025-40190: ext4: guard against EA inode refcount underflow in xattr update (bsc#1253623). - CVE-2025-40215: kABI: xfrm: delete x->tunnel as we delete x (bsc#1254959). - CVE-2025-40220: fuse: fix livelock in synchronous file put from fuseblk workers (bsc#1254520). - CVE-2025-40231: vsock: fix lock inversion in vsock_assign_transport() (bsc#1254815). - CVE-2025-40233: ocfs2: clear extent cache after moving/defragmenting extents (bsc#1254813). - CVE-2025-40240: sctp: avoid NULL dereference when chunk data buffer is missing (bsc#1254869). - CVE-2025-40242: gfs2: Fix unlikely race in gdlm_put_lock (bsc#1255075). - CVE-2025-40248: vsock: Ignore signal/timeout on connect() if already established (bsc#1254864). - CVE-2025-40250: net/mlx5: Clean up only new IRQ glue on request_irq() failure (bsc#1254854). - CVE-2025-40251: devlink: rate: Unset parent pointer in devl_rate_nodes_destroy (bsc#1254856). - CVE-2025-40252: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() (bsc#1254849). - CVE-2025-40258: mptcp: fix race condition in mptcp_schedule_work() (bsc#1254843). - CVE-2025-40268: cifs: client: fix memory leak in smb3_fs_context_parse_param (bsc#1255082). - CVE-2025-40271: fs/proc: fix uaf in proc_readdir_de() (bsc#1255297). - CVE-2025-40274: KVM: guest_memfd: Remove bindings on memslot deletion when gmem is dying (bsc#1254830). - CVE-2025-40278: net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak (bsc#1254825). - CVE-2025-40279: net: sched: act_connmark: initialize struct tc_ife to fix kernel leak (bsc#1254846). - CVE-2025-40280: tipc: Fix use-after-free in tipc_mon_reinit_self() (bsc#1254847). - CVE-2025-40287: exfat: fix improper check of dentry.stream.valid_size (bsc#1255030). - CVE-2025-40289: drm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM (bsc#1255042). - CVE-2025-40292: virtio-net: fix received length check in big packets (bsc#1255175). - CVE-2025-40293: iommufd: Don't overflow during division for dirty tracking (bsc#1255179). - CVE-2025-40297: net: bridge: fix use-after-free due to MST port state bypass (bsc#1255187). - CVE-2025-40307: exfat: validate cluster allocation bits of the allocation bitmap (bsc#1255039). - CVE-2025-40319: bpf: Sync pending IRQ work before freeing ring buffer (bsc#1254794). - CVE-2025-40330: bnxt_en: Shutdown FW DMA in bnxt_shutdown() (bsc#1254616). - CVE-2025-40331: sctp: Prevent TOCTOU out-of-bounds write (bsc#1254615). - CVE-2025-40337: net: stmmac: Correctly handle Rx checksum offload errors (bsc#1255081). - CVE-2025-40338: ASoC: Intel: avs: Do not share the name pointer between components (bsc#1255273). - CVE-2025-40346: arch_topology: Fix incorrect error check in topology_parse_cpu_capacity() (bsc#1255318). - CVE-2025-40357: net/smc: fix general protection fault in __smc_diag_dump (bsc#1255097). - CVE-2025-68197: bnxt_en: Fix null pointer dereference in bnxt_bs_trace_check_wrap() (bsc#1255242). - CVE-2025-68204: pmdomain: arm: scmi: Fix genpd leak on provider registration failure (bsc#1255224). - CVE-2025-68206: netfilter: nft_ct: add seqadj extension for natted connections (bsc#1255142). - CVE-2025-68208: bpf: account for current allocated stack depth in widen_imprecise_scalars() (bsc#1255227). - CVE-2025-68209: mlx5: Fix default values in create CQ (bsc#1255230). - CVE-2025-68239: binfmt_misc: restore write access before closing files opened by open_exec() (bsc#1255272). - CVE-2025-68255: staging: rtl8723bs: fix stack buffer overflow in OnAssocReq IE parsing (bsc#1255395). - CVE-2025-68259: KVM: SVM: Don't skip unrelated instruction if INT3/INTO is replaced (bsc#1255199). - CVE-2025-68264: ext4: refresh inline data size before write operations (bsc#1255380). - CVE-2025-68302: net: sxgbe: fix potential NULL dereference in sxgbe_rx() (bsc#1255121). - CVE-2025-68340: team: Move team device type change at the end of team_port_add (bsc#1255507). - CVE-2025-68378: bpf: Refactor stack map trace depth calculation into helper function (bsc#1255614). - CVE-2025-68742: bpf: Improve program stats run-time calculation (bsc#1255707). - CVE-2025-68744: bpf: Free special fields when update [lru_,]percpu_hash maps (bsc#1255709). The following non security issues were fixed: - ACPI: CPPC: Fix missing PCC check for guaranteed_perf (git-fixes). - ACPI: PCC: Fix race condition by removing static qualifier (git-fixes). - ACPI: processor_core: fix map_x2apic_id for amd-pstate on am4 (git-fixes). - ACPI: property: Fix fwnode refcount leak in acpi_fwnode_graph_parse_endpoint() (git-fixes). - ACPI: property: Use ACPI functions in acpi_graph_get_next_endpoint() only (stable-fixes). - ACPICA: Avoid walking the Namespace if start_node is NULL (stable-fixes). - ALSA: ac97: fix a double free in snd_ac97_controller_register() (git-fixes). - ALSA: dice: fix buffer overflow in detect_stream_formats() (git-fixes). - ALSA: firewire-motu: add bounds check in put_user loop for DSP events (git-fixes). - ALSA: firewire-motu: fix buffer overflow in hwdep read for DSP events (git-fixes). - ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_hda_read_acpi() (git-fixes). - ALSA: pcmcia: Fix resource leak in snd_pdacf_probe error path (git-fixes). - ALSA: uapi: Fix typo in asound.h comment (git-fixes). - ALSA: usb-audio: Add DSD quirk for LEAK Stereo 230 (stable-fixes). - ALSA: usb-audio: Add native DSD quirks for PureAudio DAC series (stable-fixes). - ALSA: usb-audio: fix uac2 clock source at terminal parser (git-fixes). - ALSA: usb-mixer: us16x08: validate meter packet indices (git-fixes). - ALSA: vxpocket: Fix resource leak in vxpocket_probe error path (git-fixes). - ASoC: Intel: catpt: Fix error path in hw_params() (git-fixes). - ASoC: ak4458: Disable regulator when error happens (git-fixes). - ASoC: ak4458: remove the reset operation in probe and remove (git-fixes). - ASoC: ak5558: Disable regulator when error happens (git-fixes). - ASoC: bcm: bcm63xx-pcm-whistler: Check return value of of_dma_configure() (git-fixes). - ASoC: codecs: lpass-tx-macro: fix SM6115 support (git-fixes). - ASoC: codecs: wcd938x: fix OF node leaks on probe failure (git-fixes). - ASoC: fsl_xcvr: clear the channel status control memory (git-fixes). - ASoC: qcom: q6adm: the the copp device only during last instance (git-fixes). - ASoC: qcom: q6apm-dai: set flags to reflect correct operation of appl_ptr (git-fixes). - ASoC: qcom: q6asm-dai: perform correct state check before closing (git-fixes). - ASoC: qcom: qdsp6: q6asm-dai: set 10 ms period and buffer alignment (git-fixes). - ASoC: stm32: sai: fix OF node leak on probe (git-fixes). - ASoC: stm32: sai: fix clk prepare imbalance on probe failure (git-fixes). - ASoC: stm32: sai: fix device leak on probe (git-fixes). - ASoC: sun4i-spdif: Add missing kerneldoc fields for sun4i_spdif_quirks (git-fixes). - Bluetooth: HCI: Fix tracking of advertisement set/instance 0x00 (git-fixes). - Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete (git-fixes). - Bluetooth: SMP: Fix not generating mackey and ltk when repairing (git-fixes). - Bluetooth: btrtl: Avoid loading the config file on security chips (stable-fixes). - Bluetooth: btusb: Add new VID/PID 13d3/3533 for RTL8821CE (stable-fixes). - Bluetooth: btusb: Add new VID/PID 2b89/6275 for RTL8761BUV (stable-fixes). - Bluetooth: btusb: mediatek: Avoid btusb_mtk_claim_iso_intf() NULL deref (git-fixes). - Bluetooth: btusb: mediatek: Fix kernel crash when releasing mtk iso interface (git-fixes). - Bluetooth: btusb: revert use of devm_kzalloc in btusb (git-fixes). - Bluetooth: hci_sock: Prevent race in socket write iter and sock bind (git-fixes). - Documentation/kernel-parameters: fix typo in retbleed= kernel parameter description (git-fixes). - Documentation: hid-alps: Fix packet format section headings (git-fixes). - Documentation: parport-lowlevel: Separate function listing code blocks (git-fixes). - HID: apple: Add SONiX AK870 PRO to non_apple_keyboards quirk list (stable-fixes). - HID: elecom: Add support for ELECOM M-XT3URBK (018F) (stable-fixes). - HID: hid-input: Extend Elan ignore battery quirk to USB (stable-fixes). - HID: input: map HID_GD_Z to ABS_DISTANCE for stylus/pen (stable-fixes). - HID: logitech-dj: Remove duplicate error logging (git-fixes). - HID: logitech-hidpp: Do not assume FAP in hidpp_send_message_sync() (git-fixes). - HID: quirks: work around VID/PID conflict for appledisplay (git-fixes). - Input: atkbd - skip deactivate for HONOR FMB-P's internal keyboard (git-fixes). - Input: cros_ec_keyb - fix an invalid memory access (stable-fixes). - Input: goodix - add support for ACPI ID GDIX1003 (stable-fixes). - Input: goodix - add support for ACPI ID GDX9110 (stable-fixes). - Input: i8042 - add TUXEDO InfinityBook Max Gen10 AMD to i8042 quirk table (stable-fixes). - Input: ti_am335x_tsc - fix off-by-one error in wire_order validation (git-fixes). - KEYS: trusted: Fix a memory leak in tpm2_load_cmd (git-fixes). - KEYS: trusted_tpm1: Compare HMAC values in constant time (git-fixes). - KVM: SEV: Drop GHCB_VERSION_DEFAULT and open code it (bsc#1255463). - PCI/PM: Reinstate clearing state_saved in legacy and !PM codepaths (git-fixes). - PCI: dwc: Fix wrong PORT_LOGIC_LTSSM_STATE_MASK definition (git-fixes). - PCI: keystone: Exit ks_pcie_probe() for invalid mode (git-fixes). - PCI: rcar-gen2: Drop ARM dependency from PCI_RCAR_GEN2 (git-fixes). - PM: runtime: Do not clear needs_force_resume with enabled runtime PM (git-fixes). - Revert 'drm/amd/display: Fix pbn to kbps Conversion' (stable-fixes). - Revert 'drm/amd/display: Move setup_stream_attribute' (stable-fixes). - Revert 'drm/amd: Skip power ungate during suspend for VPE' (git-fixes). - Revert 'mtd: rawnand: marvell: fix layouts' (git-fixes). - Revert 'net: r8169: Disable multicast filter for RTL8168H and RTL8107E' (jsc#PED-14353). - Revert 'r8169: don't try to disable interrupts if NAPI is, scheduled already' (jsc#PED-14353). - USB: Fix descriptor count when handling invalid MBIM extended descriptor (git-fixes). - USB: lpc32xx_udc: Fix error handling in probe (git-fixes). - USB: serial: belkin_sa: fix TIOCMBIS and TIOCMBIC (git-fixes). - USB: serial: ftdi_sio: add support for u-blox EVK-M101 (stable-fixes). - USB: serial: ftdi_sio: match on interface number for jtag (stable-fixes). - USB: serial: kobil_sct: fix TIOCMBIS and TIOCMBIC (git-fixes). - USB: serial: option: add Foxconn T99W760 (stable-fixes). - USB: serial: option: add Quectel RG255C (stable-fixes). - USB: serial: option: add Telit Cinterion FE910C04 new compositions (stable-fixes). - USB: serial: option: add Telit FN920C04 ECM compositions (stable-fixes). - USB: serial: option: add UNISOC UIS7720 (stable-fixes). - USB: serial: option: add support for Rolling RW101R-GL (stable-fixes). - USB: serial: option: move Telit 0x10c7 composition in the right place (stable-fixes). - USB: storage: Remove subclass and protocol overrides from Novatek quirk (git-fixes). - accel/ivpu: Fix DCT active percent format (git-fixes). - accel/ivpu: Fix race condition when unbinding BOs (git-fixes). - arm64: zynqmp: Fix usb node drive strength and slew rate (git-fixes). - arm64: zynqmp: Revert usb node drive strength and slew rate for (git-fixes). - atm/fore200e: Fix possible data race in fore200e_open() (git-fixes). - atm: Fix dma_free_coherent() size (git-fixes). - atm: idt77252: Add missing `dma_map_error()` (stable-fixes). - backlight: led-bl: Add devlink to supplier LEDs (git-fixes). - backlight: lp855x: Fix lp855x.h kernel-doc warnings (git-fixes). - bpf: Do not limit bpf_cgroup_from_id to current's namespace (bsc#1255433). - bpf: Reject bpf_timer for PREEMPT_RT (git-fixes). - broadcom: b44: prevent uninitialized value usage (git-fixes). - btrfs: make sure extent and csum paths are always released in scrub_raid56_parity_stripe() (git-fixes). - can: gs_usb: gs_can_open(): fix error handling (git-fixes). - can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs (git-fixes). - can: j1939: make j1939_sk_bind() fail if device is no longer registered (git-fixes). - can: kvaser_usb: leaf: Fix potential infinite loop in command parsers (git-fixes). - can: sja1000: fix max irq loop handling (git-fixes). - can: sun4i_can: sun4i_can_interrupt(): fix max irq loop handling (git-fixes). - cgroup: rstat: use LOCK CMPXCHG in css_rstat_updated (bsc#1255434). - char: applicom: fix NULL pointer dereference in ac_ioctl (stable-fixes). - cifs: Fix uncached read into ITER_KVEC iterator (bsc#1245449). - clk: qcom: camcc-sm6350: Fix PLL config of PLL2 (git-fixes). - clk: qcom: camcc-sm6350: Specify Titan GDSC power domain as a parent to other (git-fixes). - clk: renesas: cpg-mssr: Add missing 1ms delay into reset toggle callback (git-fixes). - clk: renesas: r9a06g032: Fix memory leak in error path (git-fixes). - clk: samsung: exynos-clkout: Assign .num before accessing .hws (git-fixes). - comedi: c6xdigio: Fix invalid PNP driver unregistration (git-fixes). - comedi: check device's attached status in compat ioctls (git-fixes). - comedi: multiq3: sanitize config options in multiq3_attach() (git-fixes). - comedi: pcl818: fix null-ptr-deref in pcl818_ai_cancel() (git-fixes). - cpufreq: intel_pstate: Check IDA only before MSR_IA32_PERF_CTL writes (git-fixes). - cpufreq: nforce2: fix reference count leak in nforce2 (git-fixes). - cpuidle: menu: Use residency threshold in polling state override decisions (bsc#1255026). - crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (git-fixes). - crypto: authenc - Correctly pass EINPROGRESS back up to the caller (git-fixes). - crypto: ccree - Correctly handle return of sg_nents_for_len (git-fixes). - crypto: hisilicon/qm - restore original qos values (git-fixes). - crypto: iaa - Fix incorrect return value in save_iaa_wq() (git-fixes). - crypto: qat - fix duplicate restarting msg during AER error (git-fixes). - crypto: rockchip - drop redundant crypto_skcipher_ivsize() calls (git-fixes). - crypto: seqiv - Do not use req->iv after crypto_aead_encrypt (git-fixes). - dm-integrity: limit MAX_TAG_SIZE to 255 (git-fixes). - dm-verity: fix unreliable memory allocation (git-fixes). - dm: fix queue start/stop imbalance under suspend/load/resume races (bsc#1253386). - drivers/usb/dwc3: fix PCI parent check (git-fixes). - drm/amd/amdgpu: reserve vm invalidation engine for uni_mes (stable-fixes). - drm/amd/display: Check NULL before accessing (stable-fixes). - drm/amd/display: Clear the CUR_ENABLE register on DCN20 on DPP5 (stable-fixes). - drm/amd/display: Don't change brightness for disabled connectors (stable-fixes). - drm/amd/display: Fix logical vs bitwise bug in get_embedded_panel_info_v2_1() (git-fixes). - drm/amd/display: Fix pbn to kbps Conversion (stable-fixes). - drm/amd/display: Fix scratch registers offsets for DCN35 (stable-fixes). - drm/amd/display: Fix scratch registers offsets for DCN351 (stable-fixes). - drm/amd/display: Increase DPCD read retries (stable-fixes). - drm/amd/display: Insert dccg log for easy debug (stable-fixes). - drm/amd/display: Move sleep into each retry for retrieve_link_cap() (stable-fixes). - drm/amd/display: Prevent Gating DTBCLK before It Is Properly Latched (git-fixes). - drm/amd/display: Use GFP_ATOMIC in dc_create_plane_state() (stable-fixes). - drm/amd/display: avoid reset DTBCLK at clock init (stable-fixes). - drm/amd/display: disable DPP RCG before DPP CLK enable (stable-fixes). - drm/amd: Skip power ungate during suspend for VPE (stable-fixes). - drm/amdgpu/gmc11: add amdgpu_vm_handle_fault() handling (stable-fixes). - drm/amdgpu/gmc12: add amdgpu_vm_handle_fault() handling (stable-fixes). - drm/amdgpu: Forward VMID reservation errors (git-fixes). - drm/amdgpu: Skip emit de meta data on gfx11 with rs64 enabled (stable-fixes). - drm/amdgpu: add missing lock to amdgpu_ttm_access_memory_sdma (git-fixes). - drm/amdgpu: fix cyan_skillfish2 gpu info fw handling (git-fixes). - drm/amdgpu: fix gpu page fault after hibernation on PF passthrough (stable-fixes). - drm/amdkfd: Export the cwsr_size and ctl_stack_size to userspace (stable-fixes). - drm/amdkfd: Fix GPU mappings for APU after prefetch (stable-fixes). - drm/amdkfd: Trap handler support for expert scheduling mode (stable-fixes). - drm/amdkfd: Use huge page size to check split svm range alignment (git-fixes). - drm/amdkfd: bump minimum vgpr size for gfx1151 (stable-fixes). - drm/displayid: add quirk to ignore DisplayID checksum errors (stable-fixes). - drm/displayid: pass iter to drm_find_displayid_extension() (stable-fixes). - drm/edid: add DRM_EDID_IDENT_INIT() to initialize struct drm_edid_ident (stable-fixes). - drm/gma500: Remove unused helper psb_fbdev_fb_setcolreg() (git-fixes). - drm/i915/dp: Initialize the source OUI write timestamp always (stable-fixes). - drm/i915/dp_mst: Disable Panel Replay (git-fixes). - drm/i915/gem: Zero-initialize the eb.vma array in i915_gem_do_execbuffer (git-fixes). - drm/i915: Fix format string truncation warning (git-fixes). - drm/imagination: Disallow exporting of PM/FW protected objects (git-fixes). - drm/imagination: Fix reference to devm_platform_get_and_ioremap_resource() (git-fixes). - drm/me/gsc: mei interrupt top half should be in irq disabled context (git-fixes). - drm/mediatek: Fix CCORR mtk_ctm_s31_32_to_s1_n function issue (git-fixes). - drm/mediatek: Fix device node reference leak in mtk_dp_dt_parse() (git-fixes). - drm/mediatek: Fix probe device leaks (git-fixes). - drm/mediatek: Fix probe memory leak (git-fixes). - drm/mediatek: Fix probe resource leaks (git-fixes). - drm/mediatek: ovl_adaptor: Fix probe device leaks (git-fixes). - drm/mgag200: Fix big-endian support (git-fixes). - drm/msm/a2xx: stop over-complaining about the legacy firmware (git-fixes). - drm/msm/a6xx: Fix out of bound IO access in a6xx_get_gmu_registers (git-fixes). - drm/msm/a6xx: Fix the gemnoc workaround (git-fixes). - drm/msm/a6xx: Flush LRZ cache before PT switch (git-fixes). - drm/msm/a6xx: Improve MX rail fallback in RPMH vote init (git-fixes). - drm/msm/dpu: Add missing NULL pointer check for pingpong interface (git-fixes). - drm/msm/dpu: Remove dead-code in dpu_encoder_helper_reset_mixers() (git-fixes). - drm/msm/dpu: drop dpu_hw_dsc_destroy() prototype (git-fixes). - drm/nouveau/dispnv50: Don't call drm_atomic_get_crtc_state() in prepare_fb (git-fixes). - drm/nouveau: refactor deprecated strcpy (git-fixes). - drm/nouveau: restrict the flush page to a 32-bit address (git-fixes). - drm/panel: sony-td4353-jdi: Enable prepare_prev_first (git-fixes). - drm/panel: visionox-rm69299: Don't clear all mode flags (git-fixes). - drm/panthor: Avoid adding of kernel BOs to extobj list (git-fixes). - drm/panthor: Fix UAF on kernel BO VA nodes (git-fixes). - drm/panthor: Fix group_free_queue() for partially initialized queues (git-fixes). - drm/panthor: Fix potential memleak of vma structure (git-fixes). - drm/panthor: Fix race with suspend during unplug (git-fixes). - drm/panthor: Flush shmem writes before mapping buffers CPU-uncached (git-fixes). - drm/panthor: Handle errors returned by drm_sched_entity_init() (git-fixes). - drm/pl111: Fix error handling in pl111_amba_probe (git-fixes). - drm/plane: Fix IS_ERR() vs NULL check in drm_plane_create_hotspot_properties() (git-fixes). - drm/radeon: delete radeon_fence_process in is_signaled, no deadlock (stable-fixes). - drm/sched: Fix race in drm_sched_entity_select_rq() (git-fixes). - drm/tilcdc: Fix removal actions in case of failed probe (git-fixes). - drm/tilcdc: request and mapp iomem with devres (stable-fixes). - drm/ttm: Avoid NULL pointer deref for evicted BOs (git-fixes). - drm/vgem-fence: Fix potential deadlock on release (git-fixes). - drm/vmwgfx: Use kref in vmw_bo_dirty (stable-fixes). - drm/xe/bo: Don't include the CCS metadata in the dma-buf sg-table (git-fixes). - drm/xe/oa: Disallow 0 OA property values (git-fixes). - drm/xe/oa: Fix potential UAF in xe_oa_add_config_ioctl() (git-fixes). - drm/xe/oa: Limit num_syncs to prevent oversized allocations (git-fixes). - drm/xe: Adjust long-running workload timeslices to reasonable values (git-fixes). - drm/xe: Drop preempt-fences when destroying imported dma-bufs (git-fixes). - drm/xe: Fix conversion from clock ticks to milliseconds (git-fixes). - drm/xe: Limit num_syncs to prevent oversized allocations (git-fixes). - drm/xe: Prevent BIT() overflow when handling invalid prefetch region (git-fixes). - drm/xe: Restore engine registers before restarting schedulers after GT reset (git-fixes). - drm/xe: Use usleep_range for accurate long-running workload timeslicing (git-fixes). - drm: atmel-hlcdc: fix atmel_xlcdc_plane_setup_scaler() (git-fixes). - drm: nouveau: Replace sprintf() with sysfs_emit() (git-fixes). - drm: sti: fix device leaks at component probe (git-fixes). - efi/libstub: Avoid physical address 0x0 when doing random allocation (stable-fixes). - efi/libstub: Describe missing 'out' parameter in efi_load_initrd (git-fixes). - efi/libstub: Fix page table access in 5-level to 4-level paging transition (git-fixes). - efi: stmm: Fix incorrect buffer allocation method (git-fixes). - efi: stmm: fix kernel-doc 'bad line' warnings (git-fixes). - exfat: add a check for invalid data size (git-fixes). - exfat: using hweight instead of internal logic (git-fixes). - ext4: use optimized mballoc scanning regardless of inode format (bsc#1254378). - ext4: wait for ongoing I/O to complete before freeing blocks (bsc#1256366). - fbdev: gbefb: fix to use physical address instead of dma address (stable-fixes). - fbdev: pxafb: Fix multiple clamped values in pxafb_adjust_timing (git-fixes). - fbdev: ssd1307fb: fix potential page leak in ssd1307fb_probe() (git-fixes). - fbdev: tcx.c fix mem_map to correct smem_start offset (git-fixes). - firewire: nosy: Fix dma_free_coherent() size (git-fixes). - firmware: imx: scu-irq: Init workqueue before request mbox channel (stable-fixes). - firmware: imx: scu-irq: fix OF node leak in (git-fixes). - firmware: stratix10-svc: Add mutex in stratix10 memory management (git-fixes). - firmware: stratix10-svc: fix bug in saving controller data (git-fixes). - firmware: stratix10-svc: fix make htmldocs warning for stratix10_svc (git-fixes). - fs: dlm: allow to F_SETLKW getting interrupted (bsc#1255025). - ftrace: bpf: Fix IPMODIFY + DIRECT in modify_ftrace_direct() (git-fixes). - genalloc.h: fix htmldocs warning (git-fixes). - gpio: rockchip: mark the GPIO controller as sleeping (git-fixes). - gpu: host1x: Fix race in syncpt alloc/free (git-fixes). - hwmon: (ibmpex) fix use-after-free in high/low store (git-fixes). - hwmon: (max16065) Use local variable to avoid TOCTOU (git-fixes). - hwmon: (tmp401) fix overflow caused by default conversion rate value (git-fixes). - hwmon: (w83791d) Convert macros to functions to avoid TOCTOU (git-fixes). - hwmon: (w83l786ng) Convert macros to functions to avoid TOCTOU (git-fixes). - hwmon: sy7636a: Fix regulator_enable resource leak on error path (git-fixes). - i2c: amd-mp2: fix reference leak in MP2 PCI device (git-fixes). - i2c: designware: Disable SMBus interrupts to prevent storms from mis-configured firmware (stable-fixes). - i2c: i2c.h: fix a bad kernel-doc line (git-fixes). - i3c: fix refcount inconsistency in i3c_master_register (git-fixes). - i3c: master: Inherit DMA masks and parameters from parent device (stable-fixes). - i3c: master: svc: Prevent incomplete IBI transaction (git-fixes). - idr: fix idr_alloc() returning an ID out of range (git-fixes). - iio: accel: bmc150: Fix irq assumption regression (stable-fixes). - iio: accel: fix ADXL355 startup race condition (git-fixes). - iio: adc: ad7280a: fix ad7280_store_balance_timer() (git-fixes). - iio: adc: ti_am335x_adc: Limit step_avg to valid range for gcc complains (stable-fixes). - iio: core: Clean up device correctly on iio_device_alloc() failure (git-fixes). - iio: core: add missing mutex_destroy in iio_dev_release() (git-fixes). - iio: imu: st_lsm6dsx: Fix measurement unit for odr struct member (git-fixes). - iio: imu: st_lsm6dsx: fix array size for st_lsm6dsx_settings fields (git-fixes). - iio: st_lsm6dsx: Fixed calibrated timestamp calculation (git-fixes). - ima: Handle error code returned by ima_filter_rule_match() (git-fixes). - intel_th: Fix error handling in intel_th_output_open (git-fixes). - ipmi: Fix __scan_channels() failing to rescan channels (stable-fixes). - ipmi: Fix handling of messages with provided receive message pointer (git-fixes). - ipmi: Fix the race between __scan_channels() and deliver_response() (stable-fixes). - ipmi: Rework user message limit handling (git-fixes). - irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc() (git-fixes). - kconfig/mconf: Initialize the default locale at startup (stable-fixes). - kconfig/nconf: Initialize the default locale at startup (stable-fixes). - leds: leds-lp50xx: Allow LED 0 to be added to module bank (git-fixes). - leds: leds-lp50xx: Enable chip before any communication (git-fixes). - leds: leds-lp50xx: LP5009 supports 3 modules for a total of 9 LEDs (git-fixes). - leds: netxbig: Fix GPIO descriptor leak in error paths (git-fixes). - lib/vsprintf: Check pointer before dereferencing in time_and_date() (git-fixes). - mailbox: mailbox-test: Fix debugfs_create_dir error checking (git-fixes). - media: TDA1997x: Remove redundant cancel_delayed_work in probe (git-fixes). - media: adv7842: Avoid possible out-of-bounds array accesses in adv7842_cp_log_status() (git-fixes). - media: amphion: Add a frame flush mode for decoder (stable-fixes). - media: amphion: Cancel message work before releasing the VPU core (git-fixes). - media: amphion: Make some vpu_v4l2 functions static (stable-fixes). - media: amphion: Remove vpu_vb_is_codecconfig (git-fixes). - media: atomisp: Prefix firmware paths with 'intel/ipu/' (bsc#1252973). - media: atomisp: Remove firmware_name module parameter (bsc#1252973). - media: cec: Fix debugfs leak on bus_register() failure (git-fixes). - media: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg() (git-fixes). - media: i2c: ADV7604: Remove redundant cancel_delayed_work in probe (git-fixes). - media: i2c: adv7842: Remove redundant cancel_delayed_work in probe (git-fixes). - media: imx-mipi-csis: Drop extra clock enable at probe() (git-fixes). - media: msp3400: Avoid possible out-of-bounds array accesses in msp3400c_thread() (git-fixes). - media: nxp: imx8-isi: Mark all crossbar sink pads as MUST_CONNECT (stable-fixes). - media: ov5640: fix vblank unchange issue when work at dvp mode (git-fixes). - media: pci: ivtv: Don't create fake v4l2_fh (stable-fixes). - media: pvrusb2: Fix incorrect variable used in trace message (git-fixes). - media: qcom: camss: Fix genpd cleanup (git-fixes). - media: qcom: camss: Fix ordering of pm_runtime_enable (git-fixes). - media: qcom: camss: cleanup media device allocated resource on error path (git-fixes). - media: qcom: venus: fix incorrect return value (stable-fixes). - media: radio-isa: use dev_name to fill in bus_info (stable-fixes). - media: rc: st_rc: Fix reset control resource leak (git-fixes). - media: renesas: rcar_drif: fix device node reference leak in rcar_drif_bond_enabled (git-fixes). - media: s5p-mfc: Fix potential deadlock on condlock (stable-fixes). - media: samsung: exynos4-is: fix potential ABBA deadlock on init (git-fixes). - media: uvcvideo: Force UVC version to 1.0a for 0408:4033 (stable-fixes). - media: v4l2-mem2mem: Fix outdated documentation (git-fixes). - media: verisilicon: Fix CPU stalls on G2 bus error (git-fixes). - media: verisilicon: Protect G2 HEVC decoder against invalid DPB index (git-fixes). - media: verisilicon: Store chroma and motion vectors offset (stable-fixes). - media: verisilicon: g2: Use common helpers to compute chroma and mv offsets (stable-fixes). - media: videobuf2: Fix device reference leak in vb2_dc_alloc error path (git-fixes). - media: vidtv: initialize local pointers upon transfer of memory ownership (git-fixes). - media: vpif_capture: fix section mismatch (git-fixes). - media: vpif_display: fix section mismatch (git-fixes). - mei: gsc: add dependency on Xe driver (git-fixes). - mei: me: add wildcat lake P DID (stable-fixes). - mfd: altera-sysmgr: Fix device leak on sysmgr regmap lookup (git-fixes). - mfd: da9055: Fix missing regmap_del_irq_chip() in error path (git-fixes). - mfd: max77620: Fix potential IRQ chip conflict when probing two devices (git-fixes). - mfd: mt6358-irq: Fix missing irq_domain_remove() in error path (git-fixes). - mfd: mt6397-irq: Fix missing irq_domain_remove() in error path (git-fixes). - mmc: sdhci-esdhc-imx: add alternate ARCH_S32 dependency to Kconfig (git-fixes). - mmc: sdhci-msm: Avoid early clock doubling during HS400 transition (stable-fixes). - most: usb: fix double free on late probe failure (git-fixes). - mt76: mt7615: Fix memory leak in mt7615_mcu_wtbl_sta_add() (git-fixes). - mtd: lpddr_cmds: fix signed shifts in lpddr_cmds (git-fixes). - mtd: maps: pcmciamtd: fix potential memory leak in pcmciamtd_detach() (git-fixes). - mtd: nand: relax ECC parameter validation check (git-fixes). - mtd: rawnand: lpc32xx_slc: fix GPIO descriptor leak on probe error and remove (git-fixes). - mtd: rawnand: renesas: Handle devm_pm_runtime_enable() errors (git-fixes). - net: mdio: aspeed: add dummy read to avoid read-after-write issue (git-fixes). - net: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write (git-fixes). - net: phy: adin1100: Fix software power-down ready condition (git-fixes). - net: phy: mxl-gpy: fix bogus error on USXGMII and integrated PHY (git-fixes). - net: phy: mxl-gpy: fix link properties on USXGMII and internal PHYs (git-fixes). - net: r8169: Disable multicast filter for RTL8168H and RTL8107E (jsc#PED-14353). - net: rose: fix invalid array index in rose_kill_by_device() (git-fixes). - net: usb: pegasus: fix memory leak in update_eth_regs_async() (git-fixes). - net: usb: rtl8150: fix memory leak on usb_submit_urb() failure (git-fixes). - net: usb: sr9700: fix incorrect command used to write single register (git-fixes). - net: wwan: iosm: Fix memory leak in ipc_mux_deinit() (git-fixes). - netdevsim: print human readable IP address (bsc#1255071). - nfc: pn533: Fix error code in pn533_acr122_poweron_rdr() (git-fixes). - nfsd: do not defer requests during idmap lookup in v4 compound decode (bsc#1232223). - nfsd: fix return error codes for nfsd_map_name_to_id (bsc#1232223). - nvme: Use non zero KATO for persistent discovery connections (git-fixes). - orangefs: fix xattr related buffer overflow.. (git-fixes). - perf list: Add IBM z17 event descriptions (jsc#PED-13611). - perf/x86/intel: Fix KASAN global-out-of-bounds warning (git-fixes). - phy: broadcom: bcm63xx-usbh: fix section mismatches (git-fixes). - phy: renesas: rcar-gen3-usb2: Fix an error handling path in rcar_gen3_phy_usb2_probe() (git-fixes). - pinctrl: qcom: lpass-lpi: mark the GPIO controller as sleeping (git-fixes). - pinctrl: qcom: msm: Fix deadlock in pinmux configuration (stable-fixes). - pinctrl: single: Fix PIN_CONFIG_BIAS_DISABLE handling (stable-fixes). - pinctrl: single: Fix incorrect type for error return variable (git-fixes). - pinctrl: stm32: fix hwspinlock resource leak in probe function (git-fixes). - platform/chrome: cros_ec_ishtp: Fix UAF after unbinding driver (git-fixes). - platform/mellanox: mlxbf-pmc: Remove trailing whitespaces from event names (git-fixes). - platform/x86/amd/pmc: Add spurious_8042 to Xbox Ally (stable-fixes). - platform/x86/amd: pmc: Add Lenovo Legion Go 2 to pmc quirk list (stable-fixes). - platform/x86/intel/hid: Add Dell Pro Rugged 10/12 tablet to VGBS DMI quirks (stable-fixes). - platform/x86: acer-wmi: Ignore backlight event (stable-fixes). - platform/x86: asus-wmi: use brightness_set_blocking() for kbd led (git-fixes). - platform/x86: hp-bioscfg: Fix out-of-bounds array access in ACPI package parsing (git-fixes). - platform/x86: huawei-wmi: add keys for HONOR models (stable-fixes). - platform/x86: ibm_rtl: fix EBDA signature search pointer arithmetic (git-fixes). - platform/x86: intel: chtwc_int33fe: don't dereference swnode args (git-fixes). - platform/x86: intel: punit_ipc: fix memory corruption (git-fixes). - platform/x86: msi-laptop: add missing sysfs_remove_group() (git-fixes). - power: supply: apm_power: only unset own apm_get_power_status (git-fixes). - power: supply: cw2015: Check devm_delayed_work_autocancel() return code (git-fixes). - power: supply: rt9467: Prevent using uninitialized local variable in rt9467_set_value_from_ranges() (git-fixes). - power: supply: rt9467: Return error on failure in rt9467_set_value_from_ranges() (git-fixes). - power: supply: wm831x: Check wm831x_set_bits() return value (git-fixes). - powerpc/64s/slb: Fix SLB multihit issue during SLB preload (bac#1236022 ltc#211187). - powerpc/eeh: fix recursive pci_lock_rescan_remove locking in EEH event handling (bsc#1253262 ltc#216029). - powerpc/kexec: Enable SMT before waking offline CPUs (bsc#1214285 bsc#1205462 ltc#200161 ltc#200588 git-fixes bsc#1253739 ltc#211493 bsc#1254244 ltc#216496). - pwm: bcm2835: Make sure the channel is enabled after pwm_request() (git-fixes). - r8169: Fix spelling mistake: 'tx_underun' -> 'tx_underrun' (jsc#PED-14353). - r8169: Use PCI_IRQ_INTX instead of PCI_IRQ_LEGACY (jsc#PED-14353). - r8169: add MODULE_FIRMWARE entry for RTL8126A (jsc#PED-14353). - r8169: add PHY c45 ops for MDIO_MMD_VENDOR2 registers (jsc#PED-14353). - r8169: add generic rtl_set_eee_txidle_timer function (jsc#PED-14353). - r8169: add missing MODULE_FIRMWARE entry for RTL8126A rev.b (jsc#PED-14353). - r8169: add support for Intel Killer E5000 (jsc#PED-14353). - r8169: add support for RTL8125BP rev.b (jsc#PED-14353). - r8169: add support for RTL8125D (jsc#PED-14353). - r8169: add support for RTL8125D rev.b (jsc#PED-14353). - r8169: add support for RTL8126A rev.b (jsc#PED-14353). - r8169: add support for RTL8168M (jsc#PED-14353). - r8169: add support for returning tx_lpi_timer in ethtool get_eee (jsc#PED-14353). - r8169: add support for the temperature sensor being available from RTL8125B (jsc#PED-14353). - r8169: adjust version numbering for RTL8126 (jsc#PED-14353). - r8169: align RTL8125 EEE config with vendor driver (jsc#PED-14353). - r8169: align RTL8125/RTL8126 PHY config with vendor driver (jsc#PED-14353). - r8169: align RTL8126 EEE config with vendor driver (jsc#PED-14353). - r8169: align WAKE_PHY handling with r8125/r8126 vendor drivers (jsc#PED-14353). - r8169: avoid duplicated messages if loading firmware fails and switch to warn level (jsc#PED-14353). - r8169: avoid unsolicited interrupts (jsc#PED-14353). - r8169: check for PCI read error in probe (jsc#PED-14353). - r8169: disable ALDPS per default for RTL8125 (jsc#PED-14353). - r8169: disable RTL8126 ZRX-DC timeout (jsc#PED-14353). - r8169: disable interrupt source RxOverflow (jsc#PED-14353). - r8169: don't apply UDP padding quirk on RTL8126A (jsc#PED-14353). - r8169: don't increment tx_dropped in case of NETDEV_TX_BUSY (jsc#PED-14353). - r8169: don't scan PHY addresses > 0 (jsc#PED-14353). - r8169: don't take RTNL lock in rtl_task() (jsc#PED-14353). - r8169: enable EEE at 2.5G per default on RTL8125B (jsc#PED-14353). - r8169: enable RTL8168H/RTL8168EP/RTL8168FP ASPM support (jsc#PED-14353). - r8169: fix RTL8117 Wake-on-Lan in DASH mode (git-fixes). - r8169: fix inconsistent indenting in rtl8169_get_eth_mac_stats (jsc#PED-14353). - r8169: implement additional ethtool stats ops (jsc#PED-14353). - r8169: improve RTL8411b phy-down fixup (jsc#PED-14353). - r8169: improve __rtl8169_set_wol (jsc#PED-14353). - r8169: improve handling task scheduling (jsc#PED-14353). - r8169: improve initialization of RSS registers on RTL8125/RTL8126 (jsc#PED-14353). - r8169: improve rtl_set_d3_pll_down (jsc#PED-14353). - r8169: increase max jumbo packet size on RTL8125/RTL8126 (jsc#PED-14353). - r8169: remove detection of chip version 11 (early RTL8168b) (jsc#PED-14353). - r8169: remove leftover locks after reverted change (jsc#PED-14353). - r8169: remove multicast filter limit (jsc#PED-14353). - r8169: remove not needed check in rtl_fw_write_firmware (jsc#PED-14353). - r8169: remove original workaround for RTL8125 broken rx issue (jsc#PED-14353). - r8169: remove redundant hwmon support (jsc#PED-14353). - r8169: remove rtl_dash_loop_wait_high/low (jsc#PED-14353). - r8169: remove support for chip version 11 (jsc#PED-14353). - r8169: remove unused flag RTL_FLAG_TASK_RESET_NO_QUEUE_WAKE (jsc#PED-14353). - r8169: set EEE speed down ratio to 1 (stable-fixes). - r8169: simplify EEE handling (jsc#PED-14353). - r8169: simplify code by using core-provided pcpu stats allocation (jsc#PED-14353). - r8169: support setting the EEE tx idle timer on RTL8168h (jsc#PED-14353). - r8169: use dev_err_probe in all appropriate places in rtl_init_one() (jsc#PED-14353). - r8169: use helper r8169_mod_reg8_cond to simplify rtl_jumbo_config (jsc#PED-14353). - regulator: core: Protect regulator_supply_alias_list with regulator_list_mutex (git-fixes). - regulator: core: disable supply if enabling main regulator fails (git-fixes). - reset: fix BIT macro reference (stable-fixes). - rpmsg: glink: fix rpmsg device leak (git-fixes). - rtc: gamecube: Check the return value of ioremap() (git-fixes). - scsi: lpfc: Add capability to register Platform Name ID to fabric (bsc#1254119). - scsi: lpfc: Allow support for BB credit recovery in point-to-point topology (bsc#1254119). - scsi: lpfc: Ensure unregistration of rpis for received PLOGIs (bsc#1254119). - scsi: lpfc: Fix leaked ndlp krefs when in point-to-point topology (bsc#1254119). - scsi: lpfc: Fix reusing an ndlp that is marked NLP_DROPPED during FLOGI (bsc#1254119). - scsi: lpfc: Modify kref handling for Fabric Controller ndlps (bsc#1254119). - scsi: lpfc: Remove redundant NULL ptr assignment in lpfc_els_free_iocb() (bsc#1254119). - scsi: lpfc: Revise discovery related function headers and comments (bsc#1254119). - scsi: lpfc: Update lpfc version to 14.4.0.12 (bsc#1254119). - scsi: lpfc: Update various NPIV diagnostic log messaging (bsc#1254119). - scsi: mpi3mr: Fix I/O failures during controller reset (bsc#1251752 jsc#PED-14280). - scsi: mpi3mr: Fix controller init failure on fault during queue creation (bsc#1251752 jsc#PED-14280). - scsi: mpi3mr: Fix device loss during enclosure reboot due to zero link speed (bsc#1251752 jsc#PED-14280). - scsi: mpi3mr: Fix premature TM timeouts on virtual drives (bsc#1251752 jsc#PED-14280). - scsi: mpi3mr: Update MPI headers to revision 37 (bsc#1251752 jsc#PED-14280). - scsi: mpi3mr: Update driver version to 8.14.0.5.50 (bsc#1251752 jsc#PED-14280). - scsi: mpi3mr: Update driver version to 8.15.0.5.50 (bsc#1251752 jsc#PED-14280). - selftests/bpf: Skip timer cases when bpf_timer is not supported (git-fixes). - selftests/net: calibrate txtimestamp (bsc#1255085). - selftests/net: convert fcnal-test.sh to run it in unique namespace (bsc#1254235). - selftests/net: convert fib-onlink-tests.sh to run it in unique namespace (bsc#1254235). - selftests/net: convert fib_nexthop_multiprefix to run it in unique namespace (bsc#1254235). - selftests/net: convert fib_nexthop_nongw.sh to run it in unique namespace (bsc#1254235). - selftests/net: convert fib_nexthops.sh to run it in unique namespace (bsc#1254235). - selftests/net: convert fib_rule_tests.sh to run it in unique namespace (bsc#1254235). - selftests/net: convert fib_tests.sh to run it in unique namespace (bsc#1254235). - selftests/net: convert srv6_end_dt46_l3vpn_test.sh to run it in unique namespace (bsc#1254235). - selftests/net: convert srv6_end_dt4_l3vpn_test.sh to run it in unique namespace (bsc#1254235). - selftests/net: convert srv6_end_dt6_l3vpn_test.sh to run it in unique namespace (bsc#1254235). - selftests/net: convert test_vxlan_vnifiltering.sh to run it in unique namespace (bsc#1255349). - selftests/net: convert vrf_route_leaking.sh to run it in unique namespace (bsc#1255349). - selftests/net: synchronize udpgro tests' tx and rx connection (bsc#1254235). - selftests: Introduce Makefile variable to list shared bash scripts (bsc#1254235). - selftests: bonding: Add net/forwarding/lib.sh to TEST_INCLUDES (bsc#1254235). - selftests: dsa: Replace test symlinks by wrapper script (bsc#1254235). - selftests: net: Remove executable bits from library scripts (bsc#1254235). - selftests: net: explicitly wait for listener ready (bsc#1254235). - selftests: net: fib-onlink-tests: Set high metric for default IPv6 route (bsc#1255346). - selftests: net: include forwarding lib (bsc#1254235). - selftests: net: included needed helper in the install targets (bsc#1254235). - selftests: net: more strict check in net_helper (bsc#1254235). - selftests: net: use slowwait to make sure IPv6 setup finished (bsc#1255349). - selftests: net: use slowwait to stabilize vrf_route_leaking test (bsc#1255349). - selftests: net: veth: test the ability to independently manipulate GRO and XDP (bsc#1255101). - selftests: team: Add shared library scripts to TEST_INCLUDES (bsc#1254235). - selftests: vrf_route_leaking: remove ipv6_ping_frag from default testing (bsc#1255349). - serial: add support of CPCI cards (stable-fixes). - serial: amba-pl011: prefer dma_mapping_error() over explicit address checking (git-fixes). - serial: core: Fix serial device initialization (git-fixes). - serial: core: Restore sysfs fwnode information (git-fixes). - serial: sprd: Return -EPROBE_DEFER when uart clock is not ready (stable-fixes). - slimbus: ngd: Fix reference count leak in qcom_slim_ngd_notify_slaves (git-fixes). - smc91x: fix broken irq-context in PREEMPT_RT (git-fixes). - soc/tegra: fuse: speedo-tegra210: Update speedo IDs (git-fixes). - soc: amlogic: canvas: fix device leak on lookup (git-fixes). - soc: qcom: ocmem: fix device leak on lookup (git-fixes). - soc: qcom: smem: fix hwspinlock resource leak in probe error paths (git-fixes). - spi: amlogic-spifc-a1: Handle devm_pm_runtime_enable() errors (git-fixes). - spi: bcm63xx: drop wrong casts in probe() (git-fixes). - spi: bcm63xx: fix premature CS deassertion on RX-only transactions (git-fixes). - spi: fsl-cpm: Check length parity before switching to 16 bit mode (git-fixes). - spi: imx: keep dma request disabled before dma transfer setup (stable-fixes). - spi: tegra210-qspi: Remove cache operations (git-fixes). - spi: tegra210-quad: Add support for internal DMA (git-fixes). - spi: tegra210-quad: Check hardware status on timeout (bsc#1253155). - spi: tegra210-quad: Fix timeout handling (bsc#1253155). - spi: tegra210-quad: Fix timeout handling (git-fixes). - spi: tegra210-quad: Refactor error handling into helper functions (bsc#1253155). - spi: tegra210-quad: Update dummy sequence configuration (git-fixes). - spi: xilinx: increase number of retries before declaring stall (stable-fixes). - staging: fbtft: core: fix potential memory leak in fbtft_probe_common() (git-fixes). - staging: rtl8723bs: fix out-of-bounds read in OnBeacon ESR IE parsing (stable-fixes). - staging: rtl8723bs: fix out-of-bounds read in rtw_get_ie() parser (stable-fixes). - thunderbolt: Add support for Intel Wildcat Lake (stable-fixes). - tick/sched: Limit non-timekeeper CPUs calling jiffies update (bsc#1254477). - tracing: Fix access to trace_event_file (bsc#1254373). - uio: uio_fsl_elbc_gpcm:: Add null pointer check to uio_fsl_elbc_gpcm_probe (git-fixes). - usb: cdns3: Fix double resource release in cdns3_pci_probe (git-fixes). - usb: chaoskey: fix locking for O_NONBLOCK (git-fixes). - usb: chipidea: udc: limit usb request length to max 16KB (stable-fixes). - usb: dwc2: disable platform lowlevel hw resources during shutdown (stable-fixes). - usb: dwc2: fix hang during shutdown if set as peripheral (git-fixes). - usb: dwc2: fix hang during suspend if set as peripheral (git-fixes). - usb: dwc3: Abort suspend on soft disconnect failure (git-fixes). - usb: dwc3: Fix race condition between concurrent dwc3_remove_requests() call paths (git-fixes). - usb: dwc3: keep susphy enabled during exit to avoid controller faults (git-fixes). - usb: dwc3: of-simple: fix clock resource leak in dwc3_of_simple_probe (git-fixes). - usb: dwc3: pci: Sort out the Intel device IDs (stable-fixes). - usb: dwc3: pci: add support for the Intel Nova Lake -S (stable-fixes). - usb: gadget: configfs: Correctly set use_os_string at bind (git-fixes). - usb: gadget: f_eem: Fix memory leak in eem_unwrap (git-fixes). - usb: gadget: lpc32xx_udc: fix clock imbalance in error path (git-fixes). - usb: gadget: renesas_usbf: Handle devm_pm_runtime_enable() errors (git-fixes). - usb: gadget: tegra-xudc: Always reinitialize data toggle when clear halt (git-fixes). - usb: ohci-nxp: Use helper function devm_clk_get_enabled() (stable-fixes). - usb: ohci-nxp: fix device leak on probe failure (git-fixes). - usb: phy: Initialize struct usb_phy list_head (git-fixes). - usb: phy: isp1301: fix non-OF device reference imbalance (git-fixes). - usb: raw-gadget: cap raw_io transfer length to KMALLOC_MAX_SIZE (git-fixes). - usb: raw-gadget: do not limit transfer length (git-fixes). - usb: renesas_usbhs: Fix a resource leak in usbhs_pipe_malloc() (git-fixes). - usb: storage: Fix memory leak in USB bulk transport (git-fixes). - usb: storage: sddr55: Reject out-of-bound new_pba (stable-fixes). - usb: typec: tipd: Clear interrupts first (git-fixes). - usb: typec: ucsi: Handle incorrect num_connectors capability (stable-fixes). - usb: typec: ucsi: psy: Set max current to zero when disconnected (git-fixes). - usb: uas: fix urb unmapping issue when the uas device is remove during ongoing data transfer (git-fixes). - usb: udc: Add trace event for usb_gadget_set_state (stable-fixes). - usb: usb-storage: Maintain minimal modifications to the bcdDevice range (git-fixes). - usb: usb-storage: No additional quirks need to be added to the EL-R12 optical drive (stable-fixes). - usb: vhci-hcd: Prevent suspending virtually attached devices (git-fixes). - usb: xhci: limit run_graceperiod for only usb 3.0 devices (stable-fixes). - usbip: Fix locking bug in RT-enabled kernels (stable-fixes). - via_wdt: fix critical boot hang due to unnamed resource allocation (stable-fixes). - virtio_console: fix order of fields cols and rows (stable-fixes). - watchdog: wdat_wdt: Fix ACPI table leak in probe function (git-fixes). - wifi: ath10k: Add missing include of export.h (stable-fixes). - wifi: ath10k: Avoid vdev delete timeout when firmware is already down (stable-fixes). - wifi: ath10k: move recovery check logic into a new work (git-fixes). - wifi: ath11k: fix peer HE MCS assignment (git-fixes). - wifi: ath11k: restore register window after global reset (git-fixes). - wifi: ath12k: fix potential memory leak in ath12k_wow_arp_ns_offload() (git-fixes). - wifi: avoid kernel-infoleak from struct iw_point (git-fixes). - wifi: brcmfmac: Add DMI nvram filename quirk for Acer A1 840 tablet (stable-fixes). - wifi: cfg80211: sme: store capped length in __cfg80211_connect_result() (git-fixes). - wifi: cfg80211: stop radar detection in cfg80211_leave() (stable-fixes). - wifi: cfg80211: use cfg80211_leave() in iftype change (stable-fixes). - wifi: cw1200: Fix potential memory leak in cw1200_bh_rx_helper() (git-fixes). - wifi: ieee80211: correct FILS status codes (git-fixes). - wifi: mac80211: do not use old MBSSID elements (git-fixes). - wifi: mac80211: fix CMAC functions not handling errors (git-fixes). - wifi: mac80211: restore non-chanctx injection behaviour (git-fixes). - wifi: mt76: Fix DTS power-limits on little endian systems (git-fixes). - wifi: mt76: mt7925: fix CLC command timeout when suspend/resume (stable-fixes). - wifi: mt76: mt7925: fix the unfinished command of regd_notifier before suspend (stable-fixes). - wifi: mt76: mt792x: fix wifi init fail by setting MCU_RUNNING after CLC load (stable-fixes). - wifi: nl80211: vendor-cmd: intel: fix a blank kernel-doc line warning (git-fixes). - wifi: rtl818x: Fix potential memory leaks in rtl8180_init_rx_ring() (git-fixes). - wifi: rtl818x: rtl8187: Fix potential buffer underflow in rtl8187_rx_cb() (git-fixes). - wifi: rtlwifi: 8192cu: fix tid out of range in rtl92cu_tx_fill_desc() (git-fixes). - wifi: rtw88: Add USB ID 2001:3329 for D-Link AC13U rev. A1 (stable-fixes). - wifi: rtw88: limit indirect IO under powered off for RTL8822CS (git-fixes). - x86/hyperv: Fix APIC ID and VP index confusion in hv_snp_boot_ap() (git-fixes). - x86/microcode/AMD: Add TSA microcode SHAs (bsc#1256528). - x86/microcode/AMD: Add Zen5 model 0x44, stepping 0x1 minrev (bsc#1256528). - x86/microcode/AMD: Add more known models to entry sign checking (bsc#1256528). - x86/microcode/AMD: Add some forgotten models to the SHA check (bsc#1256528). - x86/microcode/AMD: Clean the cache if update did not load microcode (bsc#1256528). - x86/microcode/AMD: Extend the SHA check to Zen5, block loading of any unreleased standalone Zen5 microcode patches (bsc#1256528). - x86/microcode/AMD: Fix Entrysign revision check for Zen5/Strix Halo (bsc#1256528). - x86/microcode/AMD: Fix __apply_microcode_amd()'s return value (bsc#1256528). - x86/microcode/AMD: Limit Entrysign signature checking to known generations (bsc#1256528). - x86/microcode/AMD: Load only SHA256-checksummed patches (bsc#1256528). - x86/microcode/AMD: Select which microcode patch to load (bsc#1256528). - x86/microcode/AMD: Use sha256() instead of init/update/final (bsc#1256528). - x86/microcode: Fix Entrysign revision check for Zen1/Naples (bsc#1256528). - xhci: dbgtty: fix device unregister (git-fixes). - xhci: fix stale flag preventig URBs after link state error is cleared (git-fixes). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:364-1 Released: Tue Feb 3 10:50:53 2026 Summary: Security update for libpng16 Type: security Severity: moderate References: 1257364,1257365,CVE-2025-28162,CVE-2025-28164 This update for libpng16 fixes the following issues: - CVE-2025-28162: memory leaks when running `pngimage` (bsc#1257364). - CVE-2025-28164: memory leaks when running `pngimage` (bsc#1257365). - CVE-2026-22695: Fixed heap buffer over-read in png_image_finish_read (bsc#1256525). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:371-1 Released: Tue Feb 3 19:08:49 2026 Summary: Security update for glibc Type: security Severity: important References: 1256437,1256766,1256822,1257005,CVE-2025-15281,CVE-2026-0861,CVE-2026-0915 This update for glibc fixes the following issues: Security fixes: - CVE-2026-0861: Fixed inadequate size check in the memalign suite may result in an integer overflow (bsc#1256766). - CVE-2026-0915: Fixed uninitialized stack buffer used as DNS query name when net==0 in _nss_dns_getnetbyaddr_r (bsc#1256822). - CVE-2025-15281: Fixed uninitialized memory may cause the process abort (bsc#1257005). Other fixes: - NPTL: Optimize trylock for high cache contention workloads (bsc#1256437). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:373-1 Released: Wed Feb 4 03:50:41 2026 Summary: Security update for glib2 Type: security Severity: important References: 1257353,1257354,1257355,CVE-2026-1484,CVE-2026-1485,CVE-2026-1489 This update for glib2 fixes the following issues: - CVE-2026-1485: Fixed buffer underflow and out-of-bounds access due to integer wraparound in content type parsing (bsc#1257354). - CVE-2026-1484: Fixed buffer underflow and out-of-bounds access due to miscalculated buffer boundaries in the Base64 encoding routine (bsc#1257355). - CVE-2026-1489: Fixed undersized heap allocation followed by out-of-bounds access due to integer overflow in Unicode case conversion (bsc#1257353). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:407-1 Released: Mon Feb 9 07:43:45 2026 Summary: Recommended update for systemd Type: recommended Severity: important References: 1228081,1244449,1248356,1254202,1254293,1254563,1256427 This update for systemd fixes the following issues: - Name libsystemd-{shared,core} based on the major version of systemd and the package release number (bsc#1228081, bsc#1256427) This way, both the old and new versions of the shared libraries will be present during the update. This should prevent issues during package updates when incompatible changes are introduced in the new versions of the shared libraries. - detect-virt: bare-metal GCE only for x86 and i386 (bsc#1254293) - timer: rebase last_trigger timestamp if needed - timer: rebase the next elapse timestamp only if timer didn't already run - timer: don't run service immediately after restart of a timer (bsc#1254563) - test: check the next elapse timer timestamp after deserialization - test: restarting elapsed timer shouldn't trigger the corresponding service - Reintroduce systemd-network as a transitional dummy package containing no files (bsc#1254202) The contents of this package were split into two independent packages: systemd-networkd and systemd-resolved. However, the initial replacement caused both network services to be disabled. Consequently, the original package has been restored as an empty transitional package to prevent the disabling of the services. It can be safely removed once the update is complete. - units: don't force the loading of the loop and dm_mod modules in systemd-repart.service (bsc#1248356) - units: add dep on systemd-logind.service by user at .service - detect-virt: add bare-metal support for GCE (bsc#1244449) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:408-1 Released: Mon Feb 9 15:12:51 2026 Summary: Recommended update for multipath-tools Type: recommended Severity: important References: 1254094,1255285,1257007,1257153,1257244,1257476 This update for multipath-tools fixes the following issues: - Update to version 0.10.6+201+suse.9f189e79: * libmultipath: reduce log level of 'map X has no targets' (bsc#1257476) - Update to version 0.10.6+200+suse.547788f4 (bsc#1257007): * kpartx: fix segfault when operating on regular files (bsc#1257244, bsc#1257153) * multipathd: print path offline message even without a checker (bsc#1254094) * Fix command descriptions in the multipathd man page. * Fix ISO C23 compatibility issue causing errors with new compilers. * Fix memory leak caused by not joining the 'init unwinder' thread. * Fix memory leaks in kpartx. * Print the warning 'setting scsi timeouts is unsupported for protocol' only once per protocol. * Make sure multipath-tools is compiled with the compiler flag `-fno-strict-aliasing` (bsc#1255285). - Update to version 0.10.5+213+suse.04c3a0ac: * Log offline path state if 'log_checker_err always' is set (bsc#1254094) * mpathpersist: Fix REPORT CAPABILITIES output ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:432-1 Released: Wed Feb 11 10:11:56 2026 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1248586,1254670,CVE-2025-7709 This update for sqlite3 fixes the following issues: - Update to v3.51.2: - CVE-2025-7709: Fixed an integer overflow in the FTS5 extension. (bsc#1254670) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:434-1 Released: Wed Feb 11 10:23:18 2026 Summary: Security update for gpg2 Type: security Severity: important References: 1256389,1257396,CVE-2026-24882 This update for gpg2 fixes the following issues: Security fixes: - CVE-2026-24882: Fixed stack-based buffer overflow in TPM2 PKDECRYPT for TPM-backed RSA and ECC keys (bsc#1257396) - Fixed GnuPG accepting Path Separators and Path Traversals in Literal Data 'Filename' Field (bsc#1256389) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:447-1 Released: Wed Feb 11 15:04:47 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1205462,1214285,1215199,1223800,1228490,1233563,1234842,1235566,1241437,1242505,1242909,1243662,1243677,1243678,1245538,1246022,1246184,1246447,1247030,1247712,1248211,1249307,1249904,1250032,1250082,1250388,1250705,1250748,1252511,1252712,1252891,1252900,1253087,1253330,1253340,1253348,1253433,1253443,1253451,1253471,1253739,1254244,1254447,1254465,1254510,1254624,1254767,1254835,1254839,1254842,1254845,1254852,1254871,1255102,1255120,1255128,1255138,1255140,1255157,1255164,1255172,1255216,1255226,1255241,1255255,1255260,1255261,1255266,1255268,1255269,1255327,1255346,1255377,1255401,1255403,1255417,1255482,1255488,1255537,1255539,1255544,1255547,1255548,1255552,1255568,1255569,1255615,1255622,1255695,1255930,1256280,1256528,1256568,1256579,1256582,1256584,1256586,1256591,1256592,1256593,1256594,1256597,1256605,1256606,1256607,1256608,1256609,1256610,1256611,1256612,1256613,1256616,1256617,1256619,1256622,1256623,1256625,1256627,1256628,1256630,1256638,1256641,1256645,1 256646,1256650,1256651,1256653,1256654,1256655,1256659,1256660,1256661,1256664,1256665,1256674,1256680,1256682,1256688,1256689,1256690,1256726,1256728,1256730,1256733,1256737,1256741,1256742,1256744,1256748,1256749,1256752,1256754,1256756,1256757,1256759,1256760,1256761,1256763,1256770,1256773,1256774,1256777,1256779,1256781,1256785,1256792,1256794,1256861,1256863,1257035,1257053,1257154,1257155,1257158,1257163,1257164,1257167,1257168,1257180,1257202,1257204,1257207,1257208,1257215,1257217,1257218,1257220,1257221,1257227,1257232,1257234,1257236,1257245,1257277,1257282,1257296,1257473,1257603,CVE-2023-53714,CVE-2023-54013,CVE-2024-27005,CVE-2024-42103,CVE-2024-53070,CVE-2024-53149,CVE-2024-56721,CVE-2025-22047,CVE-2025-37744,CVE-2025-37751,CVE-2025-37813,CVE-2025-38209,CVE-2025-38243,CVE-2025-38322,CVE-2025-38379,CVE-2025-38539,CVE-2025-39689,CVE-2025-39813,CVE-2025-39829,CVE-2025-39836,CVE-2025-39880,CVE-2025-39913,CVE-2025-40097,CVE-2025-40106,CVE-2025-40132,CVE-2025-40136,CVE-2025 -40142,CVE-2025-40166,CVE-2025-40177,CVE-2025-40181,CVE-2025-40202,CVE-2025-40238,CVE-2025-40254,CVE-2025-40257,CVE-2025-40259,CVE-2025-40261,CVE-2025-40264,CVE-2025-40328,CVE-2025-40350,CVE-2025-40355,CVE-2025-40363,CVE-2025-68171,CVE-2025-68174,CVE-2025-68178,CVE-2025-68188,CVE-2025-68200,CVE-2025-68215,CVE-2025-68227,CVE-2025-68241,CVE-2025-68245,CVE-2025-68254,CVE-2025-68256,CVE-2025-68261,CVE-2025-68284,CVE-2025-68285,CVE-2025-68296,CVE-2025-68297,CVE-2025-68301,CVE-2025-68320,CVE-2025-68325,CVE-2025-68327,CVE-2025-68337,CVE-2025-68349,CVE-2025-68363,CVE-2025-68365,CVE-2025-68366,CVE-2025-68367,CVE-2025-68372,CVE-2025-68379,CVE-2025-68725,CVE-2025-68727,CVE-2025-68728,CVE-2025-68733,CVE-2025-68764,CVE-2025-68768,CVE-2025-68770,CVE-2025-68771,CVE-2025-68773,CVE-2025-68775,CVE-2025-68776,CVE-2025-68777,CVE-2025-68783,CVE-2025-68788,CVE-2025-68789,CVE-2025-68795,CVE-2025-68797,CVE-2025-68798,CVE-2025-68800,CVE-2025-68801,CVE-2025-68802,CVE-2025-68803,CVE-2025-68804,CVE-2025-68808, CVE-2025-68813,CVE-2025-68814,CVE-2025-68815,CVE-2025-68816,CVE-2025-68819,CVE-2025-68820,CVE-2025-71064,CVE-2025-71066,CVE-2025-71076,CVE-2025-71077,CVE-2025-71078,CVE-2025-71079,CVE-2025-71080,CVE-2025-71081,CVE-2025-71082,CVE-2025-71083,CVE-2025-71084,CVE-2025-71085,CVE-2025-71086,CVE-2025-71087,CVE-2025-71088,CVE-2025-71089,CVE-2025-71091,CVE-2025-71093,CVE-2025-71094,CVE-2025-71095,CVE-2025-71096,CVE-2025-71097,CVE-2025-71098,CVE-2025-71099,CVE-2025-71100,CVE-2025-71101,CVE-2025-71108,CVE-2025-71111,CVE-2025-71112,CVE-2025-71114,CVE-2025-71116,CVE-2025-71118,CVE-2025-71119,CVE-2025-71120,CVE-2025-71123,CVE-2025-71130,CVE-2025-71131,CVE-2025-71132,CVE-2025-71133,CVE-2025-71135,CVE-2025-71136,CVE-2025-71137,CVE-2025-71138,CVE-2025-71141,CVE-2025-71142,CVE-2025-71143,CVE-2025-71145,CVE-2025-71147,CVE-2025-71149,CVE-2025-71154,CVE-2025-71156,CVE-2025-71157,CVE-2025-71162,CVE-2025-71163,CVE-2026-22976,CVE-2026-22977,CVE-2026-22978,CVE-2026-22984,CVE-2026-22985,CVE-2026-22988,CVE-202 6-22990,CVE-2026-22991,CVE-2026-22992,CVE-2026-22993,CVE-2026-22996,CVE-2026-22997,CVE-2026-22999,CVE-2026-23000,CVE-2026-23001,CVE-2026-23005,CVE-2026-23006,CVE-2026-23011 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2023-54013: interconnect: Fix locking for runpm vs reclaim (bsc#1256280). - CVE-2025-39880: libceph: fix invalid accesses to ceph_connection_v1_info (bsc#1250388). - CVE-2025-40238: net/mlx5: Fix IPsec cleanup over MPV device (bsc#1254871). - CVE-2025-40254: net: openvswitch: remove never-working support for setting nsh fields (bsc#1254852). - CVE-2025-40257: mptcp: fix a race in mptcp_pm_del_add_timer() (bsc#1254842). - CVE-2025-40259: scsi: sg: Do not sleep in atomic context (bsc#1254845). - CVE-2025-40261: nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() (bsc#1254839). - CVE-2025-40264: be2net: pass wrb_params in case of OS2BMC (bsc#1254835). - CVE-2025-40328: smb: client: fix potential UAF in smb2_close_cached_fid() (bsc#1254624). - CVE-2025-40350: net/mlx5e: RX, Fix generating skb from non-linear xdp_buff for striding RQ (bsc#1255260). - CVE-2025-40355: sysfs: check visibility before changing group attribute ownership (bsc#1255261). - CVE-2025-40363: net: ipv6: fix field-spanning memcpy warning in AH output (bsc#1255102). - CVE-2025-68171: x86/fpu: Ensure XFD state on signal delivery (bsc#1255255). - CVE-2025-68174: amd/amdkfd: enhance kfd process check in switch partition (bsc#1255327). - CVE-2025-68178: blk-cgroup: fix possible deadlock while configuring policy (bsc#1255266). - CVE-2025-68188: tcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check() (bsc#1255269). - CVE-2025-68200: bpf: Add bpf_prog_run_data_pointers() (bsc#1255241). - CVE-2025-68215: ice: fix PTP cleanup on driver removal in error path (bsc#1255226). - CVE-2025-68227: mptcp: Fix proto fallback detection with BPF (bsc#1255216). - CVE-2025-68241: ipv4: route: Prevent rt_bind_exception() from rebinding stale fnhe (bsc#1255157). - CVE-2025-68245: net: netpoll: fix incorrect refcount handling causing incorrect cleanup (bsc#1255268). - CVE-2025-68261: ext4: add i_data_sem protection in ext4_destroy_inline_data_nolock() (bsc#1255164). - CVE-2025-68284: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() (bsc#1255377). - CVE-2025-68285: libceph: fix potential use-after-free in have_mon_and_osd_map() (bsc#1255401). - CVE-2025-68296: drm, fbcon, vga_switcheroo: Avoid race condition in fbcon setup (bsc#1255128). - CVE-2025-68297: ceph: fix crash in process_v2_sparse_read() for encrypted directories (bsc#1255403). - CVE-2025-68301: net: atlantic: fix fragment overflow handling in RX path (bsc#1255120). - CVE-2025-68320: lan966x: Fix sleeping in atomic context (bsc#1255172). - CVE-2025-68325: net/sched: sch_cake: Fix incorrect qlen reduction in cake_drop (bsc#1255417). - CVE-2025-68327: usb: renesas_usbhs: Fix synchronous external abort on unbind (bsc#1255488). - CVE-2025-68337: jbd2: avoid bug_on in jbd2_journal_get_create_access() when file system corrupted (bsc#1255482). - CVE-2025-68349: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid (bsc#1255544). - CVE-2025-68363: bpf: Check skb->transport_header is set in bpf_skb_check_mtu (bsc#1255552). - CVE-2025-68365: fs/ntfs3: Initialize allocated memory before use (bsc#1255548). - CVE-2025-68366: nbd: defer config unlock in nbd_genl_connect (bsc#1255622). - CVE-2025-68367: macintosh/mac_hid: fix race condition in mac_hid_toggle_emumouse (bsc#1255547). - CVE-2025-68372: nbd: defer config put in recv_work (bsc#1255537). - CVE-2025-68379: RDMA/rxe: Fix null deref on srq->rq.queue after resize failure (bsc#1255695). - CVE-2025-68727: ntfs3: Fix uninit buffer allocated by __getname() (bsc#1255568). - CVE-2025-68728: ntfs3: fix uninit memory after failed mi_read in mi_format_new (bsc#1255539). - CVE-2025-68733: smack: fix bug: unprivileged task can create labels (bsc#1255615). - CVE-2025-68764: NFS: Automounted filesystems should inherit ro,noexec,nodev,sync flags (bsc#1255930). - CVE-2025-68768: inet: frags: add inet_frag_queue_flush() (bsc#1256579). - CVE-2025-68770: bnxt_en: Fix XDP_TX path (bsc#1256584). - CVE-2025-68771: ocfs2: fix kernel BUG in ocfs2_find_victim_chain (bsc#1256582). - CVE-2025-68775: net/handshake: duplicate handshake cancellations leak socket (bsc#1256665). - CVE-2025-68776: net/hsr: fix NULL pointer dereference in prp_get_untagged_frame() (bsc#1256659). - CVE-2025-68788: fsnotify: do not generate ACCESS/MODIFY events on child for special files (bsc#1256638). - CVE-2025-68795: ethtool: Avoid overflowing userspace buffer on stats query (bsc#1256688). - CVE-2025-68798: perf/x86/amd: Check event before enable to avoid GPF (bsc#1256689). - CVE-2025-68800: mlxsw: spectrum_mr: Fix use-after-free when updating multicast route stats (bsc#1256646). - CVE-2025-68801: mlxsw: spectrum_router: Fix neighbour use-after-free (bsc#1256653). - CVE-2025-68803: nfsd: set security label during create operations (bsc#1256770). - CVE-2025-68813: ipvs: fix ipv4 null-ptr-deref in route error path (bsc#1256641). - CVE-2025-68814: io_uring: fix filename leak in __io_openat_prep() (bsc#1256651). - CVE-2025-68815: net/sched: ets: Remove drr class from the active list if it changes to strict (bsc#1256680). - CVE-2025-68816: net/mlx5: fw_tracer, Validate format string parameters (bsc#1256674). - CVE-2025-68820: ext4: xattr: fix null pointer deref in ext4_raw_inode() (bsc#1256754). - CVE-2025-71064: net: hns3: using the num_tqps in the vf driver to apply for resources (bsc#1256654). - CVE-2025-71066: net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change (bsc#1256645). - CVE-2025-71077: tpm: Cap the number of PCR banks (bsc#1256613). - CVE-2025-71080: ipv6: fix a BUG in rt6_get_pcpu_route() under PREEMPT_RT (bsc#1256608). - CVE-2025-71084: RDMA/cm: Fix leaking the multicast GID table reference (bsc#1256622). - CVE-2025-71085: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (bsc#1256623). - CVE-2025-71087: iavf: fix off-by-one issues in iavf_config_rss_reg() (bsc#1256628). - CVE-2025-71088: mptcp: fallback earlier on simult connection (bsc#1256630). - CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256612). - CVE-2025-71091: team: fix check for port enabled in team_queue_override_port_prio_changed() (bsc#1256773). - CVE-2025-71093: e1000: fix OOB in e1000_tbi_should_accept() (bsc#1256777). - CVE-2025-71094: net: usb: asix: ax88772: Increase phy_name size (bsc#1256597). - CVE-2025-71095: net: stmmac: fix the crash issue for zero copy XDP_TX action (bsc#1256605). - CVE-2025-71096: RDMA/core: Check for the presence of LS_NLA_TYPE_DGID correctly (bsc#1256606). - CVE-2025-71097: ipv4: Fix reference count leak when using error routes with nexthop objects (bsc#1256607). - CVE-2025-71098: ip6_gre: make ip6gre_header() robust (bsc#1256591). - CVE-2025-71112: net: hns3: add VLAN id validation before using (bsc#1256726). - CVE-2025-71116: libceph: make decode_pool() more resilient against corrupted osdmaps (bsc#1256744). - CVE-2025-71120: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf (bsc#1256779). - CVE-2025-71123: ext4: fix string copying in parse_apply_sb_mount_options() (bsc#1256757). - CVE-2025-71133: RDMA/irdma: avoid invalid read in irdma_net_event (bsc#1256733). - CVE-2025-71135: md/raid5: fix possible null-pointer dereferences in raid5_store_group_thread_cnt() (bsc#1256761). - CVE-2025-71137: octeontx2-pf: fix 'UBSAN: shift-out-of-bounds error' (bsc#1256760). - CVE-2025-71149: io_uring/poll: correctly handle io_poll_add() return value on update (bsc#1257164). - CVE-2025-71156: gve: defer interrupt enabling until NAPI registration (bsc#1257167). - CVE-2025-71157: RDMA/core: always drop device refcount in ib_del_sub_device_and_put() (bsc#1257168). - CVE-2026-22976: net/sched: sch_qfq: Fix NULL deref when deactivating inactive aggregate in qfq_reset (bsc#1257035). - CVE-2026-22977: net: sock: fix hardened usercopy panic in sock_recv_errqueue (bsc#1257053). - CVE-2026-22984: libceph: prevent potential out-of-bounds reads in handle_auth_done() (bsc#1257217). - CVE-2026-22990: libceph: replace overzealous BUG_ON in osdmap_apply_incremental() (bsc#1257221). - CVE-2026-22991: libceph: make free_choose_arg_map() resilient to partial allocation (bsc#1257220). - CVE-2026-22992: libceph: return the handler error from mon_handle_auth_done() (bsc#1257218). - CVE-2026-22993: idpf: Fix RSS LUT NULL pointer crash on early ethtool operations (bsc#1257180). - CVE-2026-22996: net/mlx5e: Don't store mlx5e_priv in mlx5e_dev devlink priv. - CVE-2026-22999: net/sched: sch_qfq: do not free existing class in qfq_change_class() (bsc#1257236). - CVE-2026-23000: net/mlx5e: Fix crash on profile change rollback failure (bsc#1257234). - CVE-2026-23001: macvlan: fix possible UAF in macvlan_forward_source() (bsc#1257232). - CVE-2026-23005: x86/fpu: Clear XSTATE_BV in guest XSAVE state whenever XFD[i]=1 (bsc#1257245). - CVE-2026-23011: ipv4: ip_gre: make ipgre_header() robust (bsc#1257207). The following non security issues were fixed: - ALSA: ctxfi: Fix potential OOB access in audio mixer handling (stable-fixes). - ALSA: scarlett2: Fix buffer overflow in config retrieval (git-fixes). - ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free() (git-fixes). - ALSA: usb-audio: Update for native DSD support quirks (stable-fixes). - ALSA: usb: Increase volume range that triggers a warning (git-fixes). - ASoC: amd: yc: Add quirk for Honor MagicBook X16 2025 (stable-fixes). - ASoC: codecs: wsa881x: Drop unused version readout (stable-fixes). - ASoC: codecs: wsa881x: fix unnecessary initialisation (git-fixes). - ASoC: codecs: wsa883x: fix unnecessary initialisation (git-fixes). - ASoC: codecs: wsa884x: fix codec initialisation (git-fixes). - ASoC: fsl_sai: Add missing registers to cache default (stable-fixes). - ASoC: fsl: imx-card: Do not force slot width to sample width (git-fixes). - ASoC: Intel: sof_es8336: fix headphone GPIO logic inversion (git-fixes). - ASoC: tlv320adcx140: fix null pointer (git-fixes). - ASoC: tlv320adcx140: fix word length (git-fixes). - ata: libata: Add cpr_log to ata_dev_print_features() early return (git-fixes). - Bluetooth: hci_uart: fix null-ptr-deref in hci_uart_write_work (git-fixes). - Bluetooth: MGMT: Fix memory leak in set_ssp_complete (git-fixes). - bpf: Do not let BPF test infra emit invalid GSO types to stack (bsc#1255569). - bpf/selftests: test_select_reuseport_kern: Remove unused header (bsc#1257603). - bs-upload-kernel: Fix cve branch uploads. - btrfs: do not strictly require dirty metadata threshold for metadata writepages (stable-fixes). - can: ctucanfd: fix SSP_SRC in cases when bit-rate is higher than 1 MBit (git-fixes). - can: ems_usb: ems_usb_read_bulk_callback(): fix URB memory leak (git-fixes). - can: etas_es58x: allow partial RX URB allocation to succeed (git-fixes). - can: gs_usb: gs_usb_receive_bulk_callback(): fix error message (git-fixes). - can: gs_usb: gs_usb_receive_bulk_callback(): unanchor URL on usb_submit_urb() error (git-fixes). - can: j1939: make j1939_session_activate() fail if device is no longer registered (stable-fixes). - can: kvaser_usb: kvaser_usb_read_bulk_callback(): fix URB memory leak (git-fixes). - can: mcba_usb: mcba_usb_read_bulk_callback(): fix URB memory leak (git-fixes). - can: usb_8dev: usb_8dev_read_bulk_callback(): fix URB memory leak (git-fixes). - cifs: add new field to track the last access time of cfid (git-fixes). - cifs: after disabling multichannel, mark tcon for reconnect (git-fixes). - cifs: avoid redundant calls to disable multichannel (git-fixes). - cifs: cifs_pick_channel should try selecting active channels (git-fixes). - cifs: deal with the channel loading lag while picking channels (git-fixes). - cifs: dns resolution is needed only for primary channel (git-fixes). - cifs: do not disable interface polling on failure (git-fixes). - cifs: do not search for channel if server is terminating (git-fixes). - cifs: fix a pending undercount of srv_count (git-fixes). - cifs: Fix copy offload to flush destination region (bsc#1252511). - cifs: Fix flushing, invalidation and file size with copy_file_range() (bsc#1252511). - cifs: fix lock ordering while disabling multichannel (git-fixes). - cifs: fix stray unlock in cifs_chan_skip_or_disable (git-fixes). - cifs: fix use after free for iface while disabling secondary channels (git-fixes). - cifs: handle servers that still advertise multichannel after disabling (git-fixes). - cifs: handle when server starts supporting multichannel (git-fixes). - cifs: handle when server stops supporting multichannel (git-fixes). - cifs: make cifs_chan_update_iface() a void function (git-fixes). - cifs: make sure server interfaces are requested only for SMB3+ (git-fixes). - cifs: make sure that channel scaling is done only once (git-fixes). - cifs: reconnect worker should take reference on server struct unconditionally (git-fixes). - cifs: reset connections for all channels when reconnect requested (git-fixes). - cifs: reset iface weights when we cannot find a candidate (git-fixes). - cifs: serialize other channels when query server interfaces is pending (git-fixes). - cifs: update dstaddr whenever channel iface is updated (git-fixes). - comedi: dmm32at: serialize use of paged registers (git-fixes). - comedi: fix divide-by-zero in comedi_buf_munge() (stable-fixes). - comedi: Fix getting range information for subdevices 16 to 255 (git-fixes). - cpuset: fix warning when disabling remote partition (bsc#1256794). - crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec (git-fixes). - dmaengine: apple-admac: Add 'apple,t8103-admac' compatible (git-fixes). - dmaengine: at_hdmac: fix device leak on of_dma_xlate() (git-fixes). - dmaengine: bcm-sba-raid: fix device leak on probe (git-fixes). - dmaengine: dw: dmamux: fix OF node leak on route allocation failure (git-fixes). - dmaengine: idxd: fix device leaks on compat bind and unbind (git-fixes). - dmaengine: lpc18xx-dmamux: fix device leak on route allocation (git-fixes). - dmaengine: omap-dma: fix dma_pool resource leak in error paths (git-fixes). - dmaengine: qcom: gpi: Fix memory leak in gpi_peripheral_config() (git-fixes). - dmaengine: sh: rz-dmac: Fix rz_dmac_terminate_all() (git-fixes). - dmaengine: tegra-adma: Fix use-after-free (git-fixes). - dmaengine: ti: dma-crossbar: fix device leak on am335x route allocation (git-fixes). - dmaengine: ti: dma-crossbar: fix device leak on dra7x route allocation (git-fixes). - dmaengine: ti: k3-udma: fix device leak on udma lookup (git-fixes). - dmaengine: xilinx_dma: Fix uninitialized addr_width when 'xlnx,addrwidth' property is missing (git-fixes). - dmaengine: xilinx: xdma: Fix regmap max_register (git-fixes). - dpll: fix device-id-get and pin-id-get to return errors properly (git-fixes). - dpll: fix return value check for kmemdup (git-fixes). - dpll: indent DPLL option type by a tab (git-fixes). - dpll: Prevent duplicate registrations (git-fixes). - dpll: spec: add missing module-name and clock-id to pin-get reply (git-fixes). - drm/amd: Clean up kfd node on surprise disconnect (stable-fixes). - drm/amd/display: Apply e4479aecf658 to dml (stable-fixes). - drm/amd/display: Bump the HDMI clock to 340MHz (stable-fixes). - drm/amd/display: Fix DP no audio issue (stable-fixes). - drm/amd/display: Initialise backlight level values from hw (git-fixes). - drm/amd/display: Respect user's CONFIG_FRAME_WARN more for dml files (stable-fixes). - drm/amd/display: shrink struct members (stable-fixes). - drm/amd/pm: Don't clear SI SMC table when setting power limit (git-fixes). - drm/amd/pm: fix race in power state check before mutex lock (git-fixes). - drm/amd/pm: fix smu overdrive data type wrong issue on smu 14.0.2 (git-fixes). - drm/amd/pm: Workaround SI powertune issue on Radeon 430 (v2) (git-fixes). - drm/amdgpu: Fix cond_exec handling in amdgpu_ib_schedule() (git-fixes). - drm/amdgpu: fix NULL pointer dereference in amdgpu_gmc_filter_faults_remove (git-fixes). - drm/amdgpu: Fix query for VPE block_type and ip_count (stable-fixes). - drm/amdgpu: remove frame cntl for gfx v12 (stable-fixes). - drm/amdkfd: fix a memory leak in device_queue_manager_init() (git-fixes). - drm/amdkfd: Fix improper NULL termination of queue restore SMI event string (stable-fixes). - drm/imagination: Wait for FW trace update command completion (git-fixes). - drm/imx/tve: fix probe device leak (git-fixes). - drm/msm/a6xx: fix bogus hwcg register updates (git-fixes). - drm/nouveau: add missing DCB connector types (git-fixes). - drm/nouveau: implement missing DCB connector types; gracefully handle unknown connectors (git-fixes). - drm/nouveau/disp: Set drm_mode_config_funcs.atomic_(check|commit) (stable-fixes). - drm/nouveau/disp/nv50-: Set lock_core in curs507a_prepare (git-fixes). - drm/panel-simple: fix connector type for DataImage SCF0700C48GGU18 panel (git-fixes). - drm/radeon: Remove __counted_by from ClockInfoArray.clockInfo[] (stable-fixes). - drm/vmwgfx: Fix an error return check in vmw_compat_shader_add() (git-fixes). - drm/vmwgfx: Merge vmw_bo_release and vmw_bo_free functions (git-fixes). - exfat: check return value of sb_min_blocksize in exfat_read_boot_sector (git-fixes). - exfat: fix remount failure in different process environments (git-fixes). - gpio: omap: do not register driver in probe() (git-fixes). - gpio: pca953x: Add support for level-triggered interrupts (stable-fixes). - gpio: pca953x: fix wrong error probe return value (git-fixes). - gpio: pca953x: handle short interrupt pulses on PCAL devices (git-fixes). - gpio: pca953x: Utilise dev_err_probe() where it makes sense (stable-fixes). - gpio: pca953x: Utilise temporary variable for struct device (stable-fixes). - gpio: rockchip: Stop calling pinctrl for set_direction (git-fixes). - HID: usbhid: paper over wrong bNumDescriptor field (stable-fixes). - ice: use netif_get_num_default_rss_queues() (bsc#1247712). - iio: accel: iis328dq: fix gain values (git-fixes). - iio: adc: ad7280a: handle spi_setup() errors in probe() (git-fixes). - iio: adc: ad9467: fix ad9434 vref mask (git-fixes). - iio: adc: at91-sama5d2_adc: Fix potential use-after-free in sama5d2_adc driver (git-fixes). - iio: dac: ad5686: add AD5695R to ad5686_chip_info_tbl (git-fixes). - iio: imu: st_lsm6dsx: fix iio_chan_spec for sensors without event detection (git-fixes). - Input: i8042 - add quirk for ASUS Zenbook UX425QA_UM425QA (stable-fixes). - Input: i8042 - add quirks for MECHREVO Wujie 15X Pro (stable-fixes). - intel_th: fix device leak on output open() (git-fixes). - leds: led-class: Only Add LED to leds_list when it is fully ready (git-fixes). - lib/crypto: aes: Fix missing MMU protection for AES S-box (git-fixes). - mei: me: add nova lake point S DID (stable-fixes). - mei: me: add wildcat lake P DID (stable-fixes). - mISDN: annotate data-race around dev->work (git-fixes). - mm, page_alloc, thp: prevent reclaim for __GFP_THISNODE THP allocations (bsc#1253087). - mmc: rtsx_pci_sdmmc: implement sdmmc_card_busy function (git-fixes). - mmc: sdhci-of-dwcmshc: Prevent illegal clock reduction in HS200/HS400 mode (git-fixes). - net: can: j1939: j1939_xtp_rx_rts_session_active(): deactivate session upon receiving the second rts (git-fixes). - net: hv_netvsc: reject RSS hash key programming without RX indirection table (bsc#1257473). - net: mana: Add metadata support for xdp mode (git-fixes). - net: mana: Add standard counter rx_missed_errors (git-fixes). - net: mana: Add support for auxiliary device servicing events (git-fixes). - net: mana: Change the function signature of mana_get_primary_netdev_rcu (bsc#1256690). - net: mana: Drop TX skb on post_work_request failure and unmap resources (git-fixes). - net: mana: fix spelling for mana_gd_deregiser_irq() (git-fixes). - net: mana: Fix use-after-free in reset service rescan path (git-fixes). - net: mana: Fix warnings for missing export.h header inclusion (git-fixes). - net: mana: Handle hardware recovery events when probing the device (git-fixes). - net: mana: Handle Reset Request from MANA NIC (git-fixes). - net: mana: Handle SKB if TX SGEs exceed hardware limit (git-fixes). - net: mana: Handle unsupported HWC commands (git-fixes). - net: mana: Move hardware counter stats from per-port to per-VF context (git-fixes). - net: mana: Probe rdma device in mana driver (git-fixes). - net: mana: Reduce waiting time if HWC not responding (git-fixes). - net: tcp: allow zero-window ACK update the window (bsc#1254767). - net: usb: dm9601: remove broken SR9700 support (git-fixes). - net: wwan: t7xx: fix potential skb->frags overflow in RX path (git-fixes). - nfc: llcp: Fix memleak in nfc_llcp_send_ui_frame() (git-fixes). - nfc: nci: Fix race between rfkill and nci_unregister_device() (git-fixes). - NFS: Fix up the automount fs_context to use the correct cred (git-fixes). - nfsd: Drop the client reference in client_states_open() (git-fixes). - NFSD: Fix permission check for read access to executable-only files (git-fixes). - NFSD: use correct reservation type in nfsd4_scsi_fence_client (git-fixes). - NFSD/blocklayout: Fix minlength check in proc_layoutget (git-fixes). - NFSv4: ensure the open stateid seqid doesn't go backwards (git-fixes). - nvme: nvme-fc: move tagset removal to nvme_fc_delete_ctrl() (git-fixes). - nvmet-auth: update sc_c in host response (git-fixes). - nvmet-auth: update sc_c in target host hash calculation (git-fixes). - of: fix reference count leak in of_alias_scan() (git-fixes). - of: platform: Use default match table for /firmware (git-fixes). - phy: freescale: imx8m-pcie: assert phy reset during power on (stable-fixes). - phy: rockchip: inno-usb2: fix communication disruption in gadget mode (git-fixes). - phy: rockchip: inno-usb2: fix disconnection in gadget mode (git-fixes). - phy: stm32-usphyc: Fix off by one in probe() (git-fixes). - phy: tegra: xusb: Explicitly configure HS_DISCON_LEVEL to 0x7 (git-fixes). - platform/x86: hp-bioscfg: Fix automatic module loading (git-fixes). - platform/x86: hp-bioscfg: Fix kernel panic in GET_INSTANCE_ID macro (git-fixes). - platform/x86: hp-bioscfg: Fix kobject warnings for empty attribute names (git-fixes). - platform/x86/amd: Fix memory leak in wbrf_record() (git-fixes). - pnfs/flexfiles: Fix memory leak in nfs4_ff_alloc_deviceid_node() (git-fixes). - powercap: fix race condition in register_control_type() (stable-fixes). - powercap: fix sscanf() error return value handling (stable-fixes). - powerpc/addnote: Fix overflow on 32-bit builds (bsc#1215199). - RDMA/mana_ib: Access remote atomic for MRs (git-fixes). - RDMA/mana_ib: add additional port counters (git-fixes). - RDMA/mana_ib: Add device statistics support (git-fixes). - RDMA/mana_ib: Add port statistics support (git-fixes). - RDMA/mana_ib: Add support of 4M, 1G, and 2G pages (git-fixes). - RDMA/mana_ib: Add support of mana_ib for RNIC and ETH nic (git-fixes). - RDMA/mana_ib: add support of multiple ports (git-fixes). - RDMA/mana_ib: Allow registration of DMA-mapped memory in PDs (git-fixes). - RDMA/mana_ib: check cqe length for kernel CQs (git-fixes). - RDMA/mana_ib: Create and destroy UD/GSI QP (git-fixes). - RDMA/mana_ib: create kernel-level CQs (git-fixes). - RDMA/mana_ib: create/destroy AH (git-fixes). - RDMA/mana_ib: Drain send wrs of GSI QP (git-fixes). - RDMA/mana_ib: extend mana QP table (git-fixes). - RDMA/mana_ib: Extend modify QP (git-fixes). - RDMA/mana_ib: Fix error code in probe() (git-fixes). - RDMA/mana_ib: Fix integer overflow during queue creation (git-fixes). - RDMA/mana_ib: Handle net event for pointing to the current netdev (bsc#1256690). - RDMA/mana_ib: helpers to allocate kernel queues (git-fixes). - RDMA/mana_ib: Implement DMABUF MR support (git-fixes). - RDMA/mana_ib: implement get_dma_mr (git-fixes). - RDMA/mana_ib: implement req_notify_cq (git-fixes). - RDMA/mana_ib: indicate CM support (git-fixes). - RDMA/mana_ib: polling of CQs for GSI/UD (git-fixes). - RDMA/mana_ib: Query feature_flags bitmask from FW (git-fixes). - RDMA/mana_ib: request error CQEs when supported (git-fixes). - RDMA/mana_ib: support of the zero based MRs (git-fixes). - RDMA/mana_ib: UD/GSI QP creation for kernel (git-fixes). - RDMA/mana_ib: UD/GSI work requests (git-fixes). - RDMA/mana_ib: unify mana_ib functions to support any gdma device (git-fixes). - RDMA/mana_ib: Use safer allocation function() (git-fixes). - regmap: Fix race condition in hwspinlock irqsave routine (git-fixes). - sched: Increase sched_tick_remote timeout (bsc#1254510). - sched/rt: Skip group schedulable check with rt_group_sched=0 (bsc#1256568). - scripts: obsapi: Support URL trailing / in oscrc. - scripts: teaapi: Add paging. - scripts: uploader: Fix no change condition for _maintainership.json. - scripts: uploader: Handle missing upstream in is_pr_open. - scripts/python/git_sort/git_sort.yaml: add cifs for-next repository. - scrits: teaapi: Add list_repos. - scsi: lpfc: Rework lpfc_sli4_fcf_rr_next_index_get() (bsc#1256861). - scsi: lpfc: Update lpfc version to 14.4.0.13 (bsc#1256861). - scsi: qla2xxx: Add bsg interface to support firmware img validation (bsc#1256863). - scsi: qla2xxx: Add load flash firmware mailbox support for 28xxx (bsc#1256863). - scsi: qla2xxx: Add Speed in SFP print information (bsc#1256863). - scsi: qla2xxx: Add support for 64G SFP speed (bsc#1256863). - scsi: qla2xxx: Allow recovery for tape devices (bsc#1256863). - scsi: qla2xxx: Delay module unload while fabric scan in progress (bsc#1256863). - scsi: qla2xxx: Fix bsg_done() causing double free (bsc#1256863). - scsi: qla2xxx: Free sp in error path to fix system crash (bsc#1256863). - scsi: qla2xxx: Query FW again before proceeding with login (bsc#1256863). - scsi: qla2xxx: Update version to 10.02.10.100-k (bsc#1256863). - scsi: qla2xxx: Validate MCU signature before executing MBC 03h (bsc#1256863). - scsi: qla2xxx: Validate sp before freeing associated memory (bsc#1256863). - scsi: storvsc: Process unsupported MODE_SENSE_10 (bsc#1257296). - selftests: net: fib-onlink-tests: Convert to use namespaces by default (bsc#1255346). - selftests/bpf: Fix flaky bpf_cookie selftest (git-fixes). - serial: 8250_pci: Fix broken RS485 for F81504/508/512 (git-fixes). - slimbus: core: fix device reference leak on report present (git-fixes). - slimbus: core: fix OF node leak on registration failure (git-fixes). - slimbus: core: fix of_slim_get_device() kernel doc (git-fixes). - slimbus: core: fix runtime PM imbalance on report present (git-fixes). - smb: change return type of cached_dir_lease_break() to bool (git-fixes). - smb: client: ensure open_cached_dir_by_dentry() only returns valid cfid (git-fixes). - smb: client: fix cifs_pick_channel when channel needs reconnect (git-fixes). - smb: client: fix warning when reconnecting channel (git-fixes). - smb: client: introduce close_cached_dir_locked() (git-fixes). - smb: client: remove unused fid_lock (git-fixes). - smb: client: short-circuit in open_cached_dir_by_dentry() if !dentry (git-fixes). - smb: client: split cached_fid bitfields to avoid shared-byte RMW races (bsc#1250748). - smb: client: update cfid->last_access_time in open_cached_dir_by_dentry() (git-fixes). - smb: improve directory cache reuse for readdir operations (bsc#1252712). - smb3: add missing null server pointer check (git-fixes). - spi: spi-sprd-adi: Fix double free in probe error path (git-fixes). - spi: sprd-adi: switch to use spi_alloc_host() (stable-fixes). - spi: sprd: adi: Use devm_register_restart_handler() (stable-fixes). - svcrdma: return 0 on success from svc_rdma_copy_inline_range (git-fixes). - uacce: ensure safe queue release with state management (git-fixes). - uacce: fix cdev handling in the cleanup path (git-fixes). - uacce: fix isolate sysfs check condition (git-fixes). - uacce: implement mremap in uacce_vm_ops to return -EPERM (git-fixes). - usb: core: add USB_QUIRK_NO_BOS for devices that hang on BOS descriptor (stable-fixes). - usb: dwc3: Check for USB4 IP_NAME (stable-fixes). - USB: OHCI/UHCI: Add soft dependencies on ehci_platform (stable-fixes). - USB: serial: ftdi_sio: add support for PICAXE AXE027 cable (stable-fixes). - USB: serial: option: add Telit LE910 MBIM composition (stable-fixes). - usbnet: limit max_mtu based on device's hard_mtu (git-fixes). - w1: fix redundant counter decrement in w1_attach_slave_device() (git-fixes). - w1: therm: Fix off-by-one buffer overflow in alarms_store (git-fixes). - wifi: ath10k: fix dma_free_coherent() pointer (git-fixes). - wifi: ath12k: fix dma_free_coherent() pointer (git-fixes). - wifi: mac80211: correctly decode TTLM with default link map (git-fixes). - wifi: mac80211: don't perform DA check on S1G beacon (git-fixes). - wifi: mwifiex: Fix a loop in mwifiex_update_ampdu_rxwinsize() (git-fixes). - wifi: rsi: Fix memory corruption due to not set vif driver data size (git-fixes). - x86: make page fault handling disable interrupts properly (git-fixes). - x86/microcode: Fix Entrysign revision check for Zen1/Naples (bsc#1256528). - x86/microcode/AMD: Add more known models to entry sign checking (bsc#1256528). - x86/microcode/AMD: Add some forgotten models to the SHA check (bsc#1256528). - x86/microcode/AMD: Add TSA microcode SHAs (bsc#1256528). - x86/microcode/AMD: Add Zen5 model 0x44, stepping 0x1 minrev (bsc#1256528). - x86/microcode/AMD: Clean the cache if update did not load microcode (bsc#1256528). - x86/microcode/AMD: Extend the SHA check to Zen5, block loading of any unreleased standalone Zen5 microcode patches (bsc#1256528). - x86/microcode/AMD: Fix __apply_microcode_amd()'s return value (bsc#1256528). - x86/microcode/AMD: Fix Entrysign revision check for Zen5/Strix Halo (bsc#1256528). - x86/microcode/AMD: Limit Entrysign signature checking to known generations (bsc#1256528). - x86/microcode/AMD: Load only SHA256-checksummed patches (bsc#1256528). - x86/microcode/AMD: Use sha256() instead of init/update/final (bsc#1256528). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:466-1 Released: Thu Feb 12 10:53:14 2026 Summary: Recommended update for mdadm Type: recommended Severity: important References: 1254087,1254541 This update for mdadm fixes the following issues: - Update to version 4.4+31.g541b40d3: * fix crash with homehost=none (bsc#1254541) - Update to version 4.4+30.g9a59bf51: * mdcheck: work around bash 5.3 bug (bsc#1254087) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:486-1 Released: Thu Feb 12 19:45:57 2026 Summary: Recommended update for suse-module-tools Type: recommended Severity: important References: 1253679,1254264,1254928 This update for suse-module-tools fixes the following issues: - Update to version 15.7.10: * udev rules: write block queue attributes only if necessary (bsc#1254928) - Update to version 15.7.9: * 80-hotplug-cpu-mem.rules: remount tmpfs on 'online' uevents (bsc#1254264) * udev: use syste md service to remount tmpfs (bsc#1253679) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:597-1 Released: Mon Feb 23 16:58:08 2026 Summary: Security update for libpng16 Type: security Severity: important References: 1258020,CVE-2026-25646 This update for libpng16 fixes the following issues: - CVE-2026-25646: heap buffer overflow vulnerability in png_set_dither/png_set_quantize (bsc#1258020). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:605-1 Released: Tue Feb 24 12:19:11 2026 Summary: Security update for libxml2 Type: security Severity: moderate References: 1247850,1247858,1250553,1256804,1256805,1256807,1256808,1256809,1256810,1256811,1256812,1257593,1257594,1257595,CVE-2025-10911,CVE-2025-8732,CVE-2026-0989,CVE-2026-0990,CVE-2026-0992,CVE-2026-1757 This update for libxml2 fixes the following issues: - CVE-2026-0990: Fixed a call stack overflow leading to application crash due to infinite recursion in `xmlCatalogXMLResolveURI`. (bsc#1256807, bsc#1256811) - CVE-2026-0992: Fixed an excessive resource consumption when processing XML catalogs due to exponential behavior. (bsc#1256809, bsc#1256812) - CVE-2026-1757: Fixed a memory leak in the `xmllint` interactive shell. (bsc#1257594, bsc#1257595) - CVE-2025-10911: Fixed a use-after-free with key data stored cross-RVT. (bsc#1250553) - CVE-2025-8732: Fixed an infinite recursion in catalog parsing functions when processing malformed SGML catalog files. (bsc#1247858) - CVE-2026-0989: Fixe a call stack exhaustion leading to application crash due to RelaxNG parser not limiting the recursion depth. (bsc#1256805, bsc#1256810) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:608-1 Released: Tue Feb 24 13:49:19 2026 Summary: Recommended update for lvm2 Type: recommended Severity: important References: 1257661 This update for lvm2 fixes the following issues: - L3: LVM_SUPPRESS_FD_WARNINGS is no longer effective (bsc#1257661) * libdaemon: fix suppressing stray fd warnings ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:646-1 Released: Wed Feb 25 17:29:20 2026 Summary: Security update for expat Type: security Severity: moderate References: 1257144,1257496,CVE-2026-24515,CVE-2026-25210 This update for expat fixes the following issues: - CVE-2026-24515: Fixed a null dereference in XML_ExternalEntityParserCreate. (bsc#1257144) - CVE-2026-25210: Fixed an integer overflow in doContent. (bsc#1257496) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:677-1 Released: Fri Feb 27 10:13:42 2026 Summary: Recommended update for grub2 Type: recommended Severity: important References: 1254299,1254415,1258022 This update for grub2 fixes the following issues: - Support dm multipath bootlist on PowerPC (bsc#1254415) - Backport upstream's commit to prevent BIOS assert (bsc#1258022) - Fix error 'grub-core/script/lexer.c:352:out of memory' after PowerPC CAS Reboot (bsc#1254299) * Fix PowerPC CAS reboot to evaluate menu context ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:678-1 Released: Fri Feb 27 10:37:37 2026 Summary: Recommended update for mdadm Type: recommended Severity: important References: 1257009,1258265 This update for mdadm fixes the following issues: - Update to version 4.4+39.g6e1c3b06: * platform-intel: Deal with hot-unplugged devices (bsc#1258265) * imsm: Fix UEFI backward compatibility for RAID10D4 (bsc#1257009) - Update to version 4.4+37.gea219956: - Backport upstream fixes from 4.5 (bsc#1257009) * Re-enable mdadm --monitor ... for /dev/mdX * Allow RAID0 to be created with v0.90 metadata * Moves memory management into Assemble to avoid null pointer dereference * Support non-absolute name during monitor scan * Don't set badblock flag when adding a new disk * Fix metadata corruption when managing new imsm array ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:741-1 Released: Mon Mar 2 09:11:04 2026 Summary: Security update for shim Type: security Severity: moderate References: 1240871,1247432,CVE-2024-2312 This update for shim fixes the following issues: shim is updated to version 16.1: - shim_start_image(): fix guid/handle pairing when uninstalling protocols - Fix uncompressed ipv6 netboot - fix test segfaults caused by uninitialized memory - SbatLevel_Variable.txt: minor typo fix. - Realloc() needs to allocate one more byte for sprintf() - IPv6: Add more check to avoid multiple double colon and illegal char - Loader proto v2 - loader-protocol: add workaround for EDK2 2025.02 page fault on FreePages - Generate Authenticode for the entire PE file - README: mention new loader protocol and interaction with UKIs - shim: change automatically enable MOK_POLICY_REQUIRE_NX - Save var info - add SbatLevel entry 2025051000 for PSA-2025-00012-1 - Coverity fixes 20250804 - fix http boot - Fix double free and leak in the loader protocol shim is updated to version 16.0: - Validate that a supplied vendor cert is not in PEM format - sbat: Add grub.peimage,2 to latest (CVE-2024-2312) - sbat: Also bump latest for grub,4 (and to todays date) - undo change that limits certificate files to a single file - shim: don't set second_stage to the empty string - Fix SBAT.md for today's consensus about numbers - Update Code of Conduct contact address - make-certs: Handle missing OpenSSL installation - Update MokVars.txt - export DEFINES for sub makefile - Drop unused EFI_IMAGE_SECURITY_DATABASE_GUID definition - Null-terminate 'arguments' in fallback - Fix 'Verifiying' typo in error message - Update Fedora CI targets - Force gcc to produce DWARF4 so that gdb can use it - Minor housekeeping 2024121700 - Discard load-options that start with WINDOWS - Fix the issue that the gBS->LoadImage pointer was empty. - shim: Allow data after the end of device path node in load options - Handle network file not found like disks - Update gnu-efi submodule for EFI_HTTP_ERROR - Increase EFI file alignment - avoid EFIv2 runtime services on Apple x86 machines - Improve shortcut performance when comparing two boolean expressions - Provide better error message when MokManager is not found - tpm: Boot with a warning if the event log is full - MokManager: remove redundant logical constraints - Test import_mok_state() when MokListRT would be bigger than available size - test-mok-mirror: minor bug fix - Fix file system browser hang when enrolling MOK from disk - Ignore a minor clang-tidy nit - Allow fallback to default loader when encountering errors on network boot - test.mk: don't use a temporary random.bin - pe: Enhance debug report for update_mem_attrs - Multiple certificate handling improvements - Generate SbatLevel Metadata from SbatLevel_Variable.txt - Apply EKU check with compile option - Add configuration option to boot an alternative 2nd stage - Loader protocol (with Device Path resolution support) - netboot cleanup for additional files - Document how revocations can be delivered - post-process-pe: add tests to validate NX compliance - regression: CopyMem() in ad8692e copies out of bounds - Save the debug and error logs in mok-variables - Add features for the Host Security ID program - Mirror some more efi variables to mok-variables - This adds DXE Services measurements to HSI and uses them for NX - Add shim's current NX_COMPAT status to HSIStatus - README.tpm: reflect that vendor_db is in fact logged as 'vendor_db' - Reject HTTP message with duplicate Content-Length header fields - Disable log saving - fallback: don't add new boot order entries backwards - README.tpm: Update MokList entry to MokListRT - SBAT Level update for February 2025 GRUB CVEs ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:779-1 Released: Tue Mar 3 14:25:07 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1258045,1258049,1258054,1258080,1258081,CVE-2026-0964,CVE-2026-0965,CVE-2026-0966,CVE-2026-0967,CVE-2026-0968 This update for libssh fixes the following issues: - CVE-2026-0964: improper sanitation of paths received from SCP servers can cause path traversal (bsc#1258049). - CVE-2026-0965: possible denial of service when parsing unexpected configuration files (bsc#1258045). - CVE-2026-0966: buffer underflow in ssh_get_hexa() on invalid input (bsc#1258054). - CVE-2026-0967: specially crafted patterns could cause denial of service (bsc#1258081). - CVE-2026-0968: malformed SFTP message can lead to out of bound read (bsc#1258080). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:783-1 Released: Tue Mar 3 14:36:14 2026 Summary: Security update for zlib Type: security Severity: moderate References: 1258392,CVE-2026-27171 This update for zlib fixes the following issue: - CVE-2026-27171: Fixed infinite loop via the `crc32_combine64` and `crc32_combine_gen64` functions due to missing checks for negative lengths (bsc#1258392). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:791-1 Released: Tue Mar 3 16:59:33 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1257463 This update for gcc15 fixes the following issues: - Fix bogus expression simplification (bsc#1257463) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:813-1 Released: Thu Mar 5 09:33:59 2026 Summary: Security update for mozilla-nss Type: security Severity: moderate References: 1258568,CVE-2026-2781 This update for mozilla-nss fixes the following issues: Update to NSS 3.112.3: * CVE-2026-2781: Avoid integer overflow in platform-independent ghash (bsc#1258568) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:844-1 Released: Fri Mar 6 16:45:31 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1258319 This update for glibc fixes the following issues: - nss: Missing checks in __nss_configure_lookup, __nss_database_get (bsc#1258319, BZ #28940) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:863-1 Released: Wed Mar 11 13:41:48 2026 Summary: Recommended update for openldap2 Type: recommended Severity: moderate References: This update for openldap2 fixes the following issues: - expose ldap_log.h in -devel (jsc#PED-15735) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:903-1 Released: Tue Mar 17 11:04:44 2026 Summary: Security update for curl Type: security Severity: important References: 1259362,1259363,1259364,1259365,CVE-2026-1965,CVE-2026-3783,CVE-2026-3784,CVE-2026-3805 This update for curl fixes the following issues: - CVE-2026-1965: bad reuse of HTTP Negotiate connection (bsc#1259362). - CVE-2026-3783: token leak with redirect and netrc (bsc#1259363). - CVE-2026-3784: wrong proxy connection reuse with credentials (bsc#1259364). - CVE-2026-3805: use after free in SMB connection reuse (bsc#1259365). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:910-1 Released: Tue Mar 17 20:34:12 2026 Summary: Security update for vim Type: security Severity: moderate References: 1246602,1258229,1259051,CVE-2025-53906,CVE-2026-26269,CVE-2026-28417 This update for vim fixes the following issues: Update Vim to version 9.2.0110: - CVE-2025-53906: malicious zip archive may cause a path traversal in Vim's zip (bsc#1246602). - CVE-2026-26269: Netbeans specialKeys stack buffer overflow (bsc#1258229). - CVE-2026-28417: crafted URL parsed by netrw plugin can lead to execute arbitrary shell commands (bsc#1259051). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:912-1 Released: Wed Mar 18 07:19:42 2026 Summary: Recommended update for ca-certificates-mozilla Type: recommended Severity: moderate References: 1229003,1258002 This update for ca-certificates-mozilla fixes the following issues: - test for a concretely missing certificate rather than just the directory, as the latter is now also provided by openssl-3 - Re-create java-cacerts with SOURCE_DATE_EPOCH set for reproducible builds (bsc#1229003) - Also mark /usr/share/factory/var/lib/ca-certificates/ as writable by the user during install: allow rpm to properly execute %clean when completed. - Create /var/lib/ca-certificates during build to ensure rpm gives the %ghost'ed directory proper mode attributes. - Updated to 2.84 state (bsc#1258002) * Removed: + Baltimore CyberTrust Root + CommScope Public Trust ECC Root-01 + CommScope Public Trust ECC Root-02 + CommScope Public Trust RSA Root-01 + CommScope Public Trust RSA Root-02 + DigiNotar Root CA * Added: + e-Szigno TLS Root CA 2023 + OISTE Client Root ECC G1 + OISTE Client Root RSA G1 + OISTE Server Root ECC G1 + OISTE Server Root RSA G1 + SwissSign RSA SMIME Root CA 2022 - 1 + SwissSign RSA TLS Root CA 2022 - 1 + TrustAsia SMIME ECC Root CA + TrustAsia SMIME RSA Root CA + TrustAsia TLS ECC Root CA + TrustAsia TLS RSA Root CA - reenable the distrusted certs again. the distrust is only for certs issued after the distrust date, not for all certs of a CA. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:931-1 Released: Thu Mar 19 09:23:14 2026 Summary: Security update for jq Type: security Severity: low References: 1248600,CVE-2025-9403 This update for jq fixes the following issue: - CVE-2025-9403: test suite assertion failure in JSON parsing consistency validation (bsc#1248600). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1040-1 Released: Wed Mar 25 13:43:08 2026 Summary: Security update for systemd Type: security Severity: important References: 1259418,1259650,1259697,CVE-2026-29111,CVE-2026-4105 This update for systemd fixes the following issues: - CVE-2026-4105: privilege escalation due to improper access control in RegisterMachine D-Bus method (bsc#1259650). - CVE-2026-29111: local unprivileged user can trigger an assert in systemd (bsc#1259418). - udev: check for invalid chars in various fields received from the kernel (bsc#1259697). Changelog: - a943e3ce2f machined: reject invalid class types when registering machines - 71593f77db udev: fix review mixup - 73a89810b4 udev-builtin-net-id: print cescaped bad attributes - 0f360bfdc0 udev-builtin-net_id: do not assume the current interface name is ethX - 40905232e2 udev: ensure tag parsing stays within bounds - 7bce9026e3 udev: ensure there is space for trailing NUL before calling sprintf - d018ac1ea3 udev: check for invalid chars in various fields received from the kernel - aef6e11921 core/cgroup: avoid one unnecessary strjoina() - cc7426f38a sd-json: fix off-by-one issue when updating parent for array elements - 26a748f727 core: validate input cgroup path more prudently - 99d8308fde core/dbus-manager: propagate meaningful dbus errors from EnqueueMarkedJobs ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1065-1 Released: Thu Mar 26 11:38:12 2026 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1254670,1259619,CVE-2025-70873,CVE-2025-7709 This update for sqlite3 fixes the following issues: Update sqlite3 to 3.51.3: - CVE-2025-7709: Integer Overflow in FTS5 Extension (bsc#1254670). - CVE-2025-70873: SQLite zipfile extension may disclose uninitialized heap memory during inflation (bsc#1259619). Changelog: * Fix the WAL-reset database corruption bug: https://sqlite.org/wal.html#walresetbug ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1074-1 Released: Thu Mar 26 13:39:49 2026 Summary: Security update for nghttp2 Type: security Severity: important References: 1259845,CVE-2026-27135 This update for nghttp2 fixes the following issues: - CVE-2026-27135: Assertion failure due to missing state validation can lead to DoS (bsc#1259845). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1081-1 Released: Thu Mar 26 14:23:36 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1241345,1243055,1245728,1247180,1249587,1249998,1251135,1251186,1251966,1251971,1252008,1252266,1252911,1252924,1253049,1253129,1253455,1253644,1253691,1254214,1254306,1254992,1255084,1255129,1255265,1255379,1255530,1255698,1255811,1256564,1256640,1256645,1256679,1256683,1256708,1256716,1256755,1256784,1256802,1256863,1257159,1257179,1257209,1257228,1257231,1257246,1257279,1257332,1257466,1257472,1257473,1257552,1257553,1257554,1257556,1257557,1257559,1257560,1257562,1257570,1257573,1257576,1257579,1257580,1257586,1257635,1257679,1257687,1257704,1257706,1257707,1257709,1257714,1257715,1257716,1257718,1257722,1257723,1257729,1257732,1257734,1257735,1257739,1257740,1257741,1257742,1257743,1257745,1257749,1257750,1257755,1257757,1257758,1257759,1257761,1257762,1257763,1257765,1257768,1257770,1257772,1257775,1257776,1257788,1257789,1257790,1257805,1257808,1257809,1257811,1257813,1257814,1257816,1257830,1257891,1257942,1257952,1258037,1258153,1258176,1258181,1258184,1258222,1 258226,1258234,1258237,1258245,1258249,1258252,1258256,1258259,1258272,1258273,1258277,1258278,1258279,1258286,1258293,1258297,1258298,1258299,1258304,1258309,1258313,1258317,1258321,1258326,1258338,1258340,1258349,1258354,1258358,1258374,1258376,1258377,1258379,1258389,1258394,1258395,1258397,1258411,1258415,1258419,1258422,1258424,1258429,1258442,1258464,1258465,1258468,1258469,1258484,1258517,1258518,1258519,1258520,1258524,1258544,1258660,1258824,1258832,1258849,1258850,1258860,1258928,1259070,1259130,1259558,1259580,1259857,CVE-2023-53817,CVE-2025-37861,CVE-2025-39748,CVE-2025-39817,CVE-2025-39964,CVE-2025-40099,CVE-2025-40103,CVE-2025-40201,CVE-2025-40253,CVE-2025-68283,CVE-2025-68295,CVE-2025-68374,CVE-2025-68735,CVE-2025-68736,CVE-2025-68778,CVE-2025-68785,CVE-2025-68810,CVE-2025-71066,CVE-2025-71071,CVE-2025-71104,CVE-2025-71113,CVE-2025-71125,CVE-2025-71126,CVE-2025-71148,CVE-2025-71182,CVE-2025-71184,CVE-2025-71185,CVE-2025-71188,CVE-2025-71189,CVE-2025-71190,CVE-2025-711 91,CVE-2025-71192,CVE-2025-71194,CVE-2025-71195,CVE-2025-71196,CVE-2025-71197,CVE-2025-71198,CVE-2025-71199,CVE-2025-71200,CVE-2025-71222,CVE-2025-71224,CVE-2025-71225,CVE-2025-71229,CVE-2025-71231,CVE-2025-71232,CVE-2025-71234,CVE-2025-71235,CVE-2025-71236,CVE-2026-22979,CVE-2026-22982,CVE-2026-22989,CVE-2026-22998,CVE-2026-23003,CVE-2026-23004,CVE-2026-23010,CVE-2026-23017,CVE-2026-23021,CVE-2026-23023,CVE-2026-23026,CVE-2026-23033,CVE-2026-23035,CVE-2026-23037,CVE-2026-23038,CVE-2026-23049,CVE-2026-23053,CVE-2026-23054,CVE-2026-23056,CVE-2026-23057,CVE-2026-23058,CVE-2026-23060,CVE-2026-23061,CVE-2026-23062,CVE-2026-23063,CVE-2026-23064,CVE-2026-23065,CVE-2026-23068,CVE-2026-23069,CVE-2026-23070,CVE-2026-23071,CVE-2026-23073,CVE-2026-23074,CVE-2026-23076,CVE-2026-23078,CVE-2026-23080,CVE-2026-23082,CVE-2026-23083,CVE-2026-23084,CVE-2026-23085,CVE-2026-23086,CVE-2026-23088,CVE-2026-23089,CVE-2026-23090,CVE-2026-23091,CVE-2026-23094,CVE-2026-23095,CVE-2026-23096,CVE-2026-23099,CVE- 2026-23101,CVE-2026-23102,CVE-2026-23104,CVE-2026-23105,CVE-2026-23107,CVE-2026-23108,CVE-2026-23110,CVE-2026-23111,CVE-2026-23112,CVE-2026-23113,CVE-2026-23116,CVE-2026-23119,CVE-2026-23121,CVE-2026-23125,CVE-2026-23128,CVE-2026-23129,CVE-2026-23131,CVE-2026-23133,CVE-2026-23135,CVE-2026-23139,CVE-2026-23141,CVE-2026-23145,CVE-2026-23146,CVE-2026-23150,CVE-2026-23151,CVE-2026-23152,CVE-2026-23154,CVE-2026-23155,CVE-2026-23156,CVE-2026-23157,CVE-2026-23163,CVE-2026-23166,CVE-2026-23167,CVE-2026-23169,CVE-2026-23170,CVE-2026-23171,CVE-2026-23172,CVE-2026-23173,CVE-2026-23176,CVE-2026-23178,CVE-2026-23179,CVE-2026-23182,CVE-2026-23190,CVE-2026-23191,CVE-2026-23198,CVE-2026-23202,CVE-2026-23204,CVE-2026-23207,CVE-2026-23208,CVE-2026-23209,CVE-2026-23210,CVE-2026-23213,CVE-2026-23214,CVE-2026-23221,CVE-2026-23222,CVE-2026-23229,CVE-2026-23268,CVE-2026-23269 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2023-53817: crypto: lib/mpi - avoid null pointer deref in mpi_cmp_ui() (bsc#1254992). - CVE-2025-37861: scsi: mpi3mr: Synchronous access b/w reset and tm thread for reply queue (bsc#1243055). - CVE-2025-39748: bpf: Forget ranges when refining tnum after JSET (bsc#1249587). - CVE-2025-39817: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare (bsc#1249998). - CVE-2025-39964: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (bsc#1251966). - CVE-2025-40099: cifs: parse_dfs_referrals: prevent oob on malformed input (bsc#1252911). - CVE-2025-40103: smb: client: Fix refcount leak for cifs_sb_tlink (bsc#1252924). - CVE-2025-40201: kernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths (bsc#1253455). - CVE-2025-40253: s390/ctcm: Fix double-kfree (bsc#1255084). - CVE-2025-68283: libceph: replace BUG_ON with bounds check for map->max_osd (bsc#1255379). - CVE-2025-68295: smb: client: fix memory leak in cifs_construct_tcon() (bsc#1255129). - CVE-2025-68374: md: fix rcu protection in md_wakeup_thread (bsc#1255530). - CVE-2025-68735: drm/panthor: Prevent potential UAF in group creation (bsc#1255811). - CVE-2025-68736: landlock: Fix handling of disconnected directories (bsc#1255698). - CVE-2025-68778: btrfs: don't log conflicting inode if it's a dir moved in the current transaction (bsc#1256683). - CVE-2025-68785: net: openvswitch: fix middle attribute validation in push_nsh() action (bsc#1256640). - CVE-2025-68810: KVM: Disallow toggling KVM_MEM_GUEST_MEMFD on an existing memslot (bsc#1256679). - CVE-2025-71066: net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change (bsc#1256645). - CVE-2025-71071: iommu/mediatek: fix use-after-free on probe deferral (bsc#1256802). - CVE-2025-71104: KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer (bsc#1256708). - CVE-2025-71113: crypto: af_alg - zero initialize memory allocated via sock_kmalloc (bsc#1256716). - CVE-2025-71125: tracing: Do not register unsupported perf events (bsc#1256784). - CVE-2025-71126: mptcp: reset fallback status gracefully at disconnect() time (bsc#1256755). - CVE-2025-71148: net/handshake: restore destructor on submit failure (bsc#1257159). - CVE-2025-71184: btrfs: fix NULL dereference on root when tracing inode eviction (bsc#1257635). - CVE-2025-71194: btrfs: fix deadlock in wait_current_trans() due to ignored transaction type (bsc#1257687). - CVE-2025-71225: md: suspend array while updating raid_disks via sysfs (bsc#1258411). - CVE-2026-22979: net: fix memory leak in skb_segment_list for GRO packets (bsc#1257228). - CVE-2026-22982: net: mscc: ocelot: Fix crash when adding interface under a lag (bsc#1257179). - CVE-2026-22998: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec (bsc#1257209). - CVE-2026-23003: geneve: Fix incorrect inner network header offset when innerprotoinherit is set (bsc#1257246). - CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() (bsc#1257231). - CVE-2026-23010: ipv6: Fix use-after-free in inet6_addr_del() (bsc#1257332). - CVE-2026-23017: idpf: fix error handling in the init_task on load (bsc#1257552). - CVE-2026-23023: idpf: fix memory leak in idpf_vport_rel() (bsc#1257556). - CVE-2026-23035: net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv (bsc#1257559). - CVE-2026-23053: NFS: Fix a deadlock involving nfs_release_folio() (bsc#1257718). - CVE-2026-23057: vsock/virtio: Coalesce only linear skb (bsc#1257740). - CVE-2026-23060: crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec (bsc#1257735). - CVE-2026-23064: net/sched: act_ife: avoid possible NULL deref (bsc#1257765). - CVE-2026-23069: vsock/virtio: fix potential underflow in virtio_transport_get_credit() (bsc#1257755). - CVE-2026-23070: Octeontx2-af: Add proper checks for fwdata (bsc#1257709). - CVE-2026-23074: net/sched: Enforce that teql can only be used as root qdisc (bsc#1257749). - CVE-2026-23083: fou: Don't allow 0 for FOU_ATTR_IPPROTO (bsc#1257745). - CVE-2026-23084: be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list (bsc#1257830). - CVE-2026-23085: irqchip/gic-v3-its: Avoid truncating memory addresses (bsc#1257758). - CVE-2026-23086: vsock/virtio: cap TX credit to local buffer size (bsc#1257757). - CVE-2026-23088: tracing: Fix crash on synthetic stacktrace field usage (bsc#1257814). - CVE-2026-23089: ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free() (bsc#1257790). - CVE-2026-23095: gue: Fix skb memleak with inner IP protocol 0 (bsc#1257808). - CVE-2026-23099: bonding: limit BOND_MODE_8023AD to Ethernet devices (bsc#1257816). - CVE-2026-23102: arm64/fpsimd: signal: Mandate SVE payload for streaming-mode state (bsc#1257772). - CVE-2026-23104: ice: fix devlink reload call trace (bsc#1257763). - CVE-2026-23105: net/sched: qfq: Use cl_is_active to determine whether class is active in qfq_rm_from_ag (bsc#1257775). - CVE-2026-23107: arm64/fpsimd: signal: Allocate SSVE storage when restoring ZA (bsc#1257762). - CVE-2026-23110: scsi: core: Wake up the error handler when final completions race against each other (bsc#1257761). - CVE-2026-23111: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() (bsc#1258181). - CVE-2026-23112: nvmet-tcp: add bounds checks in nvmet_tcp_build_pdu_iovec (bsc#1258184). - CVE-2026-23113: io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop (bsc#1258278). - CVE-2026-23116: pmdomain: imx8m-blk-ctrl: Remove separate rst and clk mask for 8mq vpu (bsc#1258277). - CVE-2026-23119: bonding: provide a net pointer to __skb_flow_dissect() (bsc#1258273). - CVE-2026-23125: sctp: move SCTP_CMD_ASSOC_SHKEY right after SCTP_CMD_PEER_INIT (bsc#1258293). - CVE-2026-23139: netfilter: nf_conncount: update last_gc only when GC has been performed (bsc#1258304). - CVE-2026-23141: btrfs: send: check for inline extents in range_is_hole_in_parent() (bsc#1258377). - CVE-2026-23154: net: fix segmentation of forwarding fraglist GRO (bsc#1258286). - CVE-2026-23166: ice: Fix NULL pointer dereference in ice_vsi_set_napi_queues (bsc#1258272). - CVE-2026-23169: mptcp: fix race in mptcp_pm_nl_flush_addrs_doit() (bsc#1258389). - CVE-2026-23171: net: bonding: update the slave array for broadcast mode (bsc#1258349). - CVE-2026-23173: net/mlx5e: TC, delete flows only for existing peers (bsc#1258520). - CVE-2026-23179: nvmet-tcp: fixup hang in nvmet_tcp_listen_data_ready() (bsc#1258394). - CVE-2026-23191: ALSA: aloop: Fix racy access at PCM trigger (bsc#1258395). - CVE-2026-23198: KVM: Don't clobber irqfd routing type when deassigning irqfd (bsc#1258321). - CVE-2026-23204: net/sched: cls_u32: use skb_header_pointer_careful() (bsc#1258340). - CVE-2026-23208: ALSA: usb-audio: Prevent excessive number of frames (bsc#1258468). - CVE-2026-23209: macvlan: fix error recovery in macvlan_common_newlink() (bsc#1258518). - CVE-2026-23210: ice: Fix PTP NULL pointer dereference during VSI rebuild (bsc#1258517). - CVE-2026-23213: drm/amd/pm: Disable MMIO access during SMU Mode 1 reset (bsc#1258465). - CVE-2026-23214: btrfs: reject new transactions if the fs is fully read-only (bsc#1258464). - CVE-2026-23268: apparmor: fix unprivileged local user can do privileged policy management (bsc#1258850). - CVE-2026-23269: apparmor: validate DFA start states are in bounds in unpack_pdb (bsc#1259857). The following non security issues were fixed: - ACPI: CPPC: Fix remaining for_each_possible_cpu() to use online CPUs (git-fixes). - ACPI: OSL: fix __iomem type on return from acpi_os_map_generic_address() (git-fixes). - ACPI: PM: Add unused power resource quirk for THUNDEROBOT ZERO (git-fixes). - ACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4() (stable-fixes). - ACPICA: Abort AML bytecode execution when executing AML_FATAL_OP (stable-fixes). - ACPICA: Fix NULL pointer dereference in acpi_ev_address_space_dispatch() (git-fixes). - ALSA: hda/conexant: Add headset mic fix for MECHREVO Wujie 15X Pro (stable-fixes). - ALSA: hda/realtek - fixed speaker no sound (stable-fixes). - ALSA: hda/realtek: add HP Laptop 15s-eq1xxx mute LED quirk (stable-fixes). - ALSA: hda/realtek: Add quirk for Inspur S14-G1 (stable-fixes). - ALSA: hda/realtek: Fix headset mic for TongFang X6AR55xU (stable-fixes). - ALSA: hda/realtek: fix right sounds and mute/micmute LEDs for HP machine (stable-fixes). - ALSA: hda/realtek: Really fix headset mic for TongFang X6AR55xU (git-fixes). - ALSA: usb-audio: Add iface reset and delay quirk for AB13X USB Audio (stable-fixes). - ALSA: usb-audio: Add sanity check for OOB writes at silencing (stable-fixes). - ALSA: usb-audio: Avoid implicit feedback mode on DIYINHK USB Audio 2.0 (stable-fixes). - ALSA: usb-audio: Cap the packet size pre-calculations (git-fixes). - ALSA: usb-audio: Check max frame size for implicit feedback mode, too (stable-fixes). - ALSA: usb-audio: fix broken logic in snd_audigy2nx_led_update() (git-fixes). - ALSA: usb-audio: Remove VALIDATE_RATES quirk for Focusrite devices (git-fixes). - ALSA: usb-audio: Update the number of packets properly at receiving (stable-fixes). - ALSA: usb-audio: Use correct version for UAC3 header validation (git-fixes). - ALSA: usb-audio: Use inclusive terms (git-fixes). - ALSA: vmaster: Relax __free() variable declarations (git-fixes). - APEI/GHES: ensure that won't go past CPER allocated record (stable-fixes). - apparmor: fix differential encoding verification (bsc#1258849). - apparmor: Fix double free of ns_name in aa_replace_profiles() (bsc#1258849). - apparmor: fix memory leak in verify_header (bsc#1258849). - apparmor: fix missing bounds check on DEFAULT table in verify_dfa() (bsc#1258849). - apparmor: fix race between freeing data and fs accessing it (bsc#1258849). - apparmor: fix race on rawdata dereference (bsc#1258849). - apparmor: fix side-effect bug in match_char() macro usage (bsc#1258849). - apparmor: fix unprivileged local user can do privileged policy management (bsc#1258849). - apparmor: fix: limit the number of levels of policy namespaces (bsc#1258849). - apparmor: replace recursive profile removal with iterative approach (bsc#1258849). - apparmor: validate DFA start states are in bounds in unpack_pdb (bsc#1258849). - arm64: Add support for TSV110 Spectre-BHB mitigation (git-fixes). - arm64: Disable branch profiling for all arm64 code (git-fixes). - arm64: Set __nocfi on swsusp_arch_resume() (git-fixes). - ASoC: amd: drop unused Kconfig symbols (git-fixes). - ASoC: amd: fix memory leak in acp3x pdm dma ops (git-fixes). - ASoC: amd: yc: Add ASUS ExpertBook PM1503CDA to quirks list (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Acer TravelMate P216-41-TCO (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS Vivobook Pro 15X M6501RR (stable-fixes). - ASoC: amd: yc: Add quirk for HP 200 G2a 16 (stable-fixes). - ASoC: amd: yc: Fix microphone on ASUS M6500RE (stable-fixes). - ASoC: codecs: max98390: Check return value of devm_gpiod_get_optional() in max98390_i2c_probe() (stable-fixes). - ASoC: cs35l45: Corrects ASP_TX5 DAPM widget channel (stable-fixes). - ASoC: cs42l43: Correct handling of 3-pole jack load detection (stable-fixes). - ASoC: davinci-evm: Fix reference leak in davinci_evm_probe (stable-fixes). - ASoC: Intel: sof_es8336: Add DMI quirk for Huawei BOD-WXX9 (stable-fixes). - ASoC: nau8821: Avoid unnecessary blocking in IRQ handler (stable-fixes). - ASoC: nau8821: Cancel delayed work on component remove (git-fixes). - ASoC: nau8821: Cancel pending work before suspend (git-fixes). - ASoC: nau8821: Consistently clear interrupts before unmasking (git-fixes). - ASoC: nau8821: Fixup nau8821_enable_jack_detect() (git-fixes). - ASoC: pxa: drop unused Kconfig symbol (git-fixes). - ASoC: rockchip: i2s-tdm: Use param rate if not provided by set_sysclk (git-fixes). - ASoC: SOF: ipc4-control: If there is no data do not send bytes update (git-fixes). - ASoC: SOF: ipc4-control: Keep the payload size up to date (git-fixes). - ASoC: SOF: ipc4-control: Use the correct size for scontrol->ipc_control_data (git-fixes). - ASoC: SOF: ipc4-topology: Correct the allocation size for bytes controls (git-fixes). - ASoC: sunxi: sun50i-dmic: Add missing check for devm_regmap_init_mmio (stable-fixes). - ASoC: tlv320adcx140: Propagate error codes during probe (stable-fixes). - ASoC: wm8962: Add WM8962_ADC_MONOMIX to '3D Coefficients' mask (stable-fixes). - ASoC: wm8962: Don't report a microphone if it's shorted to ground on plug (stable-fixes). - ata: libata: avoid long timeouts on hot-unplugged SATA DAS (stable-fixes). - ata: pata_ftide010: Fix some DMA timings (git-fixes). - atm: fore200e: fix use-after-free in tasklets during device removal (git-fixes). - auxdisplay: arm-charlcd: fix release_mem_region() size (git-fixes). - backlight: qcom-wled: Change PM8950 WLED configurations (git-fixes). - backlight: qcom-wled: Support ovp values for PMI8994 (git-fixes). - batman-adv: Avoid double-rtnl_lock ELP metric worker (git-fixes). - block,bfq: fix aux stat accumulation destination (git-fixes). - Bluetooth: btintel_pcie: Use IRQF_ONESHOT and default primary handler (git-fixes). - Bluetooth: btusb: Add device ID for Realtek RTL8761BU (stable-fixes). - Bluetooth: btusb: Add new VID/PID for RTL8852CE (stable-fixes). - Bluetooth: btusb: Add USB ID 7392:e611 for Edimax EW-7611UXB (stable-fixes). - Bluetooth: hci_conn: Set link_policy on incoming ACL connections (stable-fixes). - Bluetooth: hci_conn: use mod_delayed_work for active mode timeout (stable-fixes). - Bluetooth: hci_qca: Cleanup on all setup failures (git-fixes). - Bluetooth: L2CAP: Fix invalid response to L2CAP_ECRED_RECONF_REQ (git-fixes). - Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ (git-fixes). - Bluetooth: L2CAP: Fix not checking output MTU is acceptable on L2CAP_ECRED_CONN_REQ (git-fixes). - Bluetooth: L2CAP: Fix response to L2CAP_ECRED_CONN_REQ (git-fixes). - Bluetooth: L2CAP: Fix result of L2CAP_ECRED_CONN_RSP when MTU is too short (git-fixes). - bonding: only set speed/duplex to unknown, if getting speed failed (bsc#1253691). - bpf: selftests: Move xfrm tunnel test to test_progs (bsc#1258860). - bpf: selftests: test_tunnel: Setup fresh topology for each subtest (bsc#1258860). - bpf: selftests: test_tunnel: Use vmlinux.h declarations (bsc#1258860). - bpf: verifier improvement in 32bit shift sign extension pattern (git-fixes). - bpf: xfrm: Add bpf_xdp_get_xfrm_state() kfunc (bsc#1258860). - bpf: xfrm: Add selftest for bpf_xdp_get_xfrm_state() (bsc#1258860). - btrfs: scrub: always update btrfs_scrub_progress::last_physical (git-fixes). - bus: fsl-mc: fix an error handling in fsl_mc_device_add() (git-fixes). - bus: fsl-mc: fix use-after-free in driver_override_show() (git-fixes). - bus: fsl-mc: Replace snprintf and sprintf with sysfs_emit in sysfs show functions (stable-fixes). - can: bcm: fix locking for bcm_op runtime updates (git-fixes). - can: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message (git-fixes). - can: hi311x: hi3110_open(): add check for hi3110_power_enable() return value (git-fixes). - can: mcp251x: fix deadlock in error path of mcp251x_open (git-fixes). - can: ucan: Fix infinite loop from zero-length messages (git-fixes). - can: usb: etas_es58x: correctly anchor the urb in the read bulk callback (git-fixes). - cgroup: Fix incorrect WARN_ON_ONCE() in css_release_work_fn() (bsc#1256564 bsc#1259130). - cgroup: Show # of subsystem CSSes in cgroup.stat (bsc#1256564 bsc#1259130). - char: tpm: cr50: Remove IRQF_ONESHOT (git-fixes). - char: tpm: cr50: Remove IRQF_ONESHOT (stable-fixes). - cifs: add xid to query server interface call (git-fixes). - clk: clk-apple-nco: Add 'apple,t8103-nco' compatible (git-fixes). - clk: mediatek: Fix error handling in runtime PM setup (git-fixes). - clk: meson: g12a: Limit the HDMI PLL OD to /4 (git-fixes). - clk: meson: gxbb: Limit the HDMI PLL OD to /4 on GXL/GXM SoCs (git-fixes). - clk: mvebu: cp110 add CLK_IGNORE_UNUSED to pcie_x10, pcie_x11 & (git-fixes). - clk: qcom: dispcc-sdm845: Enable parents for pixel clocks (git-fixes). - clk: qcom: gcc-msm8917: Remove ALWAYS_ON flag from cpp_gdsc (git-fixes). - clk: qcom: gcc-msm8953: Remove ALWAYS_ON flag from cpp_gdsc (git-fixes). - clk: qcom: gfx3d: add parent to parent request map (git-fixes). - clk: qcom: rcg2: compute 2d using duty fraction directly (git-fixes). - clk: renesas: rzg2l: Fix intin variable size (git-fixes). - clk: renesas: rzg2l: Select correct div round macro (git-fixes). - clk: tegra: tegra124-emc: fix device leak on set_rate() (git-fixes). - clk: tegra: tegra124-emc: Fix potential memory leak in tegra124_clk_register_emc() (git-fixes). - clocksource: hyper-v: Fix warnings for missing export.h header inclusion (git-fixes). - clocksource: Print durations for sync check unconditionally (bsc#1241345). - clocksource: Reduce watchdog readout delay limit to prevent false positives (bsc#1241345). - config.conf: add kernel-azure as additonal flavor (bsc#1258037). - config.conf: Drop armv7hl builds (bsc#1255265). - cpu: export lockdep_assert_cpus_held() (git-fixes). - cpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update (bsc#1247180). - cpufreq/amd-pstate: Add the missing cpufreq_cpu_put() (bsc#1247180). - cpufreq/amd-pstate: fix setting policy current frequency value (bsc#1247180). - cpufreq/amd-pstate: Fix the clamping of perf values (bsc#1247180). - cpufreq/amd-pstate: Modularize perf<->freq conversion (bsc#1247180). - cpufreq/amd-pstate: Refactor max frequency calculation (bsc#1247180). - cpufreq/amd-pstate: store all values in cpudata struct in khz (bsc#1247180). - cpufreq: amd-pstate: Unify computation of {max,min,nominal,lowest_nonlinear}_freq (bsc#1247180). - crypto: cavium - fix dma_free_coherent() size (git-fixes). - crypto: ccp - Add an S4 restore flow (git-fixes). - crypto: hisilicon/sec2 - support skcipher/aead fallback for hardware queue unavailable (git-fixes). - crypto: hisilicon/trng - support tfms sharing the device (git-fixes). - crypto: hisilicon/zip - adjust the way to obtain the req in the callback function (git-fixes). - crypto: iaa - Fix out-of-bounds index in find_empty_iaa_compression_mode (git-fixes). - crypto: octeontx - fix dma_free_coherent() size (git-fixes). - crypto: octeontx - Fix length check to avoid truncation in ucode_load_store (git-fixes). - crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly (git-fixes). - crypto: qat - fix parameter order used in ICP_QAT_FW_COMN_FLAGS_BUILD (git-fixes). - crypto: qat - fix warning on adf_pfvf_pf_proto.c (git-fixes). - crypto: virtio - Add spinlock protection with virtqueue notification (git-fixes). - crypto: virtio - Remove duplicated virtqueue_kick in virtio_crypto_skcipher_crypt_req (git-fixes). - device property: Allow secondary lookup in fwnode_get_next_child_node() (git-fixes). - dm mpath: make pg_init_delay_msecs settable (git-fixes). - dm-bufio: align write boundary on physical block size (git-fixes). - dm-ebs: Mark full buffer dirty even on partial write (git-fixes). - dm-snapshot: fix 'scheduling while atomic' on real-time kernels (git-fixes). - dm: clear cloned request bio pointer when last clone bio completes (git-fixes). - dm: remove fake timeout to avoid leak request (git-fixes). - dma: dma-axi-dmac: fix SW cyclic transfers (git-fixes). - dmaengine: mediatek: uart-apdma: Fix above 4G addressing TX/RX (git-fixes). - dmaengine: sun6i: Choose appropriate burst length under maxburst (stable-fixes). - Documentation: mailbox: mbox_chan_ops.flush() is optional (git-fixes). - Documentation: PCI: endpoint: Fix ntb/vntb copy & paste errors (git-fixes). - drivers/hv: add CPU offlining support (git-fixes). - drivers/hv: introduce vmbus_channel_set_cpu() (git-fixes). - Drivers: hv: Allocate interrupt and monitor pages aligned to system page boundary (git-fixes). - Drivers: hv: Always do Hyper-V panic notification in hv_kmsg_dump() (git-fixes). - Drivers: hv: Fix bad pointer dereference in hv_get_partition_id (git-fixes). - Drivers: hv: fix missing kernel-doc description for 'size' in request_arr_init() (git-fixes). - Drivers: hv: Fix the check for HYPERVISOR_CALLBACK_VECTOR (git-fixes). - Drivers: hv: Fix warnings for missing export.h header inclusion (git-fixes). - Drivers: hv: remove stale comment (git-fixes). - Drivers: hv: Resolve ambiguity in hypervisor version log (git-fixes). - Drivers: hv: use kmalloc_array() instead of kmalloc() (git-fixes). - Drivers: hv: Use kzalloc for panic page allocation (git-fixes). - Drivers: hv: util: Cosmetic changes for hv_utils_transport.c (git-fixes). - Drivers: hv: vmbus: Add comments about races with 'channels' sysfs dir (git-fixes). - Drivers: hv: vmbus: Clean up sscanf format specifier in target_cpu_store() (git-fixes). - Drivers: hv: vmbus: Fix sysfs output format for ring buffer index (git-fixes). - Drivers: hv: vmbus: Fix typos in vmbus_drv.c (git-fixes). - Drivers: hv: vmbus: Get the IRQ number from DeviceTree (git-fixes). - Drivers: hv: vmbus: Introduce hv_get_vmbus_root_device() (git-fixes). - drivers: iio: mpu3050: use dev_err_probe for regulator request (git-fixes). - drm/amd/display: Add signal type check for dcn401 get_phyd32clk_src (stable-fixes). - drm/amd/display: Add USB-C DP Alt Mode lane limitation in DCN32 (stable-fixes). - drm/amd/display: avoid dig reg access timeout on usb4 link training fail (stable-fixes). - drm/amd/display: Avoid updating surface with the same surface under MPO (stable-fixes). - drm/amd/display: bypass post csc for additional color spaces in dal (stable-fixes). - drm/amd/display: Disable FEC when powering down encoders (stable-fixes). - drm/amd/display: extend delta clamping logic to CM3 LUT helper (stable-fixes). - drm/amd/display: Fix dsc eDP issue (stable-fixes). - drm/amd/display: Fix GFX12 family constant checks (stable-fixes). - drm/amd/display: Fix out-of-bounds stream encoder index v3 (git-fixes). - drm/amd/display: Fix system resume lag issue (stable-fixes). - drm/amd/display: Fix writeback on DCN 3.2+ (stable-fixes). - drm/amd/display: fix wrong color value mapping on MCM shaper LUT (git-fixes). - drm/amd/display: Increase DCN35 SR enter/exit latency (stable-fixes). - drm/amd/display: only power down dig on phy endpoints (stable-fixes). - drm/amd/display: Reject cursor plane on DCE when scaled differently than primary (git-fixes). - drm/amd/display: remove assert around dpp_base replacement (stable-fixes). - drm/amd/display: Remove conditional for shaper 3DLUT power-on (stable-fixes). - drm/amd/display: Use same max plane scaling limits for all 64 bpp formats (git-fixes). - drm/amd/pm: Disable MMIO access during SMU Mode 1 reset (stable-fixes). - drm/amd: Disable MES LR compute W/A (git-fixes). - drm/amd: Drop 'amdgpu kernel modesetting enabled' message (git-fixes). - drm/amd: Fix hang on amdgpu unload by using pci_dev_is_disconnected() (git-fixes). - drm/amdgpu/gfx10: fix wptr reset in KGQ init (stable-fixes). - drm/amdgpu/gfx11: fix wptr reset in KGQ init (stable-fixes). - drm/amdgpu/gfx12: fix wptr reset in KGQ init (stable-fixes). - drm/amdgpu/soc21: fix xclk for APUs (stable-fixes). - drm/amdgpu: Add HAINAN clock adjustment (stable-fixes). - drm/amdgpu: add support for HDP IP version 6.1.1 (stable-fixes). - drm/amdgpu: Adjust usleep_range in fence wait (stable-fixes). - drm/amdgpu: avoid a warning in timedout job handler (stable-fixes). - drm/amdgpu: ensure no_hw_access is visible before MMIO (git-fixes). - drm/amdgpu: Fix locking bugs in error paths (git-fixes). - drm/amdgpu: Fix memory leak in amdgpu_acpi_enumerate_xcc() (git-fixes). - drm/amdgpu: Fix memory leak in amdgpu_ras_init() (git-fixes). - drm/amdgpu: fix NULL pointer issue buffer funcs (stable-fixes). - drm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify (git-fixes). - drm/amdgpu: keep vga memory on MacBooks with switchable graphics (stable-fixes). - drm/amdgpu: remove invalid usage of sched.ready (stable-fixes). - drm/amdgpu: Replace kzalloc + copy_from_user with memdup_user (stable-fixes). - drm/amdgpu: Skip loading SDMA_RS64 in VF (stable-fixes). - drm/amdgpu: stop unmapping MQD for kernel queues v3 (stable-fixes). - drm/amdgpu: Unlock a mutex before destroying it (git-fixes). - drm/amdgpu: Use kvfree instead of kfree in amdgpu_gmc_get_nps_memranges() (git-fixes). - drm/amdkfd: fix debug watchpoints for logical devices (stable-fixes). - drm/amdkfd: Fix GART PTE for non-4K pagesize in svm_migrate_gart_map() (stable-fixes). - drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (stable-fixes). - drm/amdkfd: Fix signal_eviction_fence() bool return value (git-fixes). - drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (git-fixes). - drm/amdkfd: Handle GPU reset and drain retry fault race (stable-fixes). - drm/amdkfd: Relax size checking during queue buffer get (stable-fixes). - drm/atmel-hlcdc: don't reject the commit if the src rect has fractional parts (stable-fixes). - drm/atmel-hlcdc: fix memory leak from the atomic_destroy_state callback (stable-fixes). - drm/atmel-hlcdc: fix use-after-free of drm_crtc_commit after release (stable-fixes). - drm/bridge: anx7625: Fix invalid EDID size (git-fixes). - drm/bridge: samsung-dsim: Fix memory leak in error path (git-fixes). - drm/bridge: ti-sn65dsi86: Enable HPD polling if IRQ is not used (git-fixes). - drm/buddy: Prevent BUG_ON by validating rounded allocation (git-fixes). - drm/display/dp_mst: Add protection against 0 vcpi (stable-fixes). - drm/i915/acpi: free _DSM package when no connectors (git-fixes). - drm/i915/display: Add quirk to skip retraining of dp link (bsc#1253129). - drm/i915/wakeref: clean up INTEL_WAKEREF_PUT_* flag macros (stable-fixes). - drm/logicvc: Fix device node reference leak in logicvc_drm_config_parse() (git-fixes). - drm/mgag200: fix mgag200_bmc_stop_scanout() (git-fixes). - drm/msm/a2xx: fix pixel shader start on A225 (git-fixes). - drm/msm/disp: set num_planes to 1 for interleaved YUV formats (git-fixes). - drm/msm/dpu: drop intr_start from DPU 3.x catalog files (git-fixes). - drm/msm/dpu: fix CMD panels on DPU 1.x - 3.x (git-fixes). - drm/msm/dpu: fix WD timer handling on DPU 8.x (git-fixes). - drm/msm/dpu: Set vsync source irrespective of mdp top support (git-fixes). - drm/panel: Fix a possible null-pointer dereference in jdi_panel_dsi_remove() (stable-fixes). - drm/panel: sw43408: Remove manual invocation of unprepare at remove (git-fixes). - drm/panthor: Evict groups before VM termination (git-fixes). - drm/panthor: Fix immediate ticking on a disabled tick (git-fixes). - drm/panthor: Fix the full_tick check (git-fixes). - drm/panthor: Fix the group priority rotation logic (git-fixes). - drm/panthor: Fix the logic that decides when to stop ticking (git-fixes). - drm/panthor: Make sure we resume the tick when new jobs are submitted (git-fixes). - drm/panthor: Recover from panthor_gpu_flush_caches() failures (git-fixes). - drm/radeon: Add HAINAN clock adjustment (stable-fixes). - drm/radeon: delete radeon_fence_process in is_signaled, no deadlock (stable-fixes). - drm/sched: Fix kernel-doc warning for drm_sched_job_done() (git-fixes). - drm/solomon: Fix page start when updating rectangle in page addressing mode (git-fixes). - drm/tegra: dsi: fix device leak on probe (git-fixes). - drm/tegra: hdmi: sor: Fix error: variable 'j' set but not used (stable-fixes). - drm/tests: shmem: Swap names of export tests (git-fixes). - drm/v3d: Set DMA segment size to avoid debug warnings (stable-fixes). - drm/vmwgfx: Fix invalid kref_put callback in vmw_bo_dirty_release (git-fixes). - drm/vmwgfx: Return the correct value in vmw_translate_ptr functions (git-fixes). - drm/xe/mmio: Avoid double-adjust in 64-bit reads (git-fixes). - drm/xe/pm: Also avoid missing outer rpm warning on system suspend (stable-fixes). - drm/xe/pm: Disable D3Cold for BMG only on specific platforms (git-fixes). - drm/xe/ptl: Apply Wa_13011645652 (stable-fixes). - drm/xe/query: Fix topology query pointer advance (git-fixes). - drm/xe/sync: Cleanup partially initialized sync on parse failure (git-fixes). - drm/xe/xe2_hpg: Add set of workarounds (stable-fixes). - drm/xe/xe2_hpg: Fix handling of Wa_14019988906 & Wa_14019877138 (git-fixes). - drm/xe: Add xe_tile backpointer to xe_mmio (stable-fixes). - drm/xe: Adjust mmio code to pass VF substructure to SRIOV code (stable-fixes). - drm/xe: Clarify size of MMIO region (stable-fixes). - drm/xe: Create dedicated xe_mmio structure (stable-fixes). - drm/xe: Defer gt->mmio initialization until after multi-tile setup (git-fixes). - drm/xe: Move forcewake to 'gt.pm' substructure (stable-fixes). - drm/xe: Move GSI offset adjustment fields into 'struct xe_mmio' (stable-fixes). - drm/xe: Only toggle scheduling in TDR if GuC is running (stable-fixes). - drm/xe: Populate GT's mmio iomap from tile during init (stable-fixes). - drm/xe: Switch MMIO interface to take xe_mmio instead of xe_gt (stable-fixes). - drm/xe: Switch mmio_ext to use 'struct xe_mmio' (stable-fixes). - drm/xe: Unregister drm device on probe error (git-fixes). - drm: Account property blob allocations to memcg (stable-fixes). - efi: Fix reservation of unaccepted memory table (git-fixes). - efivarfs: fix error propagation in efivar_entry_get() (git-fixes). - ext4: fix iloc.bh leak in ext4_xattr_inode_update_ref (git-fixes). - fbcon: check return value of con2fb_acquire_newinfo() (git-fixes). - fbdev: au1200fb: Fix a memory leak in au1200fb_drv_probe() (git-fixes). - fbdev: ffb: fix corrupted video output on Sun FFB1 (stable-fixes). - fbdev: of: display_timing: fix refcount leak in of_get_display_timings() (git-fixes). - fbdev: rivafb: fix divide error in nv3_arb() (git-fixes). - fbdev: smscufx: properly copy ioctl memory to kernelspace (stable-fixes). - fbdev: vt8500lcdfb: fix missing dma_free_coherent() (git-fixes). - fpga: dfl: use subsys_initcall to allow built-in drivers to be added (git-fixes). - fpga: of-fpga-region: Fail if any bridge is missing (stable-fixes). - genirq: Set IRQF_COND_ONESHOT in devm_request_irq() (git-fixes). - gpio: aspeed-sgpio: Change the macro to support deferred probe (stable-fixes). - gpio: pca953x: mask interrupts in irq shutdown (stable-fixes). - gpio: sprd: Change sprd_gpio lock to raw_spin_lock (stable-fixes). - gpu/panel-edp: add AUO panel entry for B140HAN06.4 (stable-fixes). - HID: apple: Add 'SONiX KN85 Keyboard' to the list of non-apple keyboards (stable-fixes). - HID: Apply quirk HID_QUIRK_ALWAYS_POLL to Edifier QR30 (2d99:a101) (stable-fixes). - HID: elecom: Add support for ELECOM HUGE Plus M-HT1MRBK (stable-fixes). - HID: hid-pl: handle probe errors (git-fixes). - HID: i2c-hid: fix potential buffer overflow in i2c_hid_get_report() (stable-fixes). - HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients (git-fixes). - HID: intel-ish-hid: Reset enum_devices_done before enumeration (stable-fixes). - HID: intel-ish-hid: Update ishtp bus match to support device ID table (stable-fixes). - HID: logitech-hidpp: Check maxfield in hidpp_get_report_length() (stable-fixes). - HID: magicmouse: Do not crash on missing msc->input (stable-fixes). - HID: multitouch: add eGalaxTouch EXC3188 support (stable-fixes). - HID: multitouch: add MT_QUIRK_STICKY_FINGERS to MT_CLS_VTL (stable-fixes). - HID: playstation: Add missing check for input_ff_create_memless (git-fixes). - HID: playstation: Center initial joystick axes to prevent spurious events (stable-fixes). - HID: prodikeys: Check presence of pm->input_ep82 (stable-fixes). - HID: quirks: Add another Chicony HP 5MP Cameras to hid_ignore_list (stable-fixes). - hwmon: (f71882fg) Add F81968 support (stable-fixes). - hwmon: (it87) Check the it87_lock() return value (git-fixes). - hwmon: (max16065) Use READ/WRITE_ONCE to avoid compiler optimization induced race (git-fixes). - hwmon: (nct6775) Add ASUS Pro WS WRX90E-SAGE SE (stable-fixes). - hwmon: (occ) Mark occ_init_attribute() as __printf (git-fixes). - hwmon: (pmbus/q54sj108a2) fix stack overflow in debugfs read (git-fixes). - hyperv: Convert hypercall statuses to linux error codes (git-fixes). - hyperv: Move arch/x86/hyperv/hv_proc.c to drivers/hv (git-fixes). - hyperv: Move hv_current_partition_id to arch-generic code (git-fixes). - i3c: dw: Initialize spinlock to avoid upsetting lockdep (git-fixes). - i3c: master: svc: Initialize 'dev' to NULL in svc_i3c_master_ibi_isr() (stable-fixes). - i3c: master: Update hot-join flag only on success (git-fixes). - i3c: Move device name assignment after i3c_bus_init (git-fixes). - iio: gyro: itg3200: Fix unchecked return value in read_raw (git-fixes). - iio: magnetometer: Remove IRQF_ONESHOT (stable-fixes). - iio: sca3000: Fix a resource leak in sca3000_probe() (git-fixes). - iio: Use IRQF_NO_THREAD (stable-fixes). - Input: stmfts - correct wording for the warning message (git-fixes). - Input: stmfts - make comments correct (git-fixes). - iomap: account for unaligned end offsets when truncating read range (git-fixes). - ipmi: ipmb: initialise event handler read bytes (git-fixes). - ktls, sockmap: Fix missing uncharge operation (bsc#1252008). - KVM: nSVM: Clear exit_code_hi in VMCB when synthesizing nested VM-Exits (git-fixes). - KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). - KVM: x86: Don't clear async #PF queue when CR0.PG is disabled (e.g. on #SMI) (git-fixes). - KVM: x86: Explicitly set new periodic hrtimer expiration in apic_timer_fn() (git-fixes). - KVM: x86: WARN if hrtimer callback for periodic APIC timer fires with period=0 (git-fixes). - landlock: Optimize file path walks and prepare for audit support (bsc#1255698). - leds: qcom-lpg: Check the return value of regmap_bulk_write() (git-fixes). - media: adv7180: fix frame interval in progressive mode (stable-fixes). - media: amphion: Clear last_buffer_dequeued flag for DEC_CMD_START (stable-fixes). - media: amphion: Drop min_queued_buffers assignment (git-fixes). - media: ccs: Accommodate C-PHY into the calculation (git-fixes). - media: ccs: Avoid possible division by zero (git-fixes). - media: ccs: Fix setting initial sub-device state (git-fixes). - media: chips-media: wave5: Fix memory leak on codec_info allocation failure (git-fixes). - media: cx88: Add missing unmap in snd_cx88_hw_params() (git-fixes). - media: cx23885: Add missing unmap in snd_cx23885_hw_params() (git-fixes). - media: cx25821: Add missing unmap in snd_cx25821_hw_params() (git-fixes). - media: cx25821: Fix a resource leak in cx25821_dev_setup() (stable-fixes). - media: dvb-core: dmxdevfilter must always flush bufs (stable-fixes). - media: dvb-core: fix wrong reinitialization of ringbuffer on reopen (git-fixes). - media: dvb-net: fix OOB access in ULE extension header tables (git-fixes). - media: i2c/tw9903: Fix potential memory leak in tw9903_probe() (git-fixes). - media: i2c/tw9906: Fix potential memory leak in tw9906_probe() (git-fixes). - media: i2c: ov5647: Correct minimum VBLANK value (git-fixes). - media: i2c: ov5647: Correct pixel array offset (git-fixes). - media: i2c: ov5647: Fix PIXEL_RATE value for VGA mode (git-fixes). - media: i2c: ov5647: Initialize subdev before controls (git-fixes). - media: i2c: ov5647: Sensor should report RAW color space (git-fixes). - media: i2c: ov5647: use our own mutex for the ctrl lock (git-fixes). - media: ipu6: Fix RPM reference leak in probe error paths (git-fixes). - media: ipu6: Fix typo and wrong constant in ipu6-mmu.c (git-fixes). - media: mtk-mdp: Fix a reference leak bug in mtk_mdp_remove() (git-fixes). - media: mtk-mdp: Fix error handling in probe function (git-fixes). - media: omap3isp: isp_video_mbus_to_pix/pix_to_mbus fixes (stable-fixes). - media: omap3isp: isppreview: always clamp in preview_try_format() (stable-fixes). - media: omap3isp: set initial format (stable-fixes). - media: pvrusb2: fix URB leak in pvr2_send_request_ex (stable-fixes). - media: qcom: camss: vfe: Fix out-of-bounds access in vfe_isr_reg_update() (git-fixes). - media: radio-keene: fix memory leak in error path (git-fixes). - media: rkisp1: Fix filter mode register configuration (stable-fixes). - media: solo6x10: Check for out of bounds chip_id (stable-fixes). - media: tegra-video: Fix memory leak in __tegra_channel_try_format() (git-fixes). - media: uvcvideo: Fix allocation for small frame sizes (git-fixes). - media: v4l2-async: Fix error handling on steps after finding a match (stable-fixes). - media: venus: vdec: fix error state assignment for zero bytesused (git-fixes). - media: verisilicon: AV1: Fix enable cdef computation (git-fixes). - media: verisilicon: AV1: Fix tile info buffer size (git-fixes). - media: verisilicon: AV1: Fix tx mode bit setting (git-fixes). - media: verisilicon: AV1: Set IDR flag for intra_only frame type (git-fixes). - mfd: arizona: Fix regulator resource leak on wm5102_clear_write_sequencer() failure (git-fixes). - mfd: core: Add locking around 'mfd_of_node_list' (git-fixes). - mfd: tps6105x: Fix kernel-doc warnings relating to the core struct and tps6105x_mode (git-fixes). - mfd: wm8350-core: Use IRQF_ONESHOT (git-fixes). - misc: bcm_vk: Fix possible null-pointer dereferences in bcm_vk_read() (stable-fixes). - misc: eeprom: Fix EWEN/EWDS/ERAL commands for 93xx56 and 93xx66 (stable-fixes). - mmc: mmci: Fix device_node reference leak in of_get_dml_pipe_index() (git-fixes). - mmc: rtsx_pci_sdmmc: increase power-on settling delay to 5ms (git-fixes). - mtd: parsers: Fix memory leak in mtd_parser_tplink_safeloader_parse() (git-fixes). - mtd: parsers: ofpart: fix OF node refcount leak in parse_fixed_partitions() (git-fixes). - mtd: rawnand: cadence: Fix return type of CDMA send-and-wait helper (git-fixes). - mtd: rawnand: pl353: Fix software ECC support (git-fixes). - mtd: spinand: Fix kernel doc (git-fixes). - myri10ge: avoid uninitialized variable use (stable-fixes). - net: mana: Fix double destroy_workqueue on service rescan PCI path (git-fixes). - net: mana: Implement ndo_tx_timeout and serialize queue resets per port (bsc#1257472). - net: mana: Ring doorbell at 4 CQ wraparounds (git-fixes). - net: mana: Support HW link state events (bsc#1253049). - net: nfc: nci: Fix parameter validation for packet data (git-fixes). - net: nfc: nci: Fix zero-length proprietary notifications (git-fixes). - net: usb: catc: enable basic endpoint checking (git-fixes). - net: usb: kalmia: validate USB endpoints (git-fixes). - net: usb: kaweth: remove TX queue manipulation in kaweth_set_rx_mode (git-fixes). - net: usb: kaweth: validate USB endpoints (git-fixes). - net: usb: lan78xx: fix silent drop of packets with checksum errors (git-fixes). - net: usb: lan78xx: fix TX byte statistics for small packets (git-fixes). - net: usb: lan78xx: scan all MDIO addresses on LAN7801 (git-fixes). - net: usb: pegasus: enable basic endpoint checking (git-fixes). - net: usb: r8152: fix transmit queue timeout (stable-fixes). - net: usb: sr9700: remove code to drive nonexistent multicast filter (stable-fixes). - net: usb: sr9700: support devices with virtual driver CD (stable-fixes). - net: wan/fsl_ucc_hdlc: Fix dma_free_coherent() in uhdlc_memclean() (git-fixes). - net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets (git-fixes). - nfc: hci: shdlc: Stop timers and work before freeing context (git-fixes). - nfc: nci: clear NCI_DATA_EXCHANGE before calling completion callback (git-fixes). - nfc: nci: free skb on nci_transceive early error paths (git-fixes). - nfc: nxp-nci: remove interrupt trigger type (stable-fixes). - nfc: pn533: properly drop the usb interface reference on disconnect (git-fixes). - nfc: rawsock: cancel tx_work before socket teardown (git-fixes). - nfsd: check that server is running in unlock_filesystem (bsc#1257279). - nfsd: use correct loop termination in nfsd4_revoke_states() (git-fixes). - nouveau/dpcd: return EBUSY for aux xfer if the device is asleep (git-fixes). - ntb: ntb_hw_switchtec: Fix array-index-out-of-bounds access (stable-fixes). - ntb: ntb_hw_switchtec: Fix shift-out-of-bounds for 0 mw lut (stable-fixes). - NTB: ntb_transport: Fix too small buffer for debugfs_name (git-fixes). - nvme-fc: don't hold rport lock when putting ctrl (git-fixes). - nvme-fc: release admin tagset if init fails (git-fixes). - nvme-pci: disable secondary temp for Wodposit WPBSNM8 (git-fixes). - PCI/ACPI: Restrict program_hpx_type2() to AER bits (git-fixes). - PCI/IOV: Fix race between SR-IOV enable/disable and hotplug (git-fixes). - PCI/MSI: Unmap MSI-X region on error (git-fixes). - PCI/MSI: Unmap MSI-X region on error (stable-fixes). - PCI/P2PDMA: Release per-CPU pgmap ref when vm_insert_page() fails (git-fixes). - PCI/PM: Avoid redundant delays on D3hot->D3cold (git-fixes). - PCI/portdrv: Fix potential resource leak (git-fixes). - PCI: Add ACS quirk for Pericom PI7C9X2G404 switches [12d8:b404] (git-fixes). - PCI: Add ACS quirk for Qualcomm Hamoa & Glymur (git-fixes). - PCI: Add ACS quirk for Qualcomm Hamoa & Glymur (stable-fixes). - PCI: Add defines for bridge window indexing (stable-fixes). - PCI: Add PCIE_MSG_CODE_ASSERT_INTx message macros (stable-fixes). - PCI: Correct PCI_CAP_EXP_ENDPOINT_SIZEOF_V2 value (git-fixes). - PCI: Do not attempt to set ExtTag for VFs (git-fixes). - PCI: dw-rockchip: Disable BAR 0 and BAR 1 for Root Port (git-fixes). - PCI: dw-rockchip: Disable BAR 0 and BAR 1 for Root Port (stable-fixes). - PCI: Enable ACS after configuring IOMMU for OF platforms (git-fixes). - PCI: Enable ACS after configuring IOMMU for OF platforms (stable-fixes). - PCI: endpoint: Fix swapped parameters in pci_{primary/secondary}_epc_epf_unlink() functions (git-fixes). - PCI: Fix pci_slot_lock () device locking (git-fixes). - PCI: Fix pci_slot_lock () device locking (stable-fixes). - PCI: Fix pci_slot_trylock() error handling (git-fixes). - PCI: hv: Correct a comment (git-fixes). - PCI: hv: Fix warnings for missing export.h header inclusion (git-fixes). - PCI: hv: Remove unnecessary flex array in struct pci_packet (git-fixes). - PCI: hv: remove unnecessary module_init/exit functions (git-fixes). - PCI: hv: Remove unused field pci_bus in struct hv_pcibus_device (git-fixes). - PCI: Initialize RCB from pci_configure_device() (git-fixes). - PCI: Log bridge info when first enumerating bridge (stable-fixes). - PCI: Log bridge windows conditionally (stable-fixes). - PCI: Mark 3ware-9650SA Root Port Extended Tags as broken (git-fixes). - PCI: Mark ASM1164 SATA controller to avoid bus reset (git-fixes). - PCI: Mark ASM1164 SATA controller to avoid bus reset (stable-fixes). - PCI: Mark Nvidia GB10 to avoid bus reset (git-fixes). - PCI: Mark Nvidia GB10 to avoid bus reset (stable-fixes). - PCI: mediatek: Fix IRQ domain leak when MSI allocation fails (git-fixes). - PCI: Move pci_read_bridge_windows() below individual window accessors (stable-fixes). - PCI: Supply bridge device, not secondary bus, to read window details (stable-fixes). - phy: fsl-imx8mq-usb: disable bind/unbind platform driver feature (stable-fixes). - phy: mvebu-cp110-utmi: fix dr_mode property read from dts (stable-fixes). - pinctrl: equilibrium: Fix device node reference leak in pinbank_init() (git-fixes). - pinctrl: meson: mark the GPIO controller as sleeping (git-fixes). - pinctrl: qcom: sm8250-lpass-lpi: Fix i2s2_data_groups definition (git-fixes). - pinctrl: single: fix refcount leak in pcs_add_gpio_func() (git-fixes). - platform/chrome: cros_ec_lightbar: Fix response size initialization (git-fixes). - platform/chrome: cros_typec_switch: Don't touch struct fwnode_handle::dev (git-fixes). - platform/x86/amd/pmc: Add quirk for MECHREVO Wujie 15X Pro (stable-fixes). - platform/x86: classmate-laptop: Add missing NULL pointer checks (stable-fixes). - platform/x86: dell-wmi-sysman: Don't hex dump plaintext password data (git-fixes). - platform/x86: hp-bioscfg: Skip empty attribute names (git-fixes). - platform/x86: int0002: Remove IRQF_ONESHOT from request_irq() (git-fixes). - platform/x86: intel_telemetry: Fix PSS event register mask (git-fixes). - platform/x86: intel_telemetry: Fix swapped arrays in PSS output (git-fixes). - platform/x86: ISST: Add missing write block check (git-fixes). - platform/x86: panasonic-laptop: Fix sysfs group leak in error path (stable-fixes). - platform/x86: toshiba_haps: Fix memory leaks in add/remove routines (git-fixes). - PM: sleep: wakeirq: harden dev_pm_clear_wake_irq() against races (git-fixes). - PM: sleep: wakeirq: Update outdated documentation comments (git-fixes). - PM: wakeup: Handle empty list in wakeup_sources_walk_start() (git-fixes). - pmdomain: imx: gpcv2: Fix the imx8mm gpu hang due to wrong adb400 reset (git-fixes). - power: reset: nvmem-reboot-mode: respect cell size for nvmem_cell_write (git-fixes). - power: supply: ab8500: Fix use-after-free in power_supply_changed() (git-fixes). - power: supply: act8945a: Fix use-after-free in power_supply_changed() (git-fixes). - power: supply: bq27xxx: fix wrong errno when bus ops are unsupported (git-fixes). - power: supply: bq256xx: Fix use-after-free in power_supply_changed() (git-fixes). - power: supply: bq25980: Fix use-after-free in power_supply_changed() (git-fixes). - power: supply: cpcap-battery: Fix use-after-free in power_supply_changed() (git-fixes). - power: supply: goldfish: Fix use-after-free in power_supply_changed() (git-fixes). - power: supply: qcom_battmgr: Recognize 'LiP' as lithium-polymer (git-fixes). - power: supply: rt9455: Fix use-after-free in power_supply_changed() (git-fixes). - power: supply: sbs-battery: Fix use-after-free in power_supply_changed() (git-fixes). - power: supply: wm97xx: Fix NULL pointer dereference in power_supply_changed() (git-fixes). - powercap: intel_rapl_tpmi: Remove FW_BUG from invalid version check (git-fixes). - qmi_wwan: allow max_mtu above hard_mtu to control rx_urb_size (git-fixes). - rapidio: replace rio_free_net() with kfree() in rio_scan_alloc_net() (git-fixes). - RDMA/mana_ib: Add device-memory support (git-fixes). - RDMA/mana_ib: Take CQ type from the device type (git-fixes). - RDMA/rtrs-clt: For conn rejection use actual err number (git-fixes). - regmap: maple: free entry on mas_store_gfp() failure (stable-fixes). - regulator: core: fix locking in regulator_resolve_supply() error path (git-fixes). - regulator: core: move supply check earlier in set_machine_constraints() (git-fixes). - remoteproc: sysmon: Correct subsys_name_len type in QMI request (git-fixes). - Revert 'bpf: xfrm: Add bpf_xdp_get_xfrm_state() kfunc (bsc#1258860). - Revert 'drm/amd: Check if ASPM is enabled from PCIe subsystem' (git-fixes). - Revert 'drm/nouveau/disp: Set drm_mode_config_funcs.atomic_(check|commit)' (git-fixes). - Revert 'hwmon: (ibmpex) fix use-after-free in high/low store' (git-fixes). - Revert 'mfd: da9052-spi: Change read-mask to write-mask' (stable-fixes). - Revert 'mmc: rtsx_pci_sdmmc: increase power-on settling delay to 5ms' (git-fixes). - Revert 'PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV' (git-fixes). - Revert 'selftests/bpf: Add tc helpers (bsc#1258860). - Revert 'selftests/bpf: Remove '&>' usage in the selftests (bsc#1258860). - Revert 'selftests/bpf: Remove test_tc_tunnel.sh (bsc#1258860). - Revert 'selftests/bpf: Support when CONFIG_VXLAN=m (bsc#1258860). - Revert 'selftests/bpf: test_tunnel: Add ping helpers (bsc#1258860). - Revert 'selftests/bpf: test_tunnel: Remove test_tunnel.sh (bsc#1258860). - Revert 'selftests/bpf: Use make_sockaddr in test_sock_addr (bsc#1258860). - rpmsg: core: fix race in driver_override_show() and use core helper (git-fixes). - rtc: interface: Alarm race handling should not discard preceding error (git-fixes). - rtc: zynqmp: correct frequency value (stable-fixes). - s390/cio: Update purge function to unregister the unused subchannels (bsc#1254214). - s390/ipl: Clear SBP flag when bootprog is set (bsc#1258176). - s390/mm: Fix __ptep_rdp() inline assembly (bsc#1253644). - s390: Disable ARCH_WANT_OPTIMIZE_HUGETLB_VMEMMAP (bsc#1254306). - scsi: mpi3mr: Event processing debug improvement (bsc#1251186 bsc#1258832). - scsi: storvsc: Fix scheduling while atomic on PREEMPT_RT (git-fixes). - scsi: storvsc: Remove redundant ternary operators (git-fixes). - selftests/bpf: Add tc helpers (bsc#1258860). - selftests/bpf: add verifier sign extension bound computation tests (git-fixes). - selftests/bpf: Integrate test_tc_tunnel.sh tests into test_progs (bsc#1258860). - selftests/bpf: Make test_tc_tunnel.bpf.c compatible with big endian platforms (bsc#1258860). - selftests/bpf: Remove '&>' usage in the selftests (bsc#1258860). - selftests/bpf: Remove test_tc_tunnel.sh (bsc#1258860). - selftests/bpf: Support when CONFIG_VXLAN=m (bsc#1258860). - selftests/bpf: test_tunnel: Add generic_attach* helpers (bsc#1258860). - selftests/bpf: test_tunnel: Add ping helpers (bsc#1258860). - selftests/bpf: test_tunnel: Move erspan tunnel tests to test_progs (bsc#1258860). - selftests/bpf: test_tunnel: Move geneve tunnel test to test_progs (bsc#1258860). - selftests/bpf: test_tunnel: Move gre tunnel test to test_progs (bsc#1258860). - selftests/bpf: test_tunnel: Move ip6erspan tunnel test to test_progs (bsc#1258860). - selftests/bpf: test_tunnel: Move ip6geneve tunnel test to test_progs (bsc#1258860). - selftests/bpf: test_tunnel: Move ip6gre tunnel test to test_progs (bsc#1258860). - selftests/bpf: test_tunnel: Move ip6tnl tunnel tests to test_progs (bsc#1258860). - selftests/bpf: test_tunnel: Remove test_tunnel.sh (bsc#1258860). - selftests/bpf: Use connect_to_addr in test_sock_addr (bsc#1258860). - selftests/bpf: Use log_err in open_netns/close_netns (bsc#1258860). - selftests/bpf: Use make_sockaddr in test_sock_addr (bsc#1258860). - selftests/bpf: Use start_server_addr in test_sock_addr (bsc#1258860). - serial: 8250: 8250_omap.c: Clear DMA RX running status only after DMA termination is done (git-fixes). - serial: 8250: 8250_omap.c: Clear DMA RX running status only after DMA termination is done (stable-fixes). - serial: 8250_dw: handle clock enable errors in runtime_resume (git-fixes). - serial: 8250_dw: handle clock enable errors in runtime_resume (stable-fixes). - serial: imx: change SERIAL_IMX_CONSOLE to bool (git-fixes). - serial: SH_SCI: improve 'DMA support' prompt (git-fixes). - shrink_slab_memcg: clear_bits of skipped shrinkers (bsc#1256564). - soc: mediatek: svs: Fix memory leak in svs_enable_debug_write() (git-fixes). - soc: qcom: cmd-db: Use devm_memremap() to fix memory leak in cmd_db_dev_probe (git-fixes). - soc: qcom: smem: handle ENOMEM error during probe (git-fixes). - soc: ti: k3-socinfo: Fix regmap leak on probe failure (git-fixes). - soc: ti: pruss: Fix double free in pruss_clk_mux_setup() (git-fixes). - soundwire: dmi-quirks: add mapping for Avell B.ON (OEM rebranded of NUC15) (stable-fixes). - soundwire: intel_ace2x: add SND_HDA_CORE dependency (git-fixes). - spi-geni-qcom: initialize mode related registers to 0 (stable-fixes). - spi-geni-qcom: use xfer->bits_per_word for can_dma() (stable-fixes). - spi: spi-mem: Limit octal DTR constraints to octal DTR situations (git-fixes). - spi: spi-mem: Limit octal DTR constraints to octal DTR situations (stable-fixes). - spi: spi-mem: Protect dirmap_create() with spi_mem_access_start/end (git-fixes). - spi: spi-mem: Protect dirmap_create() with spi_mem_access_start/end (stable-fixes). - spi: spidev: fix lock inversion between spi_lock and buf_lock (git-fixes). - spi: stm32: fix Overrun issue at < 8bpw (stable-fixes). - spi: tegra114: Preserve SPI mode bits in def_command1_reg (git-fixes). - spi: tegra210-quad: Move curr_xfer read inside spinlock (bsc#1257952). - spi: tegra210-quad: Move curr_xfer read inside spinlock (git-fixes). - spi: tegra210-quad: Protect curr_xfer assignment in (bsc#1257952). - spi: tegra210-quad: Protect curr_xfer assignment in tegra_qspi_setup_transfer_one (git-fixes). - spi: tegra210-quad: Protect curr_xfer check in IRQ handler (bsc#1257952). - spi: tegra210-quad: Protect curr_xfer check in IRQ handler (git-fixes). - spi: tegra210-quad: Protect curr_xfer clearing in (bsc#1257952). - spi: tegra210-quad: Protect curr_xfer clearing in tegra_qspi_non_combined_seq_xfer (git-fixes). - spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer (bsc#1257952). - spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer (git-fixes). - spi: tegra210-quad: Return IRQ_HANDLED when timeout already processed (bsc#1257952). - spi: tegra210-quad: Return IRQ_HANDLED when timeout already processed transfer (git-fixes). - spi: tegra: Fix a memory leak in tegra_slink_probe() (git-fixes). - spi: wpcm-fiu: Fix potential NULL pointer dereference in wpcm_fiu_probe() (git-fixes). - spi: wpcm-fiu: Fix uninitialized res (git-fixes). - spi: wpcm-fiu: Simplify with dev_err_probe() (stable-fixes). - spi: wpcm-fiu: Use devm_platform_ioremap_resource_byname() (stable-fixes). - staging: rtl8723bs: fix memory leak on failure path (stable-fixes). - staging: rtl8723bs: fix missing status update on sdio_alloc_irq() failure (stable-fixes). - staging: rtl8723bs: fix null dereference in find_network (git-fixes). - thermal: int340x: Fix sysfs group leak on DLVR registration failure (stable-fixes). - thermal: intel: x86_pkg_temp_thermal: Handle invalid temperature (git-fixes). - tools/hv: fcopy: Fix irregularities with size of ring buffer (git-fixes). - tools/power cpupower: Reset errno before strtoull() (stable-fixes). - tools/power/x86/intel-speed-select: Fix file descriptor leak in isolate_cpus() (git-fixes). - tools: hv: Enable debug logs for hv_kvp_daemon (git-fixes). - tpm: st33zp24: Fix missing cleanup on get_burstcount() error (git-fixes). - tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure (git-fixes). - uio_hv_generic: Align ring size to system page (git-fixes). - uio_hv_generic: Use correct size for interrupt and monitor pages (git-fixes). - Update 'drm/mgag200: fix mgag200_bmc_stop_scanout()' bug number (bsc#1258153 bsc#1258226). - Update 'drm/mgag200: fix mgag200_bmc_stop_scanout()' bug number (bsc#1258153). - usb: bdc: fix sleep during atomic (git-fixes). - usb: dwc2: fix resume failure if dr_mode is host (git-fixes). - usb: gadget: tegra-xudc: Add handling for BLCG_COREPLL_PWRDN (git-fixes). - USB: serial: option: add Telit FN920C04 RNDIS compositions (stable-fixes). - usb: typec: ucsi: psy: Fix voltage and current max for non-Fixed PDOs (git-fixes). - watchdog: imx7ulp_wdt: handle the nowayout option (stable-fixes). - wifi: ath9k: debug.h: fix kernel-doc bad lines and struct ath_tx_stats (git-fixes). - wifi: ath9k: fix kernel-doc warnings in common-debug.h (git-fixes). - wifi: ath10k: fix lock protection in ath10k_wmi_event_peer_sta_ps_state_chg() (stable-fixes). - wifi: ath10k: sdio: add missing lock protection in ath10k_sdio_fw_crashed_dump() (git-fixes). - wifi: ath11k: add pm quirk for Thinkpad Z13/Z16 Gen1 (stable-fixes). - wifi: ath11k: Fix failure to connect to a 6 GHz AP (stable-fixes). - wifi: ath12k: fix preferred hardware mode calculation (stable-fixes). - wifi: cfg80211: allow only one NAN interface, also in multi radio (stable-fixes). - wifi: cfg80211: cancel rfkill_block work in wiphy_unregister() (git-fixes). - wifi: cfg80211: Fix bitrate calculation overflow for HE rates (stable-fixes). - wifi: cfg80211: Fix use_for flag update on BSS refresh (git-fixes). - wifi: cfg80211: stop NAN and P2P in cfg80211_leave (git-fixes). - wifi: cfg80211: wext: fix IGTK key ID off-by-one (git-fixes). - wifi: cw1200: Fix locking in error paths (git-fixes). - wifi: iwlegacy: add missing mutex protection in il3945_store_measurement() (stable-fixes). - wifi: iwlegacy: add missing mutex protection in il4965_store_tx_power() (stable-fixes). - wifi: iwlwifi: mvm: check the validity of noa_len (stable-fixes). - wifi: iwlwifi: mvm: pause TCM on fast resume (git-fixes). - wifi: libertas: fix WARNING in usb_tx_block (stable-fixes). - wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration (git-fixes). - wifi: mac80211: collect station statistics earlier when disconnect (stable-fixes). - wifi: mac80211: correctly check if CSA is active (stable-fixes). - wifi: mac80211: don't increment crypto_tx_tailroom_needed_cnt twice (stable-fixes). - wifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame() (git-fixes). - wifi: mac80211: ocb: skip rx_no_sta when interface is not joined (stable-fixes). - wifi: mt76: Fix possible oob access in mt76_connac2_mac_write_txwi_80211() (git-fixes). - wifi: mt76: mt7925: Fix possible oob access in mt7925_mac_write_txwi_80211() (git-fixes). - wifi: mt76: mt7996: Fix possible oob access in mt7996_mac_write_txwi_80211() (git-fixes). - wifi: radiotap: reject radiotap with unknown bits (git-fixes). - wifi: rsi: Don't default to -EOPNOTSUPP in rsi_mac80211_config (git-fixes). - wifi: rtl8xxxu: fix slab-out-of-bounds in rtl8xxxu_sta_add (git-fixes). - wifi: rtw88: 8822b: Avoid WARNING in rtw8822b_config_trx_mode() (stable-fixes). - wifi: rtw88: Fix alignment fault in rtw_core_enable_beacon() (git-fixes). - wifi: rtw88: fix DTIM period handling when conf->dtim_period is zero (stable-fixes). - wifi: rtw88: rtw8821cu: Add ID for Mercusys MU6H (stable-fixes). - wifi: rtw89: 8922a: set random mac if efuse contains zeroes (stable-fixes). - wifi: rtw89: mac: correct page number for CSI response (stable-fixes). - wifi: rtw89: pci: restore LDO setting after device resume (stable-fixes). - wifi: rtw89: ser: enable error IMR after recovering from L1 (stable-fixes). - wifi: rtw89: wow: add reason codes for disassociation in WoWLAN mode (stable-fixes). - wifi: wlcore: ensure skb headroom before skb_push (stable-fixes). - wifi: wlcore: Fix a locking bug (git-fixes). - workqueue: mark power efficient workqueue as unbounded if (bsc#1257891). - x86/hyperv: fix an indentation issue in mshyperv.h (git-fixes). - x86/hyperv: Fix usage of cpu_online_mask to get valid cpu (git-fixes). - x86/hyperv: Fix warnings for missing export.h header inclusion (git-fixes). - x86/hyperv: Use named operands in inline asm (git-fixes). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:1113-1 Released: Fri Mar 27 10:34:35 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: moderate References: 1258311,1259825 This update for crypto-policies fixes the following issues: Enables PQC key exchange support for OpenSSH (bsc#1258311, bsc#1259825) * The sntrup761x25519-sha512 hybrid keyexchange for OpenSSH is enabled. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1177-1 Released: Thu Apr 2 17:00:30 2026 Summary: Security update for tar Type: security Severity: important References: 1246399,CVE-2025-45582 This update for tar fixes the following issue: - CVE-2025-45582: file overwrite via directory traversal in crafted TAR archives (bsc#1246399). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:1228-1 Released: Thu Apr 9 10:27:25 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1144060,1176006,1181400,1182850,1185897,1187536,1189139,1199026,1203823,1205502,1206627,1214806,1246052,916845,CVE-2013-4235,CVE-2023-4641 This update for shadow fixes the following issues: shadow is updated to 4.17.2 to bring lots of features and bug fixes. - util-linux-2.41 introduced new variable: LOGIN_ENV_SAFELIST. Recognize it and update dependencies. - Set SYS_{UID,GID}_MIN to 201: After repeated similar requests to change the ID ranges we set the above mentioned value to 201. The max value will stay at 499. This range should be sufficient and will give us leeway for the future. It's not straightforward to find out which static UIDs/GIDs are used in all packages. Update to 4.17.2: * src/login_nopam.c: Fix compiler warnings #1170 * lib/chkname.c: Put limits for LOGIN_NAME_MAX and sysconf(_SC_LOGIN_NAME_MAX) #1169 * Use HTTPS in link to Wikipedia article on password strength #1164 * lib/attr.h: use C23 attributes only with gcc >= 10 #1172 * login: Fix no-pam authorization regression #1174 * man: Add Portuguese translation #1178 * Update French translation #1177 * Add cheap defense mechanisms #1171 * Add Romanian translation #1176 Update to 4.17.1: * Fix `su -` regression #1163 Update to 4.17.0: * Fix the lower part of the domain of csrand_uniform() * Fix use of volatile pointer * Use str2[u]l() instead of atoi(3) * Use a2i() in various places * Fix const correctness * Use uid_t for holding UIDs (and GIDs) * Move all sprintf(3)-like APIs to a subdirectory * Move all copying APIs to a subdirectory * Fix forever loop on ENOMEM * Fix REALLOC() nmemb calculation * Remove id(1) * Remove groups(1) * Use local time for human-readable dates * Use %F instead of %Y-%m-%d with strftime(3) * is_valid{user,group}_name(): Set errno to distinguish the reasons * Recommend --badname only if it is useful * Add fmkomstemp() to fix mode of /etc/default/useradd * Fix use-after-free bug in sgetgrent() * Update Catalan translation * Remove references to cppw, cpgr * groupadd, groupmod: Update gshadow file with -U * Added option -a for listing active users only, optimized using if aflg,return * Added information in lastlog man page for new option '-a' * Plenty of code cleanup and clarifications - Disable flushing sssd caches. The sssd's files provider is no longer available. Update to 4.16.0: * The shadow implementations of id(1) and groups(1) are deprecated in favor of the GNU coreutils and binutils versions. They will be removed in 4.17.0. * The rlogind implementation has been removed. * The libsubid major version has been bumped, since it now requires specification of the module's free() implementation. Update to 4.15.1: * Fix a bug that caused spurious error messages about unknown login.defs configuration options #967 * Adding checks for fd omission #964 * Use temporary stat buffer #974 * Fix wrong french translation #975 Update to 4.15.0 * libshadow: + Use utmpx instead of utmp. This fixes a regression introduced in 4.14.0. + Fix build error (parameter name omitted). * Build system: + Link correctly with libdl. + Install pam configs for chpasswd(8) and newusers(8) when using ./configure --with-libpam --disable-account-tools-setuid. + Merge libshadow and libmisc into a single libshadow. This fixes problems in the linker, which were reported at least in Gentoo. + Fix build with musl libc. + Support out of tree builds * useradd(8): + Set proper SELinux labels for def_usrtemplate Update to 4.14.6: * login(1): + Fix off-by-one bugs. * passwd(1): + Don't silently truncate passwords of length >= 200 characters. Instead, accept a length of PASS_MAX, and reject longer ones. * libshadow: + Fix calculation in strtoday(), which caused a wrong half-day offset in some cases (bsc#1176006) + Fix parsing of dates in get_date() (bsc#1176006) + Use utmpx instead of utmp. This fixes a regression introduced in 4.14.0. Update to 4.14.5: * Build system: + Fix regression introduced in 4.14.4, due to a typo. chgpasswd had been deleted from a Makefile variable, but it should have been chpasswd. Update to 4.14.4: * Build system: + Link correctly with libdl. + Install pam configs for chpasswd(8) and newusers(8) when using ./configure --with-libpam --disable-account-tools-setuid. * libshadow: + Fix build error (parameter name omitted). + Fix off-by-one bug. + Remove warning. Update to 4.14.3: * libshadow: Avoid null pointer dereference (#904) * Remove pam_keyinit from PAM configuration. (bsc#1199026 bsc#1203823) This was introduced for bsc#1144060. Update to 4.14.2: * libshadow: + Fix build with musl libc. + Avoid NULL dereference. + Update utmp at an initial login * useradd(8): + Set proper SELinux labels for def_usrtemplate * Manual: + Document --prefix in chage(1), chpasswd(8), and passwd(1) Update to 4.14.1: Build system: Merge libshadow and libmisc into a single libshadow. This fixes problems in the linker, which were reported at least in Gentoo. #791 - Set proper SELinux labels for new homedirs. Update to 4.14.0: * configure: add with-libbsd option * Code cleanup * Replace utmp interface #757 * new option enable-logind #674 * shadow userdel: add the adaptation to the busybox ps in 01-kill_user_procs.sh * chsh: warn if root sets a shell not listed in /etc/shells #535 * newgrp: fix potential string injection * lastlog: fix alignment of Latest header * Fix yescrypt support #748 * chgpasswd: Fix segfault in command-line options * gpasswd: Fix password leak (bsc#1214806, CVE-2023-4641) * Add --prefix to passwd, chpasswd and chage #714 (bsc#1206627) * usermod: fix off-by-one issues #701 * ch(g)passwd: Check selinux permissions upon startup #675 * sub_[ug]id_{add,remove}: fix return values * chsh: Verify that login shell path is absolute #730 * process_prefix_flag: Drop privileges * run_parts for groupadd and groupdel #706 * newgrp/useradd: always set SIGCHLD to default * useradd/usermod: add --selinux-range argument #698 * sssd: skip flushing if executable does not exist #699 * semanage: Do not set default SELinux range #676 * Add control character check #687 * usermod: respect --prefix for --gid option * Fix null dereference in basename * newuidmap and newgidmap: support passing pid as fd * Prevent out of boundary access #633 * Explicitly override only newlines #633 * Correctly handle illegal system file in tz #633 * Supporting vendor given -shells- configuration file #599 * Warn if failed to read existing /etc/nsswitch.conf * chfn: new_fields: fix wrong fields printed * Allow supplementary groups to be added via config file #586 * useradd: check if subid range exists for user #592 (rh#2012929) - Rename lastlog to lastlog.legacy to be able to switch to Y2038 safe lastlog2 as default [jsc#PED-3144] - bsc#1205502: Fix useradd audit event logging of ID field Update to 4.13: * useradd.8: fix default group ID * Revert drop of subid_init() * Georgian translation * useradd: Avoid taking unneeded space: do not reset non-existent data in lastlog * relax username restrictions * selinux: check MLS enabled before setting serange * copy_tree: use fchmodat instead of chmod * copy_tree: don't block on FIFOs * add shell linter * copy_tree: carefully treat permissions * lib/commonio: make lock failures more detailed * lib: use strzero and memzero where applicable * Update Dutch translation * Don't test for NULL before calling free * Use libc MAX() and MIN() * chage: Fix regression in print_date * usermod: report error if homedir does not exist * libmisc: minimum id check for system accounts * fix usermod -rG x y wrongly adding a group * man: add missing space in useradd.8.xml * lastlog: check for localtime() return value * Raise limit for passwd and shadow entry length * Remove adduser-old.c * useradd: Fix buffer overflow when using a prefix * Don't warn when failed to open /etc/nsswitch.conf Update to 4.12.3: Revert removal of subid_init, which should have bumped soname. So note that 4.12 through 4.12.2 were broken for subid users. Update to 4.12.2: * Address CVE-2013-4235 (TOCTTOU when copying directories) [bsc#916845] Update to 4.12.1: * Fix uk manpages Update to 4.12: * Add absolute path hint to --root * Various cleanups * Fix Ubuntu release used in CI tests * add -F options to userad * useradd manpage updates * Check for ownerid (not just username) in subid ranges * Declare file local functions static * Use strict prototypes * Do not drop const qualifier for Basename * Constify various pointers * Don't return uninitialized memory * Don't let compiler optimize away memory cleaning * Remove many obsolete compatibility checks and defines * Modify ID range check in useradd * Use 'extern 'C'' to make libsubid easier to use from C++ * French translation updates * Fix s/with-pam/with-libpam/ * Spanish translation updates * French translation fixes * Default max group name length to 32 * Fix PAM service files without-selinux * Improve manpages - groupadd, useradd, usermod - groups and id - pwck * Fix condition under which pw_dir check happens * logoutd: switch to strncat * AUTHORS: improve markdown output * Handle ERANGE errors correctly * Check for fopen NULL return * Split get_salt() into its own fn juyin) * Get salt before chroot to ensure /dev/urandom. * Chpasswd code cleanup * Work around git safe.directory enforcement * Alphabetize order in usermod help * Erase password copy on error branches * Suggest using --badname if needed * Update translation files * Correct badnames option to badname * configure: replace obsolete autoconf macros * tests: replace egrep with grep -E * Update Ukrainian translations * Cleanups - Remove redeclared variable - Remove commented out code and FIXMEs - Add header guards - Initialize local variables * CI updates - Create github workflow to install dependencies - Enable CodeQL - Update actions version * libmisc: use /dev/urandom as fallback if other methods fail Provide /etc/login.defs.d on SLE15 since we support and use it Update to 4.11.1: * build: include lib/shadowlog_internal.h in dist tarballs Update to 4.11: * Handle possible TOCTTOU issues in usermod/userdel - (CVE-2013-4235) - Use O_NOFOLLOW when copying file - Kill all user tasks in userdel * Fix useradd -D segfault * Clean up obsolete libc feature-check ifdefs * Fix -fno-common build breaks due to duplicate Prog declarations * Have single date_to_str definition * Fix libsubid SONAME version * Clarify licensing info, use SPDX. Update to 4.10: * From this release forward, su from this package should be considered deprecated. Please replace any users of it with su rom util-linux * libsubid fixes * Rename the test program list_subid_ranges to getsubids, write a manpage, so distros can ship it. * Add libeconf dep for new*idmap * Allow all group types with usermod -G * Avoid useradd generating empty subid range * Handle NULL pw_passwd * Fix default value SHA_get_salt_rounds * Use https where possible in README * Update content and format of README * Translation updates * Switch from xml2po to itstool in 'make dist' * Fix double frees * Add LOG_INIT configurable to useradd * Add CREATE_MAIL_SPOOL documentation * Create a security.md * Fix su never being SIGKILLd when trapping TERM * Fix wrong SELinux labels in several possible cases * Fix missing chmod in chadowtb_move * Handle malformed hushlogins entries * Fix groupdel segv when passwd does not exist * Fix covscan-found newgrp segfault * Remove trailing slash on hoedir * Fix passwd -l message - it does not change expirey * Fix SIGCHLD handling bugs in su and vipw * Remove special case for '' in usermod * Implement usermod -rG to remove a specific group * call pam_end() after fork in child path for su and login * useradd: In absence of /etc/passwd, assume 0 == root * lib: check NULL before freeing data * Fix pwck segfault - Really enable USERGROUPS_ENAB [bsc#1189139]. Added hardening to systemd service(s) (bsc#1181400). * Add LOGIN_KEEP_USERNAME to login.defs. * Remove PREVENT_NO_AUTH from login.defs. Only used by the unpackaged login and su. * Remove variables BCRYPT_MIN_ROUNDS, BCRYPT_MAX_ROUNDS, YESCRYPT_COST_FACTOR, not supported by the current configuratiton. * login.defs: Enable USERGROUPS_ENAB and CREATE_HOME to be compatible with other Linux distros and the other tools creating user accounts in use on openSUSE. Set HOME_MODE to 700 for security reasons and compatibility. [bsc#1189139] [bsc#1182850] Update to 4.9: * Updated translations * Major salt updates * Various coverity and cleanup fixes * Consistently use 0 to disable PASS_MIN_DAYS in man * Implement NSS support for subids and a libsubid * setfcap: retain setfcap when mapping uid 0 * login.defs: include HMAC_CRYPTO_ALGO key * selinux fixes * Fix path prefix path handling * Manpage updates * Treat an empty passwd field as invalid(Haelwenn Monnier) * newxidmap: allow running under alternative gid * usermod: check that shell is executable * Add yescript support * useradd memleak fixes * useradd: use built-in settings by default * getdefs: add foreign * buffer overflow fixes * Adding run-parts style for pre and post useradd/del - login.defs/MOTD_FILE: Use '' instead of blank entry [bsc#1187536] - Add /etc/login.defs.d directory - Enable shadowgrp so that we can set more secure group passwords using shadow. - Disable MOTD_FILE to allow the use of pam_motd to unify motd message output [bsc#1185897]. Else motd entries of e.g. cockpit will not be shown. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1310-1 Released: Tue Apr 14 12:42:12 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1259377,CVE-2026-3731 This update for libssh fixes the following issues: - CVE-2026-3731: Denial of Service via out-of-bounds read in SFTP extension name handler (bsc#1259377). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1352-1 Released: Wed Apr 15 15:36:49 2026 Summary: Security update for expat Type: security Severity: important References: 1259711,1259726,1259729,CVE-2026-32776,CVE-2026-32777,CVE-2026-32778 This update for expat fixes the following issues: - CVE-2026-32776: NULL pointer dereference when processing empty external parameter entities inside an entity declaration value (bsc#1259726). - CVE-2026-32777: denial of service due to infinite loop in DTD content parsing (bsc#1259711). - CVE-2026-32778: NULL pointer dereference in `setContext` on retry after an out-of-memory condition (bsc#1259729). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1356-1 Released: Wed Apr 15 15:43:42 2026 Summary: Security update for nfs-utils Type: security Severity: moderate References: 1246505,1259204,CVE-2025-12801 This update for nfs-utils fixes the following issue: Security fixes: - CVE-2025-12801: rpc.mountd allows a NFSv3 client to escalate their privileges and access subdirectories and subtrees of an exported directory (bsc#1259204). Other fixes: - Split from nfs-utils into its own spec and changelog file (bsc#1246505). - Split legacy libnfsidmap0 into a separate spec file (bsc#1246505). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1368-1 Released: Wed Apr 15 16:35:24 2026 Summary: Security update for libpng16 Type: security Severity: important References: 1260754,1260755,CVE-2026-33416,CVE-2026-33636 This update for libpng16 fixes the following issues: - CVE-2026-33416: use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` can lead to arbitrary code execution (bsc#1260754). - CVE-2026-33636: out-of-bounds read/write in the palette expansion on ARM Neon can lead to information leak and crashes (bsc#1260755). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1369-1 Released: Wed Apr 15 16:42:55 2026 Summary: Security update for glibc Type: security Severity: important References: 1260078,1260082,CVE-2026-4437,CVE-2026-4438 This update for glibc fixes the following issues: - CVE-2026-4437: incorrect DNS response parsing via crafted DNS server response (bsc#1260078). - CVE-2026-4438: invalid DNS hostname returned via gethostbyaddr functions (bsc#1260082). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1375-1 Released: Wed Apr 15 19:25:40 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1260441,1260442,1260443,1260444,1260445,1261678,CVE-2026-28387,CVE-2026-28388,CVE-2026-28389,CVE-2026-28390,CVE-2026-31789,CVE-2026-31790 This update for openssl-3 fixes the following issues: Security issues fixed: - CVE-2026-28387: Potential use-after-free in DANE client code (bsc#1260441). - CVE-2026-28388: NULL Pointer Dereference When Processing a Delta CRL (bsc#1260442). - CVE-2026-28389: Possible NULL dereference when processing CMS KeyAgreeRecipientInfo (bsc#1260443). - CVE-2026-31789: Heap buffer overflow in hexadecimal conversion (bsc#1260444). - CVE-2026-31790: Incorrect failure handling in RSA KEM RSASVE encapsulation (bsc#1260445). - CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678). Other updates and bugfixes: - Enable MD2 in legacy provider (jsc#PED-15724). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:1390-1 Released: Thu Apr 16 11:37:41 2026 Summary: Recommended update for mdadm Type: recommended Severity: moderate References: 1243443,1259090 This update for mdadm fixes the following issues: - Update to version 4.4+40.g243a5d9f: * avoid mdcheck_continue.timer and mdcheck_start.timer firing simultaneously (bsc#1243443, bsc#1259090) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1406-1 Released: Thu Apr 16 14:35:15 2026 Summary: Security update for util-linux Type: security Severity: moderate References: 1222465,1234736,1258859,CVE-2026-3184 This update for util-linux fixes the following issues: Security issue: - CVE-2026-3184: access control bypass due to improper hostname canonicalization in `login` (bsc#1258859). Non security issues: - recognize fuse 'portal' as a virtual file system (bsc#1234736). - fdisk: fix possible partition overlay and data corruption if EBR gap is missing (bsc#1222465). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1418-1 Released: Thu Apr 16 18:43:02 2026 Summary: Security update for iproute2 Type: security Severity: low References: 1254324,CVE-2024-58251 This update for iproute2 fixes the following issue: - CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254324). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:1426-1 Released: Fri Apr 17 10:56:41 2026 Summary: Recommended update for grub2 Type: recommended Severity: important References: 1221126,1249385,1259543 This update for grub2 fixes the following issues: - Fix missing install device check in grub2-install on PowerPC which could lead to bootlist corruption (bsc#1221126) * add mandatoryminstallmdevicemcheckmformPowerPC - Fix PowerPC network boot prefix to correctly locate grub.cfg (bsc#1249385) * use net config for boot location instead of - Fix double free in xen booting if root filesystem is Btrfs (bsc#1259543) * btrfs: add ability to boot from subvolumes * btrfs: get default subvolume ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1432-1 Released: Fri Apr 17 12:12:08 2026 Summary: Security update for libcap Type: security Severity: important References: 1261809,CVE-2026-4878 This update for libcap fixes the following issue: - CVE-2026-4878: Address a potential TOCTOU race condition in cap_set_file() (bsc#1261809). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:1434-1 Released: Fri Apr 17 12:49:03 2026 Summary: Recommended update for apparmor Type: recommended Severity: moderate References: 1225811,1259441 This update for apparmor fixes the following issues: - samba gives denied in audit with apparmor (bsc#1225811). - apparmor denies printing with profiles on sle15-sp7 (bsc#1259441). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1443-1 Released: Fri Apr 17 16:40:44 2026 Summary: Security update for NetworkManager Type: security Severity: moderate References: 1225498,1257359,CVE-2025-9615 This update for NetworkManager fixes the following issue: Security fixes: - CVE-2025-9615: Fixed non-admin user using others' certificates (bsc#1257359). Other fixes: - Don't renew DHCP lease when software devices' MAC is empty (bsc#1225498). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:1475-1 Released: Mon Apr 20 12:02:25 2026 Summary: Recommended update for sles-release Type: recommended Severity: low References: This update for sles-release fixes the following issue: - Adjust product and codestream EOL. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1510-1 Released: Tue Apr 21 08:28:12 2026 Summary: Security update for ncurses Type: security Severity: moderate References: 1259924,CVE-2025-69720 This update for ncurses fixes the following issue: - CVE-2025-69720: buffer overflow in function `analyze_string()`of `progs/infocmp.c` (bsc#1259924). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:1561-1 Released: Thu Apr 23 08:34:49 2026 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: This update for mozilla-nss fixes the following issues: Update to NSS 3.112.4: * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * RSA_EMSAEncodePSS should validate the length of mHash. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * Remove invalid PORT_Free(). * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * make ss->ssl3.hs.cookie an owned-copy of the cookie. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1602-1 Released: Fri Apr 24 13:46:25 2026 Summary: Security update for libpng16 Type: security Severity: moderate References: 1261957,CVE-2026-34757 This update for libpng16 fixes the following issue: - CVE-2026-34757: information disclosure and data corruption due to use-after-free in `png_set_PLTE`, `png_set_tRNS` and `png_set_hIST` (bsc#1261957). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1607-1 Released: Fri Apr 24 13:50:52 2026 Summary: Security update for vim Type: security Severity: important References: 1259985,1261191,1261271,CVE-2026-33412,CVE-2026-34714,CVE-2026-34982 This update for vim fixes the following issues: Update to version 9.2.0280. - CVE-2026-34982: missing input validation allows for a modeline sandbox bypass and can lead to arbitrary OS command execution (bsc#1261271). - CVE-2026-34714: missing checks allow for a `tabpanel` modeline escape and can lead to arbitrary OS command execution (bsc#1261191). - CVE-2026-33412: improper escaping of newline characters allows for command injection in `glob` and can lead to arbitrary code execution (bsc#1259985). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1661-1 Released: Thu Apr 30 14:04:53 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1243208,1245728,1251135,1251971,1252073,1252266,1252803,1253049,1253129,1255687,1256504,1256647,1256690,1257466,1257472,1257506,1257561,1257682,1257773,1257777,1258280,1258303,1258305,1258330,1258337,1258414,1258447,1258476,1259188,1259580,1259707,1259795,1259797,1259865,1259866,1259886,1259889,1259891,1259997,1259998,1260005,1260009,1260347,1260464,1260471,1260481,1260486,1260500,1260562,1260730,1260732,1260735,1260799,1261496,1261498,CVE-2025-39998,CVE-2025-68794,CVE-2025-71268,CVE-2025-71269,CVE-2026-23030,CVE-2026-23047,CVE-2026-23103,CVE-2026-23120,CVE-2026-23136,CVE-2026-23140,CVE-2026-23187,CVE-2026-23193,CVE-2026-23201,CVE-2026-23215,CVE-2026-23216,CVE-2026-23231,CVE-2026-23242,CVE-2026-23243,CVE-2026-23255,CVE-2026-23259,CVE-2026-23270,CVE-2026-23272,CVE-2026-23274,CVE-2026-23277,CVE-2026-23278,CVE-2026-23281,CVE-2026-23292,CVE-2026-23293,CVE-2026-23317,CVE-2026-23319,CVE-2026-23361,CVE-2026-23379,CVE-2026-23381,CVE-2026-23386,CVE-2026-23398,CVE-2026-23413,CVE-2 026-23414,CVE-2026-31788 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-39998: scsi: target: target_core_configfs: Add length check to avoid buffer overflow (bsc#1252073). - CVE-2025-68794: iomap: adjust read range correctly for non-block-aligned positions (bsc#1256647). - CVE-2025-71268: btrfs: fix reservation leak in some error paths when inserting inline extent (bsc#1259865). - CVE-2025-71269: btrfs: do not free data reservation in fallback from inline due to -ENOSPC (bsc#1259889). - CVE-2026-23030: phy: rockchip: inno-usb2: Fix a double free bug in rockchip_usb2phy_probe() (bsc#1257561). - CVE-2026-23047: libceph: make calc_target() set t->paused, not just clear it (bsc#1257682). - CVE-2026-23103: ipvlan: Make the addrs_lock be per port (bsc#1257773). - CVE-2026-23120: l2tp: avoid one data-race in l2tp_tunnel_del_work() (bsc#1258280). - CVE-2026-23136: libceph: reset sparse-read state in osd_fault() (bsc#1258303). - CVE-2026-23140: bpf, test_run: Subtract size of xdp_frame from allowed metadata size (bsc#1258305). - CVE-2026-23187: pmdomain: imx8m-blk-ctrl: fix out-of-range access of bc->domains (bsc#1258330). - CVE-2026-23193: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (bsc#1258414). - CVE-2026-23201: ceph: fix oops due to invalid pointer for kfree() in parse_longname() (bsc#1258337). - CVE-2026-23215: x86/vmware: Fix hypercall clobbers (bsc#1258476). - CVE-2026-23216: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (bsc#1258447). - CVE-2026-23231: netfilter: nf_tables: register hooks last when adding new chain/flowtable (bsc#1259188). - CVE-2026-23242: RDMA/siw: Fix potential NULL pointer dereference in header processing (bsc#1259795). - CVE-2026-23243: RDMA/umad: Reject negative data_len in ib_umad_write (bsc#1259797). - CVE-2026-23255: net: add proper RCU protection to /proc/net/ptype (bsc#1259891). - CVE-2026-23259: io_uring/rw: free potentially allocated iovec on cache put failure (bsc#1259866). - CVE-2026-23270: net/sched: Only allow act_ct to bind to clsact/ingress qdiscs and shared blocks (bsc#1259886). - CVE-2026-23272: netfilter: nf_tables: unconditionally bump set->nelems before insertion (bsc#1260009). - CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (bsc#1260005). - CVE-2026-23277: net/sched: teql: fix NULL pointer dereference in iptunnel_xmit on TEQL slave xmit (bsc#1259997). - CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1259998). - CVE-2026-23281: wifi: libertas: fix use-after-free in lbs_free_adapter() (bsc#1260464). - CVE-2026-23292: scsi: target: Fix recursive locking in __configfs_open_file() (bsc#1260500). - CVE-2026-23293: net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled (bsc#1260486). - CVE-2026-23317: drm/vmwgfx: Return the correct value in vmw_translate_ptr functions (bsc#1260562). - CVE-2026-23319: bpf: export bpf_link_inc_not_zero (bsc#1260735). - CVE-2026-23361: PCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry (bsc#1260732). - CVE-2026-23379: net/sched: ets: fix divide by zero in the offload path (bsc#1260481). - CVE-2026-23381: net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled (bsc#1260471). - CVE-2026-23386: gve: fix incorrect buffer cleanup in gve_tx_clean_pending_packets for QPL (bsc#1260799). - CVE-2026-23398: icmp: fix NULL pointer dereference in icmp_tag_validation() (bsc#1260730). - CVE-2026-23413: clsact: Fix use-after-free in init/destroy rollback asymmetry (bsc#1261498). - CVE-2026-23414: tls: Purge async_hold in tls_decrypt_async_wait() (bsc#1261496). - CVE-2026-31788: xen/privcmd: restrict usage in unprivileged domU (bsc#1259707). The following non security issues were fixed: - accel/qaic: Handle DBC deactivation if the owner went away (git-fixes). - ACPI: EC: clean up handlers on probe failure in acpi_ec_setup() (git-fixes). - ACPI: OSI: Add DMI quirk for Acer Aspire One D255 (stable-fixes). - ACPI: PM: Save NVS memory on Lenovo G70-35 (stable-fixes). - ACPI: processor: Fix previous acpi_processor_errata_piix4() fix (git-fixes). - ALSA: caiaq: fix stack out-of-bounds read in init_card (git-fixes). - ALSA: firewire-lib: fix uninitialized local variable (git-fixes). - ALSA: hda: cs35l56: Fix signedness error in cs35l56_hda_posture_put() (git-fixes). - ALSA: hda/conexant: Add quirk for HP ZBook Studio G4 (stable-fixes). - ALSA: hda/conexant: Fix headphone jack handling on Acer Swift SF314 (stable-fixes). - ALSA: hda/realtek: Add headset jack quirk for Thinkpad X390 (stable-fixes). - ALSA: hda/realtek: add HP Laptop 14s-dr5xxx mute LED quirk (stable-fixes). - ALSA: pci: hda: use snd_kcontrol_chip() (stable-fixes). - ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (git-fixes). - ALSA: usb-audio: Check endpoint numbers at parsing Scarlett2 mixer interfaces (stable-fixes). - ASoC: adau1372: Fix clock leak on PLL lock failure (git-fixes). - ASoC: adau1372: Fix unchecked clk_prepare_enable() return value (git-fixes). - ASoC: amd: acp-mach-common: Add missing error check for clock acquisition (git-fixes). - ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition (git-fixes). - ASoC: amd: yc: Add ASUS EXPERTBOOK BM1503CDA to quirk table (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK PM1503CDA (stable-fixes). - ASoC: cs42l43: Report insert for exotic peripherals (stable-fixes). - ASoC: detect empty DMI strings (git-fixes). - ASoC: ep93xx: Fix unchecked clk_prepare_enable() and add rollback on failure (git-fixes). - ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_put_bits() (stable-fixes). - ASoC: fsl_easrc: Fix event generation in fsl_easrc_iec958_set_reg() (stable-fixes). - ASoC: Intel: boards: fix unmet dependency on PINCTRL (git-fixes). - ASoC: Intel: catpt: Fix the device initialization (git-fixes). - ASoC: qcom: qdsp6: Fix q6apm remove ordering during ADSP stop and start (git-fixes). - ASoC: soc-core: drop delayed_work_pending() check before flush (git-fixes). - ASoC: soc-core: flush delayed work before removing DAIs and widgets (git-fixes). - ASoC: SOF: ipc4-topology: Allow bytes controls without initial payload (git-fixes). - Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (git-fixes). - Bluetooth: btusb: clamp SCO altsetting table indices (git-fixes). - Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (git-fixes). - Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt (git-fixes). - Bluetooth: hci_ll: Fix firmware leak on error path (git-fixes). - Bluetooth: hci_sync: call destroy in hci_cmd_sync_run if immediate (git-fixes). - Bluetooth: hci_sync: Fix hci_le_create_conn_sync (git-fixes). - Bluetooth: hci_sync: Remove remaining dependencies of hci_request (stable-fixes). - Bluetooth: HIDP: Fix possible UAF (git-fixes). - Bluetooth: ISO: Fix defer tests being unstable (git-fixes). - Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ (git-fixes). - Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb (git-fixes). - Bluetooth: L2CAP: Fix send LE flow credits in ACL link (git-fixes). - Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req (git-fixes). - Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp() (git-fixes). - Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user (git-fixes). - Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access (git-fixes). - Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv() (git-fixes). - Bluetooth: LE L2CAP: Disconnect if received packet's SDU exceeds IMTU (git-fixes). - Bluetooth: LE L2CAP: Disconnect if sum of payload sizes exceed SDU (git-fixes). - Bluetooth: MGMT: Fix dangling pointer on mgmt_add_adv_patterns_monitor_complete (git-fixes). - Bluetooth: MGMT: Fix list corruption and UAF in command complete handlers (git-fixes). - Bluetooth: MGMT: validate LTK enc_size on load (git-fixes). - Bluetooth: MGMT: validate mesh send advertising payload length (git-fixes). - Bluetooth: qca: fix ROM version reading on WCN3998 chips (git-fixes). - Bluetooth: Remove 3 repeated macro definitions (stable-fixes). - Bluetooth: SCO: fix race conditions in sco_sock_connect() (git-fixes). - Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (git-fixes). - Bluetooth: SMP: derive legacy responder STK authentication from MITM state (git-fixes). - Bluetooth: SMP: force responder MITM requirements before building the pairing response (git-fixes). - Bluetooth: SMP: make SM/PER/KDU/BI-04-C happy (git-fixes). - bonding: do not set usable_slaves for broadcast mode (git-fixes). - btrfs: fix zero size inode with non-zero size after log replay (git-fixes). - btrfs: log new dentries when logging parent dir of a conflicting inode (git-fixes). - btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (bsc#1257777). - can: gw: fix OOB heap access in cgw_csum_crc8_rel() (git-fixes). - can: isotp: fix tx.buf use-after-free in isotp_sendmsg() (git-fixes). - cifs: Fix locking usage for tcon fields (git-fixes). - cifs: force interface update before a fresh session setup (git-fixes). - cifs: make default value of retrans as zero (git-fixes). - cifs: some missing initializations on replay (git-fixes). - comedi: me_daq: Fix potential overrun of firmware buffer (git-fixes). - comedi: me4000: Fix potential overrun of firmware buffer (git-fixes). - comedi: ni_atmio16d: Fix invalid clean-up after failed attach (git-fixes). - comedi: Reinit dev->spinlock between attachments to low-level drivers (git-fixes). - cpufreq/amd-pstate: Remove the redundant verify() function (bsc#1252803). - cpufreq/amd-pstate: Set the initial min_freq to lowest_nonlinear_freq (bsc#1252803). - crypto: af-alg - fix NULL pointer dereference in scatterwalk (git-fixes). - crypto: caam - fix DMA corruption on long hmac keys (git-fixes). - crypto: caam - fix overflow on long hmac keys (git-fixes). - dmaengine: idxd: Fix freeing the allocated ida too late (git-fixes). - dmaengine: idxd: Fix leaking event log memory (git-fixes). - dmaengine: idxd: Fix memory leak when a wq is reset (git-fixes). - dmaengine: idxd: Fix not releasing workqueue on .release() (git-fixes). - dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() (git-fixes). - dmaengine: idxd: Remove usage of the deprecated ida_simple_xx() API (stable-fixes). - dmaengine: sh: rz-dmac: Move CHCTRL updates under spinlock (git-fixes). - dmaengine: sh: rz-dmac: Protect the driver specific lists (git-fixes). - dmaengine: xilinx: xdma: Fix regmap init error handling (git-fixes). - dmaengine: xilinx: xilinx_dma: Fix dma_device directions (git-fixes). - dmaengine: xilinx: xilinx_dma: Fix residue calculation for cyclic DMA (git-fixes). - dmaengine: xilinx: xilinx_dma: Fix unmasked residue subtraction (git-fixes). - Drivers: hv: fix missing kernel-doc description for 'size' in request_arr_init() (git-fixes). - Drivers: hv: remove stale comment (git-fixes). - Drivers: hv: vmbus: Clean up sscanf format specifier in target_cpu_store() (git-fixes). - Drivers: hv: vmbus: Fix sysfs output format for ring buffer index (git-fixes). - Drivers: hv: vmbus: Fix typos in vmbus_drv.c (git-fixes). - drm: Fix use-after-free on framebuffers and property blobs when calling drm_dev_unplug (git-fixes). - drm/amd: fix dcn 2.01 check (git-fixes). - drm/amd: Set num IP blocks to 0 if discovery fails (stable-fixes). - drm/amd/display: Add pixel_clock to amd_pp_display_configuration (stable-fixes). - drm/amd/display: Do not skip unrelated mode changes in DSC validation (git-fixes). - drm/amd/display: Fallback to boot snapshot for dispclk (stable-fixes). - drm/amd/display: Fix DisplayID not-found handling in parse_edid_displayid_vrr() (git-fixes). - drm/amd/display: Wrap dcn32_override_min_req_memclk() in DC_FP_{START, END} (git-fixes). - drm/amd/pm: add missing od setting PP_OD_FEATURE_ZERO_FAN_BIT for smu v14 (git-fixes). - drm/amd/pm: remove invalid gpu_metrics.energy_accumulator on smu v13.0.x (stable-fixes). - drm/amdgpu: apply state adjust rules to some additional HAINAN vairants (stable-fixes). - drm/amdgpu: Change AMDGPU_VA_RESERVED_TRAP_SIZE to 64KB (git-fixes). - drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib (git-fixes). - drm/amdgpu: fix gpu idle power consumption issue for gfx v12 (stable-fixes). - drm/amdgpu: Fix kernel-doc comments for some LUT properties (git-fixes). - drm/amdgpu: Fix use-after-free race in VM acquire (stable-fixes). - drm/amdgpu: keep vga memory on MacBooks with switchable graphics (stable-fixes). - drm/amdgpu: prevent immediate PASID reuse case (stable-fixes). - drm/amdgpu/gmc9.0: add bounds checking for cid (stable-fixes). - drm/amdgpu/mmhub2.0: add bounds checking for cid (stable-fixes). - drm/amdgpu/mmhub2.3: add bounds checking for cid (stable-fixes). - drm/amdgpu/mmhub3.0: add bounds checking for cid (stable-fixes). - drm/amdgpu/mmhub3.0.1: add bounds checking for cid (stable-fixes). - drm/amdgpu/mmhub3.0.2: add bounds checking for cid (stable-fixes). - drm/amdgpu/mmhub4.1.0: add bounds checking for cid (stable-fixes). - drm/amdgpu/vcn5: Add SMU dpm interface type (stable-fixes). - drm/amdkfd: Unreserve bo if queue update failed (git-fixes). - drm/ast: dp501: Fix initialization of SCU2C (git-fixes). - drm/bridge: ti-sn65dsi83: fix CHA_DSI_CLK_RANGE rounding (git-fixes). - drm/bridge: ti-sn65dsi86: Add support for DisplayPort mode with HPD (stable-fixes). - drm/exynos: vidi: fix to avoid directly dereferencing user pointer (stable-fixes). - drm/exynos/vidi: Remove redundant error handling in vidi_get_modes() (stable-fixes). - drm/i915/display: Add module param to skip retraining of dp link (bsc#1253129). - drm/i915/dp_tunnel: Fix error handling when clearing stream BW in atomic state (git-fixes). - drm/i915/dp: Use crtc_state->enhanced_framing properly on ivb/hsw CPU eDP (git-fixes). - drm/i915/dsc: Add helper for writing DSC Selective Update ET parameters (stable-fixes). - drm/i915/dsc: Add Selective Update register definitions (stable-fixes). - drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode (git-fixes). - drm/i915/gmbus: fix spurious timeout on 512-byte burst reads (git-fixes). - drm/i915/gt: Check set_default_submission() before deferencing (git-fixes). - drm/imagination: Fix deadlock in soft reset sequence (git-fixes). - drm/ioc32: stop speculation on the drm_compat_ioctl path (git-fixes). - drm/msm: Fix dma_free_attrs() buffer size (git-fixes). - drm/msm/dsi: Document DSC related pclk_rate and hdisplay calculations (stable-fixes). - drm/msm/dsi: fix hdisplay calculation when programming dsi registers (git-fixes). - drm/msm/dsi: fix pclk rate calculation for bonded dsi (git-fixes). - drm/radeon: apply state adjust rules to some additional HAINAN vairants (stable-fixes). - drm/ttm/tests: Fix build failure on PREEMPT_RT (stable-fixes). - drm/xe: Do not preempt fence signaling CS instructions (git-fixes). - drm/xe: Open-code GGTT MMIO access protection (git-fixes). - drm/xe/oa: Allow reading after disabling OA stream (git-fixes). - drm/xe/reg_sr: Fix leak on xa_store failure (git-fixes). - firmware: arm_scpi: Fix device_node reference leak in probe path (git-fixes). - gpio: mxc: map Both Edge pad wakeup to Rising Edge (git-fixes). - HID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them (stable-fixes). - HID: apple: avoid memory leak in apple_report_fixup() (stable-fixes). - HID: asus: avoid memory leak in asus_report_fixup() (stable-fixes). - HID: magicmouse: avoid memory leak in magicmouse_report_fixup() (stable-fixes). - HID: mcp2221: cancel last I2C command on read error (stable-fixes). - hv/hv_kvp_daemon: Handle IPv4 and Ipv6 combination for keyfile format (git-fixes). - hv/hv_kvp_daemon: Pass NIC name to hv_get_dns_info as well (git-fixes). - hwmon: (adm1177) fix sysfs ABI violation and current unit conversion (git-fixes). - hwmon: (axi-fan-control) Make use of dev_err_probe() (stable-fixes). - hwmon: (axi-fan-control) Use device firmware agnostic API (stable-fixes). - hwmon: (occ) Fix division by zero in occ_show_power_1() (git-fixes). - hwmon: (occ) Fix missing newline in occ_show_extended() (git-fixes). - hwmon: (peci/cputemp) Fix crit_hyst returning delta instead of absolute temperature (git-fixes). - hwmon: (peci/cputemp) Fix off-by-one in cputemp_is_visible() (git-fixes). - hwmon: (pmbus/isl68137) Add mutex protection for AVS enable sysfs attributes (git-fixes). - hwmon: (pmbus/isl68137) Fix unchecked return value and use sysfs_emit() (git-fixes). - hwmon: (pxe1610) Check return value of page-select write in probe (git-fixes). - hwmon: (tps53679) Fix device ID comparison and printing in tps53676_identify() (git-fixes). - hwmon: axi-fan: don't use driver_override as IRQ name (git-fixes). - i2c: cp2615: fix serial string NULL-deref at probe (git-fixes). - i2c: cp2615: replace deprecated strncpy with strscpy (stable-fixes). - i2c: fsi: Fix a potential leak in fsi_i2c_probe() (git-fixes). - i2c: pxa: defer reset on Armada 3700 when recovery is used (git-fixes). - idpf: nullify pointers after they are freed (git-fixes). - iio: accel: fix ADXL355 temperature signature value (git-fixes). - iio: adc: ti-adc161s626: fix buffer read on big-endian (git-fixes). - iio: chemical: bme680: Fix measurement wait duration calculation (git-fixes). - iio: chemical: sps30_i2c: fix buffer size in sps30_i2c_read_meas() (git-fixes). - iio: chemical: sps30_serial: fix buffer size in sps30_serial_read_meas() (git-fixes). - iio: dac: ad5770r: fix error return in ad5770r_read_raw() (git-fixes). - iio: dac: ds4424: reject -128 RAW value (git-fixes). - iio: frequency: adf4377: Fix duplicated soft reset mask (git-fixes). - iio: gyro: mpu3050-core: fix pm_runtime error handling (git-fixes). - iio: gyro: mpu3050-i2c: fix pm_runtime error handling (git-fixes). - iio: gyro: mpu3050: Fix incorrect free_irq() variable (git-fixes). - iio: gyro: mpu3050: Fix irq resource leak (git-fixes). - iio: gyro: mpu3050: Fix out-of-sequence free_irq() (git-fixes). - iio: gyro: mpu3050: Move iio_device_register() to correct location (git-fixes). - iio: imu: bmi160: Remove potential undefined behavior in bmi160_config_pin() (git-fixes). - iio: imu: bno055: fix BNO055_SCAN_CH_COUNT off by one (git-fixes). - iio: imu: inv_icm42600: fix odr switch to the same value (git-fixes). - iio: imu: st_lsm6dsx: Set FIFO ODR for accelerometer and gyroscope only (git-fixes). - iio: light: vcnl4035: fix scan buffer on big-endian (git-fixes). - iio: potentiometer: mcp4131: fix double application of wiper shift (git-fixes). - Input: synaptics-rmi4 - fix a locking bug in an error path (git-fixes). - irqchip/qcom-mpm: Add missing mailbox TX done acknowledgment (git-fixes). - mac80211: fix crash in ieee80211_chan_bw_change for AP_VLAN stations (stable-fixes). - media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (git-fixes). - media: tegra-video: Use accessors for pad config 'try_*' fields (stable-fixes). - mfd: omap-usb-host: Convert to platform remove callback returning void (stable-fixes). - mfd: omap-usb-host: Fix OF populate on driver rebind (git-fixes). - mfd: qcom-pm8xxx: Convert to platform remove callback returning void (stable-fixes). - mfd: qcom-pm8xxx: Fix OF populate on driver rebind (git-fixes). - misc: fastrpc: possible double-free of cctx->remote_heap (git-fixes). - mmc: sdhci-pci-gli: fix GL9750 DMA write corruption (git-fixes). - mmc: sdhci: fix timing selection for 1-bit bus width (git-fixes). - mtd: Avoid boot crash in RedBoot partition table parser (git-fixes). - mtd: rawnand: brcmnand: skip DMA during panic write (git-fixes). - mtd: rawnand: cadence: Fix error check for dma_alloc_coherent() in cadence_nand_init() (git-fixes). - mtd: rawnand: pl353: make sure optimal timings are applied (git-fixes). - mtd: rawnand: serialize lock/unlock against other NAND operations (git-fixes). - mtd: spi-nor: core: avoid odd length/address reads on 8D-8D-8D mode (stable-fixes). - mtd: spi-nor: core: avoid odd length/address writes in 8D-8D-8D mode (stable-fixes). - net: mana: Add metadata support for xdp mode (git-fixes). - net: mana: Add standard counter rx_missed_errors (git-fixes). - net: mana: Add support for auxiliary device servicing events (bsc#1251971). - net: mana: Change the function signature of mana_get_primary_netdev_rcu (bsc#1256690). - net: mana: Drop TX skb on post_work_request failure and unmap resources (git-fixes). - net: mana: Fix double destroy_workqueue on service rescan PCI path (git-fixes). - net: mana: fix spelling for mana_gd_deregiser_irq() (git-fixes). - net: mana: fix use-after-free in add_adev() error path (git-fixes). - net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown (git-fixes). - net: mana: Fix use-after-free in reset service rescan path (git-fixes). - net: mana: Fix warnings for missing export.h header inclusion (git-fixes). - net: mana: Handle hardware recovery events when probing the device (bsc#1257466). - net: mana: Handle Reset Request from MANA NIC (bsc#1245728 bsc#1251971). - net: mana: Handle SKB if TX SGEs exceed hardware limit (git-fixes). - net: mana: Handle unsupported HWC commands (git-fixes). - net: mana: Implement ndo_tx_timeout and serialize queue resets per port (bsc#1257472). - net: mana: Move hardware counter stats from per-port to per-VF context (git-fixes). - net: mana: Probe rdma device in mana driver (git-fixes). - net: mana: Reduce waiting time if HWC not responding (bsc#1252266). - net: mana: Ring doorbell at 4 CQ wraparounds (git-fixes). - net: mana: Support HW link state events (bsc#1253049). - net: mana: Trigger VF reset/recovery on health check failure due to HWC timeout (bsc#1259580). - net: mana: use ethtool string helpers (git-fixes). - net: mana: Use mana_cleanup_port_context() for rxq cleanup (git-fixes). - net: usb: aqc111: Do not perform PM inside suspend callback (git-fixes). - net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check (git-fixes). - net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check (git-fixes). - net: usb: pegasus: validate USB endpoints (stable-fixes). - net/mana: Null service_wq on setup error to prevent double destroy (git-fix). - net/mana: Null service_wq on setup error to prevent double destroy (git-fixes). - net/mlx5: Fix crash when moving to switchdev mode (git-fixes). - net/rose: fix NULL pointer dereference in rose_transmit_link on reconnect (git-fixes). - net/x25: Fix overflow when accumulating packets (git-fixes). - net/x25: Fix potential double free of skb (git-fixes). - nfc: nci: fix circular locking dependency in nci_close_device (git-fixes). - NFC: nxp-nci: allow GPIOs to sleep (git-fixes). - NFC: pn533: bound the UART receive buffer (git-fixes). - nvme: add support for dynamic quirk configuration via module parameter (bsc#1243208). - nvme: expose active quirks in sysfs (bsc#1243208). - nvme: fix memory leak in quirks_param_set() (bsc#1243208). - PCI: hv: Correct a comment (git-fixes). - PCI: hv: Remove unnecessary flex array in struct pci_packet (git-fixes). - PCI: hv: remove unnecessary module_init/exit functions (git-fixes). - PCI: hv: Remove unused field pci_bus in struct hv_pcibus_device (git-fixes). - PCI: Update BAR # and window messages (stable-fixes). - phy: ti: j721e-wiz: Fix device node reference leak in wiz_get_lane_phy_types() (git-fixes). - pinctrl: equilibrium: fix warning trace on load (git-fixes). - pinctrl: equilibrium: rename irq_chip function callbacks (stable-fixes). - pinctrl: mediatek: common: Fix probe failure for devices without EINT (git-fixes). - pinctrl: qcom: spmi-gpio: implement .get_direction() (git-fixes). - platform/olpc: olpc-xo175-ec: Fix overflow error message to print inlen (git-fixes). - platform/x86: dell-wmi: Add audio/mic mute key codes (stable-fixes). - platform/x86: intel-hid: Add Dell 14 Plus 2-in-1 to dmi_vgbs_allow_list (stable-fixes). - platform/x86: intel-hid: Enable 5-button array on ThinkPad X1 Fold 16 Gen 1 (stable-fixes). - platform/x86: ISST: Correct locked bit width (git-fixes). - platform/x86: touchscreen_dmi: Add quirk for y-inverted Goodix touchscreen on SUPI S10 (stable-fixes). - PM: runtime: Fix a race condition related to device removal (git-fixes). - RDMA/mana_ib: Access remote atomic for MRs (bsc#1251135). - RDMA/mana_ib: add additional port counters (bsc#1251135). - RDMA/mana_ib: Add device statistics support (git-fixes). - RDMA/mana_ib: Add device-memory support (git-fixes). - RDMA/mana_ib: Add EQ creation for rnic adapter (git-fixes). - RDMA/mana_ib: Add port statistics support (git-fixes). - RDMA/mana_ib: Add support of 4M, 1G, and 2G pages (git-fixes). - RDMA/mana_ib: Add support of mana_ib for RNIC and ETH nic (git-fixes). - RDMA/mana_ib: add support of multiple ports (bsc#1251135). - RDMA/mana_ib: Adding and deleting GIDs (git-fixes). - RDMA/mana_ib: Allow registration of DMA-mapped memory in PDs (git-fixes). - RDMA/mana_ib: check cqe length for kernel CQs (git-fixes). - RDMA/mana_ib: Configure mac address in RNIC (git-fixes). - RDMA/mana_ib: Create and destroy RC QP (git-fixes). - RDMA/mana_ib: Create and destroy rnic adapter (git-fixes). - RDMA/mana_ib: create and destroy RNIC cqs (git-fixes). - RDMA/mana_ib: Create and destroy UD/GSI QP (git-fixes). - RDMA/mana_ib: create EQs for RNIC CQs (git-fixes). - RDMA/mana_ib: create kernel-level CQs (git-fixes). - RDMA/mana_ib: create/destroy AH (git-fixes). - RDMA/mana_ib: Drain send wrs of GSI QP (git-fixes). - RDMA/mana_ib: Enable RoCE on port 1 (git-fixes). - RDMA/mana_ib: extend mana QP table (git-fixes). - RDMA/mana_ib: Extend modify QP (git-fixes). - RDMA/mana_ib: extend query device (git-fixes). - RDMA/mana_ib: Fix DSCP value in modify QP (git-fixes). - RDMA/mana_ib: Fix error code in probe() (git-fixes). - RDMA/mana_ib: Fix integer overflow during queue creation (bsc#1251135). - RDMA/mana_ib: Fix missing ret value (git-fixes). - RDMA/mana_ib: Handle net event for pointing to the current netdev (bsc#1256690). - RDMA/mana_ib: helpers to allocate kernel queues (git-fixes). - RDMA/mana_ib: Implement DMABUF MR support (git-fixes). - RDMA/mana_ib: implement get_dma_mr (git-fixes). - RDMA/mana_ib: Implement port parameters (git-fixes). - RDMA/mana_ib: implement req_notify_cq (git-fixes). - RDMA/mana_ib: implement uapi for creation of rnic cq (git-fixes). - RDMA/mana_ib: Implement uapi to create and destroy RC QP (git-fixes). - RDMA/mana_ib: indicate CM support (git-fixes). - RDMA/mana_ib: introduce a helper to remove cq callbacks (git-fixes). - RDMA/mana_ib: Introduce helpers to create and destroy mana queues (git-fixes). - RDMA/mana_ib: Introduce mana_ib_get_netdev helper function (git-fixes). - RDMA/mana_ib: Introduce mana_ib_install_cq_cb helper function (git-fixes). - RDMA/mana_ib: Introduce mdev_to_gc helper function (git-fixes). - RDMA/mana_ib: Modify QP state (git-fixes). - RDMA/mana_ib: polling of CQs for GSI/UD (git-fixes). - RDMA/mana_ib: Process QP error events in mana_ib (git-fixes). - RDMA/mana_ib: Query feature_flags bitmask from FW (git-fixes). - RDMA/mana_ib: remove useless return values from dbg prints (git-fixes). - RDMA/mana_ib: request error CQEs when supported (git-fixes). - RDMA/mana_ib: Set correct device into ib (git-fixes). - RDMA/mana_ib: set node_guid (git-fixes). - RDMA/mana_ib: support of the zero based MRs (bsc#1251135). - RDMA/mana_ib: Take CQ type from the device type (git-fixes). - RDMA/mana_ib: UD/GSI QP creation for kernel (git-fixes). - RDMA/mana_ib: UD/GSI work requests (git-fixes). - RDMA/mana_ib: unify mana_ib functions to support any gdma device (git-fixes). - RDMA/mana_ib: Use num_comp_vectors of ib_device (git-fixes). - RDMA/mana_ib: Use safer allocation function() (bsc#1251135). - RDMA/mana_ib: Use struct mana_ib_queue for CQs (git-fixes). - RDMA/mana_ib: Use struct mana_ib_queue for RAW QPs (git-fixes). - RDMA/mana_ib: Use struct mana_ib_queue for WQs (git-fixes). - regmap: Synchronize cache for the page selector (git-fixes). - regulator: pca9450: Correct interrupt type (git-fixes). - regulator: pca9450: Make IRQ optional (stable-fixes). - s390/debug: Pass in and enforce output buffer size for format handlers (jsc#PED-15582. - scsi: hisi_sas: Fix NULL pointer exception during user_scan() (bsc#1255687). - scsi: scsi_transport_sas: Fix the maximum channel scanning issue (bsc#1255687, git-fixes). - scsi: storvsc: Remove redundant ternary operators (git-fixes). - serial: 8250_pci: add support for the AX99100 (stable-fixes). - serial: 8250: Add late synchronize_irq() to shutdown to handle DW UART BUSY (git-fixes). - serial: 8250: Fix TX deadlock when using DMA (git-fixes). - serial: uartlite: fix PM runtime usage count underflow on probe (git-fixes). - smb: client: add proper locking around ses->iface_last_update (git-fixes). - smb: client: fix broken multichannel with krb5+signing (git-fixes). - smb: client: fix cifs_pick_channel when channels are equally loaded (git-fixes). - smb: client: fix in-place encryption corruption in SMB2_write() (git-fixes). - smb: client: fix krb5 mount with username option (git-fixes). - smb: client: prevent races in ->query_interfaces() (git-fixes). - soc: aspeed: socinfo: Mask table entries for accurate SoC ID matching (git-fixes). - soc: fsl: qbman: fix race condition in qman_destroy_fq (git-fixes). - spi: fix statistics allocation (git-fixes). - spi: fix use-after-free on controller registration failure (git-fixes). - spi: spi-fsl-lpspi: fix teardown order issue (UAF) (git-fixes). - staging: rtl8723bs: properly validate the data in rtw_get_ie_ex() (stable-fixes). - thunderbolt: Fix property read in nhi_wake_supported() (git-fixes). - tools: hv: Enable debug logs for hv_kvp_daemon (git-fixes). - tools: hv: lsvmbus: change shebang to use python3 (git-fixes). - tools/hv: add a .gitignore file (git-fixes). - tools/hv: reduce resouce usage in hv_get_dns_info helper (git-fixes). - tools/hv: reduce resource usage in hv_kvp_daemon (git-fixes). - USB: add QUIRK_NO_BOS for video capture several devices (stable-fixes). - usb: cdc-acm: Restore CAP_BRK functionnality to CH343 (git-fixes). - usb: cdns3: call cdns_power_is_lost() only once in cdns_resume() (stable-fixes). - usb: cdns3: fix role switching during resume (git-fixes). - usb: cdns3: gadget: fix NULL pointer dereference in ep_queue (git-fixes). - usb: cdns3: gadget: fix state inconsistency on gadget init failure (git-fixes). - usb: cdns3: remove redundant if branch (stable-fixes). - usb: class: cdc-wdm: fix reordering issue in read code path (git-fixes). - usb: core: don't power off roothub PHYs if phy_set_mode() fails (git-fixes). - USB: core: Limit the length of unkillable synchronous timeouts (git-fixes). - usb: core: new quirk to handle devices with zero configurations (stable-fixes). - usb: core: phy: avoid double use of 'usb3-phy' (git-fixes). - USB: dummy-hcd: Fix interrupt synchronization error (git-fixes). - USB: dummy-hcd: Fix locking/synchronization error (git-fixes). - usb: dwc2: gadget: Fix spin_lock/unlock mismatch in dwc2_hsotg_udc_stop() (git-fixes). - usb: dwc3: pci: add support for the Intel Nova Lake -H (stable-fixes). - usb: ehci-brcm: fix sleep during atomic (git-fixes). - USB: ezcap401 needs USB_QUIRK_NO_BOS to function on 10gbs usb speed (stable-fixes). - usb: gadget: f_mass_storage: Fix potential integer overflow in check_command_size_in_blocks() (git-fixes). - usb: gadget: f_rndis: Protect RNDIS options with mutex (git-fixes). - usb: gadget: f_subset: Fix unbalanced refcnt in geth_free (git-fixes). - usb: gadget: u_ether: Fix race between gether_disconnect and eth_stop (git-fixes). - usb: gadget: uvc: fix NULL pointer dereference during unbind race (git-fixes). - usb: image: mdc800: kill download URB on timeout (stable-fixes). - usb: mdc800: handle signal and read racing (stable-fixes). - usb: misc: uss720: properly clean up reference in uss720_probe() (stable-fixes). - usb: renesas_usbhs: fix use-after-free in ISR during device removal (git-fixes). - usb: roles: get usb role switch from parent only for usb-b-connector (git-fixes). - USB: serial: f81232: fix incomplete serial port generation (stable-fixes). - usb: ulpi: fix double free in ulpi_register_interface() error path (git-fixes). - USB: usbcore: Introduce usb_bulk_msg_killable() (git-fixes). - usb: usbtmc: Flush anchored URBs in usbtmc_release (git-fixes). - USB: usbtmc: Use usb_bulk_msg_killable() with user-specified timeouts (git-fixes). - usb: xhci: Fix memory leak in xhci_disable_slot() (git-fixes). - usb: xhci: Prevent interrupt storm on host controller error (HCE) (stable-fixes). - usb: yurex: fix race in probe (stable-fixes). - usb/core/quirks: Add Huawei ME906S-device to wakeup quirk (stable-fixes). - vhost: fix caching attributes of MMIO regions by setting them explicitly (git-fixes). - vmw_vsock: bypass false-positive Wnonnull warning with gcc-16 (git-fixes). - watchdog/perf: properly initialize the turbo mode timestamp and rearm counter (bsc#1256504). - wifi: ath11k: Pass the correct value of each TID during a stop AMPDU session (git-fixes). - wifi: cfg80211: cancel pmsr_free_wk in cfg80211_pmsr_wdev_down (git-fixes). - wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler() (git-fixes). - wifi: mac80211: fix NULL deref in mesh_matches_local() (git-fixes). - wifi: mac80211: Fix static_branch_dec() underflow for aql_disable (git-fixes). - wifi: mac80211: set default WMM parameters on all links (stable-fixes). - wifi: wilc1000: fix u8 overflow in SSID scan buffer size calculation (git-fixes). - wifi: wlcore: Return -ENOMEM instead of -EAGAIN if there is not enough headroom (git-fixes). - x86/platform/uv: Handle deconfigured sockets (bsc#1260347). - xen/privcmd: unregister xenstore notifier on module exit (git-fixes). - xenbus: Use .freeze/.thaw to handle xenbus devices (git-fixes). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1673-1 Released: Sat May 2 08:12:23 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1262573,CVE-2026-31431 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix one security issue The following security issue was fixed: - CVE-2026-31431: The copy.fail security issue is fixed by revert to operating out-of-place in algif_aead (bsc#1262573). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:1814-1 Released: Mon May 11 17:16:51 2026 Summary: Recommended update for suse-build-key Type: recommended Severity: moderate References: This update for suse-build-key fixes the following issues: - Import all keys if they are not yet in the RPM db. - Added post quantum cryptographic keys for SLES 15 and SLES 16: * build-pqc-15.pem * build-pqc-16.pem ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1825-1 Released: Tue May 12 10:59:44 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1264449,CVE-2026-43284 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix the following issue: - CVE-2026-43284: xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1876-1 Released: Sat May 16 00:06:36 2026 Summary: Security update for openssh Type: security Severity: important References: 1261427,1261430,CVE-2026-35385,CVE-2026-35414 This update for openssh fixes the following issues - CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427). - CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1941-1 Released: Mon May 18 09:44:34 2026 Summary: Security update for sed Type: security Severity: moderate References: 1262144,CVE-2026-5958 This update for sed fixes the following issue: - CVE-2026-5958: a TOCTOU race can allow to read attacker-controlled content and write it to an unintended file (bsc#1262144). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1978-1 Released: Mon May 18 13:52:47 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1264013,1265209,1265308,CVE-2025-54518,CVE-2026-46300,CVE-2026-46333 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-54518: x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013). - CVE-2026-46300: net: skbuff: propagate shared-frag marker through pskb_copy() (bsc#1265209). - CVE-2026-46333: ptrace: Logic bug in the Linux kernel's __ptrace_may_access() function (bsc#1265308). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2029-1 Released: Wed May 20 11:18:08 2026 Summary: Security update for vim Type: security Severity: moderate References: 1261833,CVE-2026-39881 This update for vim fixes the following issue: Security fixes: - CVE-2026-39881: command injection in NetBeans interface can lead to arbitrary file reads and writes (bsc#1261833). Other fixes: - Update to 9.2.0398. * 9.2.0398: MS-Windows: missing strptime() support * 9.2.0397: tabpanel: double-click opens a new tab * 9.2.0396: tests: Test_error_callback_terminal is flaky on macOS * 9.2.0395: tests: Test_backupskip() may read from $HOME * 9.2.0394: xxd: offsets greater than LONG_MAX print as negative * 9.2.0393: MS-Windows: link error with XPM support on UCRT64 * 9.2.0392: tests: Some tests are flaky * 9.2.0391: tests: Comment in test_vim9_cmd breaks syntax highlighting * 9.2.0390: filetype: some Beancount files are not recognized * 9.2.0389: DECRQM still leaves stray 'pp' on Apple Terminal.app * 9.2.0388: strange indent in update_topline() * 9.2.0387: DECRQM request may leave stray chars in terminal * 9.2.0386: No scroll/scrollbar support in the tabpanel * 9.2.0385: Integer overflow with 'ze' and large 'sidescrolloff' * 9.2.0384: stale Insstart after cursor move breaks undo * 9.2.0383: [security]: runtime(netrw): shell-injection via sftp: and file: URLs * 9.2.0382: Wayland: focus-stealing is non-working * 9.2.0381: Vim9: Missing check_secure() in exec_instructions() * 9.2.0380: completion: a few issues in completion code * 9.2.0379: gui.color_approx is never used * 9.2.0378: Using int as bool type in win_T struct * 9.2.0377: Using int as bool type in gui_T struct * 9.2.0376: Vim9: elseif condition compiled in dead branch * 9.2.0375: prop_find() does not find a virt text in starting line * 9.2.0374: c_CTRL-{G,T} does not handle offset * 9.2.0373: Ctrl-R mapping not triggered during completion * 9.2.0372: pum: rendering issues with multibyte text and opacity * 9.2.0371: filetype: ghostty config files are not recognized * 9.2.0370: duplicate code with literal string_T assignment * 9.2.0369: multiple definitions of STRING_INIT macro * 9.2.0368: too many strlen() calls when adding strings to dicts * 9.2.0367: runtime(netrw): ~ note expanded on MS Windows * 9.2.0366: pum: flicker when updating pum in place * 9.2.0365: using int as bool * 9.2.0364: tests: test_smoothscroll_textoff_showbreak() fails * 9.2.0363: Vim9: variable shadowed by script-local function * 9.2.0362: division by zero with smoothscroll and small windows * 9.2.0361: tests: no tests for ch_listen() with IPs * 9.2.0360: Cannot handle mouse-clicks in the tabpanel * 9.2.0359: wrong VertSplitNC highlighting on winbar * 9.2.0358: runtime(vimball): still path traversal attacks possible * 9.2.0357: [security]: command injection via backticks in tag files * 9.2.0356: Cannot apply 'scrolloff' context lines at end of file * 9.2.0355: runtime(tar): missing path traversal checks in tar#Extract() * 9.2.0354: filetype: not all Bitbake include files are recognized * 9.2.0353: Missing out-of-memory check in register.c * 9.2.0352: 'winhighlight' of left window blends into right window * 9.2.0351: repeat_string() can be improved * 9.2.0350: Enabling modelines poses a risk * 9.2.0349: cannot style non-current window separator * 9.2.0348: potential buffer underrun when setting statusline like option * 9.2.0347: Vim9: script-local variable not found * 9.2.0346: Wrong cursor position when entering command line window * 9.2.0345: Wrong autoformatting with 'autocomplete' * 9.2.0344: channel: ch_listen() can bind to network interface * 9.2.0343: tests: test_clientserver may fail on slower systems * 9.2.0342: tests: test_excmd.vim leaves swapfiles behind * 9.2.0341: some functions can be run from the sandbox * 9.2.0340: pum_redraw() may cause flicker * 9.2.0339: regexp: nfa_regmatch() allocates and frees too often * 9.2.0338: Cannot handle mouseclicks in the tabline * 9.2.0337: list indexing broken on big-endian 32-bit platforms * 9.2.0336: libvterm: no terminal reflow support * 9.2.0335: json_encode() uses recursive algorithm * 9.2.0334: GTK: window geometry shrinks with with client-side decorations * 9.2.0333: filetype: PklProject files are not recognized * 9.2.0332: popup: still opacity rendering issues * 9.2.0331: spellfile: stack buffer overflows in spell file generation * 9.2.0330: tests: some patterns in tar and zip plugin tests not strict enough * 9.2.0329: tests: test_indent.vim leaves swapfiles behind * 9.2.0328: Cannot handle mouseclicks in the statusline * 9.2.0327: filetype: uv scripts are not detected * 9.2.0326: runtime(tar): but with dotted path * 9.2.0325: runtime(tar): bug in zstd handling * 9.2.0324: 0x9b byte not unescaped in mapping * 9.2.0323: filetype: buf.lock files are not recognized * 9.2.0322: tests: test_popupwin fails * 9.2.0321: MS-Windows: No OpenType font support * 9.2.0320: several bugs with text properties * 9.2.0319: popup: rendering issues with partially transparent popups * 9.2.0318: cannot configure opacity for popup menu * 9.2.0317: listener functions do not check secure flag * 9.2.0316: [security]: command injection in netbeans interface via defineAnnoType * 9.2.0315: missing bound-checks * 9.2.0314: channel: can bind to all network interfaces * 9.2.0313: Callback channel not registered in GUI * 9.2.0312: C-type names are marked as translatable * 9.2.0311: redrawing logic with text properties can be improved * 9.2.0310: unnecessary work in vim_strchr() and find_term_bykeys() * 9.2.0309: Missing out-of-memory check to may_get_cmd_block() * 9.2.0308: Error message E1547 is wrong * 9.2.0307: more mismatches between return types and documentation * 9.2.0306: runtime(tar): some issues with lz4 support * 9.2.0305: mismatch between return types and documentation * 9.2.0304: tests: test for 9.2.0285 doesn't always fail without the fix * 9.2.0303: tests: zip plugin tests don't check for warning message properly * 9.2.0302: runtime(netrw): RFC2396 decoding double escaping spaces * 9.2.0301: Vim9: void function return value inconsistent * 9.2.0300: The vimball plugin needs some love * 9.2.0299: runtime(zip): may write using absolute paths * 9.2.0298: Some internal variables are not modified * 9.2.0297: libvterm: can improve CSI overflow code * 9.2.0296: Redundant and incorrect integer pointer casts in drawline.c * 9.2.0295: 'showcmd' shows wrong Visual block size with 'linebreak' * 9.2.0294: if_lua: lua interface does not work with lua 5.5 * 9.2.0293: :packadd may lead to heap-buffer-overflow * 9.2.0292: E340 internal error when using method call on void value * 9.2.0291: too many strlen() calls * 9.2.0290: Amiga: no support for AmigaOS 3.x * 9.2.0289: 'linebreak' may lead to wrong Visual block highlighting * 9.2.0288: libvterm: signed integer overflow parsing long CSI args * 9.2.0287: filetype: not all ObjectScript routines are recognized * 9.2.0286: still some unnecessary (int) casts in alloc() * 9.2.0285: :syn sync grouphere may go beyond end of line * 9.2.0284: tabpanel: crash when tabpanel expression returns variable line count * 9.2.0283: unnecessary (int) casts before alloc() calls * 9.2.0282: tests: Test_viminfo_len_overflow() fails * 9.2.0281: tests: Test_netrw_FileUrlEdit.. fails on Windows ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2038-1 Released: Thu May 21 15:33:31 2026 Summary: Security update for rsync Type: security Severity: important References: 1234100,1234101,1234102,1234103,1234104,1235475,1254441,1262223,1264511,1264512,1264513,1264514,1264515,1265296,CVE-2024-12084,CVE-2024-12085,CVE-2024-12086,CVE-2024-12087,CVE-2024-12088,CVE-2024-12747,CVE-2025-10158,CVE-2026-29518,CVE-2026-41035,CVE-2026-43617,CVE-2026-43618,CVE-2026-43619,CVE-2026-43620,CVE-2026-45232 This update for rsync fixes the following issues - CVE-2026-29518: Symlink-Race TOCTOU in Daemon (bsc#1264511). - CVE-2026-41035: Count of entries mismatch can lead to a use-after-free (bsc#1262223) - CVE-2026-43617: Authorization Bypass via Hostname Resolution (bsc#1264515). - CVE-2026-43618: Integer Overflow Information Disclosure (bsc#1264512). - CVE-2026-43619: Symlink Race Condition via Path-Based Syscalls (bsc#1264514). - CVE-2026-43620: Out-of-Bounds Array Read via recv_files() (bsc#1264513). - CVE-2026-45232: Off-by-one stack OOB write in HTTP CONNECT proxy response parsing (bsc#1265296). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2051-1 Released: Mon May 25 15:59:43 2026 Summary: Security update for xz Type: security Severity: important References: 1261280,CVE-2026-34743 This update for xz fixes the following issue - CVE-2026-34743: buffer overflow in lzma_index_append() (bsc#1261280). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2231-1 Released: Wed Jun 3 12:57:18 2026 Summary: Security update for glibc Type: security Severity: important References: 1261206,1262464,1262465,CVE-2026-4046,CVE-2026-5450,CVE-2026-5928 This update for glibc fixes the following issues - CVE-2026-4046: assertion failure when converting inputs may be used to remotely crash an application (bsc#1261206). - CVE-2026-5450: stdio-common: scanf %mc pattern will cause heap overflow when width > 1024 (bsc#1262465). - CVE-2026-5928: libio: ungetwc could be used to leak data on special conditions (bsc#1262464). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2236-1 Released: Wed Jun 3 13:00:40 2026 Summary: Security update for vim Type: security Severity: important References: 1262395,1264706,1264707,1264708,1265349,1265360,CVE-2026-42307,CVE-2026-43961,CVE-2026-44656,CVE-2026-45130,CVE-2026-46483 This update for vim fixes the following issues - CVE-2026-42307: Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim (bsc#1264706). - CVE-2026-43961: Vimscript Code Injection in netrw NetrwMarkFile() via crafted filename (bsc#1265349). - CVE-2026-44656: Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's: find command-line completion (bsc#1264707). - CVE-2026-45130: Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (.spl) with UTF-8 encoding active (bsc#1264708). - CVE-2026-46483: command injection via ` tar#Vimuntar()` in `runtime/autoload/tar.vim` when decompressing `.tgz` archives on Unix-like systems (bsc#1265360). Changes for vim: - Update to v9.2.0530. - Fix for incorrectly detecting scientific parameter files as bitbake recipies. (bsc#1262395) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2238-1 Released: Wed Jun 3 13:35:03 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1215199,1225897,1234634,1237452,1241166,1243603,1248754,1249104,1253122,1253754,1254518,1255160,1255752,1256863,1257183,1257631,1258518,1258718,1258826,1258849,1258850,1258854,1258855,1258856,1258857,1258961,1259186,1259199,1259222,1259461,1259484,1259485,1259535,1259672,1259799,1259806,1259857,1259868,1259869,1259870,1259871,1259873,1259878,1259995,1260010,1260012,1260018,1260428,1260468,1260483,1260484,1260485,1260489,1260497,1260501,1260504,1260505,1260507,1260522,1260523,1260526,1260527,1260528,1260529,1260530,1260531,1260532,1260533,1260536,1260537,1260538,1260541,1260544,1260546,1260549,1260550,1260551,1260552,1260553,1260555,1260561,1260566,1260572,1260580,1260581,1260728,1260729,1260731,1260800,1260801,1260811,1260989,1261020,1261287,1261295,1261348,1261412,1261503,1261504,1261505,1261507,1261555,1261581,1261582,1261584,1261585,1261601,1261602,1261618,1261628,1261632,1261636,1261637,1261638,1261641,1261644,1261645,1261648,1261669,1261679,1261685,1261686,1261687,1 261692,1261694,1261700,1261702,1261703,1261707,1261710,1261713,1261714,1261719,1261738,1261750,1261751,1261752,1261768,1261778,1261779,1261780,1261781,1261786,1261788,1261789,1261796,1261797,1261896,1262019,1262020,1262053,1262054,1262055,1262061,1262063,1262074,1262078,1262086,1262087,1262099,1262100,1262101,1262179,1262181,1262250,1262480,1262526,1262599,1262602,1262616,1262665,1262671,1262673,1262709,1262725,1262731,1262734,1262746,1262752,1262758,1263001,1263012,1263018,1263064,1263065,1263085,1263093,1263095,1263104,1263131,1263140,1263141,1263149,1263165,1263170,1263176,1263255,1263556,1263582,1263592,1263593,1263595,1263596,1263600,1263668,1263723,1263797,1263815,1263877,1263882,1263901,1263931,1263933,1263995,1264013,1264014,1264059,1264082,1264087,1264097,1264183,1264427,1264449,1264469,1264482,1264634,1264651,1264661,1264674,1264801,1264848,1265085,1265090,1265116,1265119,1265126,1265144,1265209,1265421,1265449,1265456,1265626,1265846,1265960,CVE-2023-20585,CVE-2025-40219, CVE-2025-54518,CVE-2025-68310,CVE-2025-71183,CVE-2025-71238,CVE-2026-23168,CVE-2026-23209,CVE-2026-23236,CVE-2026-23237,CVE-2026-23239,CVE-2026-23240,CVE-2026-23245,CVE-2026-23246,CVE-2026-23253,CVE-2026-23260,CVE-2026-23261,CVE-2026-23262,CVE-2026-23264,CVE-2026-23266,CVE-2026-23268,CVE-2026-23269,CVE-2026-23271,CVE-2026-23273,CVE-2026-23276,CVE-2026-23279,CVE-2026-23290,CVE-2026-23291,CVE-2026-23298,CVE-2026-23300,CVE-2026-23304,CVE-2026-23306,CVE-2026-23307,CVE-2026-23308,CVE-2026-23312,CVE-2026-23313,CVE-2026-23315,CVE-2026-23318,CVE-2026-23321,CVE-2026-23324,CVE-2026-23325,CVE-2026-23335,CVE-2026-23336,CVE-2026-23339,CVE-2026-23340,CVE-2026-23343,CVE-2026-23346,CVE-2026-23351,CVE-2026-23354,CVE-2026-23357,CVE-2026-23362,CVE-2026-23363,CVE-2026-23365,CVE-2026-23367,CVE-2026-23368,CVE-2026-23370,CVE-2026-23372,CVE-2026-23373,CVE-2026-23374,CVE-2026-23378,CVE-2026-23382,CVE-2026-23383,CVE-2026-23391,CVE-2026-23392,CVE-2026-23393,CVE-2026-23395,CVE-2026-23396,CVE-2026-23397,CVE-202 6-23399,CVE-2026-23403,CVE-2026-23404,CVE-2026-23405,CVE-2026-23406,CVE-2026-23407,CVE-2026-23408,CVE-2026-23409,CVE-2026-23410,CVE-2026-23411,CVE-2026-23412,CVE-2026-23418,CVE-2026-23419,CVE-2026-23420,CVE-2026-23426,CVE-2026-23434,CVE-2026-23440,CVE-2026-23441,CVE-2026-23442,CVE-2026-23443,CVE-2026-23445,CVE-2026-23446,CVE-2026-23447,CVE-2026-23448,CVE-2026-23449,CVE-2026-23450,CVE-2026-23452,CVE-2026-23454,CVE-2026-23455,CVE-2026-23456,CVE-2026-23457,CVE-2026-23458,CVE-2026-23460,CVE-2026-23461,CVE-2026-23462,CVE-2026-23463,CVE-2026-23465,CVE-2026-23466,CVE-2026-23468,CVE-2026-23470,CVE-2026-23472,CVE-2026-23473,CVE-2026-23474,CVE-2026-23475,CVE-2026-31389,CVE-2026-31392,CVE-2026-31393,CVE-2026-31394,CVE-2026-31395,CVE-2026-31400,CVE-2026-31402,CVE-2026-31403,CVE-2026-31404,CVE-2026-31405,CVE-2026-31407,CVE-2026-31408,CVE-2026-31411,CVE-2026-31412,CVE-2026-31415,CVE-2026-31416,CVE-2026-31417,CVE-2026-31420,CVE-2026-31421,CVE-2026-31422,CVE-2026-31423,CVE-2026-31424,CVE-2026-31425 ,CVE-2026-31426,CVE-2026-31427,CVE-2026-31428,CVE-2026-31436,CVE-2026-31449,CVE-2026-31470,CVE-2026-31488,CVE-2026-31494,CVE-2026-31496,CVE-2026-31504,CVE-2026-31505,CVE-2026-31507,CVE-2026-31512,CVE-2026-31515,CVE-2026-31519,CVE-2026-31525,CVE-2026-31528,CVE-2026-31533,CVE-2026-31547,CVE-2026-31550,CVE-2026-31565,CVE-2026-31570,CVE-2026-31586,CVE-2026-31588,CVE-2026-31602,CVE-2026-31607,CVE-2026-31622,CVE-2026-31649,CVE-2026-31656,CVE-2026-31662,CVE-2026-31668,CVE-2026-31669,CVE-2026-31675,CVE-2026-31679,CVE-2026-31681,CVE-2026-31682,CVE-2026-31684,CVE-2026-31685,CVE-2026-31694,CVE-2026-31700,CVE-2026-31738,CVE-2026-31787,CVE-2026-43009,CVE-2026-43025,CVE-2026-43027,CVE-2026-43037,CVE-2026-43038,CVE-2026-43044,CVE-2026-43050,CVE-2026-43060,CVE-2026-43088,CVE-2026-43110,CVE-2026-43120,CVE-2026-43126,CVE-2026-43190,CVE-2026-43214,CVE-2026-43265,CVE-2026-43329,CVE-2026-43330,CVE-2026-43334,CVE-2026-43365,CVE-2026-43366,CVE-2026-43419,CVE-2026-43437,CVE-2026-43441,CVE-2026-43494,CVE-20 26-43503,CVE-2026-46300 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2023-20585: x86/CPU: Fix FPDSS on Zen1 (bsc#1243603). - CVE-2025-54518: x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache (bsc#1264013). - CVE-2025-68310: s390/pci: Use pci_uevent_ers() in PCI recovery (bsc#1255160). - CVE-2025-71183: btrfs: always detect conflicting inodes when logging inode refs (bsc#1257631). - CVE-2026-23168: flex_proportions: make fprop_new_period() hardirq safe (bsc#1258826). - CVE-2026-23239: espintcp: Fix race condition in espintcp_close() (bsc#1259485). - CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1259484). - CVE-2026-23245: net/sched: act_gate: snapshot parameters with RCU on replace (bsc#1259799). - CVE-2026-23262: gve: Fix stats report corruption on queue count change (bsc#1259870). - CVE-2026-23271: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018). - CVE-2026-23276: net: move dev_xmit_recursion() helpers to net/core/dev.h (bsc#1260012). - CVE-2026-23300: net: ipv6: fix panic when IPv4 route references loopback IPv6 nexthop (bsc#1260538). - CVE-2026-23304: ipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu() (bsc#1260544). - CVE-2026-23306: scsi: pm8001: Fix use-after-free in pm8001_queue_command() (bsc#1260501). - CVE-2026-23313: i40e: Fix preempt count leak in napi poll tracepoint (bsc#1260555). - CVE-2026-23321: mptcp: pm: in-kernel: always mark signal+subflow endp as used (bsc#1260505). - CVE-2026-23335: RDMA/irdma: Fix kernel stack leak in irdma_create_user_ah() (bsc#1260550). - CVE-2026-23340: net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs (bsc#1260523). - CVE-2026-23343: xdp: produce a warning when calculated tailroom is negative (bsc#1260527). - CVE-2026-23346: mm/ioremap: define generic_ioremap_prot() and generic_iounmap() (bsc#1260529). - CVE-2026-23351: netfilter: nft_set_pipapo: split gc into unlink and reclaim phase (bsc#1260526). - CVE-2026-23354: x86/fred: Correct speculative safety in fred_extint() (bsc#1260801). - CVE-2026-23368: net: phy: register phy led_triggers during probe to avoid AB-BA deadlock (bsc#1260530). - CVE-2026-23374: blktrace: fix __this_cpu_read/write in preemptible context (bsc#1260811). - CVE-2026-23378: net/sched: act_ife: Fix metalist update behavior (bsc#1260546). - CVE-2026-23383: bpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing (bsc#1260497). - CVE-2026-23391: netfilter: xt_CT: drop pending enqueued packets on template removal (bsc#1260566). - CVE-2026-23392: netfilter: nf_tables: release flowtable after rcu grace period on error (bsc#1260531). - CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260522). - CVE-2026-23395: Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ (bsc#1260580). - CVE-2026-23397: nfnetlink_osf: validate individual option lengths in fingerprints (bsc#1260728). - CVE-2026-23399: nf_tables: nft_dynset: fix possible stateful expression memleak in error path (bsc#1261020). - CVE-2026-23412: netfilter: bpf: defer hook memory release until rcu readers are done (bsc#1261412). - CVE-2026-23419: net/rds: Fix circular locking dependency in rds_tcp_tune (bsc#1261507). - CVE-2026-23440: net/mlx5e: Fix race condition during IPSec ESN update (bsc#1261641). - CVE-2026-23441: net/mlx5e: Prevent concurrent access to IPSec ASO context (bsc#1261768). - CVE-2026-23442: ipv6: add NULL checks for idev in SRv6 paths (bsc#1261581). - CVE-2026-23445: igc: fix page fault in XDP TX timestamps handling (bsc#1261702). - CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1261779). - CVE-2026-23450: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() (bsc#1261584). - CVE-2026-23455: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (bsc#1261687). - CVE-2026-23456: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case (bsc#1261703). - CVE-2026-23457: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() (bsc#1261686). - CVE-2026-23458: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() (bsc#1261781). - CVE-2026-23461: Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user (bsc#1261707). - CVE-2026-23462: Bluetooth: HIDP: Fix possible UAF (bsc#1261710). - CVE-2026-23468: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (bsc#1261692). - CVE-2026-23472: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN (bsc#1261636). - CVE-2026-23473: io_uring/poll: fix multishot recv missing EOF on wakeup race (bsc#1261694). - CVE-2026-31395: bnxt_en: fix OOB access in DBG_BUF_PRODUCER async event handler (bsc#1261786). - CVE-2026-31400: sunrpc: fix cache_request leak in cache_release (bsc#1261645). - CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261638). - CVE-2026-31403: NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd (bsc#1261796). - CVE-2026-31404: xfs: avoid dereferencing log items after push callbacks (bsc#1261628). - CVE-2026-31407: netfilter: conntrack: add missing netlink policy validations (bsc#1261632). - CVE-2026-31411: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (bsc#1261752). - CVE-2026-31415: ipv6: avoid overflows in ip6_datagram_send_ctl() (bsc#1262099). - CVE-2026-31416: netfilter: nfnetlink_log: account for netlink header size (bsc#1262100). - CVE-2026-31420: bridge: mrp: reject zero test interval to avoid OOM panic (bsc#1262055). - CVE-2026-31421: net/sched: cls_fw: fix NULL pointer dereference on shared blocks (bsc#1262061). - CVE-2026-31422: net/sched: cls_flow: fix NULL pointer dereference on shared blocks (bsc#1262054). - CVE-2026-31423: net/sched: sch_hfsc: fix divide-by-zero in rtsc_min() (bsc#1262063). - CVE-2026-31424: netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP (bsc#1262053). - CVE-2026-31425: rds: ib: reject FRMR registration before IB connection is established (bsc#1262074). - CVE-2026-31427: netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp (bsc#1262086). - CVE-2026-31428: netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD (bsc#1262087). - CVE-2026-31436: dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() (bsc#1262602). - CVE-2026-31449: ext4: validate p_idx bounds in ext4_ext_correct_indexes (bsc#1262616). - CVE-2026-31470: virt: tdx-guest: Fix handling of host controlled 'quote' buffer length (bsc#1262665). - CVE-2026-31488: drm/amd/display: Do not skip unrelated mode changes in DSC validation (bsc#1262746). - CVE-2026-31494: net: cadence: macb: Synchronize stats calculations (bsc#1262671). - CVE-2026-31496: netfilter: nf_conntrack_expect: skip expectations in other netns via proc (bsc#1262673). - CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263085). - CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263093). - CVE-2026-31507: net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (bsc#1263095). - CVE-2026-31512: Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv() (bsc#1262734). - CVE-2026-31515: af_key: validate families in pfkey_send_migrate() (bsc#1262752). - CVE-2026-31519: btrfs: set BTRFS_ROOT_ORPHAN_CLEANUP during subvol create (bsc#1263012). - CVE-2026-31525: bpf: Fix undefined behavior in interpreter sdiv/smod for INT_MIN (bsc#1262725). - CVE-2026-31528: perf: Make sure to use pmu_ctx->pmu for groups (bsc#1263001). - CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262758). - CVE-2026-31547: drm/xe: Fix missing runtime PM reference in ccs_mode_store (bsc#1263018). - CVE-2026-31550: pmdomain: bcm: bcm2835-power: Increase ASB control timeout (bsc#1263104). - CVE-2026-31565: RDMA/irdma: Fix deadlock during netdev reset with active connections (bsc#1263064). - CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263065). - CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176). - CVE-2026-31588: KVM: x86: Use scratch field in MMIO fragment to hold small write values (bsc#1263165). - CVE-2026-31602: ALSA: ctxfi: Limit PTP to a single page (bsc#1263723). - CVE-2026-31607: usbip: validate number_of_packets in usbip_pack_ret_submit() (bsc#1263600). - CVE-2026-31622: NFC: digital: Bounds check NFC-A cascade depth in SDD response handler (bsc#1263797). - CVE-2026-31649: net: stmmac: fix integer underflow in chain mode (bsc#1263582). - CVE-2026-31656: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (bsc#1263170). - CVE-2026-31662: tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (bsc#1263131). - CVE-2026-31668: seg6: separate dst_cache for input and output paths in seg6 lwtunnel (bsc#1263140). - CVE-2026-31669: mptcp: fix slab-use-after-free in __inet_lookup_established (bsc#1263141). - CVE-2026-31675: net/sched: sch_netem: fix out-of-bounds access in packet corruption (bsc#1263556). - CVE-2026-31679: openvswitch: validate MPLS set/set_masked payload length (bsc#1263592). - CVE-2026-31681: netfilter: xt_multiport: validate range encoding in checkentry (bsc#1263593). - CVE-2026-31682: bridge: br_nd_send: linearize skb before parsing ND options (bsc#1263595). - CVE-2026-31684: net: sched: act_csum: validate nested VLAN headers (bsc#1263596). - CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263668). - CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263901). - CVE-2026-31700: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (bsc#1263882). - CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264059). - CVE-2026-31787: xen/privcmd: fix double free via VMA splitting (bsc#1262181). - CVE-2026-43009: bpf: Fix incorrect pruning due to atomic fetch precision tracking (bsc#1264014). - CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1263931). - CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1263933). - CVE-2026-43037: ip6_tunnel: clear skb2->cb in ip4ip6_err() (bsc#1263995). - CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097). - CVE-2026-43044: crypto: caam - fix DMA corruption on long hmac keys (bsc#1264087). - CVE-2026-43050: atm: lec: fix use-after-free in sock_def_readable() (bsc#1264082). - CVE-2026-43060: netfilter: nft_ct: drop pending enqueued packets on removal (bsc#1264183). - CVE-2026-43088: net: af_key: zero aligned sockaddr tail in PF_KEY exports (bsc#1264469). - CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264482). - CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr. - CVE-2026-43126: ALSA: mixer: oss: Add card disconnect checkpoints (bsc#1264634). - CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264848). - CVE-2026-43214: KVM: x86: Add SRCU protection for reading PDPTRs in __get_sregs2() (bsc#1264651). - CVE-2026-43265: KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() (bsc#1264427). - CVE-2026-43329: netfilter: flowtable: strictly check for maximum number of actions (bsc#1265085). - CVE-2026-43330: crypto: caam - fix overflow on long hmac keys (bsc#1264801). - CVE-2026-43334: Bluetooth: SMP: force responder MITM requirements before building the pairing response (bsc#1265090). - CVE-2026-43365: xfs: fix undersized l_iclog_roundoff values (bsc#1265119). - CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265116). - CVE-2026-43419: ceph: fix memory leaks in ceph_mdsc_build_path() (bsc#1264661). - CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265126). - CVE-2026-43441: net: bonding: Fix nd_tbl NULL dereference when IPv6 is disabled (bsc#1264674). - CVE-2026-43494: net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - CVE-2026-43503: net: skbuff: propagate shared-frag marker through frag-transfer helpers (bsc#1265960). - CVE-2026-46300: net: skbuff: preserve shared-frag marker during coalescing (bsc#1265209). The following non security issues were fixed: - accel/qaic: Add overflow check to remap_pfn_range during mmap (git-fixes). - ACPI: AGDI: fix missing newline in error message (git-fixes). - ACPI: CPPC: Fix related_cpus inconsistency during CPU hotplug (git-fixes). - ACPI: scan: Use acpi_dev_put() in object add error paths (git-fixes). - ACPI: video: Add backlight=native quirk for Dell OptiPlex 7770 AIO (git-fixes). - ACPI: video: force native backlight on HP OMEN 16 (8A44) (stable-fixes). - ALSA: 6fire: Fix input volume change detection (git-fixes). - ALSA: 6fire: fix use-after-free on disconnect (git-fixes). - ALSA: aoa: i2sbus: clear stale prepared state (git-fixes). - ALSA: aoa: i2sbus: fix OF node lifetime handling (git-fixes). - ALSA: aoa: Skip devices with no codecs in i2sbus_resume() (git-fixes). - ALSA: aoa: Use guard() for mutex locks (stable-fixes). - ALSA: asihpi: avoid write overflow check warning (stable-fixes). - ALSA: caiaq: Don't abort when no input device is available (git-fixes). - ALSA: caiaq: Fix control_put() result and cache rollback (git-fixes). - ALSA: caiaq: Fix potentially leftover ep1_in_urb at error path (git-fixes). - ALSA: caiaq: fix usb_dev refcount leak on probe failure (git-fixes). - ALSA: caiaq: Handle probe errors properly (git-fixes). - ALSA: caiaq: take a reference on the USB device in create_card() (git-fixes). - ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() (git-fixes). - ALSA: core: Fix potential data race at fasync handling (git-fixes). - ALSA: core: Serialize deferred fasync state checks (git-fixes). - ALSA: core: Validate compress device numbers without dynamic minors (git-fixes). - ALSA: ctxfi: Add fallback to default RSR for S/PDIF (git-fixes). - ALSA: ctxfi: Fix missing SPDIFI1 index handling (stable-fixes). - ALSA: ctxfi: Limit PTP to a single page (git-fixes). - ALSA: firewire-tascam: Do not drop unread control events (git-fixes). - ALSA: fireworks: bound device-supplied status before string array lookup (git-fixes). - ALSA: hda/realtek - fixed speaker no sound update (git-fixes). - ALSA: hda/realtek: Add HP ENVY Laptop 13-ba0xxx quirk (stable-fixes). - ALSA: hda/realtek: Add mute LED quirk for HP Pavilion 15-eg0xxx (stable-fixes). - ALSA: hda/realtek: Add quirk for ASUS ROG Flow Z13-KJP GZ302EAC (stable-fixes). - ALSA: hda/realtek: add quirk for Framework F111:000F (stable-fixes). - ALSA: hda/realtek: Add quirk for Lenovo Yoga Pro 7 14IAH10 (stable-fixes). - ALSA: hda/realtek: fix code style (ERROR: else should follow close brace '}') (git-fixes). - ALSA: hda: cs35l41: Put ACPI device on missing physical node (git-fixes). - ALSA: hda: cs35l56: Propagate ASP TX source control errors (git-fixes). - ALSA: hda: cs35l56: Put ACPI device after setting companion (git-fixes). - ALSA: hda: Fix NULL pointer dereference in snd_hda_ctl_add() (git-fixes). - ALSA: misc: Use guard() for spin locks (stable-fixes). - ALSA: scarlett2: Add missing error check when initialise Autogain Status (git-fixes). - ALSA: scarlett2: Add missing sentinel initializer field (git-fixes). - ALSA: seq: Notify client and port info changes (stable-fixes). - ALSA: seq_oss: return full count for successful SEQ_FULLSIZE writes (stable-fixes). - ALSA: usb-audio: apply quirk for MOONDROP JU Jiu (stable-fixes). - ALSA: usb-audio: Avoid false E-MU sample-rate notifications (git-fixes). - ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Evaluate packsize caps at the right place (git-fixes). - ALSA: usb-audio: Fix Audio Advantage Micro II SPDIF switch (git-fixes). - ALSA: usb-audio: Fix potential leak of pd at parsing UAC3 streams (git-fixes). - ALSA: usb-audio: Fix quirk flags for NeuralDSP Quad Cortex (stable-fixes). - ALSA: usb-audio: Fix UAC3 cluster descriptor size check (git-fixes). - ALSA: usb-audio: midi2: Restart output URBs on resume (git-fixes). - ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (git-fixes). - amdgpu/jpeg: fix deepsleep register for jpeg 5_0_0 and 5_0_2 (stable-fixes). - ASoC: amd: acp: Add DMI quirk for Valve Steam Deck OLED (git-fixes). - ASoC: amd: yc: Add DMI entry for HP Laptop 15-fc0xxx (stable-fixes). - ASoC: amd: yc: Add DMI quirk for ASUS EXPERTBOOK BM1403CDA (stable-fixes). - ASoC: amd: yc: Add DMI quirk for Thin A15 B7VF (stable-fixes). - ASoC: amd: yc: Add HP OMEN Gaming Laptop 16-ap0xxx product line in quirk table (stable-fixes). - ASoC: codecs: ab8500: Fix casting of private data (git-fixes). - ASoC: cs35l56: Destroy workqueue in probe error path (git-fixes). - ASoC: cs35l56: Don't use devres to unregister component (git-fixes). - ASoC: cs35l56: Fix hibernate write in runtime resume error path (git-fixes). - ASoC: fsl_easrc: Change the type for iec958 channel status controls (git-fixes). - ASoC: fsl_easrc: Check the variable range in fsl_easrc_iec958_put_bits() (git-fixes). - ASoC: fsl_easrc: fix comment typo (git-fixes). - ASoC: fsl_easrc: Fix value type in fsl_easrc_iec958_get_bits() (git-fixes). - ASoC: fsl_micfil: Add access property for 'VAD Detected' (git-fixes). - ASoC: fsl_micfil: Fix event generation in hwvad_put_enable() (git-fixes). - ASoC: fsl_micfil: Fix event generation in hwvad_put_init_mode() (git-fixes). - ASoC: fsl_micfil: Fix event generation in micfil_put_dc_remover_state() (git-fixes). - ASoC: fsl_micfil: Fix event generation in micfil_quality_set() (git-fixes). - ASoC: fsl_xcvr: Fix event generation for cached controls (git-fixes). - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_arc_mode_put() (git-fixes). - ASoC: fsl_xcvr: Fix event generation in fsl_xcvr_mode_put() (git-fixes). - ASoC: Intel: bytcr_wm5102: Fix MCLK leak on platform_clock_control error (git-fixes). - ASoC: qcom: q6apm-dai: reset queue ptr on trigger stop (git-fixes). - ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens (git-fixes). - ASoC: qcom: q6apm: move component registration to unmanaged version (git-fixes). - ASoC: qcom: q6apm: remove child devices when apm is removed (git-fixes). - ASoC: qcom: qdsp6: topology: check widget type before accessing data (git-fixes). - ASoC: soc-core: call missing INIT_LIST_HEAD() for card_aux_list (stable-fixes). - ASoC: SOF: compress: return the configured codec from get_params (git-fixes). - ASoC: SOF: Don't allow pointer operations on unconfigured streams (git-fixes). - ASoC: SOF: Intel: hda: Place check before dereference (git-fixes). - ASoC: SOF: topology: reject invalid vendor array size in token parser (stable-fixes). - ASoC: sti: Return errors from regmap_field_alloc() (git-fixes). - ASoC: sti: use managed regmap_field allocations (git-fixes). - ASoC: stm32_sai: fix incorrect BCLK polarity for DSP_A/B, LEFT_J (stable-fixes). - ata: ahci: force 32-bit DMA for JMicron JMB582/JMB585 (stable-fixes). - batman-adv: bla: only purge non-released claims (git-fixes). - batman-adv: bla: prevent use-after-free when deleting claims (git-fixes). - batman-adv: bla: put backbone reference on failed claim hash insert (git-fixes). - batman-adv: fix integer overflow on buff_pos (git-fixes). - batman-adv: hold claim backbone gateways by reference (git-fixes). - batman-adv: reject new tp_meter sessions during teardown (git-fixes). - batman-adv: reject oversized global TT response buffers (git-fixes). - batman-adv: stop caching unowned originator pointers in BAT IV (git-fixes). - Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (git-fixes). - Bluetooth: btmtk: validate WMT event SKB length before struct access (git-fixes). - Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (git-fixes). - Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt (git-fixes). - Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (git-fixes). - Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error (git-fixes). - Bluetooth: HIDP: serialise l2cap_unregister_user via hidp_session_sem (git-fixes). - Bluetooth: ISO: Fix data-race on dst in iso_sock_connect() (git-fixes). - Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (git-fixes). - Bluetooth: l2cap: fix MPS check in l2cap_ecred_reconf_req (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (git-fixes). - Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_state_change_cb() (git-fixes). - Bluetooth: L2CAP: Fix printing wrong information if SDU length exceeds MTU (git-fixes). - Bluetooth: RFCOMM: pull credit byte with skb_pull_data() (git-fixes). - Bluetooth: SCO: check for codecs->num_codecs == 1 before assigning to sco_pi(sk)->codec (git-fixes). - Bluetooth: SCO: fix sleeping under spinlock in sco_conn_ready (git-fixes). - Bluetooth: SCO: hold sk properly in sco_conn_ready (git-fixes). - Bluetooth: virtio_bt: clamp rx length before skb_put (git-fixes). - Bluetooth: virtio_bt: validate rx pkt_type header length (git-fixes). - btrfs: do not skip logging new dentries when logging a new name (git-fixes). - btrfs: reject root items with drop_progress and zero drop_level (git-fixes). - btrfs: replace BUG() with error handling in __btrfs_balance() (git-fixes). - can: mcp251x: add error handling for power enable in open and resume (stable-fixes). - can: raw: fix ro->uniq use-after-free in raw_rcv() (git-fixes). - can: ucan: fix devres lifetime (git-fixes). - cdc-acm: new quirk for EPSON HMD (stable-fixes). - cgroup/cpuset: Fix incorrect change to effective_xcpus in partition_xcpus_del() (bsc#1241166). - cgroup/cpuset: Fix incorrect use of cpuset_update_tasks_cpumask() in update_cpumasks_hier() (bsc#1241166). - check-for-config-changes: Exclude CC_MS_EXTENSIONS. - check-for-config-changes: Exclude HAVE_CFI_ICALL_NORMALIZE_INTEGERS{,_RUSTC}. - checkpatch: add support for Assisted-by tag (stable-fixes). - comedi: dt2815: add hardware detection to prevent crash (stable-fixes). - cpufreq: intel_pstate: Drop Arrow Lake from 'scaling factor' list (bsc#1249104). - crypto: algif_aead - Fix minimum RX size check for decryption (git-fixes). - crypto: arm64/aes - Fix 32-bit aes_mac_update() arg treated as 64-bit (git-fixes). - crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup (git-fixes). - crypto: atmel-ecc - Release client on allocation failure (git-fixes). - crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path (git-fixes). - crypto: atmel-tdes - fix DMA sync direction (git-fixes). - crypto: authencesn - reject short ahash digests during instance creation (git-fixes). - crypto: ccp - copy IV using skcipher ivsize (git-fixes). - crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (git-fixes). - crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (git-fixes). - crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (git-fixes). - crypto: ccree - fix a memory leak in cc_mac_digest() (git-fixes). - crypto: hisilicon - Fix dma_unmap_single() direction (git-fixes). - crypto: jitterentropy - replace long-held spinlock with mutex (git-fixes). - crypto: pcrypt - Fix handling of MAY_BACKLOG requests (git-fixes). - crypto: qat - fix type mismatch in RAS sysfs show functions (git-fixes). - crypto: qat - use swab32 macro (git-fixes). - crypto: sa2ul - Fix AEAD fallback algorithm names (git-fixes). - crypto: simd - reject compat registrations without __ prefixes (git-fixes). - crypto: talitos - fix SEC1 32k ahash request limitation (git-fixes). - crypto: testmgr - Hide ENOENT errors (stable-fixes). - crypto: testmgr - Hide ENOENT errors better (git-fixes). - devres: fix missing node debug info in devm_krealloc() (git-fixes). - dm init: ensure device probing has finished in dm-mod.waitfor= (git-fixes). - dmaengine: dw-axi-dmac: Remove unnecessary return statement from void function (git-fixes). - dmaengine: mxs-dma: Fix missing return value from of_dma_controller_register() (git-fixes). - dpll: zl3073x: Add support to adjust phase (bsc#1255752). - dpll: zl3073x: Fix output pin phase adjustment sign (bsc#1255752). - dpll: zl3073x: Fix output pin registration (bsc#1255752). - dpll: zl3073x: fix REF_PHASE_OFFSET_COMP register width for some chip IDs (bsc#1255752). - dpll: zl3073x: Specify phase adjustment granularity for pins (bsc#1255752). - drm/amd/display: Add NULL check for integrated_info in clk_mgr_construct (git-fixes). - drm/amd/display: Allow DCE link encoder without AUX registers (git-fixes). - drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths (git-fixes). - drm/amd/display: Change dither policy for 10 bpc output back to dithering (git-fixes). - drm/amd/display: Correct logic check error for fastboot (git-fixes). - drm/amd/display: Disable 10-bit truncation and dithering on DCE 6.x (git-fixes). - drm/amd/display: Disable fastboot on DCE 6 too (stable-fixes). - drm/amd/display: Read EDID from VBIOS embedded panel info (git-fixes). - drm/amd/pm/ci: Clear EnabledForActivity field for memory levels (git-fixes). - drm/amd/pm/ci: Disable MCLK DPM on problematic CI ASICs (git-fixes). - drm/amd/pm/ci: Fill DW8 fields from SMC (git-fixes). - drm/amd/pm/ci: Fix powertune defaults for Hawaii 0x67B0 (git-fixes). - drm/amd/pm/ci: Use highest MCLK on CI when MCLK DPM is disabled (git-fixes). - drm/amd/pm/smu7: Add SCLK cap for quirky Hawaii board (git-fixes). - drm/amd/pm/smu7: Fix SMU7 voltage dependency on display clock (git-fixes). - drm/amd/pm: fix incorrect FeatureCtrlMask setting on smu v14.0.x (git-fixes). - drm/amdgpu/gfx6: Support harvested SI chips with disabled TCCs (v2) (git-fixes). - drm/amdgpu/gfx9: drop unnecessary 64-bit fence flag check in KIQ (stable-fixes). - drm/amdgpu/gfx10: look at the right prop for gfx queue priority (git-fixes). - drm/amdgpu/gfx11: look at the right prop for gfx queue priority (git-fixes). - drm/amdgpu/gmc: Fix AMDGPU_GART_PLACEMENT_LOW to not overlap with VRAM (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring (git-fixes). - drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring (git-fixes). - drm/amdgpu/pm: add missing revision check for CI (git-fixes). - drm/amdgpu/pm: align Hawaii mclk workaround with radeon (git-fixes). - drm/amdgpu/pm: drop SMU driver if version not matched messages (stable-fixes). - drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (git-fixes). - drm/amdgpu/vce: Prevent partial address patches (stable-fixes). - drm/amdgpu/vcn3: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn4: Avoid overflow on msg bound check (git-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg (stable-fixes). - drm/amdgpu/vcn4: Prevent OOB reads when parsing IB (stable-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring (git-fixes). - drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring (git-fixes). - drm/amdgpu: Add bounds checking to ib_{get,set}_value (stable-fixes). - drm/amdgpu: Add default case in DVI mode validation (git-fixes). - drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG (git-fixes). - drm/amdgpu: fix the idr allocation flags (git-fixes). - drm/amdgpu: fix zero-size GDS range init on RDNA4 (stable-fixes). - drm/amdgpu: gate VM CPU HDP flush on reset lock (stable-fixes). - drm/amdgpu: replace PASID IDR with XArray (git-fixes). - drm/amdgpu: Use SMUIO 15.0.0 offsets for TSC upper and lower count (stable-fixes). - drm/amdgpu: zero-initialize GART table on allocation (stable-fixes). - drm/amdkfd: Add upper bound check for num_of_nodes (stable-fixes). - drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (stable-fixes). - drm/amdkfd: Make all TLB-flushes heavy-weight (stable-fixes). - drm/amdkfd: validate SVM ioctl nattr against buffer size (stable-fixes). - drm/arcpgu: fix device node leak (git-fixes). - drm/bridge: cadence: cdns-mhdp8546-core: Add mode_valid hook to drm_bridge_funcs (git-fixes). - drm/bridge: cadence: cdns-mhdp8546-core: Handle HDCP state in bridge atomic check (git-fixes). - drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable() (git-fixes). - drm/bridge: stm_lvds: Do not fail atomic_check on disabled connector (git-fixes). - drm/etnaviv: Fix armed job not being pushed to the DRM scheduler (git-fixes). - drm/exynos: remove bridge when component_add fails (git-fixes). - drm/fb-helper: Fix clipping when damage area spans a single scanline (git-fixes). - drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (git-fixes). - drm/gma500/oaktrail_hdmi: fix i2c adapter leak on setup (git-fixes). - drm/gma500/oaktrail_lvds: fix hang on init failure (git-fixes). - drm/gma500/oaktrail_lvds: fix i2c adapter leaks on init (git-fixes). - drm/i915/dp: Fix VSC dynamic range signaling for RGB formats (git-fixes). - drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (git-fixes). - drm/i915/wm: Verify the correct plane DDB entry (git-fixes). - drm/i915: skip __i915_request_skip() for already signaled requests (git-fixes). - drm/imagination: Switch reset_reason fields from enum to u32 (git-fixes). - drm/komeda: fix integer overflow in AFBC framebuffer size check (git-fixes). - drm/loongson: Use managed KMS polling (git-fixes). - drm/msm/a6xx: Fix dumping A650+ debugbus blocks (git-fixes). - drm/msm/a6xx: Fix HLSQ register dumping (git-fixes). - drm/msm/a6xx: Use barriers while updating HFI Q headers (git-fixes). - drm/msm/dpu: fix mismatch between power and frequency (git-fixes). - drm/msm/dsi: add the missing parameter description (git-fixes). - drm/msm/dsi: fix bits_per_pclk (git-fixes). - drm/msm/dsi: fix hdisplay calculation for CMD mode panel (git-fixes). - drm/msm/dsi: rename MSM8998 DSI version from V2_2_0 to V2_0_0 (git-fixes). - drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata() (git-fixes). - drm/msm/shrinker: Fix can_block() logic (git-fixes). - drm/msm: add missing MODULE_DEVICE_ID definitions (git-fixes). - drm/nouveau: fix nvkm_device leak on aperture removal failure (git-fixes). - drm/nouveau: fix u32 overflow in pushbuf reloc bounds check (git-fixes). - drm/panel: boe-tv101wum-nl6: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: himax-hx83102: restore MODE_LPM after sending disable cmds (git-fixes). - drm/panel: sharp-ls043t1le01: make use of prepare_prev_first (git-fixes). - drm/panel: simple: Correct G190EAN01 prepare timing (git-fixes). - drm/panfrost: Fix wait_bo ioctl leaking positive return from dma_resv_wait_timeout() (git-fixes). - drm/panthor: Fix outdated function documentation (git-fixes). - drm/radeon: add missing revision check for CI (git-fixes). - drm/sun4i: backend: fix error pointer dereference (git-fixes). - drm/sun4i: Fix resource leaks (git-fixes). - drm/v3d: Handle error from drm_sched_entity_init() (git-fixes). - drm/vc4: Fix a memory leak in hang state error path (git-fixes). - drm/vc4: Fix memory leak of BO array in hang state (git-fixes). - drm/vc4: platform_get_irq_byname() returns an int (stable-fixes). - drm/vc4: Protect madv read in vc4_gem_object_mmap() with madv_lock (git-fixes). - drm/vc4: Release runtime PM reference after binding V3D (git-fixes). - drm/vram: remove DRM_VRAM_MM_FILE_OPERATIONS from docs (git-fixes). - drm/xe/bo: Fix bo leak on GGTT flag validation in xe_bo_init_locked() (git-fixes). - drm/xe/bo: Fix bo leak on unaligned size validation in xe_bo_init_locked() (git-fixes). - drm/xe/debugfs: Correct printing of register whitelist ranges (git-fixes). - drm/xe/dma-buf: handle empty bo and UAF races (git-fixes). - drm/xe/gsc: Fix BO leak on error in query_compatibility_version() (git-fixes). - drm/xe/uapi: update used tracking kernel-doc (git-fixes). - drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() (git-fixes). - drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl() (git-fixes). - dt-bindings: net: Fix Tegra234 MGBE PTP clock (git-fixes). - efi/capsule-loader: fix incorrect sizeof in phys array reallocation (git-fixes). - efi: pstore: Drop efivar lock when efi_pstore_open() returns with an error (git-fixes). - ext4: fix fsync(2) for nojournal mode (git-fixes). - ext4: make recently_deleted() properly work with lazy itable initialization (git-fixes). - ext4: reject mount if bigalloc with s_first_data_block != 0 (git-fixes). - extcon: ptn5150: handle pending IRQ events during system resume (git-fixes). - fbdev: matroxfb: Mark variable with __maybe_unused to avoid W=1 build break (git-fixes). - fbdev: offb: fix PCI device reference leak on probe failure (git-fixes). - fbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (stable-fixes). - fbdev: udlfb: add vm_ops to dlfb_ops_mmap to prevent use-after-free (stable-fixes). - fbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO (git-fixes). - firmware: dmi: Correct an indexing error in dmi.h (git-fixes). - gpio: tegra: fix irq_release_resources calling enable instead of disable (git-fixes). - gtp: disable BH before calling udp_tunnel_xmit_skb() (git-fixes). - HID: alps: fix NULL pointer dereference in alps_raw_event() (git-fixes). - HID: asus: do not abort probe when not necessary (git-fixes). - HID: asus: make asus_resume adhere to linux kernel coding standards (git-fixes). - HID: core: clamp report_size in s32ton() to avoid undefined shift (stable-fixes). - HID: multitouch: Check to ensure report responses match the request (stable-fixes). - HID: playstation: Clamp num_touch_reports (git-fixes). - HID: quirks: add HID_QUIRK_ALWAYS_POLL for 8BitDo Pro 3 (stable-fixes). - HID: roccat: fix use-after-free in roccat_report_event (stable-fixes). - HID: usbhid: fix deadlock in hid_post_reset() (git-fixes). - HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (stable-fixes). - hv_sock: fix ARM64 support (git-fixes). - hwmon: (ads7871) Fix endianness bug in 16-bit register reads (git-fixes). - hwmon: (corsair-psu) Close HID device on probe errors (git-fixes). - hwmon: (lm63) Add locking to avoid TOCTOU (git-fixes). - hwmon: (ltc2992) Clamp threshold writes to hardware range (git-fixes). - hwmon: (ltc2992) Fix u32 overflow in power read path (git-fixes). - i2c: s3c24xx: check the size of the SMBUS message before using it (stable-fixes). - i2c: smbus: reject oversized block transfers in the common path (git-fixes). - i2c: stm32f7: reinit_completion() per transfer not per msg (git-fixes). - i2c: stub: Reject I2C block transfers with invalid length (git-fixes). - i3c: master: Fix error codes at send_ccc_cmd (git-fixes). - i3c: mipi-i3c-hci: fix IBI payload length calculation for final status (git-fixes). - ibmveth: Disable GSO for packets with small MSS (bsc#1265144). - ice: set max queues in alloc_etherdev_mqs() (git-fixes). - iio: adc: ad7768-1: fix one-shot mode data acquisition (git-fixes). - iio: adc: ti-adc161s626: use DMA-safe memory for spi_read() (git-fixes). - iio: adc: ti-ads7950: use iio_push_to_buffers_with_ts_unaligned() (git-fixes). - Input: i8042 - add TUXEDO InfinityBook Max 16 Gen10 AMD to i8042 quirk table (stable-fixes). - Input: uinput - fix circular locking dependency with ff-core (git-fixes). - Input: uinput - take event lock when submitting FF request 'event' (stable-fixes). - Input: xpad - add support for BETOP BTP-KP50B/C controller's wireless mode (stable-fixes). - Input: xpad - add support for Razer Wolverine V3 Pro (stable-fixes). - intel_idle: add Clearwater Forest SoC support (jsc#PED-10383). - ipmi: Add limits to event and receive message requests (git-fixes). - ipmi: Check event message buffer response for bad data (git-fixes). - ipmi: ssif_bmc: change log level to dbg in irq callback (git-fixes). - ipmi: ssif_bmc: fix message desynchronization after truncated response (git-fixes). - ipmi: ssif_bmc: fix missing check for copy_to_user() partial failure (git-fixes). - irqchip/irq-pic32-evic: Address warning related to wrong printf() formatter (git-fixes). - kdump, documentation: describe craskernel CMA reservation (jsc#PED-7249). - KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (git-fixes). - KVM: SVM: Fix a missing kunmap_local() in sev_gmem_post_populate() (git-fixes). - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE (bsc#1259461). - KVM: x86/mmu: Retry fault before acquiring mmu_lock if mapping is changing (bsc#1253122). - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - KVM: x86: check for nEPT/nNPT in slow flush hypercalls (git-fixes). - KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (git-fixes). - KVM: x86: hyper-v: Validate all GVAs during PV TLB flush (git-fixes). - KVM: x86: Ignore cpuid faulting in SMM (git-fixes). - leds: lgm-sso: Remove duplicate assignments for priv->mmap (git-fixes). - leds: qcom-lpg: Check for array overflow when selecting the high resolution (stable-fixes). - lib/hexdump: print_hex_dump_bytes() calls print_hex_dump_debug() (git-fixes). - md/raid1: fix the comparing region of interval tree (bsc#1261555). - md/raid1: serialize overlap io for writemostly disk (bsc#1261555). - media: amphion: Fix race between m2m job_abort and device_run (git-fixes). - media: as102: fix to not free memory after the device is registered in as102_usb_probe() (git-fixes). - media: chips-media: wave5: add missing spinlock protection for handle_dynamic_resolution_change() (git-fixes). - media: chips-media: wave5: add missing spinlock protection for send_eos_event() (git-fixes). - media: chips-media: wave5: fix a potential memory leak in wave5_vdi_init() (git-fixes). - media: dib8000: avoid division by 0 in dib8000_set_dds() (git-fixes). - media: em28xx: fix use-after-free in em28xx_v4l2_open() (git-fixes). - media: hackrf: fix to not free memory after the device is registered in hackrf_probe() (git-fixes). - media: i2c: imx219: Check return value of devm_gpiod_get_optional() in imx219_probe() (git-fixes). - media: i2c: imx412: Assert reset GPIO during probe (git-fixes). - media: i2c: ov08d10: fix image vertical start setting (git-fixes). - media: i2c: ov8856: free control handler on error in ov8856_init_controls() (git-fixes). - media: intel/ipu6: fix error pointer dereference (git-fixes). - media: mtk-jpeg: fix use-after-free in release path due to uncancelled work (git-fixes). - media: nxp: imx8-isi: Reduce minimum queued buffers from 2 to 0 (git-fixes). - media: omap3isp: drop the use count of v4l2 pipeline (git-fixes). - media: pci: zoran: fix potential memory leak in zoran_probe() (git-fixes). - media: rc: streamzap: Error handling in probe (git-fixes). - media: rc: xbox_remote: heed DMA restrictions (git-fixes). - media: saa7164: add ioremap return checks and cleanups (git-fixes). - media: staging: imx: configure src_mux in csi_start (git-fixes). - media: staging: imx: request mbus_config in csi_start (git-fixes). - media: uvcvideo: Enable VB2_DMABUF for metadata stream (git-fixes). - media: videobuf2: Set vma_flags in vb2_dma_sg_mmap (git-fixes). - media: vidtv: fix nfeeds state corruption on start_streaming failure (git-fixes). - media: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections (git-fixes). - media: vidtv: fix pass-by-value structs causing MSAN warnings (git-fixes). - memory: tegra30-emc: Fix dll_change check (git-fixes). - memory: tegra124-emc: Fix dll_change check (git-fixes). - mfd: mc13xxx-core: Fix memory leak in mc13xxx_add_subdevice_pdata() (git-fixes). - mkspec: Add signature to source list only when it exists. - mmc: sdhci-of-dwcmshc: Disable clock before DLL configuration (git-fixes). - mmc: vub300: fix NULL-deref on disconnect (git-fixes). - modpost: Amend ppc64 save/restfpr symnames for -Os build (bsc#1215199). - mtd: docg3: Convert to platform remove callback returning void (stable-fixes). - mtd: docg3: fix use-after-free in docg3_release() (git-fixes). - mtd: parsers: ofpart: call of_node_get() for dedicated subpartitions (git-fixes). - mtd: parsers: ofpart: call of_node_put() only in ofpart_fail path (git-fixes). - mtd: physmap_of_gemini: Fix disabled pinctrl state check (git-fixes). - mtd: rawnand: sunxi: fix sunxi_nfc_hw_ecc_read_extra_oob (git-fixes). - mtd: spi-nor: core: correct the op.dummy.nbytes when check read operations (git-fixes). - mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() (git-fixes). - mtd: spi-nor: sst: Factor out common write operation to `sst_nor_write_data()` (stable-fixes). - mtd: spi-nor: sst: Fix SST write failure (git-fixes). - mtd: spi-nor: sst: Fix write enable before AAI sequence (git-fixes). - mtd: spi-nor: swp: check SR_TB flag when getting tb_mask (git-fixes). - net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626). - net/sched: cls_fw: fix NULL dereference of 'old' filters before change() (git-fixes). - net/sched: fix pedit partial COW leading to page cache corruption (bsc#1265421). - net: gro: don't merge zcopy skbs (git-fixes). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - net: mana: check xdp_rxq registration before unreg in mana_destroy_rxq() (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Fix crash from unvalidated SHM offset read from BAR0 during FLR (bsc#1265846). - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Fix RX skb truesize accounting (bsc#1248754). - net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - net: mana: remove double CQ cleanup in mana_create_rxq error path (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - net: mana: Skip WQ object destruction for uninitialized RXQ (git-fixes). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: phy: dp83869: fix setting CLK_O_SEL field (git-fixes). - net: stmmac: Fix PTP ref clock for Tegra234 (git-fixes). - net: usb: asix: ax88772: re-add usbnet_link_change() in phylink callbacks (git-fixes). - net: usb: cdc-phonet: fix skb frags[] overflow in rx_complete() (git-fixes). - net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (git-fixes). - net: usb: rtl8150: free skb on usb_submit_urb() failure in xmit (git-fixes). - net: wan: fsl_ucc_hdlc: fix ucc_hdlc_remove (git-fixes). - net: wan: fsl_ucc_hdlc: fix uhdlc_memclean (git-fixes). - net: wan: fsl_ucc_hdlc: free tx_skbuff in uhdlc_memclean (git-fixes). - NFC: digital: Bounds check NFC-A cascade depth in SDD response handler (git-fixes). - nfc: llcp: add missing return after LLCP_CLOSED checks (git-fixes). - nfc: pn533: allocate rx skb before consuming bytes (git-fixes). - nfc: s3fwrn5: allocate rx skb before consuming bytes (git-fixes). - NFC: trf7970a: Ignore antenna noise when checking for RF field (git-fixes). - nvme-auth: Include SC_C in RVAL controller hash (bsc#1260428). - nvme-fabrics: use kfree_sensitive() for DHCHAP secrets (git-fixes). - nvme-loop: do not cancel I/O and admin tagset during ctrl reset/shutdown (bsc#1262709). - nvme-pci: cap queue creation to used queues (git-fixes). - nvme-pci: ensure we're polling a polled queue (git-fixes). - nvme: Allow reauth from sysfs (bsc#1259672). - nvme: Expose the tls_configured sysfs for secure concat connections (bsc#1259672). - nvme: expose TLS mode (bsc#1259672). - nvme: fix PCIe subsystem reset controller state transition (bsc#1261738). - nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers (git-fixes). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718). - Partial revert 'x86/xen: fix balloon target initialization for PVH dom0' (bsc#1262599). - PCI/AER: Clear only error bits in PCIe Device Status (git-fixes). - PCI/AER: Stop ruling out unbound devices as error source (git-fixes). - PCI: dwc: Apply ECRC workaround to DesignWare 5.00a as well (git-fixes). - PCI: Enable AtomicOps only if Root Port supports them (git-fixes). - PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown (git-fixes). - PCI: hv: Set default NUMA node to 0 for devices without affinity info (git-fixes). - PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found (git-fixes). - PCI: tegra194: Allow system suspend when the Endpoint link is not up (git-fixes). - PCI: tegra194: Disable direct speed change for Endpoint mode (git-fixes). - PCI: tegra194: Disable LTSSM after transition to Detect on surprise link down (git-fixes). - PCI: tegra194: Disable PERST# IRQ only in Endpoint mode (git-fixes). - PCI: tegra194: Fix polling delay for L2 state (git-fixes). - PCI: tegra194: Increase LTSSM poll time on surprise link down (git-fixes). - PCI: tegra194: Set LTR message request before PCIe link up in Endpoint mode (git-fixes). - PCI: tegra194: Use devm_gpiod_get_optional() to parse 'nvidia,refclk-select' (git-fixes). - PCI: tegra194: Use DWC IP core version (git-fixes). - pinctrl: abx500: Fix type of 'argument' variable (git-fixes). - pinctrl: Fix spelling problem (git-fixes). - pinctrl: intel: Fix the revision for new features (1kOhm PD, HW debouncer) (stable-fixes). - pinctrl: pic32: change all cases of bare 'unsigned' to 'unsigned int' (git-fixes). - pinctrl: pic32: use consistent spacing around '+' (git-fixes). - pinctrl: pinctrl-pic32: Fix resource leak (git-fixes). - platform/chrome: chromeos_tbmc: Drop wakeup source on remove (git-fixes). - platform/surface: surfacepro3_button: Drop wakeup source on remove (git-fixes). - platform/x86/amd: pmc: Add Thinkpad L14 Gen3 to quirk_s2idle_bug (stable-fixes). - platform/x86/intel-uncore-freq: Handle autonomous UFS status bit (git-fixes). - platform/x86/intel: power-domains: Add Clearwater Forest support (jsc#PED-16221). - platform/x86: dell-wmi-sysman: bound enumeration string aggregation (git-fixes). - platform/x86: dell_rbu: avoid uninit value usage in packet_size_write() (git-fixes). - platform/x86: hp-wmi: Ignore backlight and FnLock events (stable-fixes). - platform/x86: ISST: Add Clearwater Forest to support list (jsc#PED-16221). - platform/x86: panasonic-laptop: Fix OPTD notifier registration and cleanup (git-fixes). - power: supply: axp288_charger: Do not cancel work before initializing it (git-fixes). - power: supply: max17042: avoid overflow when determining health (git-fixes). - powerpc/crash: adjust the elfcorehdr size (jsc#PED-11175 git-fixes). - powerpc/crash: fix backup region offset update to elfcorehdr (bsc#1259535). - powerpc/crash: Update backup region offset in elfcorehdr on memory hotplug (bsc#1259535). - powerpc/kdump: Fix size calculation for hot-removed memory ranges (jsc#PED-11175 git-fixes). - RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() (git-fixes). - RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() (git-fixes). - RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (git-fixes). - RDMA/mana: Validate rx_hash_key_len (git-fixes). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (git-fixes). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (git-fixes). - RDMA/mana_ib: Support memory windows (git-fixes). - regulator: act8945a: fix OF node reference imbalance (git-fixes). - regulator: bd9571mwv: fix OF node reference imbalance (git-fixes). - regulator: max77650: fix OF node reference imbalance (git-fixes). - regulator: mt6357: fix OF node reference imbalance (git-fixes). - remoteproc: xlnx: Only access buffer information if IPI is buffered (git-fixes). - Revert 'ALSA: usb: Increase volume range that triggers a warning' (git-fixes). - rtc: abx80x: Disable alarm feature if no interrupt attached (git-fixes). - rtc: ntxec: fix OF node reference imbalance (git-fixes). - s390/dasd: Copy detected format information to secondary device (bsc#1259995). - s390/dasd: Fix gendisk parent after copy pair swap (bsc#1259995). - s390/dasd: Move quiesce state with pprc swap (bsc#1259995). - sched/balancing: Switch the 'DEFINE_SPINLOCK(balancing)' spinlock into an 'atomic_t sched_balance_running' flag (bsc#1253754). - sched/fair: Change likelyhood of nohz.nr_cpus (bsc#1234634 bsc#1258961). - sched/fair: Have SD_SERIALIZE affect newidle balancing (bsc#1253754). - sched/fair: Move checking for nohz cpus after time check (bsc#1234634 bsc#1258961). - sched/fair: Remove nohz.nr_cpus and use weight of cpumask instead (bsc#1234634 bsc#1258961). - sched/fair: Skip sched_balance_running cmpxchg when balance is not due (bsc#1253754). - scsi: lpfc: Add clean up of aborted NVMe commands during PCI fcn reset (bsc#1262019). - scsi: lpfc: Add log messages to fabric login error labels (bsc#1262019). - scsi: lpfc: Add PCI ID support for LPe42100 series adapters (bsc#1262019). - scsi: lpfc: Add REG_VFI mailbox cmd error handling (bsc#1262019). - scsi: lpfc: Break out of IRQ affinity assignment when mask reaches nr_cpu_ids (bsc#1262019). - scsi: lpfc: Check ASIC_ID register to aid diagnostics during failed fw updates (bsc#1262019). - scsi: lpfc: Cleanup error exit paths in lpfc_fdmi_cmd() and associated messages (bsc#1262019). - scsi: lpfc: ELIMINATE kernel-doc warnings in lpfc.h (bsc#1262019). - scsi: lpfc: Fix incorrect txcmplq_cnt during cleanup in lpfc_sli_abort_ring() (bsc#1262019). - scsi: lpfc: Introduce 128G link speed selection and support (bsc#1262019). - scsi: lpfc: Log discarded and insufficient RQE buffer events (bsc#1262019). - scsi: lpfc: Log MCQE contents for mbox commands with no context (bsc#1262019). - scsi: lpfc: Properly set WC for DPP mapping (bsc#1262019). - scsi: lpfc: Reduce pointer chasing when accessing vmid_flag (bsc#1262019). - scsi: lpfc: Remove deprecated PBDE feature (bsc#1262019). - scsi: lpfc: Remove unnecessary ndlp kref get in lpfc_check_nlp_post_devloss (bsc#1262019). - scsi: lpfc: Restrict first burst to non-FCoE and SLI4 adapters only (bsc#1262019). - scsi: lpfc: Select mailbox rq_create cmd version based on SLI4 if_type (bsc#1262019). - scsi: lpfc: Update class of service bit field to 3 bits for WQE submissions (bsc#1262019). - scsi: lpfc: Update construction of SGL when XPSGL is enabled (bsc#1262019). - scsi: lpfc: Update copyright year string for 2026 (bsc#1262019). - scsi: lpfc: Update log message when ndlp kref get is unsuccessful (bsc#1262019). - scsi: lpfc: Update lpfc version to 14.4.0.14 (bsc#1262019). - scsi: lpfc: Update lpfc version to 15.0.0.0 (bsc#1262019). - scsi: lpfc: Update outdated comment for renamed lpfc_freenode() (bsc#1262019). - scsi: lpfc: Use min_t() instead of min() in lpfc_sli4_driver_resource_setup (bsc#1262019). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - scsi: target: iscsi: validate CHAP_R length before base64 decode (bsc#1265449). - selftests/powerpc: make sub-folders buildable on their own (bsc#1261669 ltc#212590). - selftests/powerpc: Re-order *FLAGS to follow lib.mk (bsc#1261669 ltc#212590). - selftests/powerpc: Suppress -Wmaybe-uninitialized with GCC 15 (bsc#1261669 ltc#212590). - serial: 8250: Add serial8250_handle_irq_locked() (bsc#1262480). - serial: 8250: Protect LCR write in shutdown (bsc#1262480). - serial: 8250_dw: Avoid unnecessary LCR writes (bsc#1262480). - serial: 8250_dw: Ensure BUSY is deasserted (bsc#1262480). - serial: 8250_dw: Rework dw8250_handle_irq() locking and IIR handling (bsc#1262480). - serial: 8250_dw: Rework IIR_NO_INT handling to stop interrupt storm (bsc#1262480). - soc/tegra: cbb: Set ERD on resume for err interrupt (git-fixes). - soc: qcom: aoss: compare against normalized cooling state (git-fixes). - soc: qcom: llcc: fix v1 SB syndrome register offset (git-fixes). - sound: ua101: fix division by zero at probe (git-fixes). - soundwire: bus: demote UNATTACHED state warnings to dev_dbg() (git-fixes). - soundwire: cadence: Clear message complete before signaling waiting thread (git-fixes). - spi: at91-usart: fix controller deregistration (git-fixes). - spi: atmel: fix controller deregistration (git-fixes). - spi: cadence: fix controller deregistration (git-fixes). - spi: fix controller cleanup() documentation (git-fixes). - spi: fix misleading controller deregistration kernel-doc (git-fixes). - spi: fix misleading controller registration kernel-doc (git-fixes). - spi: fsl-qspi: Use reinit_completion() for repeated operations (git-fixes). - spi: hisi-kunpeng: prevent infinite while() loop in hisi_spi_flush_fifo (git-fixes). - spi: imx: fix runtime pm leak on probe deferral (git-fixes). - spi: imx: fix use-after-free on unbind (git-fixes). - spi: microchip-core-qspi: fix controller deregistration (git-fixes). - spi: microchip-core-qspi: Use helper function devm_clk_get_enabled() (stable-fixes). - spi: mpc52xx: fix use-after-free on unbind (git-fixes). - spi: mtk-nor: fix controller deregistration (git-fixes). - spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback (git-fixes). - spi: omap2-mcspi: fix controller deregistration (git-fixes). - spi: orion: fix clock imbalance on registration failure (git-fixes). - spi: orion: fix runtime pm leak on unbind (git-fixes). - spi: rockchip: fix controller deregistration (git-fixes). - spi: rspi: fix controller deregistration (git-fixes). - spi: sh-hspi: fix controller deregistration (git-fixes). - spi: spi-ti-qspi: Convert to platform remove callback returning void (stable-fixes). - spi: sprd: fix controller deregistration (git-fixes). - spi: sun4i: fix controller deregistration (git-fixes). - spi: sun4i: switch to use modern name (stable-fixes). - spi: syncuacer: fix controller deregistration (git-fixes). - spi: synquacer: switch to use modern name (stable-fixes). - spi: uniphier: fix controller deregistration (git-fixes). - spi: uniphier: Simplify clock handling with devm_clk_get_enabled() (stable-fixes). - spi: uniphier: switch to use modern name (stable-fixes). - spi: zynq-qspi: switch to use modern name (stable-fixes). - spi: zynqmp-gqspi: fix controller deregistration (git-fixes). - staging: media: atomisp: Disallow all private IOCTLs (git-fixes). - staging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify() (git-fixes). - staging: sm750fb: fix division by zero in ps_to_hz() (git-fixes). - staging: vme_user: added bound check to geoid (stable-fixes). - staging: vme_user: fix root device leak on init failure (git-fixes). - tg3: Fix race for querying speed/duplex (bsc#1257183). - tg3: replace placeholder MAC address with device property (git-fixes). - thermal/drivers/spear: Fix error condition for reading st,thermal-flags (git-fixes). - thermal/drivers/sprd: Fix raw temperature clamping in sprd_thm_rawdata_to_temp (git-fixes). - thermal/drivers/sprd: Fix temperature clamping in sprd_thm_temp_to_rawdata (git-fixes). - tpm: avoid -Wunused-but-set-variable (git-fixes). - tpm: tpm_tis: add error logging for data transfer (git-fixes). - tpm: tpm_tis: stop transmit if retries are exhausted (git-fixes). - tty: tty_io: update timestamps on all device nodes (bsc#1262020). - unshare: fix unshare_fs() handling (git-fixes). - USB: cdc-acm: Add quirks for Yoga Book 9 14IAH10 INGENIC touchscreen (stable-fixes). - usb: chipidea: core: allow ci_irq_handler() handle both ID and VBUS change (git-fixes). - usb: chipidea: otg: not wait vbus drop if use role_switch (git-fixes). - USB: core: add NO_LPM quirk for Razer Kiyo Pro webcam (stable-fixes). - usb: gadget: dummy_hcd: fix premature URB completion when ZLP follows partial transfer (stable-fixes). - usb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb() (git-fixes). - usb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete() (stable-fixes). - usb: gadget: f_uac1_legacy: validate control request size (stable-fixes). - usb: gadget: renesas_usb3: validate endpoint index in standard request handlers (git-fixes). - USB: omap_udc: DMA: Don't enable burst 4 mode (git-fixes). - usb: port: add delay after usb_hub_set_port_power() (git-fixes). - usb: quirks: add DELAY_INIT quirk for another Silicon Motion flash drive (stable-fixes). - USB: serial: io_edgeport: add support for Blackbox IC135A (stable-fixes). - USB: serial: option: add MeiG Smart SRM825WN (stable-fixes). - USB: serial: option: add support for Rolling Wireless RW135R-GL (stable-fixes). - USB: serial: option: add Telit Cinterion FN990A MBIM composition (stable-fixes). - USB: serial: option: add Telit Cinterion LE910Cx compositions (stable-fixes). - usb: storage: Expand range of matched versions for VL817 quirks entry (stable-fixes). - usb: typec: tcpm: reset internal port states on soft reset AMS (git-fixes). - usb: ulpi: fix memory leak on ulpi_register() error paths (git-fixes). - usb: usblp: fix heap leak in IEEE 1284 device ID via short response (stable-fixes). - usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (stable-fixes). - usb: xhci: Make usb_host_endpoint.hcpriv survive endpoint_disable() (git-fixes). - usbip: validate number_of_packets in usbip_pack_ret_submit() (git-fixes). - virt: tdx-guest: Fix handling of host controlled 'quote' buffer length (git-fixes). - virt: tdx-guest: Return error for GetQuote failures (git-fixes). - wifi: ath5k: do not access array OOB (git-fixes). - wifi: ath9k: Fix typo (git-fixes). - wifi: ath11k: Pass the correct value of each TID during a stop AMPDU session (git-fixes). - wifi: ath11k: skip status ring entry processing (stable-fixes). - wifi: ath11k: Use dma_alloc_noncoherent for rx_tid buffer allocation (stable-fixes). - wifi: ath12k: fix leak in some ath12k_wmi_xxx() functions (git-fixes). - wifi: b43: enforce bounds check on firmware key index in b43_rx() (git-fixes). - wifi: b43legacy: enforce bounds check on firmware key index in RX path (git-fixes). - wifi: brcmfmac: Fix error pointer dereference (git-fixes). - wifi: brcmfmac: validate bsscfg indices in IF events (stable-fixes). - wifi: brcmsmac: Fix dma_free_coherent() size (git-fixes). - wifi: cw1200: Revert 'Fix locking in error paths' (git-fixes). - wifi: libertas: notify firmware load wait on disconnect (git-fixes). - wifi: mac80211: check ieee80211_rx_data_set_link return in pubsta MLO path (git-fixes). - wifi: mac80211: check tdls flag in ieee80211_tdls_oper (stable-fixes). - wifi: mac80211: drop stray 'static' from fast-RX rx_result (git-fixes). - wifi: mac80211: handle VHT EXT NSS in ieee80211_determine_our_sta_mode() (git-fixes). - wifi: mac80211: remove station if connection prep fails (git-fixes). - wifi: mac80211: use safe list iteration in radar detect work (git-fixes). - wifi: mt76: mt792x: describe USB WFSYS reset with a descriptor (stable-fixes). - wifi: mt76: mt792x: fix mt7925u USB WFSYS reset handling (git-fixes). - wifi: mt76: mt7615: fix use_cts_prot support (git-fixes). - wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work() (git-fixes). - wifi: mt76: mt7915: fix use_cts_prot support (git-fixes). - wifi: mt76: mt7921: fix 6GHz regulatory update on connection (git-fixes). - wifi: mt76: mt7921: fix a potential clc buffer length underflow (git-fixes). - wifi: mt76: mt7921: fix ROC abort flow interruption in mt7921_roc_work (git-fixes). - wifi: mt76: mt7921: Reset ampdu_state state in case of failure in mt76_connac2_tx_check_aggr() (git-fixes). - wifi: mt76: mt7925: fix incorrect length field in txpower command (git-fixes). - wifi: mt76: mt7996: fix FCS error flag check in RX descriptor (git-fixes). - wifi: mt76: mt7996: fix struct mt7996_mcu_uni_event (git-fixes). - wifi: mwifiex: Fix memory leak in mwifiex_11n_aggregate_pkt() (git-fixes). - wifi: nl80211: fix NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST usage (git-fixes). - wifi: nl80211: require admin perm on SET_PMK / DEL_PMK (git-fixes). - wifi: rsi: fix kthread lifetime race between self-exit and external-stop (git-fixes). - wifi: rt2x00usb: fix devres lifetime (git-fixes). - wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet (git-fixes). - wifi: rtw88: check for PCI upstream bridge existence (git-fixes). - wifi: rtw88: fix device leak on probe failure (git-fixes). - wifi: rtw89: phy: fix uninitialized variable access in rtw89_phy_cfo_set_crystal_cap() (git-fixes). - wifi: wl1251: validate packet IDs before indexing tx_frames (stable-fixes). - workqueue: Break up enum definitions and give names to the types (bsc#1260522). - workqueue: Clean up enum work_bits and related constants (bsc#1260522). - workqueue: Factor out work_grab_pending() from __cancel_work_sync() (bsc#1260522). - workqueue: Fix UBSAN 'subtraction overflow' error in shift_and_mask() (bsc#1260522). - workqueue: Implement disable/enable for (delayed) work items (bsc#1260522). - workqueue: Introduce work_cancel_flags (bsc#1260522). - workqueue: Make @flags handling consistent across set_work_data() and friends (bsc#1260522). - workqueue: Preserve OFFQ bits in cancel[_sync] paths (bsc#1260522). - workqueue: Rename __cancel_work_timer() to __cancel_timer_sync() (bsc#1260522). - workqueue: Reorganize flush and cancel[_sync] functions (bsc#1260522). - x86/boot/64: Clear most of CR4 in startup_64(), except PAE, MCE and LA57 (git-fixes). - x86/boot/sev: Avoid shared GHCB page for early memory acceptance (git-fixes). - x86/boot: Don't add the EFI stub to targets, again (git-fixes). - x86/boot: Fix page table access in 5-level to 4-level paging transition (git-fixes). - x86/CPU/AMD: Add models 0x60-0x6f to the Zen5 range (bsc#1263255). - x86/CPU/AMD: Add X86_FEATURE_ZEN6 (bsc#1263255). - x86/cpu: Remove X86_CR4_FRED from the CR4 pinned bits mask (git-fixes). - x86/cpufeatures: Free up unused feature bits (bsc#1263255). - x86/fred: Remove ENDBR64 from FRED entry points (git-fixes). - x86: KVM: Advertise CPUIDs for new instructions in Clearwater Forest (jsc#PED-16245). - X.509: Fix out-of-bounds access when parsing extensions (git-fixes). - Xarray: do not return sibling entries from xas_find_marked() (bsc#1263815). - xfrm: esp: avoid in-place decrypt on shared skb frags (bsc#1264449). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2276-1 Released: Fri Jun 5 10:56:23 2026 Summary: Recommended update for apparmor Type: recommended Severity: important References: 1265620 This update for apparmor fixes the following issues: - Allow execution of /usr/bin/zstd (bsc#1265620) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2278-1 Released: Fri Jun 5 11:00:12 2026 Summary: Recommended update for timezone Type: recommended Severity: important References: 1264965 This update for timezone fixes the following issues: - Update to 2026b: * British Columbia moved to permanent -07 on 2026-03-09. (bsc#1264965) * Some more overflow bugs have been fixed in zic. - Update to 2026a: * Moldova has used EU transition times since 2022. * The 'right' TZif files are no longer installed by default. * -DTZ_RUNTIME_LEAPS=0 disables runtime support for leap seconds. * TZif files are no longer limited to 50 bytes of abbreviations. * zic is no longer limited to 50 leap seconds. * Several integer overflow bugs have been fixed. - Update to 2025c: * Update Baja California DST rules in 1953, 1961-1975 * An unset TZ is no longer invalid when /etc/localtime is missing, and is abbreviated 'UTC' not '-00'. This reverts to 2024b behavior * tzset etc. are now more cautious about questionable TZ settings. * tzset etc. now treat ' ' like '_' in time zone abbreviations * tzfree now preserves errno, consistently with POSIX.1-2024 'free'. * zic has new options inspired by FreeBSD. * multiple changes visible to developers - Use 'REDO=posix_right' to keep installing 'right' TZif files. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2283-1 Released: Fri Jun 5 14:14:57 2026 Summary: Security update for jq Type: security Severity: moderate References: 1262043,CVE-2026-33948 This update for jq fixes the following issue - CVE-2026-33948: CLI input parsing may allow validation bypass via embedded NUL bytes (bsc#1262043) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2349-1 Released: Wed Jun 10 16:53:45 2026 Summary: Security update for wicked Type: security Severity: important References: 1265221,CVE-2026-44932 This update for wicked fixes the following issue - CVE-2026-44932: indirect remote shell command injection via unsanitized DHCP options (bsc#1265221). Changes for wicked: - Update to version 0.6.79 - Fix to escape single-quotes in leaseinfo dump output used by the `wicked test dhcp4` and `wicked test dhcp6` and written to the /run/wicked/leaseinfo.* files, e.g. to pass them to netconfig. A netconfig modify filtered for strict key='value' lines without any escaped quotes and discarded these lines already before. - Fix posix-tz-dbname and tz-string option processing checks to permit only valid characters according to RFC4833. - Discard string values containing single-quotes in other options. - Trigger to regenerate initrd that may contain wicked binaries on updates from wicked versions <= 0.6.78. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2357-1 Released: Wed Jun 10 18:40:57 2026 Summary: Recommended update for dracut Type: recommended Severity: moderate References: 1263940 This update for dracut fixes the following issues: - Update to version 059+suse.568.g200aa75e: * fix(systemd): explicitly install /bin/bash (bsc#1263940) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2371-1 Released: Thu Jun 11 16:01:35 2026 Summary: Security update for openssh Type: security Severity: important References: 1259642,1261427,1261430,1261441,1264568,CVE-2026-3497,CVE-2026-35385,CVE-2026-35388,CVE-2026-35414 This update for openssh fixes the following issues - CVE-2026-3497: information disclosure or denial of service due to uninitialized variables (bsc#1259642). - CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427). - CVE-2026-35388: omitted connection multiplexing confirmation for proxy-mode multiplexing sessions (bsc#1261441). - CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430). - potential security issue when validating mac (bsc#1264568). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2382-1 Released: Fri Jun 12 10:07:34 2026 Summary: Recommended update for hwdata Type: recommended Severity: moderate References: This update for hwdata fixes the following issues: - update to version 0.406: * Update pci and vendor ids - update to version 0.405: * Update pci and vendor ids - Update to version 0.397: * Update pci and vendor ids - Update to version 0.395: * Update pci and vendor ids ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2425-1 Released: Wed Jun 17 08:48:32 2026 Summary: Recommended update for iproute2 Type: recommended Severity: important References: 1255752 This update for iproute2 fixes the following issues: - add DPLL support (bsc#1255752 jsc#PED-14083): * dpll: add dpll command * dpll: fix missing notifications in monitor mode * dpll: send object per event in JSON monitor mode * dpll: add client side filtering for device and pin show * dpll: add direction and state filtering for pin show * dpll: add mode setting support * dpll: add pin filtering by parent device * dpll: add support for fractional frequency offset * dpll: fix pin id get type filter parsing * lib: add string to boolean helper function * lib: move mnlg to lib for shared use * sync UAPI header copies with SL-16.0 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2434-1 Released: Wed Jun 17 16:40:10 2026 Summary: Recommended update for coreutils Type: recommended Severity: important References: 1259327 This update for coreutils fixes the following issues: - proc: Use affinity mask even on systems with more than 1024 CPUs (bsc#1259327) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2482-1 Released: Mon Jun 22 13:10:20 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1248235,1255416,1258538,1260502,1260548,1260584,1261591,1261619,1261791,1262606,1262615,1262619,1262622,1262624,1262634,1262649,1262656,1262663,1262668,1262755,1263006,1263068,1263115,1263122,1263143,1263152,1263169,1263319,1263562,1263724,1263769,1263774,1263790,1263883,1263932,1263945,1264000,1264011,1264014,1264040,1264063,1264091,1264093,1264124,1264184,1264243,1264245,1264255,1264300,1264409,1264415,1264430,1264449,1264476,1264484,1264551,1264669,1264671,1264672,1264716,1264719,1264720,1264722,1264726,1264765,1264805,1264835,1264989,1265020,1265044,1265073,1265110,1265128,1265170,1265240,1265579,1265925,1265928,1266001,1266009,1266036,1266214,1266238,1266307,1266394,1266395,1266400,1266402,1266414,1266452,1266696,1266697,1266711,1266720,1266759,1266765,1266767,1266810,1266816,1266826,1266827,1266888,1266889,1266901,1266927,1266969,1266972,1267205,1267214,1267218,1267220,1267222,1267531,1267626,1267652,1267663,1267726,1267732,CVE-2025-38549,CVE-2025-68324,CVE-2026-23 303,CVE-2026-23327,CVE-2026-23359,CVE-2026-23438,CVE-2026-23444,CVE-2026-31396,CVE-2026-31446,CVE-2026-31448,CVE-2026-31454,CVE-2026-31455,CVE-2026-31464,CVE-2026-31473,CVE-2026-31480,CVE-2026-31493,CVE-2026-31516,CVE-2026-31518,CVE-2026-31546,CVE-2026-31580,CVE-2026-31590,CVE-2026-31591,CVE-2026-31596,CVE-2026-31613,CVE-2026-31614,CVE-2026-31629,CVE-2026-31655,CVE-2026-31671,CVE-2026-31673,CVE-2026-31678,CVE-2026-31703,CVE-2026-31758,CVE-2026-31767,CVE-2026-31774,CVE-2026-43009,CVE-2026-43013,CVE-2026-43026,CVE-2026-43030,CVE-2026-43040,CVE-2026-43052,CVE-2026-43054,CVE-2026-43059,CVE-2026-43065,CVE-2026-43066,CVE-2026-43068,CVE-2026-43109,CVE-2026-43150,CVE-2026-43206,CVE-2026-43234,CVE-2026-43249,CVE-2026-43252,CVE-2026-43261,CVE-2026-43284,CVE-2026-43296,CVE-2026-43325,CVE-2026-43333,CVE-2026-43338,CVE-2026-43341,CVE-2026-43359,CVE-2026-43360,CVE-2026-43361,CVE-2026-43362,CVE-2026-43406,CVE-2026-43407,CVE-2026-43411,CVE-2026-43413,CVE-2026-43414,CVE-2026-43455,CVE-2026-43470,CVE -2026-43483,CVE-2026-43499,CVE-2026-43501,CVE-2026-45842,CVE-2026-45843,CVE-2026-45846,CVE-2026-45852,CVE-2026-45856,CVE-2026-45878,CVE-2026-45886,CVE-2026-45898,CVE-2026-45910,CVE-2026-45932,CVE-2026-45970,CVE-2026-45983,CVE-2026-45984,CVE-2026-46004,CVE-2026-46021,CVE-2026-46024,CVE-2026-46043,CVE-2026-46079,CVE-2026-46083,CVE-2026-46090,CVE-2026-46094,CVE-2026-46110,CVE-2026-46111,CVE-2026-46113,CVE-2026-46114,CVE-2026-46157,CVE-2026-46159,CVE-2026-46176,CVE-2026-46181,CVE-2026-46209,CVE-2026-46243 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-38549: efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths (bsc#1248235). - CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). - CVE-2026-3150: bcache: fix cached_dev.sb_bio use-after-free and crash (bsc#1263169). - CVE-2026-23303: smb: client: Don't log plaintext credentials in cifs_set_cifscreds (bsc#1260502). - CVE-2026-23327: cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (bsc#1260548). - CVE-2026-23359: bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584). - CVE-2026-23438: net: mvpp2: guard flow control update with global_tx_fc in buffer switching (bsc#1261619). - CVE-2026-23444: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (bsc#1266307). - CVE-2026-31396: net: macb: fix use-after-free access to PTP clock (bsc#1261791). - CVE-2026-31446: ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619). - CVE-2026-31448: ext4: avoid infinite loops caused by residual data (bsc#1262622). - CVE-2026-31454: xfs: save ailp before dropping the AIL lock in push callbacks (bsc#1262624). - CVE-2026-31455: xfs: stop reclaim before pushing AIL during unmount (bsc#1262615). - CVE-2026-31464: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (bsc#1262656). - CVE-2026-31473: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (bsc#1262663). - CVE-2026-31480: tracing: Fix potential deadlock in cpu hotplug with osnoise (bsc#1262634). - CVE-2026-31493: RDMA/efa: Fix use of completion ctx after free (bsc#1262668). - CVE-2026-31516: xfrm: prevent policy_hthresh.work from racing with netns teardown (bsc#1262755). - CVE-2026-31518: esp: fix skb leak with espintcp and async crypto (bsc#1262606). - CVE-2026-31546: net: bonding: fix NULL deref in bond_debug_rlb_hash_show (bsc#1263006). - CVE-2026-31590: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (bsc#1263152). - CVE-2026-31591: KVM: SEV: Lock all vCPUs when synchronzing VMSAs for SNP launch finish (bsc#1263122). - CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). - CVE-2026-31613: smb: client: fix OOB reads parsing symlink error response (bsc#1263769). - CVE-2026-31614: smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774). - CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790). - CVE-2026-31655: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724). - CVE-2026-31671: xfrm_user: fix info leak in build_report() (bsc#1263115). - CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). - CVE-2026-31678: openvswitch: defer tunnel netdev_put to RCU release (bsc#1263562). - CVE-2026-31703: writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883). - CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264093). - CVE-2026-31767: drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode (bsc#1264124). - CVE-2026-31774: io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (bsc#1264040). - CVE-2026-43013: net/mlx5: lag: Check for LAG device before creating debugfs (bsc#1264011). - CVE-2026-43026: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (bsc#1263932). - CVE-2026-43030: bpf: Fix regsafe() for pointers to packet (bsc#1264000). - CVE-2026-43040: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info- leak (bsc#1264091). - CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211_tdls_oper (bsc#1263945). - CVE-2026-43054: scsi: target: tcm_loop: Drain commands in target_reset handler (bsc#1264063). - CVE-2026-43059: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete (bsc#1264184). - CVE-2026-43065: ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243). - CVE-2026-43066: ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245). - CVE-2026-43068: ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255). - CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). - CVE-2026-43150: perf/arm-cmn: Ensure dtm_idx is big enough (bsc#1264415). - CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1264551). - CVE-2026-43234: team: avoid NETDEV_CHANGEMTU event when unregistering slave (bsc#1264409). - CVE-2026-43249: 9p/xen: protect xen_9pfs_front_free against concurrent calls (bsc#1264476). - CVE-2026-43252: mptcp: pm: in-kernel: always set ID as avail when rm endp (bsc#1264300). - CVE-2026-43261: arm64: Add support for TSV110 Spectre-BHB mitigation (bsc#1264430). - CVE-2026-43296: octeontx2-af: Workaround SQM/PSE stalls by disabling sticky (bsc#1264805). - CVE-2026-43325: wifi: iwlwifi: mvm: don't send a 6E related command when not supported (bsc#1265110). - CVE-2026-43333: bpf: reject direct access to nullable PTR_TO_BUF pointers (bsc#1264726). - CVE-2026-43338: btrfs: reserve enough transaction items for qgroup ioctls (bsc#1264716). - CVE-2026-43341: net/ipv6: ioam6: prevent schema length wraparound in trace fill (bsc#1265044). - CVE-2026-43359: btrfs: fix transaction abort on set received ioctl due to item overflow (bsc#1264719). - CVE-2026-43360: btrfs: fix transaction abort on file creation due to name hash collision (bsc#1264720). - CVE-2026-43361: btrfs: fix transaction abort when snapshotting received subvolumes (bsc#1264722). - CVE-2026-43362: smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989). - CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() (bsc#1265073). - CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). - CVE-2026-43411: tipc: fix divide-by-zero in tipc_sk_filter_connect() (bsc#1264672). - CVE-2026-43413: scsi: hisi_sas: Fix NULL pointer exception during user_scan() (bsc#1264671). - CVE-2026-43414: scsi: qla2xxx: Completely fix fcport double free (bsc#1264669). - CVE-2026-43455: net: mctp: Ensure keys maintain only one ref to corresponding dev (bsc#1264765). - CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (bsc#1265128). - CVE-2026-43483: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated (bsc#1265240). - CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001). - CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266009). - CVE-2026-45842: slip: reject VJ receive packets on instances with no rstate array (bsc#1266400). - CVE-2026-45843: slip: bound decode() reads against the compressed packet length (bsc#1266395). - CVE-2026-45846: bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (bsc#1266394). - CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init (bsc#1266711). - CVE-2026-45856: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (bsc#1266720). - CVE-2026-45878: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (bsc#1266767). - CVE-2026-45886: bpf: Fix bpf_xdp_store_bytes proto for read-only arg (bsc#1266810). - CVE-2026-45898: RDMA/iwcm: Fix workqueue list corruption by removing work_list (bsc#1266888). - CVE-2026-45910: RDMA/rxe: Fix race condition in QP timer handlers (bsc#1266889). - CVE-2026-45932: bpf: Fix tcx/netkit detach permissions when prog fd isn't given (bsc#1266827). - CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). - CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). - CVE-2026-45984: gfs2: Add metapath_dibh helper (bsc#1267214). - CVE-2026-46004: ALSA: caiaq: Handle probe errors properly (bsc#1267222). - CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220). - CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). - CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (bsc#1266901). - CVE-2026-46079: rbd: fix null-ptr-deref when device_add_disk() fails (bsc#1266452). - CVE-2026-46083: spi: fix resource leaks on device setup failure (bsc#1266696). - CVE-2026-46090: ALSA: aloop: Use guard() for spin locks (bsc#1267531). - CVE-2026-46094: ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927). - CVE-2026-46110: net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (bsc#1266759). - CVE-2026-46111: Bluetooth: hci_conn: fix potential UAF in create_big_sync (bsc#1267626). - CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266969). - CVE-2026-46114: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (bsc#1266972). - CVE-2026-46157: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (bsc#1267726). - CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652). - CVE-2026-46176: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (bsc#1266816). - CVE-2026-46181: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (bsc#1266826). - CVE-2026-46209: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (bsc#1267663). - CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). The following non security issues were fixed: - accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). - ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes). - ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes). - ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes). - ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). - ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes). - ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). - ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes). - ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes). - ALSA: sc6000: Use standard print API (stable-fixes). - ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes). - ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes). - ALSA: seq: dummy: fix UMP event stack overread (git-fixes). - ALSA: seq: Serialize UMP output teardown with event_input (git-fixes). - ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes). - ALSA: ua101: Reject too-short USB descriptors (git-fixes). - ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). - ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes). - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes). - ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). - ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). - ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes). - ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). - ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). - ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes). - ASoC: SOF: Intel: hda-dai: add support for dspless mode beyond HDAudio (stable-fixes). - ASoC: SOF: Intel: hda-dai: remove dspless special case (stable-fixes). - ASoC: SOF: Intel: hda: Fix NULL pointer dereference (stable-fixes). - auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes). - batman-adv: bla: fix report_work leak on backbone_gw purge (git-fixes). - batman-adv: clear current gateway during teardown (git-fixes). - batman-adv: dat: handle forward allocation error (git-fixes). - batman-adv: fix batadv_skb_is_frag() kernel-doc (git-fixes). - batman-adv: fix fragment reassembly length accounting (git-fixes). - batman-adv: fix tp_meter counter underflow during shutdown (git-fixes). - batman-adv: frag: disallow unicast fragment in fragment (git-fixes). - batman-adv: tp_meter: avoid use of uninit sender vars (git-fixes). - batman-adv: tt: fix negative last_changeset_len (git-fixes). - batman-adv: tt: fix negative tt_buff_len (git-fixes). - bcache: fix uninitialized closure object (git-fixes). - Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes). - Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). - Bluetooth: bnep: reject short frames before parsing (git-fixes). - Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes). - Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes). - Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes). - Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes). - Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes). - Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes). - Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). - Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes). - Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes). - Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). - Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). - Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes). - Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes). - Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes). - Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). - Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes). - Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). - Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). - Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). - Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). - Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). - Bluetooth: serialize accept_q access (git-fixes). - cgroup: Increment nr_dying_subsys_* from rmdir context (git-fixes). - comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). - comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). - device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). - dm: fix a buffer overflow in ioctl processing (git-fixes). - drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). - drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). - drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes). - drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). - drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes). - drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). - drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). - drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes). - drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). - drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes). - drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes). - drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes). - drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). - drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). - drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes). - drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes). - drm/amdgpu: fix spelling typos (stable-fixes). - drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes). - drm/amdgpu: update the handle ptr in early_init (stable-fixes). - drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). - drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). - drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes). - drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). - drm/bridge: megachips: remove bridge when irq request fails (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes). - drm/i915: Extract intel_dbuf_mdclk_cdclk_ratio_update() (stable-fixes). - drm/i915: Fix potential UAF in TTM object purge (git-fixes). - drm/i915: Loop over all active pipes in intel_mbus_dbox_update (stable-fixes). - drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). - drm/msm/dsi: don't dump registers past the mapped region (git-fixes). - drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). - drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). - drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). - drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). - drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes). - drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes). - drm/xe/pf: Fix CFI failure in debugfs access (git-fixes). - drm/xe/vf: Fix signature of print functions (git-fixes). - drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). - drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes). - efi: Allocate runtime workqueue before ACPI init (git-fixes). - firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). - firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). - gve: Add RSS cache for non RSS device option scenario (bsc#1265925). - gve: add XDP DROP and PASS support for DQ (bsc#1265925). - gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925). - gve: introduce config-based allocation for XDP (bsc#1265925). - gve: merge packet buffer size fields (bsc#1265925). - gve: process XSK TX descriptors as part of RX NAPI (bsc#1265925). - gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925). - gve: trigger RX NAPI instead of TX NAPI in gve_xsk_wakeup (bsc#1265925). - gve: update GQ RX to use buf_size (bsc#1265925). - gve: Update QPL page registration logic (bsc#1265925). - gve: update XDP allocation path support RX buffer posting (bsc#1265925). - HID: quirks: really enable the intended work around for appledisplay (git-fixes). - HID: uclogic: Fix regression of input name assignment (git-fixes). - HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (git-fixes). - hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). - hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). - hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes). - hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes). - hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). - hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). - hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). - hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). - hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). - hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). - iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). - iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes). - iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). - iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). - iio: dac: ad5686: fix input raw value check (git-fixes). - iio: dac: max5821: fix return value check in powerdown sync (git-fixes). - iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). - iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). - iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes). - iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes). - iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). - iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). - Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes). - Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). - Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). - Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes). - Input: xpad - fix out-of-bounds access for Share button (git-fixes). - KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested #VMEXIT (git-fixes). - KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC (git-fixes). - KVM: X86: Fix array_index_nospec protection in __pv_send_ipi (git-fixes). - KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). - mmc: core: Fix host controller programming for fixed driver type (git-fixes). - mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). - mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes). - mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). - mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). - net: gro: don't merge zcopy skbs (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (git-fixes). - nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes). - parport: Fix race between port and client registration (git-fixes). - phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (git-fixes). - platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). - platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). - platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). - r8152: fix incorrect register write to USB_UPHY_XTAL (git-fixes). - RDMA/efa: Check stored completion CTX command ID with received one (git-fixes). - RDMA/efa: Extend admin timeout error print (git-fixes). - RDMA/efa: Fix possible deadlock (git-fixes). - RDMA/efa: Improve admin completion context state machine (git-fixes). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261591). - s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1263068). - s390/entry: Scrub r12 register on kernel entry (bsc#1261591). - s390/entry: Scrub r12 register on kernel entry (bsc#1263068). - s390/mm: Add missing secure storage access fixups for donated memory (bsc#1264835). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261591). - s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1263068). - sched/rt: Skip currently executing CPU in rto_next_cpu() (bsc#1262649). - scsi: qla2xxx: Add support to report MPI FW state (git-fixes). - scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes). - security/keys: fix missed RCU read section on lookup (stable-fixes). - serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes). - serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). - smb: client: correctly handle ErrorContextData as a flexible array (git-fixes). - soundwire: debugfs: initialize firmware_file to empty string (git-fixes). - spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). - spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). - spi: st-ssc4: switch to use modern name (stable-fixes). - spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). - string: add mem_is_zero() helper to check if memory area is all zeros (stable-fixes). - thermal: core: Free thermal zone ID later during removal (git-fixes). - thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). - thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes). - tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). - tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). - USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes). - usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). - usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). - usb: dwc2: Fix use after free in debug code (git-fixes). - usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). - usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). - usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). - usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). - usb: gadget: net2280: Fix double free in probe error path (git-fixes). - USB: serial: belkin_sa: validate interrupt status length (git-fixes). - USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). - USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). - USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes). - USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). - USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). - USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes). - USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes). - usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes). - usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes). - usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes). - usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). - wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes). - wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). - wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). - wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). - wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). - wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). - wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes). - wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). - wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). - wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). - wifi: nl80211: reject oversized EMA RNR lists (git-fixes). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2485-1 Released: Mon Jun 22 14:06:22 2026 Summary: Security update for util-linux Type: security Severity: moderate References: 1261606,CVE-2026-27456 This update for util-linux fixes the following issue - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2528-1 Released: Tue Jun 23 11:06:07 2026 Summary: Security update for sqlite3 Type: security Severity: important References: 1268012,1268013,CVE-2026-11822,CVE-2026-11824 This update for sqlite3 fixes the following issues Update to 3.53.2: - CVE-2026-11822: memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution (bsc#1268012). - CVE-2026-11824: heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code (bsc#1268013). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2531-1 Released: Tue Jun 23 12:25:09 2026 Summary: Security update for libsolv, libzypp, zypper Type: security Severity: important References: 1158038,1239718,1246504,1247948,1249435,1252744,1253193,1253740,1257068,1257882,1258193,1259311,1259706,1259802,1259842,1265223,1265935,1265938,1266039,1267426,1267874,CVE-2026-25707,CVE-2026-44933,CVE-2026-44941,CVE-2026-44942,CVE-2026-48863,CVE-2026-9149,CVE-2026-9150 This update for libsolv, libzypp, zypper fixes the following issues - CVE-2026-9149: Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file (bsc#1265935). - CVE-2026-9150: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums (bsc#1265938). - CVE-2026-25707: Handcrafted repo metadata may cause arbitrary local files to be overwritten (bsc#1259802). - CVE-2026-44933: scan of the Mandatory signature verification plugin support (bsc#1265223). - CVE-2026-44941: path traversal via 'keyhint' (bsc#1267426). - CVE-2026-44942: .repo files can have an optional path which can lead to path traversal attacks (bsc#1267874). - CVE-2026-48863: Fix buffer overflow when parsing EdDSA signature (bsc#1266039). Changes in libzypp: Updated to version 17.38.13 (35): - A .repo files 'path=' entry must not refer to a location outside the repo (bsc#1267874, CVE-2026-44942) A 'path=' entry may solely denote a sub-directory of the baseurl where the metadata are located. A relative path trying to access data outside the baseurl is reported and sanitized. - Fix potential crash on malformed or malicious repository metadata (fixes #740) - Repo metadata: discard entries referring to a location outside the repo (bsc#1259802, CVE-2026-25707) Mirroring those data locally would refer to a location outside the repo's local cache directory. Those data entries are reported and discarded. - zypp.conf: Allow [env] section to add environment variables. This feature is designed to enable environment-specific settings or debugging options over an extended period. See zypp.conf(5). - Prevent configured scripts from escaping the sigcheck directory (bsc#1265223, CVE-2026-44933) - StringV: guard hasPrefix/hasPrefixCI against reading past the view end (fixes #735) - Mandatory signature verification plugin support (PED#11922) - Fix purge-kernel -rc kernel handling (bsc#1239718) - Explicitly_set_pool_DISTTYPE_RPM (fixes #726) - Check for trusted key updates when updating the general keyring (bsc#1259706) - Support multiple MirroredOrigin authorities (bsc#1253193) - Workaround doxygen bug: doxygen/doxygen#12057 - libzypp.spec: Add missing graphviz-gd BuildRequires (boo#1259842) - Fix preloader not caching packages from arch specific subrepos (bsc#1253740) - Deprioritize invalid mirrors (fixes openSUSE/zypper#636) - Fix Product::referencePackage lookup (bsc#1259311) Use a provided autoproduct() as hint to the package name of the release package. It might be that not just multiple versions of the same release package provide the same product version, but also different release packages. - specfile: on fedora use %{_prefix}/share as zyppconfdir if %{_distconfdir} is undefined (fixes #693) This will set '-DZYPPCONFDIR=%{zyppconfdir}' for cmake. - Fall back to a writable location when precaching packages without root (bsc#1247948) - Prepare a legacy /etc/zypp/zypp.conf to be installed on old distros. See the ZYPP.CONF(5) man page for details. - Fix runtime check for broken rpm --runposttrans (bsc#1257068) - Avoid libcurl-mini4 when building as it does not support ftp protocol. - Translation: updated .pot file. - zypp.conf: follow the UAPI configuration file specification (PED-14658) In short terms it means we will no longer ship an /etc/zypp/zypp.conf, but store our own defaults in /usr/etc/zypp/zypp.conf. The systems administrator may choose to keep a full copy in /etc/zypp/zypp.conf ignoring our config file settings completely, or - the preferred way - to overwrite specific settings via /etc/zypp/zypp.conf.d/*.conf overlay files. See the ZYPP.CONF(5) man page for details. - cmake: correctly detect rpm6 (fixes #689) - Use 'zypp.tmp' as temp directory component to ease setting up SELinux policies (bsc#1249435) - zyppng: Update Provider to current MediaCurl2 download approach, drop Metalink ( fixes #682 ) Changes in libsolv: Updated to version 0.7.39: - fix solv_chksum_free segfault when called with a NULL pointer - made repo_add_solv more robust against corrupt files [bsc#1265935] [CVE-2026-9149] - fix potential buffer overflow when verifying EdDSA signatures [bsc#1266039] [CVE-2026-48863] - added limit checks in multiple places to catch overflows - reduce the size of the language id cache - fixed Debian canon selection - fixed dbpath detection in repo_rpmdb_librpm - reduced stack usage in repo page compression (needed for musl) - fix parsing of sha512 checksums in debian repositories [bsc#1265938] [CVE-2026-9150] - improve speed of dirpool_add_dir makeing parsing of filelists.xml twice as fast - fix parsing of recommends in the old Mandriva synthesis format - respect the 'default' attribute in environment optionlist in the comps parser - support suse namespace deps in boolean dependencies [bsc#1258193] - support for the Elbrus2000 (e2k) architecture - support language() suse namespace rewriting Changes in zypper: Update to version 1.14.98: - Transactional systems: Delegate rw-commands to transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607) On a transactional system where the root filesystem is mounted read-only, zypper commands that modify the system cannot be executed directly. If the system provides a transactional-wrapper utility, zypper will automatically attempt to invoke it. The wrapper transparently executes the zypper command within a new, writable snapshot and manages the lifecycle of that snapshot based on the command's exit status. On transactional systems lacking a transactional-wrapper, users must manually invoke specialized tools -such as transactional-update- to install, update, or remove software. - Add --filter-version-change to zypper lu. Adds filtering by version change significance to reduce noise in update listings. Supports levels: rebuild (hides rebuild-only changes) and package (hides all release-only changes). - Autorefresh ris-services the way as plugin-services (bsc#1246504) It's actually wrong to treat service refreshes different depending on the service type. For the purpose of a service it makes no difference how the data about the repos to use are acquired. - Report download progress for command line rpms (fixes #613) - Hint to '-vv ref' to see the mirrors used to download the metadata (bsc#1257882) - Service: Allow 'zypper ls SERVICE ...' to test whether a service with this alias is defined (bsc#1252744) The command prints an abstract of all services passed on the command line. It returns 3-ZYPPER_EXIT_ERR_INVALID_ARGS if some argument does not name an existing service. - Keep repo data when updating the service settings (bsc#1252744) - info: Enhance pattern content table (bsc#1158038) Alternatives (multiple packages providing the same requirement) are now listed as a single entry in the content table. The entry shows either the installed package which satisfies the requirement or the requirement itself as type 'Provides'. Listing all potential alternatives was miss leading, especially if the alternatives were mutual exclusive. It looked like an installed pattern had not-installed requirements and it was not possible to install all requirements at the same time. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2637-1 Released: Thu Jun 25 17:42:10 2026 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: This update for mozilla-nss fixes the following issues: Update to NSS 3.112.5: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max. * update to version 2.84 of builtins module. - Added 'Suggests: p11-kit-nss-trust' to favor over mozilla-nss-certs (jsc#PED-15633) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2648-1 Released: Fri Jun 26 13:05:57 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266340,1266341,1266342,1266343,1266345,1266349,1266350,1266351,1266352,1266353,1266355,1266356,1266357,CVE-2026-34180,CVE-2026-34181,CVE-2026-34183,CVE-2026-42766,CVE-2026-42767,CVE-2026-42768,CVE-2026-42769,CVE-2026-42770,CVE-2026-45445,CVE-2026-45446,CVE-2026-45447,CVE-2026-7383,CVE-2026-9076 This update for openssl-3 fixes the following issues - CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340). - CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341). - CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342). - CVE-2026-34181: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (bsc#1266343). - CVE-2026-34183: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (bsc#1266345). - CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349). - CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). - CVE-2026-42768: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (bsc#1266351). - CVE-2026-42769: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (bsc#1266352). - CVE-2026-42770: FFC-DH Peer Validation Uses Attacker-Supplied q (bsc#1266353). - CVE-2026-45445: AES-OCB IV Ignored on EVP_Cipher() Path (bsc#1266355). - CVE-2026-45446: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes (bsc#1266356). - CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2661-1 Released: Fri Jun 26 15:15:48 2026 Summary: Recommended update for curl Type: recommended Severity: important References: 1264971 This update for curl fixes the following issues: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2688-1 Released: Tue Jun 30 10:20:42 2026 Summary: Security update for sg3_utils Type: security Severity: important References: 1267823 This update for sg3_utils fixes the following issue - sg_inq: --export output conformance for SCSI name string and ATA fields (bsc#1267823). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2714-1 Released: Tue Jun 30 14:02:53 2026 Summary: Security update for tar Type: security Severity: important References: 1261900,1265450,1267189,CVE-2026-5704 This update for tar fixes the following issues Security fixes: - CVE-2026-5704: crafted archives can be used to to hide file injection (bsc#1261900). Other fixes: - Fix tar changing dir permissions temporarily even when using --no-overwrite-dir. - Fix --dereference/-h not working properly after CVE-2025-45582 fix (bsc#1265450). - Fix extraction failure for paths like 'a/./b' caused by the gnulib openat2 implementation (bsc#1267189). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2722-1 Released: Wed Jul 1 15:35:13 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1256668,1260531,1262085,1262392,1262617,1262620,1262674,1262748,1262798,1262993,1263057,1263123,1263124,1263137,1263178,1263563,1263568,1263578,1263930,1263934,1263993,1263996,1264045,1264076,1264080,1264137,1264239,1264266,1264437,1264444,1264470,1264549,1264561,1264595,1264603,1264610,1264741,1264763,1265103,1265143,1265628,1266290,1266390,1266397,1266698,1266704,1266705,1266840,1266878,1266895,1266903,1266916,1266922,1266933,1267208,1267251,1267361,1267387,1267431,1267621,1267624,1267628,1267651,1267654,1267685,1267744,CVE-2025-10263,CVE-2025-68822,CVE-2026-23392,CVE-2026-31414,CVE-2026-31429,CVE-2026-31452,CVE-2026-31453,CVE-2026-31469,CVE-2026-31492,CVE-2026-31495,CVE-2026-31499,CVE-2026-31500,CVE-2026-31555,CVE-2026-31560,CVE-2026-31592,CVE-2026-31593,CVE-2026-31664,CVE-2026-31665,CVE-2026-31674,CVE-2026-31680,CVE-2026-31693,CVE-2026-31752,CVE-2026-31759,CVE-2026-43023,CVE-2026-43024,CVE-2026-43028,CVE-2026-43035,CVE-2026-43036,CVE-2026-43049,CVE-2026-43077,CVE-202 6-43083,CVE-2026-43101,CVE-2026-43112,CVE-2026-43119,CVE-2026-43158,CVE-2026-43171,CVE-2026-43187,CVE-2026-43198,CVE-2026-43239,CVE-2026-43339,CVE-2026-43345,CVE-2026-43405,CVE-2026-43469,CVE-2026-43491,CVE-2026-45840,CVE-2026-45841,CVE-2026-45862,CVE-2026-45870,CVE-2026-45894,CVE-2026-45940,CVE-2026-45961,CVE-2026-45964,CVE-2026-45965,CVE-2026-45974,CVE-2026-46005,CVE-2026-46037,CVE-2026-46101,CVE-2026-46119,CVE-2026-46123,CVE-2026-46150,CVE-2026-46160,CVE-2026-46162,CVE-2026-46172,CVE-2026-46244,CVE-2026-46259,CVE-2026-46273 The SUSE Linux Enterprise 15 SP7 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). - CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). - CVE-2026-23392: netfilter: nf_tables: release flowtable after rcu grace period on error (bsc#1260531). - CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). - CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). - CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). - CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false - CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). - CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). - CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). - CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). - CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). - CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057). - CVE-2026-31592: KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). - CVE-2026-31593: KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU (bsc#1263124). - CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). - CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). - CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). - CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). - CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). - CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). - CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). - CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). - CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). - CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). - CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). - CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). - CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). - CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). - CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). - CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). - CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). - CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). - CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). - CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). - CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). - CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). - CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). - CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). - CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). - CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). - CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). - CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). - CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). - CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). - CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). - CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). - CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). - CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). - CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). - CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). - CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). - CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). - CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). - CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). - CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). - CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). - CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). - CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). - CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). - CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840). - CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). - CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). - CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). - CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: - ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). - ACPI: IPMI: Fix message kref handling on dead device (git-fixes). - ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). - ALSA: aloop: Drop superfluous break (git-fixes). - ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). - ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git-fixes). - ALSA: es1938: check snd_ctl_new1() return value (git-fixes). - ALSA: gus: check snd_ctl_new1() return value (git-fixes). - ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes). - ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). - ALSA: seq: Clear variable event pointer on read (git-fixes). - ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes). - ALSA: seq: Fix partial userptr event expansion (git-fixes). - ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). - ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). - ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). - ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). - ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). - ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). - ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). - ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). - ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). - ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). - ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). - ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git-fixes). - ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). - ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). - ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git-fixes). - ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). - ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). - ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). - ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). - ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). - ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes). - ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes). - ASoC: meson: aiu: Validate written enum values (git-fixes). - ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). - ASoC: topology: Check PCM and DAI name strings before use (git-fixes). - ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git-fixes). - Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes). - Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git-fixes). - Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). - Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). - Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). - Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). - Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git-fixes). - Bluetooth: hci: validate codec capability element length (git-fixes). - Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device (git-fixes). - Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). - KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). - KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). - KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). - KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). - KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). - KVM: SVM: check validity of VMCB controls when returning from SMM (git-fixes). - KVM: arm64: Discard PC update state on vcpu reset (git-fixes). - KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). - KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). - KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). - KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). - KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). - KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). - KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). - KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git-fixes). - PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). - USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). - USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). - USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). - X.509: Fix validation of ASN.1 certificate header (git-fixes). - accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes). - agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). - batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). - batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). - batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). - batman-adv: tp_meter: avoid window underflow (git-fixes). - batman-adv: tp_meter: fix fast recovery precondition (git-fixes). - batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). - batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). - batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). - batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). - crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). - crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). - crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git-fixes). - crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). - crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). - crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). - crypto: ccp - Treat zero-length cert chain as query for blob lengths (git-fixes). - crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). - crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). - crypto: drbg - Fix the fips_enabled priority boost (git-fixes). - crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). - crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). - crypto: hisilicon/qm - disable error report before flr (git-fixes). - crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git-fixes). - crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). - crypto: qat - protect service table iterations with service_lock (git-fixes). - crypto: qat - validate RSA CRT component lengths (git-fixes). - crypto: rng - Free default RNG on module exit (git-fixes). - driver core: reject devices with unregistered buses (git-fixes). - driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git-fixes). - drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). - drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git-fixes). - drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). - drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). - drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). - drm/amdkfd: always resume_all after suspend_all (git-fixes). - drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). - drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git-fixes). - drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git-fixes). - drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). - drm/gpuvm: Do not prepare NULL objects (git-fixes). - drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git-fixes). - drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). - drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). - drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). - drm/imagination: Count paired job fence as dependency in prepare_job() (git-fixes). - drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes). - drm/msm/dp: Fix the ISR_* enum values (git-fixes). - drm/msm/dp: fix HPD state status bit shift value (git-fixes). - drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). - drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes). - drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). - drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git-fixes). - drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git-fixes). - drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes). - drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). - drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git-fixes). - drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). - drm/tidss: Fix missing drm_bridge_add() call (git-fixes). - drm/vc4: fix krealloc() memory leak (git-fixes). - drm/virtio: Fix driver removal with disabled KMS (git-fixes). - drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). - drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes). - drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes). - fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git-fixes). - fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). - fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). - fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git-fixes). - fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). - fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). - fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git-fixes). - fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). - fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). - fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). - fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). - fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git-fixes). - fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). - fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). - firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). - firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). - firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). - firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). - gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). - gpu: host1x: Allow entries in BO caches to be freed (git-fixes). - gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). - hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). - hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). - hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). - i2c: core: fix irq domain leak on adapter registration failure (git-fixes). - i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). - i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). - ice: ptp: do not WARN when controlling PF is unavailable (bsc#1267251). - misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). - misc: fastrpc: fix DMA address corruption due to find_vma misuse (git-fixes). - misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git-fixes). - misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). - of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). - scripts/submit_branch: add SLE15-SP7 submission script - serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git-fixes). - serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git-fixes). - slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). - soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). - soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). - spi: at91-usart: drop dead runtime pm support (git-fixes). - spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). - spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). - spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git-fixes). - spi: meson-spifc: fix runtime PM leak on remove (git-fixes). - spi: xilinx: use FIFO occupancy register to determine buffer size (git-fixes). - thermal: hwmon: Fix critical temperature attribute removal (git-fixes). - thunderbolt: Bound root directory content to block size (git-fixes). - thunderbolt: Clamp XDomain response data copy to allocation size (git-fixes). - thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). - thunderbolt: Reject zero-length property entries in validator (git-fixes). - thunderbolt: Validate XDomain request packet size before type cast (git-fixes). - watchdog: apple: Add 'apple,t8103-wdt' compatible (git-fixes). - watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). - watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). - watchdog: unregister PM notifier on watchdog unregister (git-fixes). - wifi: ath11k: fix warning when unbinding (git-fixes). - wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). - wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). - wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). - wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). - wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). - wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). - wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). - wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). - wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). - wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). - wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). - wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). - wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). - wifi: rtw89: Correct data type for scan index to avoid infinite loop (git-fixes). - wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). - wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git-fixes). - wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git-fixes). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2777-1 Released: Mon Jul 6 10:57:12 2026 Summary: Security update for cryptsetup, s390-tools Type: security Severity: moderate References: 1241612,1259314,1261813,1270185,CVE-2026-41676 This update for cryptsetup, s390-tools fixes the following issue Security fixes: - CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270185). Changes for s390-tools: - Upgrade s390-tools to version 2.41.0 (jsc#PED-15860) - Automatically set appropriate MTU for HSCI (bsc#1259314) - Changes of existing tools: * chreipl: Make --bootparms work for ECKD re-IPL * cpacfstats: Add 'unauthorized' state to CPU-MF counters * cpictl: Detect RHCOS using VARIANT_ID * hsci: Automatically set appropriate MTU for HSCI * libutil: Add util_readlink() and util_readlinkat() helpers * libutil: Add util_startswith() to util_str * libutil: Add utility parsing functions * lschp: Add support for structured output (--format) * lsreipl: Suppress 'clear' output if not supported * pvimg: Add '--format text' support to 'pvimg info' * pvimg: Add '--print-schema ' option to 'pvimg info' * pvimg: Add '--show-secrets' flag to 'pvimg info' * pvimg: Provide improved JSON output to 'pvimg info --format json' * pvinfo: Improve User experience on non-SE enabled systems * zipl/ngdump: Ensure ext4 file system is used on dump partition * zkey: Add support for integrity protected disks using HMAC keys - Bug Fixes: * cpumf/pai: Handle different size of perf_event_attr * lscss: Fix memory leak * zipl: Fix dump job on tape devices --- s390-tools 2.40 includes --- - Add new tools / libraries: * Add project-wide .clang-tidy configuration * libutil: Introduce util_time for time related functionality * libutil: Introduce zsh/bash autocompletion tooling based on util_opt * pvinfo: Tool to display Secure Execution system information * pvverify: Tool to verify host-key documents - Changes of existing tools: * cpumf: Implement zsh and bash autocompletion * dasdfmt: Implement zsh and bash autocompletion * dbginfo.sh: Add NetworkManager and netplan * dbginfo.sh: Add kvm_stat * dbginfo.sh: Adding stp time information * dbginfo.sh: Simplify procfs collection * hyptop: Add physical information row * hyptop: Calculate sample time delta for physical partition * hyptop: Replace long option names using _ with - for consistency For example: --cpu_types > --cpu-types (Options with _ are still supported for backward compatibility) * libekmfweb: Add function to validate a certificate against the identity key * netboot: Add longer kernel command lines support * udev/rules.d: Make virtio-blk devices non-rotational * udev/rules.d: Set default io scheduler to 'none' for virtio-blk * ziomon: Add support to sample device symlinks (/dev/disk/...) * ziorep_config: Add fcp-lun details to -M option output * ziorep_config: Add port_id and failed attributes to -A option output * netboot: Install on non-s390 architectures - Bug Fixes: * lib(ekmfweb|kmipclient): Use ln without -r * s390-tools: Fix various compilation issues with musl libc * zipl/boot: Fix unused loadparm when SCLP line-mode console is absent --- s390-tools 2.39 includes --- - Changes of existing tools: * chpstat: Add options to select IEC units for scaling (SI units are default) * chzdev: Introduce --no-module-load option * cpi: Disable CPI for SEL guests by default * dbginfo.sh: Enhance logging on timeout triggered * iucvterm: Install symlink for lsiucvallow.8 man page * lshwc: Add command line flag to specify individual counters * lspai: Add command line flag for delta values * lspai: Add command line flag for short counter names * lspai: Add command line flag to specify individual counters * lspai: Add command line flags for all cpus * lspai: Add command line flags for hexadecimal output * man: Use CR for constant width font * pvimg: Add '--image-key' option * zdev: Allow dynamic control of module load * zipl/boot: Fix EBCDIC code page 500 conversion and decrease size by 200 bytes * zipl: Add support of heterogeneous mirrors (remove technical limitations on mirrored targets, thus allowing mirrored devices consist of partitions at different offsets on disks of different types and geometry). * zkey: Add support for generating and importing exportable secure keys - Bug Fixes: * chpstat: Fix scaling of DPU utilization calculation * zdev/dracut: Prevent loading of unused kernel modules * zdev: Fix double device configuration on DPM systems * zdev: Fix double device configuration with rd.dasd * zipl_helper.device-mapper: Fix segfault in an error path --- s390-tools 2.38 includes --- * Add new tools - udev: New rule to set newly hotplugged CPUs online - zmemtopo: Display memory topology information - zpwr: Display power readings of a partition and CPC * Removed tools / features - check_hostkeydoc: Remove installation target - scsi_logging_level: Delete SCSI logging script (available in sg3_utils) - zdump: Drop build_arch for s390 DASD dumps - zdump: Drop non-extended multi-volume DASD dump support - zdump: Drop support of 32-bit dump architecture - zdump: Drop support of non-extended single volume DASD dumpers - zdump: Drop support of obsolete dumps and dumpers * Changes of existing tools / libraries - Various man-pages fixes - check_hostkeydoc: Add deprecation warning - check_hostkeydoc: Move to scripts directory - cpuplugd: Allow cpu hotplugging on systems without polarization - dbginfo.sh: Add Ubuntu snap tool - dbginfo.sh: Add missing config data and logs - dbginfo.sh: Reworking the container section - dbginfo.sh: Update for network commands - dbginfo.sh: Updating info for disks and lvm - libutil: Add machine type definition for machines 9175 and 9176 - lscpumf: Add support for IBM z17 counter sets - lshwc: Add command line flag for run time - lshwc: Add flags to display counter values in hex - lshwc: Add output '--format' option - lshwc: Add support for delta counter value display - lspai: Add output '--format' option - lsreipl: Add secure boot state to output - lswhc: Add short names to lshwc output - pv_tools: Add Bash and Zsh completions - pvapconfig: Add '--unbind' option - pvimg/boot: Print error messages from stage3a bootloader - pvimg: Add support for CCK update - pvsecret: Add support for CCK update - pvsecret: Allow retrieving secrets by index; warn for duplicated entries - pvsecret: Deny adding secrets with duplicated secret IDs - zdev: Add support for virtio devices - zipl: Enhance mirror support - zipl: Implement '--dry-run' option for all dump jobs - zipl_helper.device-mapper: Support mirrors over NVMe devices - zkey/dracut: Add a dracut config file for zkey - zkey/initramfs: Update initramfs hook to correct drivers and include zkey plugins - zkey: Add support for converting a clear-key LUKS2 volume to use a secure key * Bug Fixes - chpstat: Add missing CMG 5 data fields - chpstat: Fix DPU utilization calculation - libutil/util_file: Handle over-read in util_file_read_fd() - pvattest: Fix successful 'check' evaluation - pvsecret: Fix some edge cases for plaintext keys - zipl_helper.device-mapper: Fix imprecise is_device_mapper() predicate - zkey: Fix EP11 secure key reencipher function - zpcictl: Fix command line parsing for invalid options - Amended the .spec file * 'Installing' all shipped rules from etc/udev/rules.d to /usr/lib/udev/rules.d * BuildRequires: cryptsetup-devel > 2.8.2 - Updated the code for IBM z17 machine type 9176: * read_values.c * cputype * Renamed cputype.1 to cputype.8 and amended * Amended read_values.8 - 'Improved' the read_values.c: * Added functionalities for '-a' and '-L attributes' - Removed legacy suse_version and sle_version conditionals, standardizing on UsrMerge paths. - Reworked and combined all s390-tools patches (jsc#PED-14586) - Added new combined and reworked patches - Removed obsolete patches - Applied patches (bsc#1261813) * Replace sort_field option with sort * hyptop opts Fix long command line option abbreviations - Removed obsolete patch - Re-vendor-ed vendor.tar.zst Changes for cryptsetup: - Update to 2.8.4: (jsc#PED-15889) * Fix integritysetup resize (grow) of the device if integrity bitmap mode is used. Increasing the integrity device in bitmap mode did not work as integritysetup incorrectly used journal settings that were not applicable. * Fix device size status reports in cryptsetup and integritysetup. If the device uses a sector size larger than 512 bytes, the newly reported byte sizes (introduced in 2.8.0) in the status report were incorrectly displayed. * BITLK: Fix unlocking BitLocker device with recovery passphrase. If the recovery passphrase was present in the first keyslot, the device failed to unlock. This bug was introduced in 2.8.2 with Clear Key support. - Update to 2.8.3: * Stable bug-fix release with minor extensions. - Update to 2.8.2: * BITLK: Fix for BitLocker metadata validation on big-endian systems. - Update to 2.8.1: * Fix status and deactivation of TCRYPT (VeraCrypt compatible) devices that use chained ciphers. * Fix unlocking BITLK (BitLocker compatible) devices with multibyte UTF8 characters in the passphrase. * Do not allow activation of the LUKS2 device if the used keyslot is not encrypted (it uses a null cipher). - Such a configuration cannot be created by cryptsetup, but can be crafted outside of it. - Null cipher is sometimes used to create an empty container for later reencryption. - Only an empty passphrase can activate such a container (the same as in LUKS1). * Do not silently decrease PBKDF parallel cost (threads) if set by an option. - The maximum parallel cost is limited to 4 threads. * Fixes to configuration and installation scripts. - Meson and autoconf tools now properly support --prefix option for temporary directory installation. - Multiple fixes and cleanups to config.h for compatibility between Meson and autoconf. - Fix the luks2-external-tokens-path Meson option to work the same as in autoconf. - Fix Meson install for tool binaries, install fvault2Open man page and include test/fuzz/meson.build in release. * Major update to manual pages. - Try to explain the PBKDF hardcoded limits. - Add a better explanation for automatic integrity tag recalculation. - Mention crypt/verity/integritytab. - Remove or reformulate some misleading warnings present only with old and no longer supported kernels. - Clarify that some commands do not wipe data and unify OPAL reset wording. - Clarify the --label option. - There are also many other grammar and stylistic fixes to unify the man-page style. * Fixes for false-positive and annoying (optional) warnings added in recent compilers. - Update to 2.8.0: * Full release notes in: - https://cdn.kernel.org/pub/linux/utils/cryptsetup/v2.8/v2.8.0-ReleaseNotes * Introduce support for inline mode (use HW sectors with additional hardware metadata space). * Finalize use of keyslot context API. * Make all keyslot context types fully self-contained. * Add --key-description and --new-key-description cryptsetup options. * Support more precise keyslot selection in reencryption initialization. * Allow reencryption to resume using token and volume keys. * Cryptsetup repair command now tries to check LUKS keyslot areas for corruption. * Opal2 SED: PSID keyfile is now expected to be 32 alphanumeric characters. * Opal2: Avoid the Erase method and use Secure Erase for locking range. * Opal2: Fix some error description (in debug only). * Opal2: Do not allow deferred deactivation. * Allow --reduce-device-size and --device-size combination for reencryption (encrypt) action. * Fix the userspace storage backend to support kernel 'capi:' cipher specification format. * Disallow conversion from LUKS2 to LUKS1 if kernel 'capi:' cipher specification is used. * Explicitly disallow kernel 'capi:' cipher specification format for LUKS2 keyslot encryption. * Do not allow conversion of LUKS2 to LUKS1 if an unbound keyslot is present. * cryptsetup: Adjust the XTS key size for kernel 'capi:' cipher specification. * Remove keyslot warning about possible failure due to low memory. * Do not limit Argon2 KDF memory cost on systems with more than 4GB of available memory. * Properly report out of memory error for cryptographic backends implementing Argon2. * Avoid KDF2 memory cost overflow on 32-bit platforms. * Do not use page size as a fallback for device block size. * veritysetup: Check hash device size in advance. * Print a better error message for unsupported LUKS2 AEAD device resize. * Optimize LUKS2 metadata writes. * veritysetup: support --error-as-corruption option. * Report all sizes in status and dump command output in the correct units. * Add --integrity-key-size option to cryptsetup. * Support trusted; encrypted keyrings for plain devices. * Support plain format resize with a keyring key. * TCRYPT: Clear mapping of system-encrypted partitions. * TCRYPT: Print all information from the decrypted metadata header in the tcryptDump command. * Always lock the volume key structure in memory. * Do not run direct-io read check on block devices. * Fix a possible segfault in deferred deactivation. * Exclude cipher allocation time from the cryptsetup benchmark. * Add Mbed-TLS optional crypto backend. * Fix the wrong preprocessor use of #ifdef for config.h processed by Meson. * Reorganize license files. The license text files are now in docs/licenses. The COPYING file in the root directory is the default license. * Remove cc-by-sa-4.0.txt as already shipped now in docs/licenses and named as COPYING.CC-BY-SA-4.0. * Libcryptsetup API extensions. The libcryptsetup API is backward compatible with all existing symbols. Due to the self-contained memory allocation, these symbols have the new version: - crypt_keyslot_context_init_by_passphrase; - crypt_keyslot_context_init_by_keyfile; - crypt_keyslot_context_init_by_token; - crypt_keyslot_context_init_by_volume_key; - crypt_keyslot_context_init_by_signed_key; - crypt_keyslot_context_init_by_keyring; - crypt_keyslot_context_init_by_vk_in_keyring; * New symbols: - crypt_format_inline - crypt_get_old_volume_key_size - crypt_reencrypt_init_by_keyslot_context - crypt_safe_memcpy * New defines: - CRYPT_ACTIVATE_HIGH_PRIORITY - CRYPT_ACTIVATE_ERROR_AS_CORRUPTION - CRYPT_ACTIVATE_INLINE_MODE - CRYPT_REENCRYPT_CREATE_NEW_DIGEST * New requirement flag: - CRYPT_REQUIREMENT_INLINE_HW_TAGS - Add a dependency on device-mapper to libcryptsetup12 to install the required device-mapper udev rules. (bsc#1241612) - Update to 2.7.5: * Fix possible online reencryption data corruption (only in 2.7.x). In some situations (initializing a suspended device-mapper device), cryptsetup disabled direct-io device access. This caused unsafe online reencryption operations that could lead to data corruption. The code now adds strict checks (and aborts the operation) and changes direct-io detection code to prevent data corruption. * Fix a clang compilation error in SSH token plugin. As clang linker treats missing symbols as errors, the linker phase for the SSH token failed as the optional cryptsetup_token_buffer_free was not defined. * Fix crypto backend initialization in crypt_format_luks2_opal API call. - Update to 2.7.4: * Detect device busy failure for device-mapper table-referenced devices. * Fix shared activation for dm-verity devices. * Add --shared option for veritysetup open action. * Do not use exclusive flag for the allocated backing loop files. * Fixes for problems found by static analyzers and Valgrind. * Fixes to tests and CI scripts. - Use fdupes to link identical man pages. - Update to 2.7.3: * Do not allow formatting LUKS2 with Opal SED (hardware encryption) if the reported logical sector size for the block device and Opal encryption logical block differs. * Fixes to wiping LUKS2 headers after Opal locking area erase. * Mention the need for possible PSID revert before Opal format for some drives (man page). * Fix Bitlocker-compatible code to ignore newly seen metadata entries. * Fix interactive query retry if LUKS2 unbound keyslot is present. * Detect unsupported zoned devices for LUKS header devices. * Allow 'capi' cipher format for benchmark command and fix parsing of plain IV in 'capi' format. * Add support for HCTR2 encryption mode. * Source code now uses SPDX license identifiers instead of full license preambles. * Fix missing includes for cryptographic backend that could cause compilation errors for some systems. * Fix tests to work correctly in FIPS mode with recent OpenSSL 3.2. * Fix various (mostly false positive) issues detected by Coverity. - License: Replace legacy 'AND SUSE-GPL-2.0-with-openssl-exception' with 'WITH cryptsetup-OpenSSL-exception' (the official SPDX exception). - update to 2.7.2: * Fix activation of OPAL-only encrypted LUKS device with tokens * Fix formatting of OPAL devices with 4096-byte sector size * Fix incorrect OPAL locking range alignment calculation if used over an unaligned device partition. * Do not check the passphrase quality for OPAL Admin PIN, as this passphrase already exists. * Update license for FAQ document to CC BY-SA 4.0. NOTE: Please note that with OPAL-only (--hw-opal-only) encryption, the configured OPAL administrator PIN (passphrase) allows unlocking all configured locking ranges without LUKS keyslot decryption (without knowledge of LUKS passphrase). Because of many observed problems with compatibility, cryptsetup currently DOES NOT use OPAL single-user mode, which would allow such decoupling of OPAL admin PIN access. - Update to 2.7.1: * Fix interrupted LUKS1 decryption resume. With the replacement of the cryptsetup-reencrypt tool by the cryptsetup reencrypt command, resuming the interrupted LUKS1 decryption operation could fail. LUKS2 was not affected. * Allow --link-vk-to-keyring with --test-passphrase option. This option allows uploading the volume key in a user-specified kernel keyring without activating the device. * Fix crash when --active-name was used in decryption initialization. * Updates and changes to man pages, including indentation, sorting options alphabetically, fixing mistakes in crypt_set_keyring_to_link, and fixing some typos. * Fix compilation with libargon2 when --disable-internal-argon2 was used. * Do not require installed argon2.h header and never compile internal libargon2 code if the crypto library directly supports Argon2. * Fixes to regression tests to support older Linux distributions. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2800-1 Released: Wed Jul 8 16:59:16 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1236743,1255029,1259764,1261256,1261562,1261604,1262618,1262655,1263072,1263560,1263573,1263581,1263879,1263880,1263998,1264001,1264015,1264084,1264116,1264145,1264228,1264230,1264231,1264236,1264241,1264254,1264258,1264261,1264263,1264286,1264294,1264320,1264337,1264449,1264484,1264562,1264612,1264734,1264748,1264814,1264974,1265113,1265421,1265629,1266008,1266396,1266700,1266717,1266734,1266830,1266847,1266899,1266928,1266929,1267228,1267365,1267369,1267381,1267427,1267430,1267437,1267458,1267567,1267582,1267591,1267635,1267637,1267640,1267682,1267684,1267697,1267717,1267722,1267825,1267918,1267937,1267953,1267966,1267993,1268022,1268037,1268049,1268159,1268237,1268307,1268335,1268428,1268660,1268661,1269022,1269033,1269090,1269100,1269103,1269135,1269136,1269137,1269184,1269195,1269199,1269281,1269310,1269314,1269397,1269398,1269418,1269493,1269506,1269519,1269574,1269617,1269678,1269681,1269798,1269821,1269884,1270059,CVE-2025-40216,CVE-2025-40341,CVE-2025-71294,CVE- 2026-23451,CVE-2026-31450,CVE-2026-31462,CVE-2026-31466,CVE-2026-31502,CVE-2026-31647,CVE-2026-31670,CVE-2026-31677,CVE-2026-31697,CVE-2026-31698,CVE-2026-31699,CVE-2026-31771,CVE-2026-43010,CVE-2026-43022,CVE-2026-43034,CVE-2026-43053,CVE-2026-43074,CVE-2026-43079,CVE-2026-43080,CVE-2026-43081,CVE-2026-43085,CVE-2026-43086,CVE-2026-43089,CVE-2026-43093,CVE-2026-43094,CVE-2026-43107,CVE-2026-43109,CVE-2026-43128,CVE-2026-43139,CVE-2026-43233,CVE-2026-43238,CVE-2026-43284,CVE-2026-43303,CVE-2026-43336,CVE-2026-43420,CVE-2026-43456,CVE-2026-43472,CVE-2026-43492,CVE-2026-43502,CVE-2026-45838,CVE-2026-45848,CVE-2026-45891,CVE-2026-45912,CVE-2026-45948,CVE-2026-45985,CVE-2026-46028,CVE-2026-46053,CVE-2026-46063,CVE-2026-46065,CVE-2026-46069,CVE-2026-46071,CVE-2026-46076,CVE-2026-46112,CVE-2026-46116,CVE-2026-46120,CVE-2026-46124,CVE-2026-46133,CVE-2026-46173,CVE-2026-46185,CVE-2026-46197,CVE-2026-46214,CVE-2026-46227,CVE-2026-46229,CVE-2026-46253,CVE-2026-46254,CVE-2026-46266,CVE-2026-46 274,CVE-2026-46289,CVE-2026-46291,CVE-2026-46315,CVE-2026-46319,CVE-2026-46320,CVE-2026-46328,CVE-2026-46330,CVE-2026-46331,CVE-2026-52908,CVE-2026-52909,CVE-2026-52918,CVE-2026-52923,CVE-2026-52943,CVE-2026-52954,CVE-2026-52957,CVE-2026-52962,CVE-2026-52969,CVE-2026-52972,CVE-2026-53016,CVE-2026-53040,CVE-2026-53041,CVE-2026-53052,CVE-2026-53053,CVE-2026-53071,CVE-2026-53072,CVE-2026-53122,CVE-2026-53133,CVE-2026-53138,CVE-2026-53182,CVE-2026-53253,CVE-2026-53266,CVE-2026-53281,CVE-2026-53287,CVE-2026-53359,CVE-2026-53362 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-40216: io_uring/rsrc: don't rely on user vaddr alignment (bsc#1259764). - CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). - CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). - CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). - CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). - CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). - CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). - CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). - CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581). - CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). - CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). - CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). - CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). - CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). - CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). - CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). - CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). - CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). - CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). - CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). - CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). - CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). - CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). - CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). - CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). - CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). - CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). - CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231). - CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). - CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). - CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). - CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). - CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). - CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). - CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). - CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). - CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). - CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). - CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). - CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). - CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). - CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). - CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). - CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). - CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). - CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). - CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). - CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). - CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). - CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). - CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). - CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). - CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). - CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). - CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). - CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). - CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). - CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). - CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). - CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). - CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). - CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). - CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). - CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). - CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). - CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). - CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). - CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). - CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). - CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). - CVE-2026-46315: io_uring/waitid: clear waitid info before copying it to userspace (bsc#1267953). - CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). - CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). - CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). - CVE-2026-46330: Revert 'net/smc: Introduce TCP ULP support' (bsc#1268049). - CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). - CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). - CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). - CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). - CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). - CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). - CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). - CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). - CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). - CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). - CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). - CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). - CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). - CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). - CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). - CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). - CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). - CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). - CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). - CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). - CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). - CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). - CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). - CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). - CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). - CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). - CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). - CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: - ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). - ACPI: resource: Amend kernel-doc style (git-fixes). - ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). - ALSA: firewire: isight: bound the sample count to the packet payload (git-fixes). - ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). - ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). - ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). - ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). - ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). - ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git-fixes). - ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git-fixes). - ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git-fixes). - Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable-fixes). - bnxt_en: Fix NULL pointer dereference (bsc#1268307). - bus: mhi: ep: Add missing state_lock protection for mhi_state access (git-fixes). - bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). - bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). - char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). - dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). - dmaengine: Fix possible use after free (git-fixes). - dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). - dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). - dmaengine: tegra: Fix burst size calculation (git-fixes). - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes). - drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable-fixes). - drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). - drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes). - drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes). - drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes). - drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git-fixes). - drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). - drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). - drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git-fixes). - drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). - drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). - drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable-fixes). - drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). - drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). - drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes). - drm/dp: Add eDP 1.5 bit definition (stable-fixes). - drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). - drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). - drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). - drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes). - drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). - drm/nouveau: fix reversed error cleanup order in ucopy functions (git-fixes). - ethtool: provide customized dim profile management (bsc#1261256). - fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). - fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). - fpga: region: fix use-after-free in child_regions_with_firmware() (git-fixes). - HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). - HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). - HID: wacom: stop hardware after post-start probe failures (git-fixes). - HID: wiimote: Fix table layout and whitespace errors (git-fixes). - hv: utils: handle and propagate errors in kvp_register (git-fixes). - hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). - hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). - i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). - i2c: mpc: Fix timeout calculations (git-fixes). - i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). - i3c: master: Prevent reuse of dynamic address on device add failure (git-fixes). - iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). - iio: adc: npcm: Convert to platform remove callback returning void (stable-fixes). - iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). - iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). - iio: chemical: scd30: fix division by zero in write_raw (git-fixes). - iio: chemical: scd30: Use guard(mutex) to allow early returns (stable-fixes). - iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git-fixes). - iio: gyro: bmg160: wait full startup time after mode change at probe (git-fixes). - iio: light: opt3001: fix missing state reset on timeout (git-fixes). - iio: light: si1133: prevent race condition on timeout (git-fixes). - iio: light: si1133: reset counter to prevent race condition (git-fixes). - iio: light: veml6030: fix channel type when pushing events (git-fixes). - iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). - iio: magnetometer: ak8975: fix potential kernel stack memory leak (git-fixes). - iio: tcs3472: power down chip on probe failure (git-fixes). - iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). - Input: elan_i2c - validate firmware size before use (stable-fixes). - Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable-fixes). - Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). - Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git-fixes). - Input: xpad - add 'Nova 2 Lite' from GameSir (stable-fixes). - Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). - iommu/s390: allow larger region tables (jsc#PED-15880). - iommu/s390: Fix memory corruption when using identity domain (jsc#PED-15880). - iommu/s390: handle IOAT registration based on domain (jsc#PED-15880). - iommu/s390: implement iommu passthrough via identity domain (jsc#PED-15880). - iommu/s390: set appropriate IOTA region type (jsc#PED-15880). - iommu/s390: support cleanup of additional table regions (jsc#PED-15880). - iommu/s390: support iova_to_phys for additional table regions (jsc#PED-15880). - iommu/s390: support map/unmap for additional table regions (jsc#PED-15880). - KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). - KVM: s390: Limit adapter indicator access to mapped page (bsc#1268159). - KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). - KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). - KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). - KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). - KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git-fixes). - KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). - KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). - KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). - leds: uleds: Fix potential buffer overread (git-fixes). - linux/dim: move useful macros to .h file (bsc#1261256). - loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). - loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). - mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). - media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). - media: cec: seco: unregister adapter on IR probe failure (git-fixes). - media: cedrus: Fix failure to clean up hardware on probe failure (git-fixes). - media: cedrus: Fix missing cleanup in error path (git-fixes). - media: cedrus: skip invalid H.264 reference list entries (git-fixes). - media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). - media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). - media: pci: dm1105: Free allocated workqueue (git-fixes). - media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). - media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). - media: vidtv: fix reference leak on failed device registration (git-fixes). - media: vimc: fix reference leak on failed device registration (git-fixes). - media: vpif_capture: fix OF node reference imbalance (git-fixes). - module: fix init_module_from_file() error handling (jsc#PED-16303). - module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). - module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). - module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). - module: warn about excessively long module waits (jsc#PED-16303). - modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). - mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git-fixes). - mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). - mtd: rawnand: pl353: fix probe resource allocation (git-fixes). - mtd: slram: remove failed entries from the device list (git-fixes). - mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). - mtd: spi-nor: swp: Improve locking user experience (git-fixes). - net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). - net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). - net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). - net: mana: Add support for PF device 0x00C1 (bsc#1268237). - net: mana: Add support for RX CQE Coalescing (bsc#1261256). - net: mana: Allocate interrupt context for each EQ when creating vPort (git-fixes). - net: mana: Create separate EQs for each vPort (git-fixes). - net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-fixes). - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git-fixes). - net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). - net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). - net: mana: Optimize irq affinity for low vcpu configs (git-fixes). - net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). - net: mana: Use GIC functions to allocate global EQs (git-fixes). - nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). - nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). - nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). - page_pool: Move pp_magic check into helper functions (bsc#1261562). - page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562). - platform/x86: intel-hid: Protect ACPI notify handler against recursion (git-fixes). - platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). - power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). - power: supply: charger-manager: fix refcount leak in is_full_charged() (git-fixes). - power: supply: core: fix supplied_from allocations (git-fixes). - power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). - powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). - powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git-fixes). - RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). - RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). - rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). - rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). - rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). - rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git-fixes). - rtc: mpfs: fix counter upload completion condition (git-fixes). - rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). - s390/pci: check for relaxed translation capability (jsc#PED-15880). - s390/pci: Fix dev.dma_range_map missing sentinel element (jsc#PED-15880). - s390/pci: store DMA offset in bus_dma_region (jsc#PED-15880). - scsi: storvsc: Replace symbolic permissions with octal (git-fixes). - scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). - selftests/bpf: Add BPF_STRICT_BUILD toggle (bsc#1269617). - selftests/bpf: Allow test_progs to link with a partial object set (bsc#1269617). - selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (bsc#1269617). - selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (bsc#1269617). - selftests/bpf: Provide weak definitions for cross-test functions (bsc#1269617). - selftests/bpf: Skip tests whose objects were not built (bsc#1269617). - selftests/bpf: Tolerate benchmark build failures (bsc#1269617). - selftests/bpf: Tolerate BPF and skeleton generation failures (bsc#1269617). - selftests/bpf: Tolerate missing files during install (bsc#1269617). - selftests/bpf: Tolerate test file compilation failures (bsc#1269617). - serdev: make serdev_bus_type const (stable-fixes). - spi: dw: fix wrong BAUDR setting after resume (git-fixes). - spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). - spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). - Split off kABI workaround for bsc#1267458 (bsc#1267458). - staging: most: video: avoid double free on video register failure (git-fixes). - staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). - thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). - tpm: fix event_size output in tpm1_binary_bios_measurements_show (git-fixes). - tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). - usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). - usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). - usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). - usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git-fixes). - usb: host: max3421: Reject hub port requests for non-existent ports (git-fixes). - USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). - USB: serial: option: add MeiG SRM813Q (stable-fixes). - USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). - usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). - usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). - usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). - usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). - usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). - usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). - usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). - vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). - watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199). - x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). - x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2836-1 Released: Fri Jul 10 08:27:12 2026 Summary: Recommended update for sysconfig Type: recommended Severity: moderate References: 1263889 This update for sysconfig fixes the following issues: - Update to version 0.85.11: * netconfig: Do not remove custom /etc/{resolv,yp}.conf on uninstall of sysconfig-netconfig, but only the symlinks to /run/netconfig files created by netconfig or tmpfiles.d(5) (bsc#1263889). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2851-1 Released: Fri Jul 10 15:19:10 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,CVE-2026-6893 This update for dracut fixes the following issue - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: - Update to version 059+suse.570.g2b84048d7: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2925-1 Released: Mon Jul 13 19:53:23 2026 Summary: Security update for curl Type: security Severity: important References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2951-1 Released: Tue Jul 14 11:32:32 2026 Summary: Recommended update for dmidecode Type: recommended Severity: moderate References: This update for dmidecode fixes the following issues: - Update to upstream version 3.7 (jsc#PED-16217): * Support for SMBIOS 3.8.0. This includes a new processor family. * Support for SMBIOS 3.9.0. This includes chassis type name adjustments, new rack attributes, slot ID for more slot types, and new memory device form factors and types. * Decode HPE OEM records 193, 195, 202, 211, 226, 229, 232 and 244. * Update HPE OEM records 203, 216, 242 and 245. * EDSFF slot names now include their .S/.L suffix. - Preserve the use of term 'BIOS' to avoid breaking customer scripts. - Preserve the use of non-binary units to avoid breaking customer scripts. - Drop legacy 'Provides:' and 'Obsoletes:' tags. The split from the pmtools package happened 15 years ago so they are no longer relevant. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2983-1 Released: Tue Jul 14 15:19:38 2026 Summary: Security update for jq Type: security Severity: moderate References: 1262044,1262069,1262070,1262071,1262072,CVE-2026-32316,CVE-2026-33947,CVE-2026-39956,CVE-2026-39979,CVE-2026-40164 This update for jq fixes the following issues: - CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). - CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). - CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). - CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). - CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre-computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3077-1 Released: Thu Jul 16 17:53:44 2026 Summary: Security update for rpcbind Type: security Severity: moderate References: 1267212 This update for rpcbind fixes the following issue - Fix several memory leaks and buffer overflow (bsc#1267212). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3103-1 Released: Fri Jul 17 15:29:55 2026 Summary: Security update for wpa_supplicant Type: security Severity: moderate References: 1239461,1269892,CVE-2025-24912,CVE-2026-58374 This update for wpa_supplicant fixes the following issues: - CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). - CVE-2026-58374: missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) MLO association request processing allows an unauthenticated user to send a crafted management frame and cause an out-of-bounds write (bsc#1269892). - Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/ - Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/ ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3106-1 Released: Fri Jul 17 16:02:05 2026 Summary: Recommended update for kmod Type: recommended Severity: moderate References: This update for kmod fixes the following issues: - Use in-kernel decompression if available (jsc#PED-16303): * libkmod: + Add a separate function to load the file contents when it's needed. When it's not needed on the path of loading modules via finit_module(), there is no need to mmap the file. + Extract 2 functions to handle finit_module vs init_modules differences, with a fallback from the former to the latter. + Don't only set the type as direct, but also keep track of the compression being used. + When creating the context, read /sys/kernel/compression to check. what's the compression type supported by the kernel. + Use kernel decompression when available + add fallback MODULE_INIT_COMPRESSED_FILE define ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3166-1 Released: Tue Jul 21 19:09:06 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1204315,1243603,1251942,1256564,1257605,1257777,1260012,1260593,1261250,1261562,1262391,1262603,1262605,1262614,1262637,1262639,1262649,1262653,1262658,1262659,1262678,1262723,1262751,1262757,1262765,1262768,1262992,1263008,1263011,1263013,1263014,1263016,1263017,1263020,1263025,1263030,1263031,1263045,1263055,1263059,1263068,1263073,1263075,1263077,1263097,1263111,1263128,1263134,1263139,1263142,1263145,1263167,1263173,1263175,1263491,1263493,1263495,1263539,1263562,1263598,1263657,1263776,1263777,1263778,1263780,1263782,1263785,1263786,1263806,1263876,1263904,1263905,1263911,1263923,1263975,1263999,1264003,1264006,1264008,1264009,1264019,1264030,1264032,1264033,1264035,1264039,1264041,1264044,1264048,1264056,1264065,1264070,1264071,1264073,1264074,1264075,1264079,1264088,1264100,1264101,1264110,1264121,1264122,1264125,1264129,1264142,1264180,1264188,1264189,1264190,1264197,1264237,1264247,1264257,1264270,1264296,1264302,1264304,1264308,1264313,1264315,1264317,1264321,1 264322,1264328,1264331,1264336,1264338,1264339,1264340,1264365,1264377,1264379,1264386,1264387,1264388,1264414,1264416,1264417,1264419,1264423,1264424,1264425,1264429,1264431,1264436,1264442,1264451,1264473,1264477,1264479,1264480,1264520,1264526,1264531,1264538,1264540,1264544,1264545,1264548,1264553,1264556,1264560,1264564,1264580,1264584,1264590,1264592,1264594,1264598,1264600,1264613,1264615,1264616,1264618,1264620,1264624,1264626,1264630,1264633,1264637,1264640,1264642,1264644,1264645,1264668,1264677,1264731,1264739,1264744,1264746,1264758,1264768,1264780,1264781,1264782,1264783,1264785,1264788,1264790,1264791,1264794,1264803,1264809,1264815,1264816,1264819,1264821,1264822,1264826,1264830,1264835,1264837,1264844,1264846,1264853,1264978,1264987,1264988,1264991,1264993,1264997,1265019,1265023,1265032,1265037,1265041,1265047,1265054,1265074,1265078,1265079,1265080,1265089,1265092,1265093,1265096,1265100,1265101,1265102,1265105,1265112,1265133,1265138,1265142,1265249,1265257,126526 4,1265627,1266000,1266003,1266399,1266411,1266412,1266458,1266467,1266468,1266677,1266679,1266684,1266686,1266688,1266692,1266703,1266707,1266721,1266722,1266726,1266729,1266732,1266739,1266740,1266741,1266743,1266744,1266751,1266755,1266762,1266773,1266774,1266775,1266777,1266780,1266805,1266806,1266831,1266832,1266834,1266836,1266838,1266839,1266841,1266842,1266846,1266854,1266855,1266863,1266864,1266870,1266872,1266879,1266883,1266884,1266886,1266893,1266894,1266898,1266908,1266910,1266917,1266920,1266925,1266934,1266935,1266939,1266947,1267021,1267027,1267198,1267204,1267213,1267226,1267234,1267251,1267360,1267367,1267380,1267432,1267435,1267436,1267445,1267448,1267449,1267466,1267472,1267473,1267479,1267491,1267493,1267494,1267495,1267496,1267497,1267502,1267524,1267555,1267565,1267571,1267583,1267592,1267595,1267611,1267615,1267616,1267618,1267623,1267627,1267630,1267632,1267636,1267638,1267643,1267646,1267649,1267658,1267661,1267666,1267667,1267669,1267676,1267677,1267680,126 7683,1267690,1267691,1267693,1267701,1267702,1267704,1267712,1267719,1267725,1267728,1267922,1267932,1267939,1267948,1267968,1267987,1267990,1267991,1267992,1267994,1268024,1268049,1268051,1268220,1268221,1268223,1268981,1268986,1268989,1269001,1269002,1269008,1269025,1269030,1269031,1269036,1269081,1269095,1269098,1269106,1269111,1269116,1269124,1269125,1269129,1269131,1269133,1269141,1269151,1269153,1269159,1269164,1269172,1269174,1269177,1269178,1269187,1269188,1269190,1269193,1269230,1269236,1269239,1269245,1269254,1269255,1269257,1269258,1269262,1269273,1269283,1269304,1269364,1269378,1269385,1269386,1269389,1269392,1269403,1269404,1269410,1269414,1269493,1269505,1269527,1269532,1269537,1269556,1269587,1269637,1269644,1269645,1269646,1269651,1269652,1269654,1269661,1269663,1269669,1269670,1269674,1269675,1269677,1269680,1269682,1269684,1269690,1269691,1269700,1269709,1269710,1269711,1269719,1269726,1269733,1269768,1269770,1269772,1269786,1269795,1269796,1269799,1269809,1269811, 1269814,1269817,1269826,1269877,1269886,1269889,1269898,1269899,1269904,1269976,1269984,1269986,1269988,1269989,1269992,1269993,1269996,1269997,1269998,1270022,1270042,1270058,1270059,1270112,1270226,1270241,1270244,1270248,1270249,1270257,1270260,1270263,1270268,1270302,1270396,1271040,1271050,1271248,1271249,1271287,1271366,1271402,CVE-2023-20585,CVE-2025-71274,CVE-2025-71286,CVE-2025-71291,CVE-2025-71297,CVE-2025-71302,CVE-2025-71305,CVE-2025-71314,CVE-2026-23276,CVE-2026-31430,CVE-2026-31439,CVE-2026-31440,CVE-2026-31441,CVE-2026-31447,CVE-2026-31474,CVE-2026-31479,CVE-2026-31485,CVE-2026-31497,CVE-2026-31498,CVE-2026-31503,CVE-2026-31509,CVE-2026-31510,CVE-2026-31511,CVE-2026-31513,CVE-2026-31520,CVE-2026-31522,CVE-2026-31523,CVE-2026-31524,CVE-2026-31532,CVE-2026-31540,CVE-2026-31545,CVE-2026-31548,CVE-2026-31549,CVE-2026-31551,CVE-2026-31552,CVE-2026-31561,CVE-2026-31566,CVE-2026-31568,CVE-2026-31576,CVE-2026-31578,CVE-2026-31581,CVE-2026-31583,CVE-2026-31585,CVE-2026-31587,C VE-2026-31599,CVE-2026-31603,CVE-2026-31604,CVE-2026-31605,CVE-2026-31615,CVE-2026-31616,CVE-2026-31617,CVE-2026-31618,CVE-2026-31619,CVE-2026-31623,CVE-2026-31624,CVE-2026-31625,CVE-2026-31626,CVE-2026-31627,CVE-2026-31651,CVE-2026-31657,CVE-2026-31659,CVE-2026-31660,CVE-2026-31661,CVE-2026-31667,CVE-2026-31672,CVE-2026-31678,CVE-2026-31687,CVE-2026-31701,CVE-2026-31720,CVE-2026-31726,CVE-2026-31727,CVE-2026-31728,CVE-2026-31730,CVE-2026-31747,CVE-2026-31748,CVE-2026-31749,CVE-2026-31751,CVE-2026-31754,CVE-2026-31755,CVE-2026-31756,CVE-2026-31761,CVE-2026-31762,CVE-2026-31763,CVE-2026-31765,CVE-2026-31768,CVE-2026-31770,CVE-2026-31773,CVE-2026-31776,CVE-2026-31778,CVE-2026-31779,CVE-2026-31780,CVE-2026-31781,CVE-2026-43007,CVE-2026-43011,CVE-2026-43017,CVE-2026-43018,CVE-2026-43019,CVE-2026-43020,CVE-2026-43032,CVE-2026-43043,CVE-2026-43047,CVE-2026-43051,CVE-2026-43057,CVE-2026-43058,CVE-2026-43061,CVE-2026-43062,CVE-2026-43064,CVE-2026-43069,CVE-2026-43072,CVE-2026-43092,CVE-2026 -43098,CVE-2026-43104,CVE-2026-43105,CVE-2026-43111,CVE-2026-43113,CVE-2026-43117,CVE-2026-43118,CVE-2026-43123,CVE-2026-43124,CVE-2026-43129,CVE-2026-43133,CVE-2026-43134,CVE-2026-43135,CVE-2026-43136,CVE-2026-43137,CVE-2026-43140,CVE-2026-43141,CVE-2026-43143,CVE-2026-43147,CVE-2026-43149,CVE-2026-43152,CVE-2026-43156,CVE-2026-43157,CVE-2026-43159,CVE-2026-43162,CVE-2026-43167,CVE-2026-43169,CVE-2026-43177,CVE-2026-43180,CVE-2026-43182,CVE-2026-43183,CVE-2026-43189,CVE-2026-43191,CVE-2026-43194,CVE-2026-43196,CVE-2026-43199,CVE-2026-43200,CVE-2026-43202,CVE-2026-43203,CVE-2026-43204,CVE-2026-43205,CVE-2026-43207,CVE-2026-43211,CVE-2026-43215,CVE-2026-43218,CVE-2026-43220,CVE-2026-43221,CVE-2026-43222,CVE-2026-43223,CVE-2026-43225,CVE-2026-43226,CVE-2026-43231,CVE-2026-43232,CVE-2026-43236,CVE-2026-43240,CVE-2026-43241,CVE-2026-43242,CVE-2026-43243,CVE-2026-43244,CVE-2026-43246,CVE-2026-43248,CVE-2026-43251,CVE-2026-43253,CVE-2026-43255,CVE-2026-43256,CVE-2026-43257,CVE-2026-43260, CVE-2026-43264,CVE-2026-43269,CVE-2026-43270,CVE-2026-43277,CVE-2026-43278,CVE-2026-43279,CVE-2026-43287,CVE-2026-43291,CVE-2026-43294,CVE-2026-43295,CVE-2026-43300,CVE-2026-43302,CVE-2026-43304,CVE-2026-43312,CVE-2026-43313,CVE-2026-43314,CVE-2026-43316,CVE-2026-43318,CVE-2026-43319,CVE-2026-43320,CVE-2026-43324,CVE-2026-43327,CVE-2026-43337,CVE-2026-43340,CVE-2026-43342,CVE-2026-43343,CVE-2026-43346,CVE-2026-43353,CVE-2026-43357,CVE-2026-43370,CVE-2026-43373,CVE-2026-43380,CVE-2026-43381,CVE-2026-43382,CVE-2026-43383,CVE-2026-43387,CVE-2026-43395,CVE-2026-43397,CVE-2026-43412,CVE-2026-43425,CVE-2026-43426,CVE-2026-43427,CVE-2026-43428,CVE-2026-43429,CVE-2026-43430,CVE-2026-43432,CVE-2026-43436,CVE-2026-43443,CVE-2026-43444,CVE-2026-43445,CVE-2026-43449,CVE-2026-43450,CVE-2026-43452,CVE-2026-43459,CVE-2026-43465,CVE-2026-43466,CVE-2026-43467,CVE-2026-43468,CVE-2026-43473,CVE-2026-43476,CVE-2026-43480,CVE-2026-43488,CVE-2026-43493,CVE-2026-43496,CVE-2026-43497,CVE-2026-45834,CVE-202 6-45835,CVE-2026-45839,CVE-2026-45851,CVE-2026-45853,CVE-2026-45857,CVE-2026-45858,CVE-2026-45867,CVE-2026-45868,CVE-2026-45869,CVE-2026-45871,CVE-2026-45875,CVE-2026-45877,CVE-2026-45879,CVE-2026-45880,CVE-2026-45881,CVE-2026-45883,CVE-2026-45885,CVE-2026-45899,CVE-2026-45902,CVE-2026-45911,CVE-2026-45914,CVE-2026-45916,CVE-2026-45919,CVE-2026-45920,CVE-2026-45921,CVE-2026-45922,CVE-2026-45923,CVE-2026-45928,CVE-2026-45936,CVE-2026-45941,CVE-2026-45946,CVE-2026-45947,CVE-2026-45954,CVE-2026-45958,CVE-2026-45963,CVE-2026-45969,CVE-2026-45976,CVE-2026-45981,CVE-2026-45982,CVE-2026-45986,CVE-2026-45987,CVE-2026-45994,CVE-2026-45996,CVE-2026-45997,CVE-2026-46006,CVE-2026-46009,CVE-2026-46011,CVE-2026-46016,CVE-2026-46018,CVE-2026-46019,CVE-2026-46023,CVE-2026-46027,CVE-2026-46033,CVE-2026-46040,CVE-2026-46046,CVE-2026-46048,CVE-2026-46049,CVE-2026-46050,CVE-2026-46051,CVE-2026-46052,CVE-2026-46056,CVE-2026-46058,CVE-2026-46059,CVE-2026-46064,CVE-2026-46068,CVE-2026-46075,CVE-2026-46077 ,CVE-2026-46082,CVE-2026-46086,CVE-2026-46088,CVE-2026-46089,CVE-2026-46092,CVE-2026-46099,CVE-2026-46102,CVE-2026-46103,CVE-2026-46108,CVE-2026-46122,CVE-2026-46125,CVE-2026-46128,CVE-2026-46131,CVE-2026-46132,CVE-2026-46136,CVE-2026-46138,CVE-2026-46140,CVE-2026-46143,CVE-2026-46146,CVE-2026-46151,CVE-2026-46152,CVE-2026-46161,CVE-2026-46163,CVE-2026-46165,CVE-2026-46166,CVE-2026-46167,CVE-2026-46177,CVE-2026-46178,CVE-2026-46179,CVE-2026-46184,CVE-2026-46186,CVE-2026-46187,CVE-2026-46190,CVE-2026-46191,CVE-2026-46198,CVE-2026-46199,CVE-2026-46201,CVE-2026-46204,CVE-2026-46205,CVE-2026-46206,CVE-2026-46207,CVE-2026-46211,CVE-2026-46212,CVE-2026-46216,CVE-2026-46218,CVE-2026-46219,CVE-2026-46220,CVE-2026-46225,CVE-2026-46230,CVE-2026-46231,CVE-2026-46232,CVE-2026-46233,CVE-2026-46235,CVE-2026-46236,CVE-2026-46238,CVE-2026-46242,CVE-2026-46247,CVE-2026-46249,CVE-2026-46252,CVE-2026-46261,CVE-2026-46263,CVE-2026-46267,CVE-2026-46270,CVE-2026-46275,CVE-2026-46276,CVE-2026-46285,CVE-20 26-46286,CVE-2026-46294,CVE-2026-46307,CVE-2026-46312,CVE-2026-46313,CVE-2026-46314,CVE-2026-46321,CVE-2026-46322,CVE-2026-46330,CVE-2026-52904,CVE-2026-52914,CVE-2026-52915,CVE-2026-52916,CVE-2026-52919,CVE-2026-52922,CVE-2026-52924,CVE-2026-52926,CVE-2026-52931,CVE-2026-52933,CVE-2026-52936,CVE-2026-52948,CVE-2026-52951,CVE-2026-52953,CVE-2026-52955,CVE-2026-52956,CVE-2026-52958,CVE-2026-52961,CVE-2026-52963,CVE-2026-52964,CVE-2026-52976,CVE-2026-52981,CVE-2026-52982,CVE-2026-52989,CVE-2026-52993,CVE-2026-52995,CVE-2026-53003,CVE-2026-53004,CVE-2026-53009,CVE-2026-53013,CVE-2026-53021,CVE-2026-53022,CVE-2026-53035,CVE-2026-53036,CVE-2026-53037,CVE-2026-53039,CVE-2026-53045,CVE-2026-53047,CVE-2026-53049,CVE-2026-53050,CVE-2026-53056,CVE-2026-53058,CVE-2026-53060,CVE-2026-53065,CVE-2026-53066,CVE-2026-53068,CVE-2026-53070,CVE-2026-53073,CVE-2026-53075,CVE-2026-53078,CVE-2026-53080,CVE-2026-53086,CVE-2026-53090,CVE-2026-53093,CVE-2026-53098,CVE-2026-53112,CVE-2026-53135,CVE-2026-5313 6,CVE-2026-53137,CVE-2026-53139,CVE-2026-53140,CVE-2026-53143,CVE-2026-53144,CVE-2026-53146,CVE-2026-53147,CVE-2026-53148,CVE-2026-53149,CVE-2026-53150,CVE-2026-53158,CVE-2026-53159,CVE-2026-53160,CVE-2026-53161,CVE-2026-53167,CVE-2026-53168,CVE-2026-53176,CVE-2026-53178,CVE-2026-53181,CVE-2026-53186,CVE-2026-53190,CVE-2026-53192,CVE-2026-53194,CVE-2026-53195,CVE-2026-53196,CVE-2026-53202,CVE-2026-53203,CVE-2026-53208,CVE-2026-53209,CVE-2026-53213,CVE-2026-53215,CVE-2026-53216,CVE-2026-53217,CVE-2026-53218,CVE-2026-53224,CVE-2026-53225,CVE-2026-53227,CVE-2026-53229,CVE-2026-53237,CVE-2026-53239,CVE-2026-53241,CVE-2026-53242,CVE-2026-53245,CVE-2026-53246,CVE-2026-53249,CVE-2026-53254,CVE-2026-53255,CVE-2026-53256,CVE-2026-53258,CVE-2026-53268,CVE-2026-53272,CVE-2026-53274,CVE-2026-53279,CVE-2026-53285,CVE-2026-53293,CVE-2026-53306,CVE-2026-53313,CVE-2026-53325,CVE-2026-53329,CVE-2026-53339,CVE-2026-53347,CVE-2026-53350,CVE-2026-53355,CVE-2026-53356,CVE-2026-53357,CVE-2026-53358,CVE-2 026-53359,CVE-2026-53360,CVE-2026-53362,CVE-2026-53366 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2023-20585: iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603). - CVE-2025-71302: drm/panthor: fix for dma-fence safe access rules (bsc#1264837). - CVE-2026-31479: drm/xe: always keep track of remap prev/next (bsc#1262765). - CVE-2026-31503: udp: Fix wildcard bind conflict check when using hash2 (bsc#1263077). - CVE-2026-43019: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (bsc#1264003). - CVE-2026-43057: net: mpls: error out if inner headers are not set (bsc#1264056). - CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). - CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). - CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). - CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). - CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35 (bsc#1264548). - CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). - CVE-2026-43199: net/mlx5e: Fix 'scheduling while atomic' in IPsec MAC address query (bsc#1264556). - CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531). - CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). - CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). - CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). - CVE-2026-43244: kcm: fix zero-frag skb in frag_list on partial sendmsg error (bsc#1264321). - CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). - CVE-2026-43253: iommu/amd: move wait_on_sem() out of spinlock (bsc#1260593 bsc#1264419). - CVE-2026-43260: bnxt_en: Fix RSS context delete logic (bsc#1264429). - CVE-2026-43294: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels (bsc#1264853). - CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993). - CVE-2026-43320: drm/amd/display: Fix dsc eDP issue (bsc#1264987). - CVE-2026-43337: drm/amd/display: Fix NULL pointer dereference in dcn401_init_hw() (bsc#1265112). - CVE-2026-43353: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue (bsc#1265089). - CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). - CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). - CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041). - CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). - CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). - CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). - CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). - CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). - CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978). - CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues (bsc#1264731). - CVE-2026-43496: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1266000). - CVE-2026-45839: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (bsc#1266399). - CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). - CVE-2026-45858: ext4: subdivide EXT4_EXT_DATA_VALID1 (bsc#1266773). - CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). - CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). - CVE-2026-45922: RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler (bsc#1266805). - CVE-2026-45981: s390/cio: Fix device lifecycle handling in css_alloc_subchannel() (bsc#1267204). - CVE-2026-45987: KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (bsc#1267213). - CVE-2026-45994: ibmasm: fix OOB reads in command_file_write due to missing size checks (bsc#1267432). - CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). - CVE-2026-46023: dm mirror: fix integer overflow in create_dirty_log() (bsc#1267449). - CVE-2026-46027: net/smc: avoid early lgr access in smc_clc_wait_msg (bsc#1266744). - CVE-2026-46040: inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (bsc#1267472). - CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). - CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). - CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). - CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). - CVE-2026-46059: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (bsc#1267495). - CVE-2026-46064: ibmasm: fix heap over-read in ibmasm_send_i2o_message() (bsc#1267497). - CVE-2026-46068: crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx (bsc#1267592). - CVE-2026-46086: net: bridge: use a stable FDB dst snapshot in RCU readers (bsc#1267524). - CVE-2026-46089: zram: do not forget to endio for partial discard requests (bsc#1267445). - CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). - CVE-2026-46102: net: strparser: fix skb_head leak in strp_abort_strp() (bsc#1267502). - CVE-2026-46132: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (bsc#1267616). - CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). - CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). - CVE-2026-46191: fbcon: Avoid OOB font access if console rotation fails (bsc#1267690). - CVE-2026-46207: vsock/virtio: fix length and offset in tap skb for split packets (bsc#1267691). - CVE-2026-46216: drm/xe/hdcp: Add NULL check for media_gt in (bsc#1267234). - CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). - CVE-2026-46249: octeontx2-af: Fix PF driver crash with kexec kernel booting (bsc#1267683). - CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). - CVE-2026-46321: tun: free page on short-frame rejection in tun_xdp_one() (bsc#1268024). - CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). - CVE-2026-52915: netfilter: ip6t_hbh: reject oversized option lists (bsc#1269001). - CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). - CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). - CVE-2026-52953: iommu/vt-d: Fix oops due to out of scope access (bsc#1269133). - CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). - CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). - CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). - CVE-2026-52961: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (bsc#1269129). - CVE-2026-52981: neigh: let neigh_xmit take skb ownership (bsc#1269254). - CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). - CVE-2026-52995: net/rds: zero per-item info buffer before handing it to visitors (bsc#1269124). - CVE-2026-53003: pppoe: drop PFC frames (bsc#1269111). - CVE-2026-53004: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (bsc#1269106). - CVE-2026-53009: ice: fix double-free of tx_buf skb (bsc#1269098). - CVE-2026-53013: macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF (bsc#1269095). - CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). - CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190). - CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389). - CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). - CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). - CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). - CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). - CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). - CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). - CVE-2026-53086: net: bcmgenet: fix racing timeout handler (bsc#1269537). - CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). - CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). - CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). - CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). - CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). - CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). - CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886). - CVE-2026-53186: RDMA/srp: bound SRP_RSP sense copy by the received length (bsc#1269663). - CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). - CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). - CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). - CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). - CVE-2026-53218: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (bsc#1269273). - CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997). - CVE-2026-53225: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (bsc#1269711). - CVE-2026-53227: net: openvswitch: fix possible kfree_skb of ERR_PTR (bsc#1269877). - CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). - CVE-2026-53239: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (bsc#1269677). - CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675). - CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988). - CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). - CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). - CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). - CVE-2026-53268: netfilter: conntrack_irc: fix possible out-of-bounds read (bsc#1269257). - CVE-2026-53272: erofs: fix use-after-free on sbi->sync_decompress (bsc#1269809). - CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). - CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). - CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). - CVE-2026-53355: net: rds: clear i_sends on setup unwind (bsc#1270249). - CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). - CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270302). - CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271366). The following non security issues were fixed: - ALSA: hda: conexant: Remove mic bias threshold override (git-fixes). - ALSA: hda: Fix cached processing coefficient verbs (git-fixes). - ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (git-fixes). - ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() (git-fixes). - ASoC: cs42l43: Correct report for forced microphone jack (git-fixes). - ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (git-fixes). - ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (git-fixes). - batman-adv: access unicast_ttvn skb->data only after skb realloc (git-fixes). - batman-adv: bla: reacquire gw address after skb realloc (git-fixes). - batman-adv: dat: acquire ARP hw source only after skb realloc (git-fixes). - batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes). - batman-adv: gw: acquire ethernet header only after skb realloc (git-fixes). - Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). - Bluetooth: bnep: pin L2CAP connection during netdev registration (git-fixes). - Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git-fixes). - Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() (git-fixes). - Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). - Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). - Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). - Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). - Bluetooth: L2CAP: validate option length before reading conf opt value (git-fixes). - Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). - Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git-fixes). - bnxt_en: Add a timeout parameter to bnxt_hwrm_port_ts_query() (bsc#1264180). - bnxt_en: Add is_ts_pkt field to struct bnxt_sw_tx_bd (bsc#1264180). - bnxt_en: Add new TX timestamp completion definitions (bsc#1264180). - bnxt_en: Add TX timestamp completion logic (bsc#1264180). - bnxt_en: Allow some TX packets to be unprocessed in NAPI (bsc#1264180). - bnxt_en: fix module unload sequence (bsc#1264180). - bnxt_en: Fix PTP firmware timeout parameter (bsc#1264180). - bnxt_en: improve TX timestamping FIFO configuration (bsc#1264180). - bnxt_en: Increase the max total outstanding PTP TX packets to 4 (bsc#1264180). - bnxt_en: Let bnxt_stamp_tx_skb() return error code (bsc#1264180). - bnxt_en: Refactor all PTP TX timestamp fields into a struct (bsc#1264180). - bnxt_en: Remove an impossible condition check for PTP TX pending SKB (bsc#1264180). - bnxt_en: Remove atomic operations on ptp->tx_avail (bsc#1264180). - bnxt_en: Retry PTP TX timestamp from FW for 1 second (bsc#1264180). - bnxt_en: silence clang build warning (bsc#1264180). - bpf: Disambiguate SCALAR register state output in verifier logs (bsc#1271249). - crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (stable-fixes). - crypto: qat - Return pointer directly in adf_ctl_alloc_resources (stable-fixes). - drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes). - drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git-fixes). - drm/amd/pm: fix amdgpu_pm_info power display units (git-fixes). - drm/amd/pm: fix smu13 power limit range calculation (git-fixes). - drm/amdgpu: fix aperture mapping leak (git-fixes). - drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes). - drm/gfx10: Program DB_RING_CONTROL (git-fixes). - drm/i915/bios: range check LFP Data Block panel_type2 (git-fixes). - drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes). - drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes). - drm/i915: Return NULL on error in active_instance (git-fixes). - drm/imagination: Fix double call to drm_sched_entity_fini() (git-fixes). - drm/imagination: fix error checking of pvr_vm_context_lookup() (git-fixes). - drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY (git-fixes). - drm/imagination: Fix user array stride in pvr_set_uobj_array() (git-fixes). - drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() (git-fixes). - drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced (git-fixes). - drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() (git-fixes). - drm/panthor: Interrupt group start/resumption if group_bind_locked() fails (git-fixes). - drm/v3d: Reject invalid indirect BO handle in indirect CSD setup (git-fixes). - drm/virtio: bound EDID block reads to the response buffer (git-fixes). - drm/xe/hw_engine: Fix double-free of managed BO in error path (git-fixes). - drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays (git-fixes). - drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() (git-fixes). - drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds (git-fixes). - drm/xe: remove duplicate include (git-fixes). - fbdev: efifb: fix memory leak in efifb_probe() (git-fixes). - fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). - fbdev: fix use-after-free in store_modes() (stable-fixes). - fbdev: modedb: fix a possible UAF in fb_find_mode() (stable-fixes). - git_sort: Add workqueue maintainer tree. - git_sort: Update nf-next branch. - gpio-f7188x: Add support for NCT6126D version B (git-fixes). - gpio: htc-egpio: use managed gpiochip registration (git-fixes). - gpio: mvebu: fail probe if gpiochip registration fails (git-fixes). - gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). - gpios: palmas: add .get_direction() op (git-fixes). - HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). - HID: lg-g15: cancel pending work on remove to fix a use-after-free (git-fixes). - HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). - hwmon: (asus_atk0110) Check package count before accessing element (git-fixes). - hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). - hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). - hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). - i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue (git-fixes). - i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring (git-fixes). - iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes). - iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git-fixes). - iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes). - iio: adc: spear: Initialize completion before requesting IRQ (git-fixes). - iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes). - iio: event: Fix event FIFO reset race (git-fixes). - iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes). - iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes). - iio: light: al3010: fix incorrect scale for the highest gain range (git-fixes). - iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes). - iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes). - Input: maplemouse - fix NULL pointer dereference in open() (git-fixes). - Input: mms114 - fix multi-touch slot corruption (git-fixes). - io_uring/kbuf: fix missing BUF_MORE for incremental buffers at EOF (bsc#1261250). - io_uring/kbuf: propagate BUF_MORE through early buffer commit path (bsc#1261250). - io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE (git-fixes bsc#1261250 bsc#1271287). - iommu/amd: serialize sequence allocation under concurrent TLB invalidations (git-fixes). - ipvs: Move defense_work to system_dfl_long_wq (bsc#1257605). - ixgbe: reduce number of reads when getting OROM data (bsc#1269637). - KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). - KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). - KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). - KVM: x86: Fix shadow paging use-after-free due to unexpected role (git-fixes). - mm/vmstat: defer the refresh_zone_stat_thresholds after all CPUs bringup (bsc#1270042 bsc#1270396). - mm: Do not allocate shrinker info with cgroup.memory=nokmem (bsc#1256564). - net/handshake: do not send request when the socket is closed (bsc#1251942). - net: mana: Sync page pool RX frags for CPU (git-fixes). - net: mana: Validate the packet length reported by the NIC (git-fixes). - net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). - net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). - net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). - net: wwan: iosm: bound device offsets in the MUX downlink decoder (git-fixes). - page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches (bsc#1261562). - pinctrl: meson: restore non-sleeping GPIO access (git-fixes). - ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). - regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes). - s390/ap: Externalize AP bus specific bitmap reading function (jsc#PED-15897). - s390/pkey: Check length in pkey_pckmo handler implementation (bsc#1270268). - s390/pkey: Check length in PKEY_VERIFYPROTK ioctl (bsc#1270263). - s390/vfio-ap: Add sysfs attr, ap_config, to export mdev state (jsc#PED-15897). - s390/vfio-ap: Add write support to sysfs attr ap_config (jsc#PED-15897). - s390/vfio-ap: Driver feature advertisement (jsc#PED-15897). - s390/vfio-ap: Ignore duplicate link requests in vfio_ap_mdev_link_queue (jsc#PED-15897). - scripts/submit_branch: do submission right after upload. - sctp: validate embedded address parameter length (git-fixes). - selftests/alsa: Fix memory leak in find_controls error path (git-fixes). - selftests/bpf: Add uprobe_multi to gen_tar target (bsc#1271248). - selftests/bpf: Make align selftests more robust (bsc#1271249). - serial: 8250_omap: clear rx_running on zero-length DMA completes (git-fixes). - serial: msm: Disable DMA for kernel console UART (git-fixes). - staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes). - staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git-fixes). - staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes). - staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes). - staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes). - staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git-fixes). - tools: hv: Fix cross-compilation (git-fixes). - tpm: Make the TPM character devices non-seekable (git-fixes). - usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git-fixes). - USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes). - usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git-fixes). - usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes). - usb: free iso schedules on failed submit (git-fixes). - usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git-fixes). - usb: gadget: f_printer: take kref only for successful open (git-fixes). - USB: idmouse: fix use-after-free on disconnect race (git-fixes). - USB: iowarrior: fix use-after-free on disconnect (git-fixes). - USB: ldusb: fix use-after-free on disconnect race (git-fixes). - USB: legousbtower: fix use-after-free on disconnect race (git-fixes). - USB: misc: uss720: unregister parport on probe failure (git-fixes). - usb: mtu3: unmap request DMA on queue failure (git-fixes). - USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes). - USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes). - USB: serial: digi_acceleport: fix write buffer corruption (git-fixes). - USB: serial: keyspan_pda: fix information leak (git-fixes). - usb: sl811-hcd: disable controller wakeup on remove (git-fixes). - USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes). - usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes). - usb: typec: class: drop PD lookup reference (git-fixes). - usb: typec: tcpm: Fix VDM type for Enter Mode commands (git-fixes). - usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes). - usb: typec: ucsi: cancel pending work on system suspend (git-fixes). - usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes). - usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes). - usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes). - USB: ulpi: fix memory leak on registration failure (git-fixes). - USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes). - usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes). - usbip: tools: support SuperSpeedPlus devices (git-fixes). - usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes). - usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). - wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). - wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). - wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain (stable-fixes). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3243-1 Released: Fri Jul 24 15:09:32 2026 Summary: Security update for gpg2 Type: security Severity: low References: 1269279,CVE-2026-57062 This update for gpg2 fixes the following issue: - CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3323-1 Released: Tue Jul 28 08:11:54 2026 Summary: Recommended update for multipath-tools Type: recommended Severity: important References: 1254094,1268144,1268145 This update for multipath-tools fixes the following issues: - Fix ALUA asymmetric access state descriptions in multipathd logs, so that the same terms are used as by the kernel ('lba-dependent', 'transitioning'). - Don't set a hardware handler for bio-based multipath devices. - Fix WWID detection for legacy devices that use the older SCSI-2 VPD page 0x83 format for their device identifier. - kpartx: * Fix an integer overflow in the GPT partition table size calculation. (bsc#1268145) * Fix several issues in the DASD partition table reader that could be triggered by a maliciously crafted disk image. (bsc#1268144) - Fix duplicate 'checker timed out' log messages when `log_checker_err` is set to `once`. (bsc#1254094) - Avoid potential buffer overflows in the iet and datacore prioritizers. - iet prioritizer: avoid misleading error message with systemd 256 and newer, and properly use udev to derive path parameters. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3458-1 Released: Mon Aug 3 14:00:20 2026 Summary: Security update for vim Type: security Severity: important References: 1268162,1271193,1271194,1271195,1271684,CVE-2026-59856,CVE-2026-59857,CVE-2026-59858 This update for vim fixes the following issues: This update for vim fixes the following issues: Security issues fixed: - CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194). - CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195). - CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193). Non security issue fixed: - Guard suse.vimrc against re-entry to prevent an infinite sourcing loop (bsc#1271684). - allow 'wrap' and 'linebreak' to be set from a modeline (bsc#1268162). Changes for vim: - Updated to version 9.2.0780: * filetype detect missing from completion (9.2.0726). * popup images not rendered correctly when unfocused (9.2.0727). * filetype: supertux info pattern is relative to current dir (9.2.0728). * % skips parens on continued quoted lines (9.2.0729). * GTK4 GUI tabline is not updated (9.2.0730). * GTK4 GUI scrollbar size not updated when restoring a session (9.2.0731). * session: terminal restored using absolute columns/rows (9.2.0732). * GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733). * function pointer passed to STRNCMP() instead of a length (9.2.0734). * tests: comment test can be improved (9.2.0737). * completion: 'autocompletedelay' blocks the main loop and drops autocommands (9.2.0739). * GTK4: scrollbar wrongly displayed (9.2.0740). * complete_check() does not return TRUE for mapped input (9.2.0741). * filetype: SSH keys and related filetypes not recognized (9.2.0742). * string macros silently accept a size of the wrong type (9.2.0743). * popup_atcursor() closes immediately on white space (9.2.0744). * cscope: connection leak when growing the array fails (9.2.0747). * 'autocompletedelay' interferes with CTRL-G U (9.2.0748). * 'autocompletedelay' interferes with i_CTRL-K (9.2.0749). * completion: 'autocompletedelay' deferral leaks state (9.2.0750). * GTK3 GUI is slow under Wayland (9.2.0751). * GTK4: drag-and-drop does not support HTML (9.2.0752). * GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753). * repeated completion length lookup in search_for_exact_line (9.2.0754). * 'autocomplete' behaves inconsistently when recording (9.2.0755). * session with multiple tabpages sets 'winminheight' to 0 (9.2.0756). * pum: no opacity when background not set for Popup menu group (9.2.0758). * some code for 'autocompletedelay' is no longer needed (9.2.0759). * compiler warning for using potentially uninitialized var (9.2.0760). * runtime(netrw): Unix: unable to open '\' file (9.2.0761). * duplicated sub-option name check in :set completion (9.2.0762). * compiler warning about unused function (9.2.0764). * popup: opacity popup over a terminal is not cleared when moved (9.2.0765). * quick_tab entries for empty letters point to the wrong index (9.2.0766). * legacy/vim9cmd modifiers do not set script version for options values (9.2.0767). * legacy/vim9cmd modifiers are not exclusive (9.2.0768). * conversion to utf-16be using iconv is inconsistent (9.2.0769). * dict_add_dict() has inconsistent ownership on failure (9.2.0770). * dict_add_list() has inconsistent ownership on failure (9.2.0771). * Vim9: null dereference inside alloc_type() (9.2.0772). * memory leak in evalfunc.c on alloc failure (9.2.0773). * memory leak in f_getscriptinfo() on alloc failure (9.2.0774). * memory leak in highlight_get_info() on alloc failure (9.2.0775). * memory leak in sign_getlist() on alloc failure (9.2.0776). * memory leak in add_defer() on alloc failure (9.2.0777). * memory leak in compile_dict() on alloc failure (9.2.0778). * memory leak in type_name_func() on alloc failure (9.2.0779). * memory leak in evalvars.c on alloc failure (9.2.0780). - Updated to version 9.2.0725: * GTK: preedit font size is wrong for fractional point sizes (9.2.0532). * '[ mark moved to end of inserted text after CTRL-R CTRL-P paste (9.2.0533). * GTK UI does not support fullscreen mode (9.2.0534). * GTK4: mouse popup menu does not show up at mouse pointer (9.2.0537). * Cannot keep leading whitespace in %{} statusline expr (9.2.0538). * filetype: too many Bitbake include files are recognized (9.2.0539). * Vim9: endclass/endenum/endinterface can give errors (9.2.0541). * Vim9: wrong error when redeclaring a typed variable (9.2.0543). * GTK4: window blank after a resize or drag (9.2.0544). * popup: blending uses hardcoded fallback colors (9.2.0545). * configure: GTK4 build requires GTK >= 4.10 (9.2.0546). * '%v' in 'errorformat' is affected by 'tabstop' (9.2.0547). * GTK4: terminal and pty job output is not processed (9.2.0548). * Cursor wrong after autoindent strip is skipped (9.2.0549). * GTK4: 'mousehide' unhides cursor when switching tabs (9.2.0550). * filetype: Tolk files are not recognized (9.2.0551). * GTK4: F10 does nothing when the menubar is hidden (9.2.0552). * runtime(netrw): netrw rejects hostnames containing _ (9.2.0553). * GTK4: memory leak in free_menu() (9.2.0554). * too many strlen() in ex_substitute() (9.2.0555). * GTK4: scrollbars not shown and do not respond to clicks (9.2.0556). * filetype: Kawasaki Robots files are not recognized (9.2.0557). * filetype: Popcap Reanimation files are not recognized (9.2.0558). * filetype: Kaitai struct files are not recogonized (9.2.0559). * filetype: busybox shebang lines are not recognized (9.2.0560). * [security]: possible code execution with python3complete (9.2.0561). * filetype: SGF files are not recognized (9.2.0562). * GTK3/Wayland: crash with right mouse-button in tabline (9.2.0563). * GTK4: tabline does not respond to mouse clicks (9.2.0564). * [security]: out-of-bounds read in update_snapshot() (9.2.0565). * f duplicates window if do_ecmd() is aborted (9.2.0566). * dict function name allocation failure not handled (9.2.0567). * pythoncomplete: g:pythoncomplete_allow_import had no effect (9.2.0568). * out-of-bounds access in libvterm CSI 8 t resize (9.2.0569). * GTK4: mouse wheel scrolling does not work correctly (9.2.0570). * Vim9: memory leak in compile_nested_function() on failure (9.2.0571). * lines disappear with wrapping virtual text after a double-width char (9.2.0572). * Vim9: missing EX_WHOLE on some block keywords (9.2.0573). * popup_create() not blocked in secure/sandbox (9.2.0576). * GTK4: window resizing issues (9.2.0577). * GTK4: :unmenu does not remove entries from the menubar (9.2.0578). * :mksession, :mkview and :mkvimrc emit legacy Vim script (9.2.0579). * xxd: binary output is not colored with -R (9.2.0580). * After maximizing and deleting the quickfix buffer, window height is wrong (9.2.0581). * GTK4: compile error when XFONTSET is defined (9.2.0582). * completion: indent not ignored for fuzzy line completion (9.2.0583). * GTK4: missing UI features (9.2.0584). * line number wrong after undoing a deletion in quickfix buffer (9.2.0585). * Crash with TextPut autocmd when pasting in terminal buffer (9.2.0586). * GTK4: left scrollbar overlaps drawarea (9.2.0587). * GTK4: drawing area loses focus after closing a menubar popover (9.2.0588). * filetype: xinitrc files are not recognized (9.2.0589). * GTK4: drawing area loses focus shape on popup menu open (9.2.0590). * 'scrolljump' ignored when scrolling up (9.2.0591). * Error when restoring session with terminal window (9.2.0592). * :wqall ignores term_setkill() on running terminal buffers (9.2.0593). * Use-after-free with ':wqall' and a running terminal job (9.2.0594). * MS-Windows: Wrong buffer size calculation for gvimext (9.2.0595). * cmdline completion popup cannot be scrolled with the mouse (9.2.0596). * [security]: possible code execution with python complete (9.2.0597). * popup: title set with popup_setoptions() is not shown (9.2.0599). * clientserver method needs to be given as argument (9.2.0600). * matchfuzzypos() returns garbage positions for long candidates (9.2.0601). * popup: No opacity when background not set for Popup group (9.2.0602). * possible heap-buffer-overflow when resizing the GUI (9.2.0603). * GTK4: does not support all clipboard formats (9.2.0606). * GTK4: inputdialog() does not work as expected (9.2.0607). * popup_setoptions()/ch_setoptions() does not check secure mode (9.2.0608). * completion info popup cannot be scrolled with the keyboard (9.2.0609). * cindent: closing brace in a comment affects the next line's indent (9.2.0610). * MS-Windows: evim.exe not working with VIMDLL (9.2.0611). * Cannot render images in popup windows (9.2.0612). * opacity popup leaves stale cells (9.2.0614). * sixel encoder drops pixels on the right edge of shapes (9.2.0615). * GTK4: use-after-free on clipboard read timeout (9.2.0616). * GvimExt: does not support different runtime dirs (9.2.0617). * use-after-free in popup_getoptions() on dict_add() failure (9.2.0618). * integer overflow in popup image size validation (9.2.0619). * runtime(netrw): fix 2match pattern rebuild (9.2.0620). * 'autoindent' not stripped with virtualedit=onemore (9.2.0621). * str2blob() does not work with wide UTF-16 encoding (9.2.0622). * possible integer overflow in spellfile tree bounds check (9.2.0623). * C-N/C-P cannot be mapped in complete() completion (9.2.0624). * GTK4: Link error when Wayland is disabled (9.2.0625). * Vim9: illegal characters allowed in dict key names with dot notation (9.2.0626). * :vim9cmd source handles all scripts as Vim9 script (9.2.0627). * popup image: wrong overlap layering, kitty laggy (9.2.0628). * 0x80 and 0x9b byte not unescaped when check for valid abbr (9.2.0629). * popup images: kitty images output in GUI mode (9.2.0630). * DECRQM and SGR Mouse not supported in foot terminal (9.2.0631). * GTK4: no support for hardware-accelerated rendering (9.2.0632). * MS-Windows: No support for kitty graphics support in terminal (9.2.0633). * GTK4: no minimum resize limit (9.2.0634). * checking the syntax contains/cluster list is slow (9.2.0635). * popup image: stale pixels under RGBA animation frames (9.2.0636). * sixel: anti-aliased RGBA images render with visible outline (9.2.0637). * cannot return matches containing spaces from a custom completion (9.2.0638). * gq with 'formatprg' fails on an empty buffer (9.2.0639). * the '%' command jumps to parens and braces inside comments (9.2.0640). * GTK4: crash in gui_mch_menu_hidden() (9.2.0641). * statusline: buffer overflow with item groups (9.2.0642). * Missing Image ifdefs (9.2.0643). * popup image: duplicate sync-output code (9.2.0644). * Composing chars no longer accepted in end-id abbr (9.2.0645). * GTK3 GUI slow on HiDPI/4K with software rendering (9.2.0646). * matchfuzzypos() false exact match for long equal-length candidates (9.2.0647). * MS-Windows: Compile warnings (9.2.0648). * filetype: tf files sometimes incorrectly recognized (9.2.0649). * Vim aborts at startup when built with the example -O2 CFLAGS (9.2.0650). * completion: 'smartcase' doesn't work with 'longest' (9.2.0651). * popup: stale kitty image after clipwindow scrolls out of view (9.2.0652). * [security]: out-of-bounds write in tree_count_words() (9.2.0653). * GTK4: using uninitialised colors in gui_mch_init() (9.2.0654). * GTK4: missing NULL checks in vim_form_measure() (9.2.0655). * completion: using wrong tolower() in smartcase filtering (9.2.0656). * GTK4: missing menu when right-clicking in tabline (9.2.0657). * xxd: signed integer overflow in huntype() (9.2.0658). * GTK4: no balloon support in GUI (9.2.0659). * Dragging the scrollbar does not trigger WinScrolled (9.2.0660). * unintended wipe of Vim's temp dir, causes errors (9.2.0661). * [security] Stack out-of-bounds write in dump_prefixes() (9.2.0662). * [security]: runtime(netrw): code injection in local file deletion (9.2.0663). * GTK4: GTK critical error on exit printed (9.2.0665). * Terminal-Normal mode does not color empty lines with a background color (9.2.0666). * patch 9.2.0590 was wrong (9.2.0667). * GTK4: minimum horizontal size is too small (9.2.0668). * GTK4: toolbar can be improved (9.2.0669). * [security]: Out-of-bounds read with text properties (9.2.0670). * [security]: possible out-of-bounds read with sodium encrypted files (9.2.0671). * corrupted text property causes internal error (9.2.0672). * configure: clears dynamic ruby linker flags (9.2.0674). * MS-Windows: cannot switch to a buffer with '%' in its name (9.2.0676). * Cannot clear the alternate file register # (9.2.0677). * [security]: potential powershell code execution in zip.vim (9.2.0678). * [security]: Out-of-bounds read with text property virtual text (9.2.0679). * keytrans() doesn't replace '|' and '\' (9.2.0680). * configure: -lruby added even for a dynamic ruby build (9.2.0681). * Wrong dot-repeat when calling complete() while filtering completion (9.2.0682). * filetype completion mishandles finished sub options (9.2.0683). * :reg # does not display the value of the '#' register (9.2.0684). * clipboard.c does not get the Wayland CFLAGS on GTK2 (9.2.0685). * style: strcmp usage is inconsistent (9.2.0686). * popup_image_composites_frames() has improper if block scope (9.2.0687). * Terminal-Normal mode does not show the Visual selection on a colored empty line (9.2.0688). * the '%' command is slow on a long line with many slashes (9.2.0689). * Solaris: swap file names are too long (9.2.0690). * Solaris: Test_terminal_composing_unicode() fails (9.2.0691). * GTK2: build failure, popup images not drawn correctly (9.2.0692). * Solaris: some tests faiures due to Solaris peculiarities (9.2.0694). * Solaris: test_delete_temp_dir() fails because of missing flock (9.2.0695). * GTK4: A few issues with toolbar support (9.2.0696). * possible overflow when parsing CSI keys (9.2.0697). * [security]: Out-of-bounds write with soundfold() (9.2.0698). * [security]: possible code execution with python complete (9.2.0699). * configure: -lrt requirement for timer_create not detected (9.2.0700). * :windo and :tabdo create an extra window with 'winfixbuf' (9.2.0702). * session file does not store relative Vim9 autoload imports (9.2.0703). * GTK4: not handling mouse events (9.2.0704). * :delete # silently fails to update '# and clobbers '0 (9.2.0705). * completion: popup misplaced when text before it is concealed (9.2.0707). * Leaks in do_autocmd in error case (9.2.0708). * GTK4: a few minor issues (9.2.0709). * GTK4 GUI resize handling can be improved (9.2.0710). * leak in ins_compl_infercase_gettext() in error case (9.2.0711). * GTK4: dialogs not handling mnemonics correctly (9.2.0712). * completion: ruler not updated correctly when the popup menu is visible (9.2.0713). * Coverity warns for NULL deref (9.2.0714). * Coverity warns about copy/paste error in hl_blend_attr() (9.2.0715). * filetype: not all supertux files are recognized (9.2.0716). * :syn sync without an argument also lists syntax cluster (9.2.0718). * GTK4: default menu is lacking (9.2.0719). * GTK4: no support for browsefilter (9.2.0720). * serverlist() returns strings separated by \n (9.2.0721). * GTK4: find/replace dialog can be improved (9.2.0722). * term_start() does not support 'noclose' (9.2.0723). * use-after-free when freeing exit_cb job on exit (9.2.0724). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3567-1 Released: Tue Aug 11 07:34:13 2026 Summary: Recommended update for grub2 Type: recommended Severity: important References: 1259132,1271980 This update for grub2 fixes the following issues: - Fix crash in booting kernel on some AMD systems (bsc#1271980) - Fix broken bash completion on arm64 images when the bash-completion package is not installed (bsc#1259132) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3605-1 Released: Thu Aug 13 08:35:24 2026 Summary: Security update for openssh Type: security Severity: important References: 1271044,1271046,1271048,1271049,1271052,1271053,1271054,1271055,CVE-2026-59995,CVE-2026-59996,CVE-2026-59997,CVE-2026-59998,CVE-2026-59999,CVE-2026-60000,CVE-2026-60001,CVE-2026-60002 This update for openssh fixes the following issues: - Backported support for the mlkemx25519 key exchange from upstream (jsc#PED-16473). - CVE-2026-59995: sftp: location of downloaded files not properly constrained when `sftp server:/path .` is used with an attacker-controlled server (bsc#1271044). - CVE-2026-59996: scp: file placed in the parent directory of an intended target directory when copy occurs between two remote destinations (bsc#1271046). - CVE-2026-59997: sshd: `internal-sftp` command lines are silently truncated after the 9th argument (bsc#1271048). - CVE-2026-59998: sshd: undocumented security-relevant `GSSAPIStrictAcceptorCheck` behavior in Windows Active Directory is not documented (bsc#1271049). - CVE-2026-59999: sshd: `DisableForwarding=yes` does not override `PermitTunnel=yes` (bsc#1271052). - CVE-2026-60000: sshd: pre-authentication denial of service when GSSAPIAuthentication is enabled (bsc#1271053). - CVE-2026-60001: sshd: minimum authentication delay is not honored (bsc#1271054). - CVE-2026-60002: ssh: client-side use-after-free when a server changes its host key during a key reexchange (bsc#1271055). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3613-1 Released: Thu Aug 13 19:59:17 2026 Summary: Security update for dracut Type: security Severity: important References: 1274432,CVE-2026-15816 This update for dracut fixes the following issue: Update to version 059+suse.572.g753fdae1b. Securitys issue fixed: - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()` (bsc#1274432). Other updates and bugfixes: - Fix(base): sanitize message written by `die()` to the emergency hook. - Feat(base): add escape function implementing `printf %q`. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3647-1 Released: Wed Aug 19 11:53:46 2026 Summary: Security update for open-iscsi Type: security Severity: important References: 1268352,1268353,CVE-2026-44943,CVE-2026-44944 This update for open-iscsi fixes the following issues: - CVE-2026-44943: remote file-write as root via discovery (bsc#1268353). - CVE-2026-44944: iscsiuio control-socket auth bypass (bsc#1268352). Changes for open-iscsi: - Update to version 2.1.12.suse+0.8f77cf16: * Preparing for version 2.1.12 (#536) * iscsi-init.service: Use iscsi-gen-initiatorname * iscsi-gen-initiatorname use @IQN_PREFIX@ as default * avoid possible double free of found in idbm_rec_update_param (#528) * iscsi: validate interface IP against target address family (#527) - Update to version 2.1.11.suse+88.8e0635b3: * Make iface.example a doc file. (#526) * Updated SPEC file to deliver iface.example as a %doc file, no longer in the database directory. - Update to version 2.1.11.suse+85.4ef97a15: * Fix unused variable warning in usr/io.c (#524) * Remove old rpm subdirectory, no longer needed. * Add tcp.congestion_control configuration option (#520) * Small cleanups for firmware discovery. (#522) * Fix incorrect parsing of node.discovery_type 'static' and 'fw' (#518) * iscsi_net_util: avoid copying NULL pointers with strlcpy() (#515) * iscsi: delay reconnect until interface has valid IP. (#511) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3657-1 Released: Thu Aug 20 19:06:03 2026 Summary: Security update for rsync Type: security Severity: important References: 1269039,1269040,1269041,1269042,1269043,1269044,1269045,1269046,1269047,1269048,1269049,1269050,1269051,1269052,1269053,1269054,1269055,1269056,1269057,1269058,1269060,1273429,1273430,1273431,1273432,1273433,1273434,1273435,1273436,1273437,1273438,1273439,1273440,1273441,CVE-2026-53783,CVE-2026-53784,CVE-2026-53785,CVE-2026-53786,CVE-2026-53788,CVE-2026-53789,CVE-2026-53790,CVE-2026-53791,CVE-2026-53792,CVE-2026-53793,CVE-2026-53794,CVE-2026-53795,CVE-2026-53796,CVE-2026-53797,CVE-2026-53798,CVE-2026-53799,CVE-2026-53800,CVE-2026-53801,CVE-2026-53802,CVE-2026-53803,CVE-2026-70452,CVE-2026-70453,CVE-2026-70454,CVE-2026-70455,CVE-2026-70456,CVE-2026-70457,CVE-2026-70458,CVE-2026-70459,CVE-2026-70460,CVE-2026-70461,CVE-2026-70462,CVE-2026-70463,CVE-2026-70464 This update for rsync fixes the following issues: - CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) (bsc#1269041). - CVE-2026-53784: Daemon module-root chdir escape under 'use chroot = no' (bsc#1269042). - CVE-2026-53785: --relative implied-parent creation escapes the destination tree (bsc#1269043). - CVE-2026-53786: Daemon --filter merge file bypasses the module filter list (bsc#1269044). - CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol (bsc#1269046). - CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent (bsc#1269047). - CVE-2026-53790: Command / argument injection via unquoted peer- or host-controlled values (bsc#1269048). - CVE-2026-53791: PROXY-protocol mode lets a direct client spoof the daemon's source address (bsc#1269049). - CVE-2026-53792: Receiver-supplied zero checksum block length drives sender matching negative (bsc#1269050). - CVE-2026-53793: Chroot '/./' inner-module escape via a parent-component symlink (bsc#1269051). - CVE-2026-53794: Remote peer disables the per-allocation sanity cap via --max-alloc=0 (bsc#1269052). - CVE-2026-53795: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement (bsc#1269053). - CVE-2026-53796: Non-daemon receiver destination-chdir symlink race (TOCTOU) (bsc#1269054). - CVE-2026-53797: Sender source-tree parent-component symlink race -> out-of-tree disclosure (bsc#1269055). - CVE-2026-53798: Daemon name-converter empty response maps an unknown name to uid/gid 0 (bsc#1269045). - CVE-2026-53799: Receiver ACL/xattr application follows a symlink-race -> arbitrary ACL set (local privilege escalation) (bsc#1269056). - CVE-2026-53800: Sender --remove-source-files unlink follows a parent-component symlink race -> arbitrary file deletion outside the source tree (bsc#1269057). - CVE-2026-53801: Sender/daemon directory-scan enumeration escapes the transfer root / module -> out-of-tree disclosure (bsc#1269058). - CVE-2026-53802: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files (bsc#1269039). - CVE-2026-53803: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths (bsc#1269040). - CVE-2026-70452: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to block (bsc#1273441). - CVE-2026-70453: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain (bsc#1273440). - CVE-2026-70454: rsync-ssl establishes an unauthenticated TLS connection (bsc#1273439). - CVE-2026-70455: Peer-controlled Zstandard worker exhaustion on an rsync daemon (bsc#1273438). - CVE-2026-70456: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs (bsc#1273437). - CVE-2026-70457: Attacker-chosen-offset write in parse_size_arg() error formatting (bsc#1273436). - CVE-2026-70458: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H (bsc#1273435). - CVE-2026-70459: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root (bsc#1273434). - CVE-2026-70460: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in- module symlink (bsc#1273433). - CVE-2026-70461: Peer-driven one-byte heap out-of-bounds write in add_implied_include() (bsc#1273432). - CVE-2026-70462: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (bsc#1273431). - CVE-2026-70463: 'auth users' ignores documented comma-only parsing, silently skipping a deny/read-only rule (bsc#1273430). - CVE-2026-70464: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module (bsc#1273429). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3680-1 Released: Fri Aug 21 16:21:23 2026 Summary: Security update for vim Type: security Severity: important References: 1275011,1275012,1275013,1275014,1275015,1275016,1275017,1275018,CVE-2026-73070,CVE-2026-73071,CVE-2026-73072,CVE-2026-73074,CVE-2026-73075,CVE-2026-73076,CVE-2026-73077,CVE-2026-73078 This update for vim fixes the following issues: - CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018). - CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017). - CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution (bsc#1275016). - CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution (bsc#1275015). - CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014). - CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013). - CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012). - CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011). Changes for vim: - Updated to version 9.2.0957. * tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781). * tests: missing cleanup in test_mksession.vim (9.2.0782). * tests: personal spell files leak into later tests (9.2.0783). * crash when borrowing statusline highlight in silent Ex mode (9.2.0784). * WinResized not triggered when the whole Vim is resized (9.2.0785). * filetype: containerfile is not recognized (9.2.0786). * regexp: code 0x1ecb duplicated for equivalence class (9.2.0787). * filetype: hip files are not recognized (9.2.0788). * 'statuslineopt' status line too high after a window is minimized (9.2.0789). * 'completeslash' breaks :find completion with 'findfunc' (9.2.0790). * wincol() counts from right side for 'rightleft' (9.2.0791). * runtime(netrw): explore without optional dir broken (9.2.0792). * if session restored a tiny window, restore fails (9.2.0793). * extend() and extendnew() don't handle NULL expr2 properly (9.2.0794). * popup menu shadow is not cleared when the menu shrinks (9.2.0795). * Visual block reselection wrong with 'virtualedit' (9.2.0796). * memory leak in get_qfline_items() on alloc failure (9.2.0797). * memory leak in compile_expr6() on alloc failure (9.2.0798). * memory leak in compile_def_function_body() on alloc failure (9.2.0799). * memory leak in call_func() on alloc failure (9.2.0800). * memory leak in f_getreginfo() on alloc failure (9.2.0801). * memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802). * memory leak on alloc failure with taglist/gettagstack() (9.2.0803). * wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804). * screenpos() 'curscol' is wrong with 'rightleft' (9.2.0805). * 'showcmd' may show internal command keys (9.2.0806). * MS-Windows: ellipsis character is garbled (9.2.0807). * getregionpos: double-free on alloc failure (9.2.0808). * getframelayout() uses wrong function to free lists (9.2.0809). * add_llist_tags() uses wrong function to free dict (9.2.0810). * mksession writes terminal command unquoted (9.2.0811). * :argdelete with pattern leads to wrong argidx() (9.2.0812). * dict_add_func() may corrupt funcref count on failure (9.2.0813). * Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814). * deeply nested regexp patterns may cause stack overflow (9.2.0815). * GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816). * crash when building a stacktrace during an autocommand (9.2.0817). * tests: client-server test fails without X11 server (9.2.0818). * MS-Windows: sixel image shown as raw text in the console (9.2.0819). * GUI: hidden popup image is displayed and not erased (9.2.0820). * filetype: msmtp system-wide rc file not detected (9.2.0821). * GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822). * tests: Test_clientserver_servlist_list may fail (9.2.0823). * Makefile: make tags depends on configure (9.2.0824). * regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825). * highlighting for broken terminals can be improved (9.2.0826). * :startinsert enters Insert mode in a non-modifiable buffer (9.2.0827). * GTK4: hardware rendering can be improved (9.2.0828). * sessions do not preserve script version for expression options (9.2.0829). * the completion menu is not used on terminals without colors (9.2.0830). * diff highlighting hard to read with syntax enabled (9.2.0831). * socketserver: remote commands can be processed in reverse order (9.2.0832). * GTK4: menu mnemonics do not work properly (9.2.0833). * cleared last search pattern is restored from viminfo (9.2.0834). * features in version.c are not sorted (9.2.0835). * filetype: .git-blame-ignore-revs file is not recognized (9.2.0836). * using wrong colors in hl_blend_attr() (9.2.0837). * searchcount() returns wrong cached maxcount (9.2.0838). * [security]: arbitrary code execution via keyword lookup (9.2.0839). * [security]: code injection in netrw via bookmarks (9.2.0840). * [security]: heap overflow when adding > 65535 text properties (9.2.0841). * [security]: stack buffer overflow in socket server (9.2.0842). * [security]: popup: opacity mask indexed out of bounds (9.2.0843). * [security]: use-after-free on json decode error (9.2.0844). * [security]: arbitrary Ex command execution during C omni-completion (9.2.0845). * [security]: heap buffer overflow in set_sofo() (9.2.0846). * [security]: vimball: code execution via .VimballRecord file (9.2.0847). * tagfunc 'cmd' with a generic Ex command corrupts the tag entry (9.2.0848). * filetype: osquery config files are not recognized (9.2.0849). * MS-Windows: commands from a client can be lost (9.2.0850). * focus autocommands triggered inconsistently (9.2.0851). * GTK: ligatures not correctly displayed (9.2.0852). * popup: popup images do not support scaling (9.2.0853). * memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854). * 'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855). * GTK4: undercurl rendering is inefficient (9.2.0856). * popup: opacity popup over a terminal is not cleared when closed (9.2.0857). * MS-Windows GUI: white flash when VimEnter is slow (9.2.0858). * GTK2: link error (9.2.0859). * filetype: xilinx design constraint files are not recognized (9.2.0860). * GTK4: bleed region updates in jumps (9.2.0861). * missing test change from v9.2.0857 (9.2.0862). * MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863). * using some dead code in Wayland feature (9.2.0864). * GTK4: non-hardware accelerated UI is too slow (9.2.0865). * MS-Windows: ':language messages' only works once (9.2.0866). * MS-Windows: messages are not in the display language (9.2.0867). * GTK: window Manager hint prevents giving focus to dialog (9.2.0868). * buf_copy_options() can lose the P_INSECURE flag (9.2.0869). * filetype: marko files are not recognized (9.2.0870). * screen line is lost when splitting a 'winfixheight' window (9.2.0871). * popup with opacity does not use the font of the highlight group (9.2.0872). * :redrawstatus does not update the ruler of the last window (9.2.0873). * fold size is compared against 'foldminlines' of the wrong window (9.2.0874). * GTK4: GUI does not support command-line arguments (9.2.0875). * GTK4: compile error with disabled netbeans feat (9.2.0876). * Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877). * Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878). * popup: 'maxwidth' is not respected when 'wrap' is off (9.2.0879). * scroll: window scrolls when using the autocommand window (9.2.0880). * 'smoothscroll' position is lost when the window height changes (9.2.0881). * :bwipe crashes if WinLeave wipes all other buffers (9.2.0882). * scroll: 'smoothscroll' position is lost when using '|' (9.2.0883). * scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884). * scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885). * :set completion works for an invalid sub-option name (9.2.0886). * scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887). * mapping: modifier is not recognized after a partial mapping (9.2.0888). * VMS: spurious 'INVALID DECC FEATURE VALUE' message at every startup (9.2.0889). * test: test for patch v9.2.0888 can be clarified (9.2.0890). * MS-Windows: filename-modifier ':8:t' causes underflow (9.2.0891). * highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892). * MS-Windows: '*.vim' also matches files with a longer extension (9.2.0893). * filetype: ed script files not recognised (9.2.0894). * test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895). * scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896). * GTK3 X11 redraws are not coalesced (9.2.0897). * printing support is lacking (9.2.0898). * command output temporary files may collide (9.2.0899). * FocusGained still triggered when closing dialog (9.2.0900). * textprop: wrong cursor line with truncated virtual text (9.2.0901). * Vim9: iterating over a tuple leaks memory (9.2.0902). * Vim9: cannot use an exported function of an autoload import (9.2.0903). * 'zb' scrolls incorrectly with cursor just above fold (9.2.0904). * MS-Windows: ghost cursor with ligatures (9.2.0905). * slow transstr() with long strings (9.2.0906). * popup: virtual text is not redrawn when a text property changes (9.2.0907). * cannot use a {} block in a nested :autocmd (9.2.0908). * insert completion is slow to collect many matches (9.2.0909). * runtime(vim): update syntax, contain Ex commands (9.2.0910). * makefiles do not build hardcopy_postscript.c (9.2.0911). * hardcopy: prototypes are hand-written instead of generated (9.2.0912). * statusline: cell below the vertical separator keeps the old highlight (9.2.0913). * diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914). * tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915). * configure: honor `--disable-hardcopy-pango` with GTK UI (9.2.0916). * :quitall not allowed in the command-line window (9.2.0917). * screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918). * screen: the wrong array is copied into ScreenCols on a resize (9.2.0919). * filetype: json-ld files are not recognized (9.2.0920). * test: terminal tests fail on FreeBSD (9.2.0921). * Wayland: modeless selection not redrawn (9.2.0922). * tabpage: closing a tab page loses the alternate tab page (9.2.0923). * tests: Test_termwinscroll() fails on FreeBSD (9.2.0924). * crash when getcompletiontype() gets a NULL string (9.2.0925). * filetype: business Central files are not recognized (9.2.0926). * curswant not set on 8g8 (9.2.0927). * MinGW: tests hang when Vim is built with coverage enabled (9.2.0928). * incorrect completion for 'pumopt' and 'pumborder' (9.2.0929). * floating point exception when displaying pum (9.2.0930). * the GTK4 GUI is still experimental and untested by CI (9.2.0931). * NFA engine fallback can double free the compiled program (9.2.0932). * u_read_undo() leaks the file name when the undo file owner differs (9.2.0933). * filetype: hlsl files are not recognized (9.2.0934). * reading an undo file is slow with many undo headers (9.2.0935). * stringifying a list or dict can free the item being iterated (9.2.0936). * sort() with a numeric option converts each item on every comparison (9.2.0937). * cursorbind: cursor in the other window is not updated after undo (9.2.0938). * mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939). * GTK4: columns are lost when a scrollbar appears (9.2.0940). * tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941). * test: test_mksession_winpos() fails on GTK4 UI (9.2.0942). * test: test_hardcopy fails on GTK4 UI (9.2.0943). * test: tests fail when checking for GTK4 feature (9.2.0944). * sort() with a numeric option can be improved (9.2.0945). * GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946). * GTK4: screen is cleared when moving the mouse after startup (9.2.0947). * GTK4: mouse move starts Visual selection after a dialog (9.2.0948). * GDK_KEY_VoidSymbol might be undefined (9.2.0949). * transstr() can be improved (after 9.2.0906) (9.2.0950). * GTK3: cursor does no longer blink (9.2.0951). * locking a container while stringifying can be improved (9.2.0952). * insert completion code can be improved (9.2.0953). * u_read_undo() can be improved (after 9.2.0935) (9.2.0954). * tests: terminal tests are flaky (9.2.0955). * GTK4: crash when the window is resized while redrawing (9.2.0956). * filetype: ArgoCD config file is not recognized (9.2.0957). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3684-1 Released: Fri Aug 21 20:23:10 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3790-1 Released: Tue Aug 25 14:24:18 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1185845,1239511,1243603,1246182,1247455,1253262,1253674,1255357,1255703,1256675,1257815,1258718,1260347,1262573,1262745,1262771,1263010,1263068,1263718,1263788,1264007,1264013,1264053,1264076,1264089,1264090,1264184,1264319,1264333,1264418,1264422,1264452,1264532,1264534,1264537,1264539,1264543,1264558,1264601,1264712,1264779,1264793,1264795,1264827,1264832,1265009,1265141,1265308,1266238,1266685,1266695,1266710,1266715,1266758,1266813,1266850,1266869,1266876,1266880,1266890,1266891,1266896,1266900,1266904,1266913,1266918,1267025,1267203,1267210,1267375,1267384,1267439,1267570,1267584,1267596,1267656,1267662,1267678,1267682,1267689,1267714,1267715,1267943,1267986,1267995,1268029,1268307,1268648,1268659,1268966,1268967,1268983,1269003,1269024,1269027,1269094,1269104,1269112,1269115,1269117,1269118,1269119,1269132,1269134,1269138,1269154,1269181,1269185,1269186,1269229,1269233,1269240,1269270,1269272,1269289,1269290,1269307,1269318,1269362,1269376,1269383,1269512,1269513,1 269577,1269633,1269643,1269658,1269659,1269660,1269672,1269688,1269689,1269694,1269697,1269714,1269724,1269734,1269773,1269797,1269808,1269810,1269819,1269964,1269981,1269990,1269991,1269994,1270000,1270102,1270113,1270132,1270230,1271250,1271283,1271285,1271291,1271349,1271368,1271402,1271526,1271717,1271731,1271813,1271818,1271825,1271826,1271827,1271831,1271832,1271833,1271834,1271858,1271866,1271869,1271870,1271899,1271904,1271908,1271912,1271937,1271955,1271964,1271967,1272146,1272149,1272176,1272180,1272183,1272187,1272194,1272197,1272204,1272207,1272211,1272242,1272246,1272263,1272268,1272282,1272296,1272325,1272360,1272361,1272362,1272373,1272374,1272380,1272384,1272387,1272389,1272406,1272434,1272466,1272467,1272468,1272470,1272472,1272474,1272478,1272480,1272482,1272483,1272489,1272492,1272494,1272499,1272500,1272501,1272513,1272517,1272522,1272523,1272573,1272578,1272591,1272600,1272607,1272614,1272617,1272620,1272642,1272646,1272659,1272664,1272665,1272668,1272670,127267 1,1272678,1272681,1272685,1272686,1272689,1272690,1272691,1272693,1272694,1272706,1272781,1272785,1272787,1272797,1272800,1272807,1272836,1272843,1272850,1272853,1272855,1272863,1272865,1272871,1272891,1272892,1272897,1272903,1272904,1272907,1272918,1272920,1272973,1273004,1273023,1273035,1273044,1273117,1273231,1273550,1274072,CVE-2023-2058,CVE-2025-21845,CVE-2025-38250,CVE-2025-38469,CVE-2025-40213,CVE-2025-54518,CVE-2025-68223,CVE-2025-68741,CVE-2025-68818,CVE-2026-23097,CVE-2026-31431,CVE-2026-31482,CVE-2026-31483,CVE-2026-31542,CVE-2026-31598,CVE-2026-31628,CVE-2026-31759,CVE-2026-43016,CVE-2026-43033,CVE-2026-43046,CVE-2026-43056,CVE-2026-43059,CVE-2026-43114,CVE-2026-43130,CVE-2026-43161,CVE-2026-43168,CVE-2026-43170,CVE-2026-43172,CVE-2026-43216,CVE-2026-43230,CVE-2026-43262,CVE-2026-43266,CVE-2026-43276,CVE-2026-43281,CVE-2026-43308,CVE-2026-43309,CVE-2026-43328,CVE-2026-43352,CVE-2026-43439,CVE-2026-43440,CVE-2026-43451,CVE-2026-43475,CVE-2026-45860,CVE-2026-45873,CVE-2026 -45904,CVE-2026-45905,CVE-2026-45913,CVE-2026-45915,CVE-2026-45917,CVE-2026-45944,CVE-2026-45973,CVE-2026-46003,CVE-2026-46015,CVE-2026-46026,CVE-2026-46038,CVE-2026-46080,CVE-2026-46084,CVE-2026-46109,CVE-2026-46117,CVE-2026-46126,CVE-2026-46137,CVE-2026-46144,CVE-2026-46145,CVE-2026-46147,CVE-2026-46158,CVE-2026-46168,CVE-2026-46170,CVE-2026-46174,CVE-2026-46180,CVE-2026-46189,CVE-2026-46193,CVE-2026-46234,CVE-2026-46243,CVE-2026-46245,CVE-2026-46265,CVE-2026-46292,CVE-2026-46306,CVE-2026-46323,CVE-2026-46324,CVE-2026-46333,CVE-2026-52910,CVE-2026-52921,CVE-2026-52927,CVE-2026-52930,CVE-2026-52937,CVE-2026-52941,CVE-2026-52942,CVE-2026-52947,CVE-2026-52967,CVE-2026-52970,CVE-2026-52974,CVE-2026-52984,CVE-2026-52986,CVE-2026-52988,CVE-2026-52991,CVE-2026-52998,CVE-2026-52999,CVE-2026-53000,CVE-2026-53002,CVE-2026-53006,CVE-2026-53011,CVE-2026-53012,CVE-2026-53032,CVE-2026-53062,CVE-2026-53063,CVE-2026-53064,CVE-2026-53069,CVE-2026-53074,CVE-2026-53083,CVE-2026-53088,CVE-2026-53106, CVE-2026-53107,CVE-2026-53123,CVE-2026-53129,CVE-2026-53131,CVE-2026-53132,CVE-2026-53134,CVE-2026-53175,CVE-2026-53177,CVE-2026-53183,CVE-2026-53184,CVE-2026-53185,CVE-2026-53189,CVE-2026-53212,CVE-2026-53221,CVE-2026-53230,CVE-2026-53236,CVE-2026-53250,CVE-2026-53252,CVE-2026-53262,CVE-2026-53265,CVE-2026-53267,CVE-2026-53270,CVE-2026-53275,CVE-2026-53289,CVE-2026-53291,CVE-2026-53297,CVE-2026-53321,CVE-2026-53324,CVE-2026-53331,CVE-2026-53332,CVE-2026-53345,CVE-2026-53354,CVE-2026-53369,CVE-2026-53374,CVE-2026-53375,CVE-2026-53376,CVE-2026-53379,CVE-2026-53382,CVE-2026-53385,CVE-2026-53388,CVE-2026-53391,CVE-2026-53392,CVE-2026-53393,CVE-2026-53397,CVE-2026-53398,CVE-2026-53399,CVE-2026-53402,CVE-2026-53403,CVE-2026-63794,CVE-2026-63795,CVE-2026-63802,CVE-2026-63806,CVE-2026-63807,CVE-2026-63809,CVE-2026-63821,CVE-2026-63822,CVE-2026-63824,CVE-2026-63826,CVE-2026-63829,CVE-2026-63836,CVE-2026-63843,CVE-2026-63844,CVE-2026-63845,CVE-2026-63846,CVE-2026-63847,CVE-2026-63848,CVE-202 6-63851,CVE-2026-63852,CVE-2026-63853,CVE-2026-63854,CVE-2026-63855,CVE-2026-63856,CVE-2026-63861,CVE-2026-63862,CVE-2026-63869,CVE-2026-63882,CVE-2026-63884,CVE-2026-63892,CVE-2026-63893,CVE-2026-63895,CVE-2026-63896,CVE-2026-63897,CVE-2026-63899,CVE-2026-63900,CVE-2026-63901,CVE-2026-63902,CVE-2026-63903,CVE-2026-63904,CVE-2026-63905,CVE-2026-63908,CVE-2026-63912,CVE-2026-63915,CVE-2026-63916,CVE-2026-63917,CVE-2026-63919,CVE-2026-63921,CVE-2026-63922,CVE-2026-63924,CVE-2026-63927,CVE-2026-63928,CVE-2026-63930,CVE-2026-63931,CVE-2026-63934,CVE-2026-63938,CVE-2026-63939,CVE-2026-63940,CVE-2026-63942,CVE-2026-63943,CVE-2026-63945,CVE-2026-63946,CVE-2026-63947,CVE-2026-63948,CVE-2026-63949,CVE-2026-63952,CVE-2026-63957,CVE-2026-63958,CVE-2026-63959,CVE-2026-63960,CVE-2026-63961,CVE-2026-63962,CVE-2026-63964,CVE-2026-63967,CVE-2026-63968,CVE-2026-63971,CVE-2026-63974,CVE-2026-63975,CVE-2026-63976,CVE-2026-63984,CVE-2026-63991,CVE-2026-63994,CVE-2026-64025,CVE-2026-64089,CVE-2026-64106 ,CVE-2026-64174,CVE-2026-64179,CVE-2026-64182,CVE-2026-64183,CVE-2026-64187,CVE-2026-64189,CVE-2026-64191,CVE-2026-64220,CVE-2026-64221,CVE-2026-64223,CVE-2026-64231,CVE-2026-64234,CVE-2026-64242,CVE-2026-64298,CVE-2026-64330,CVE-2026-64336,CVE-2026-64345,CVE-2026-64347,CVE-2026-64465,CVE-2026-64530,CVE-2026-64560,CVE-2026-64561,CVE-2026-64564,CVE-2026-64600 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2025-68741: scsi: qla2xxx: Fix improper freeing of purex item (bsc#1255703). - CVE-2025-68818: scsi: Revert 'scsi: qla2xxx: Perform lockless command completion in abort path' (bsc#1256675). - CVE-2026-23097: migrate: correct lock ordering for hugetlb file folios (bsc#1257815). - CVE-2026-43016: bpf: sockmap: Fix use-after-free of sk->sk_socket in sk_psock_verdict_data_ready() (bsc#1264007). - CVE-2026-43114: netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry (bsc#1264601). - CVE-2026-43130: iommu/vt-d: Flush dev-IOTLB only when PCIe device is accessible in scalable mode (bsc#1264532). - CVE-2026-43161: iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode (bsc#1264333). - CVE-2026-43168: ocfs2: fix reflink preserve cleanup issue (bsc#1264537). - CVE-2026-43170: usb: dwc3: gadget: Move vbus draw to workqueue context (bsc#1264452). - CVE-2026-43172: wifi: iwlwifi: fix 22000 series SMEM parsing (bsc#1264543). - CVE-2026-43216: net: Drop the lock in skb_may_tx_timestamp() (bsc#1264319). - CVE-2026-43230: net/rds: Clear reconnect pending bit (bsc#1264539). - CVE-2026-43262: gfs2: fiemap page fault fix (bsc#1264422). - CVE-2026-43266: EFI/CPER: don't go past the ARM processor CPER record buffer (bsc#1264418). - CVE-2026-43281: mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate() (bsc#1264534). - CVE-2026-43308: btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() (bsc#1264712). - CVE-2026-43309: md raid: fix hang when stopping arrays with metadata through dm-raid (bsc#1264827). - CVE-2026-43328: cpufreq: governor: Free dbs_data directly when gov->init() fails (bsc#1264832). - CVE-2026-43439: cgroup: fix race between task migration and iteration (bsc#1265141). - CVE-2026-43451: netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path (bsc#1265009). - CVE-2026-45860: netfilter: nf_conncount: increase the connection clean up limit to 64 (bsc#1266710). - CVE-2026-45873: netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets (bsc#1266715). - CVE-2026-45905: xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path (bsc#1266685). - CVE-2026-45913: net: bridge: mcast: always update mdb_n_entries for vlan contexts (bsc#1266891). - CVE-2026-45915: fat: avoid parent link count underflow in rmdir (bsc#1266896). - CVE-2026-45917: ipvs: do not keep dest_dst if dev is going down (bsc#1266900). - CVE-2026-45944: iommu/vt-d: Clear Present bit before tearing down context entry (bsc#1267203). - CVE-2026-45973: RDMA/mlx5: Fix UMR hang in LAG error state unload (bsc#1267025). - CVE-2026-46003: net: qrtr: ns: Limit the total number of nodes (bsc#1267210). - CVE-2026-46015: tcp: call sk_data_ready() after listener migration (bsc#1267439). - CVE-2026-46026: net: qrtr: ns: Limit the maximum number of lookups (bsc#1266876). - CVE-2026-46038: net: qrtr: ns: Free the node during ctrl_cmd_bye() (bsc#1266695). - CVE-2026-46137: mptcp: pm: ADD_ADDR rtx: fix potential data-race (bsc#1267570). - CVE-2026-46147: KVM: arm64: Factor out pKVM hyp vcpu creation to separate function (bsc#1267689). - CVE-2026-46158: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount (bsc#1266880). - CVE-2026-46168: mptcp: sockopt: set timestamp flags on subflow socket, not msk (bsc#1266869). - CVE-2026-46170: mptcp: pm: reuse ID 0 after delete and re-add (bsc#1267714). - CVE-2026-46180: wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (bsc#1266813). - CVE-2026-46189: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (bsc#1266918). - CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656). - CVE-2026-46234: vsock: fix buffer size clamping order (bsc#1266904). - CVE-2026-46245: drm/amd/display: Fix dc_link NULL handling in HPD init (bsc#1267678). - CVE-2026-46265: RDMA/hns: Fix WQ_MEM_RECLAIM warning (bsc#1267662). - CVE-2026-46292: pmdomain: core: Fix detach procedure for virtual devices in genpd (bsc#1267943). - CVE-2026-46306: flow_dissector: do not dissect PPPoE PFC frames (bsc#1267986). - CVE-2026-46324: netfilter: nf_tables: Introduce functions freeing nft_hook objects (bsc#1267995). - CVE-2026-52910: pf: Free reuseport cBPF prog after RCU grace period (bsc#1268659). - CVE-2026-52921: netfilter: ipset: stop hash:* range iteration at end (bsc#1269024). - CVE-2026-52927: netfilter: ebtables: fix OOB read in compat_mtw_from_user (bsc#1269027). - CVE-2026-52930: ipc/shm: serialize orphan cleanup with shm_nattch updates (bsc#1269003). - CVE-2026-52937: tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR (bsc#1268983). - CVE-2026-52941: net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint (bsc#1268966). - CVE-2026-52942: netfilter: nf_log: validate MAC header was set before dumping it (bsc#1268967). - CVE-2026-52947: net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove (bsc#1269115). - CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181). - CVE-2026-52970: netfilter: nft_ct: fix missing expect put in obj eval (bsc#1269229). - CVE-2026-52974: net: tls: fix strparser anchor skb leak on offload RX setup failure (bsc#1269233). - CVE-2026-52984: net/sched: netem: fix queue limit check to include reordered packets (bsc#1269272). - CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289). - CVE-2026-52988: rculist: add list_splice_rcu() for private lists (bsc#1269362). - CVE-2026-52991: sched/psi: fix race between file release and pressure write (bsc#1269134). - CVE-2026-52998: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (bsc#1269118). - CVE-2026-52999: netfilter: nfnetlink_osf: fix out-of-bounds read on option matching (bsc#1269119). - CVE-2026-53000: netfilter: nat: use kfree_rcu to release ops (bsc#1269117). - CVE-2026-53002: netfilter: conntrack: remove sprintf usage (bsc#1269112). - CVE-2026-53006: ipv6: fix possible UAF in icmpv6_rcv() (bsc#1269104). - CVE-2026-53011: net/sched: taprio: fix use-after-free in advance_sched() on schedule switch (bsc#1269094). - CVE-2026-53012: nexthop: fix IPv6 route referencing IPv4 nexthop (bsc#1269154). - CVE-2026-53032: bpf: Fix NULL deref in map_kptr_match_type for scalar regs (bsc#1269138). - CVE-2026-53062: dm cache policy smq: fix missing locks in invalidating cache blocks (bsc#1269658). - CVE-2026-53063: dm cache: fix write hang in passthrough mode (bsc#1269659). - CVE-2026-53064: dm cache: fix null-deref with concurrent writes in passthrough mode (bsc#1269132). - CVE-2026-53069: net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master (bsc#1269186). - CVE-2026-53074: bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb (bsc#1269688). - CVE-2026-53083: bpf: Fix RCU stall in bpf_fd_array_map_clear() (bsc#1269964). - CVE-2026-53088: net: bcmgenet: fix off-by-one in bcmgenet_put_txcb (bsc#1269185). - CVE-2026-53106: bpf: Do not allow deleting local storage in NMI (bsc#1269990). - CVE-2026-53107: wifi: libertas: use USB anchors for tracking in-flight URBs (bsc#1269991). - CVE-2026-53123: md: wake raid456 reshape waiters before suspend (bsc#1269643). - CVE-2026-53129: fs/mbcache: cancel shrink work before destroying the cache (bsc#1269633). - CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773). - CVE-2026-53132: vsock/virtio: fix potential unbounded skb queue (bsc#1269290). - CVE-2026-53134: netfilter: nft_fib: fix stale stack leak via the OIFNAME register (bsc#1269819). - CVE-2026-53175: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush (bsc#1269714). - CVE-2026-53183: mptcp: allow subflow rcv wnd to shrink (bsc#1269376). - CVE-2026-53184: udp: clear skb->dev before running a sockmap verdict (bsc#1269689). - CVE-2026-53185: zram: fix use-after-free in zram_bvec_write_partial() (bsc#1269660). - CVE-2026-53189: mm/huge_memory: update file PMD counter before folio_put() (bsc#1269797). - CVE-2026-53212: netfilter: nft_tunnel: fix use-after-free on object destroy (bsc#1269672). - CVE-2026-53221: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() (bsc#1269318). - CVE-2026-53230: net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list (bsc#1269270). - CVE-2026-53236: tcp: restrict SO_ATTACH_FILTER to priv users (bsc#1269994). - CVE-2026-53250: xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() (bsc#1269808). - CVE-2026-53252: adaption to srcu change of hci_dev in hci_sysfs (bsc#1269307). - CVE-2026-53262: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() (bsc#1270000). - CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577). - CVE-2026-53270: ipvs: clear the svc scheduler ptr early on edit (bsc#1269240). - CVE-2026-53275: ipv6: mcast: Fix use-after-free when processing MLD queries (bsc#1269810). - CVE-2026-53289: ice: fix NULL pointer dereference in ice_reset_all_vfs() (bsc#1269694). - CVE-2026-53291: ALSA: hda/conexant: Fix missing error check for jack detection (bsc#1269697). - CVE-2026-53321: io_uring/napi: cap busy_poll_to 10 msec (bsc#1269724). - CVE-2026-53345: KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying (bsc#1270132). - CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1270230). - CVE-2026-53369: udf: reject descriptors with oversized CRC length (bsc#1271818). - CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899). - CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825). - CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904). - CVE-2026-53392: NFSv4/flexfiles: reject zero filehandle version count (bsc#1271826). - CVE-2026-53393: nfsd: Don't reset the write verifier on a commit EAGAIN (bsc#1271858). - CVE-2026-53397: nfsd: fix posix_acl leak on SETACL decode failure (bsc#1271869). - CVE-2026-53398: NFSD: Fix SECINFO_NO_NAME decode error cleanup (bsc#1271870). - CVE-2026-53399: nfsd: release layout stid on setlease failure (bsc#1271832). - CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908). - CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964). - CVE-2026-63795: 9p: avoid putting oldfid in p9_client_walk() error path (bsc#1271955). - CVE-2026-63802: blk-cgroup: fix UAF in __blkcg_rstat_flush() (bsc#1272282). - CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (bsc#1272268). - CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (bsc#1272263). - CVE-2026-63809: bpf: NUL-terminate replaced sysctl value (bsc#1272296). - CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2() (bsc#1272180). - CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176). - CVE-2026-63901: USB: serial: digi_acceleport: fix memory corruption with small endpoints (bsc#1272501). - CVE-2026-63912: xfrm: esp: restore combined single-frag length gate (bsc#1272836). - CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904). - CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907). - CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918). - CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: refresh nh after handling HAO option (bsc#1272855). - CVE-2026-63938: KVM: SEV: Check PSC request indices against the actual size of the buffer (bsc#1272620). - CVE-2026-63939: KVM: SEV: Compute the correct max length of the in-GHCB scratch area (bsc#1272691). - CVE-2026-63952: memfd: deny writeable mappings when implying SEAL_WRITE (bsc#1272468). - CVE-2026-63962: usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() (bsc#1272482). - CVE-2026-63968: ipv6: fix possible infinite loop in fib6_select_path() (bsc#1272466). - CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678). - CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865). - CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035). - CVE-2026-64025: bpf, skmsg: fix verdict sk_data_ready racing with ktls rx (bsc#1273117). - CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242). - CVE-2026-64187: xfs: fail recovery on a committed log item with no regions (bsc#1272204). - CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207). - CVE-2026-64298: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (bsc#1273550). - CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1273004). - CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231). - CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072). - CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526). The following non security issues were fixed: - accel/ivpu: Fix wrong register read in LNL failure diagnostics (git-fixes). - accel/ivpu: Reject firmware log with size smaller than header (git-fixes). - accel/qaic: use sizeof(*trans_hdr) for transaction length check (git-fixes). - ALSA: hda: codecs: hdmi: disable keep-alive before audio format change (git-fixes). - ALSA: hda: cs35l41: validate and free ACPI mute object (git-fixes). - ALSA: lx6464es: fix period byte count for 16-bit streams (git-fixes). - ALSA: pcm: wake linked drain waiters on unlink (git-fixes). - ALSA: seq: close a re-opened queue timer in the destructor (git-fixes). - ALSA: ump: fix double free of out_cvts on rawmidi error (git-fixes). - ALSA: usb-audio: Clamp frame size in implicit-feedback mode (git-fixes). - ALSA: usb-audio: Fix DMA buffer out-of-bounds write when fill_max is set (git-fixes). - ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output() (git-fixes). - ALSA: usb-audio: fix use-after-free in ump_to_endpoint() (git-fixes). - ASoC: bt-sco: fix duplicate DAPM widget names for wideband DAI (git-fixes). - ASoC: cs35l56: Fix potential probe() deadlock (git-fixes). - ASoC: cs35l56: Use complete_all() to signal init_completion (git-fixes). - ASoC: fsl_sai: Fix spurious BCLK on resume by clearing BYP (git-fixes). - ASoC: max98090: fix missing IS_ERR() before PTR_ERR() on mclk lookup (git-fixes). - ASoC: max98095: fix missing IS_ERR() before PTR_ERR() on mclk lookup (git-fixes). - ASoC: mediatek: mt8192-afe-pcm: Convert to devm_pm_runtime_enable() (stable-fixes). - ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (stable-fixes). - ASoC: mediatek: mt8192-afe-pcm: Simplify with dev_err_probe() (stable-fixes). - ASoC: tas2562: fix broken entries in the volume lookup table (git-fixes). - ASoC: tas2562: fix DVC coefficient write order (git-fixes). - ASoC: tas2781: bound firmware description string parsing (git-fixes). - assoc_array: trim the final shortcut word using the current chunk end (git-fixes). - batman-adv: dat: fix tie-break for candidate selection (git-fixes). - batman-adv: fix VLAN priority offset (git-fixes). - batman-adv: frag: fix primary_if leak on failed linearization (git-fixes). - batman-adv: frag: free unfragmentable packet (git-fixes). - batman-adv: tt: avoid request storms during pending request (git-fixes). - batman-adv: tt: prevent TVLV OOB check overflow (git-fixes). - bitops: make BYTES_TO_BITS() treewide-available (stable-fixes). - Bluetooth: 6lowpan: fix cyclic locking warning on netdev unregister (stable-fixes). - Bluetooth: 6lowpan: Fix using chan->conn as indication to no remote netdev (git-fixes). - Bluetooth: btintel: Validate length before parsing diagnostics TLV (git-fixes). - Bluetooth: btrtl: validate firmware patch bounds (git-fixes). - Bluetooth: btusb: Add USB ID 2c4e:0128 for Mercusys MA60XNB (stable-fixes). - Bluetooth: btusb: mediatek: remove the unnecessary goto tag (stable-fixes). - Bluetooth: btusb: validate Realtek vendor event length (git-fixes). - Bluetooth: hci_qca: Clear memdump state on invalid dump size (git-fixes). - Bluetooth: hci_sync: Fix advertising data UAFs (git-fixes). - Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks (git-fixes). - Bluetooth: hci_sync: Protect UUID list traversal (git-fixes). - Bluetooth: HIDP: reject frames without a transaction header (git-fixes). - Bluetooth: HIDP: validate numbered report payloads (git-fixes). - Bluetooth: ISO: clear iso_data always when detaching conn from hcon (git-fixes). - Bluetooth: ISO: fix CONNECTED -> CLOSED transition on shutdown/release (git-fixes). - Bluetooth: ISO: fix timeout vs sync_timeout typo in check_bcast_qos (git-fixes). - Bluetooth: ISO: validate sockaddr_iso first in iso_sock_rebind_bis() (git-fixes). - Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp (git-fixes). - Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync (git-fixes). - Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds (git-fixes). - Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update (git-fixes). - Bluetooth: mgmt: Translate HCI reason in Device Disconnected event (git-fixes). - Bluetooth: qca: fix NVM tag length underflow in TLV parser (git-fixes). - Bluetooth: RFCOMM: Fix session UAF in set_termios (git-fixes). - bus: sunxi-rsb: Always check register address validity (git-fixes). - can: bcm: add missing rcu list annotations and operations (git-fixes). - can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (git-fixes). - can: bcm: fix lockless bound/ifindex race and silent RX_SETUP failure (git-fixes). - can: c_can: c_can_chip_config(): keep controller in init mode until bittiming is configured (git-fixes). - can: ctucanfd: add missing MODULE_DEVICE_TABLE() (git-fixes). - can: ctucanfd: handle bus error interrupts (git-fixes). - can: ctucanfd: mark error-active controller status valid (git-fixes). - can: ctucanfd: unmap BAR0 using base address (git-fixes). - can: ctucanfd: use self-test mode for PRESUME_ACK (git-fixes). - can: ems_usb: validate CPC message lengths (git-fixes). - can: esd_usb: kill anchored URBs before freeing netdevs (git-fixes). - can: etas_es58x: es58x_read_bulk_callback(): fix RX buffer leak on URB resubmit failure (git-fixes). - can: isotp: check register_netdevice_notifier() error in module init (git-fixes). - can: isotp: use unconditional synchronize_rcu() in isotp_release() (git-fixes). - can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer (git-fixes). - can: kvaser_usb: kvaser_usb_hydra_get_busparams(): fix memory leak in kvaser_usb_hydra_get_busparams() (git-fixes). - can: kvaser_usb_leaf: kvaser_usb_leaf_wait_cmd(): validate received command extents (git-fixes). - can: peak_usb: add bounds check for USB channel index (git-fixes). - can: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error (git-fixes). - can: peak_usb: validate uCAN receive record lengths (git-fixes). - can: softing: fw_parse(): validate firmware record spans (git-fixes). - cdrom: fix stack out-of-bounds read in CDROMVOLCTRL (git-fixes). - comedi: comedi_parport: deal with premature interrupt (git-fixes). - dm cache policy smq: check allocation under invalidate lock (git-fixes). - dm cache: fix missing return in invalidate_committed's error path (git-fixes). - dmaengine: idxd: fix double free of wq, engine, and group structs (git-fixes). - dmaengine: idxd: fix fdev setup failure cleanup in idxd_cdev_open() (git-fixes). - dmaengine: qcom: bam_dma: Fix command element mask field for BAM v1.6.0+ (git-fixes). - dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA (git-fixes). - driver core: Fix missing jiffies conversion in deferred_probe_extend_timeout() (git-fixes). - driver core: Guard deferred probe timeout extension with delayed_work_pending() (git-fixes). - driver core: Use mod_delayed_work to prevent lost deferred probe work (git-fixes). - Drivers: hv: vmbus: Set DMA coherent mask for VMBus devices (git-fixes). - drm/amd/display: dce100: skip non-DP stream encoders for DP MST (stable-fixes). - drm/amd/display: set new_stream to NULL after release (git-fixes). - drm/amd/display: use proper context for logging (git-fixes). - drm/amd/pm/ci: Don't disable MCLK DPM on Bonaire 0x6658 (R7 260X) (git-fixes). - drm/amd/pm: fix smu14 power limit range calculation (stable-fixes). - drm/amd/pm: make pp_features read-only when scpm is enabled (stable-fixes). - drm/amdgpu/gfx8: drop unecessary BUG_ON() (stable-fixes). - drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) (stable-fixes). - drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older (stable-fixes). - drm/amdgpu/vce: fix integer overflow in image size (stable-fixes). - drm/amdgpu/vcn4: avoid rereading IB param length (stable-fixes). - drm/amdgpu: Disable PCIe dynamic speed switching on Ryzen Pinnacle Ridge (git-fixes). - drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved (stable-fixes). - drm/amdgpu: fix division by zero with invalid uvd dimensions (stable-fixes). - drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() (stable-fixes). - drm/amdgpu: Fix VFCT bus number matching with soft filter (stable-fixes). - drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (stable-fixes). - drm/amdkfd: Check bounds in allocate_event_notification_slot (stable-fixes). - drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (stable-fixes). - drm/amdkfd: fix uint32_t overflow in EOP ring buffer size alignment (git-fixes). - drm/amdkfd: free MQD managers on DQM init failures (git-fixes). - drm/amdkfd: hold event_mutex while checkpointing CRIU events (git-fixes). - drm/amdkfd: Use kvcalloc to allocate arrays (stable-fixes). - drm/dp: Read the PCON max FRL bandwidth only for HDMI DFPs (git-fixes). - drm/i915/gt: use correct selftest config symbol (git-fixes). - drm/i915/selftests: Fix GT PM sort comparators (git-fixes). - drm/i915: ensure segment offset never exceeds allowed max (stable-fixes). - drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM (git-fixes). - drm/mediatek: Check CRTC state before freeing (git-fixes). - drm/mediatek: ovl_adaptor: balance component registrations (git-fixes). - drm/panthor: reject firmware sections with oversized data (git-fixes). - drm/panthor: return error on truncated firmware (git-fixes). - drm/panthor: validate firmware interface structure sizes (git-fixes). - drm/radeon: fix r100_copy_blit for large BOs (stable-fixes). - drm/tegra: gr2d/gr3d: Contain PM in the gr*d_probe/gr*d_remove (git-fixes). - drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is registered (stable-fixes). - drm/tests: shmem: Set DMA mask to 64-bit in drm_gem_shmem (git-fixes). - drm/vc4: hvs/v3d: Fix null dereference in unbind (git-fixes). - drm/vc4: Prevent shader BO mappings from becoming writable (git-fixes). - drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size (git-fixes). - drm/vc4: Zero the tile state data array before each BIN job (git-fixes). - drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker (git-fixes). - drm/vmwgfx: avoid destroy_workqueue(NULL) on vkms init failure (git-fixes). - drm/vmwgfx: bound DMA command body size against suffix pointer (git-fixes). - drm/vmwgfx: drop dma_buf reference on foreign-fd prime import (git-fixes). - drm/vmwgfx: fix guest_memory_dirty bitfield clobbered as size (git-fixes). - drm/vmwgfx: reject DX_BIND_QUERY without a DX context (git-fixes). - drm/vmwgfx: use check_add_overflow for shader size+offset bound (git-fixes). - drm/vmwgfx: validate DRAW_PRIMITIVES header size before division (git-fixes). - drm/vmwgfx: validate external BO copy bounds for both stride paths (git-fixes). - drm/vmwgfx: Validate vmw_surface_metadata::array_size (git-fixes). - drm/xe/wopcm: fix WOPCM size for LNL+ (git-fixes). - fbcon: fix NULL pointer dereference for a console without vc_data (stable-fixes). - fbdev/efifb: Replace references to global screen_info by local pointer (stable-fixes). - fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() (git-fixes). - fbdev: efifb: fix memory leak in efifb_probe() (git-fixes). - firewire: net: Fix fragmented datagram reassembly (git-fixes). - firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get() (git-fixes). - firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (git-fixes). - firmware_loader: introduce __free() cleanup hanler (stable-fixes). - gpio: eic-sprd: use raw_spinlock_t in the irq startup path (git-fixes). - gpio: mlxbf3: fail probe if gpiochip registration fails (git-fixes). - gpio: pca953x: fix cache_only and IRQ state on restore_context() failure (git-fixes). - gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (git-fixes). - gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings (stable-fixes). - HID: add haptics page defines (stable-fixes). - HID: playstation: validate num_touch_reports in DualShock 4 reports (stable-fixes). - hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912). - hwmon: (adt7470) Fix busy-loop and I2C flooding in update thread (git-fixes). - hwmon: (adt7470) Fix cache updated before hardware write on I2C error (git-fixes). - hwmon: (adt7470) Fix divide-by-zero TOCTOU crash in fan speed read (git-fixes). - hwmon: (adt7470) Fix fans stuck in manual mode on I2C errors (git-fixes). - hwmon: (adt7470) Fix PWM auto temp state array and bounds check (git-fixes). - hwmon: (adt7470) Fix swapped PWM3 and PWM4 auto mode masks (git-fixes). - hwmon: (adt7470) Fix temperature alarm logic in hwmon_temp_read() (git-fixes). - hwmon: (adt7470) Use cached PWM frequency value (git-fixes). - hwmon: (asus-ec-sensors) add missed handle for ENOMEM (git-fixes). - hwmon: (asus-ec-sensors) fix EC read intervals (git-fixes). - hwmon: (asus-ec-sensors) fix looping over banks while reading from EC (git-fixes). - hwmon: (corsair-cpro) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (corsair-psu) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (lm90) Only report alarms if driver is ready (git-fixes). - hwmon: (nct6775-core) Prevent access to unsupported weight registers (git-fixes). - hwmon: (npcm750-pwm-fan): stop fan timer on device detach (git-fixes). - hwmon: (nzxt-smart2) Stop device IO before calling hid_hw_stop (git-fixes). - hwmon: (pmbus) Fix return value from pmbus_update_byte_data() (git-fixes). - hwmon: (pmbus/core) notify on the hwmon device, not the i2c client (git-fixes). - hwmon: (w83627hf) remove VID sysfs files on error and remove (stable-fixes). - hwmon: (w83793) remove vrm sysfs file on probe failure (stable-fixes). - hwmon: occ: validate poll response sensor blocks (git-fixes). - i2c: amd-mp2: Unregister callback on adapter add failure (git-fixes). - i2c: imx: Cancel hrtimer before clearing slave pointer (git-fixes). - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (git-fixes). - i2c: imx: Fix slave registration race and error handling (git-fixes). - i2c: imx: separate atomic, dma and non-dma use case (stable-fixes). - i2c: jz4780: Cache host clock rate at probe to prevent CCF prepare_lock deadlock (git-fixes). - i2c: mediatek: fix WRRD for SoCs without auto_restart option (git-fixes). - i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() (git-fixes). - ice: don't check has_ready_bitmap in E810 functions (bsc#1269981). - ice: factor out ice_ptp_rebuild_owner() (bsc#1269981). - ice: fix PTP Call Trace during PTP release (bsc#1269981). - ice: Fix PTP NULL pointer dereference during VSI rebuild (bsc#1269981). - ice: introduce PTP state machine (bsc#1269981). - ice: pass reset type to PTP reset functions (bsc#1269981). - ice: rename ice_ptp_tx_cfg_intr (bsc#1269981). - ice: rename verify_cached to has_ready_bitmap (bsc#1269981). - ice: stop destroying and reinitalizing Tx tracker during reset (bsc#1269981). - ieee802154: admin-gate legacy LLSEC dump operations (git-fixes). - ieee802154: allow legacy LLSEC ADD/DEL ops to pass strict validation (git-fixes). - ieee802154: ca8210: fix cas_ctl leak on spi_async failure (git-fixes). - ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit (git-fixes). - ieee802154: fix kernel-infoleak in dgram_recvmsg() (git-fixes). - ieee802154: Remove WARN_ON() in cfg802154_pernet_exit() (git-fixes). - iio: common: st_sensors: honour channel endianness in read_axis_data (git-fixes). - Input: atkbd - validate scancode in firmware keymap entries (git-fixes). - Input: elan_i2c - prevent division by zero and arithmetic underflow (git-fixes). - Input: goodix - clamp the device-reported contact count (git-fixes). - Input: iforce - bound the device-reported force-feedback effect index (git-fixes). - Input: ims-pcu - add response length checks (git-fixes). - Input: ims-pcu - fix DMA mapping violation in line setup (git-fixes). - Input: ims-pcu - fix firmware leak in async update (git-fixes). - Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() (git-fixes). - Input: ims-pcu - fix logic error in packet reset (git-fixes). - Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging (git-fixes). - Input: ims-pcu - fix potential infinite loop in CDC union descriptor parsing (git-fixes). - Input: ims-pcu - fix race condition in reset_device sysfs callback (git-fixes). - Input: ims-pcu - fix type confusion in CDC union descriptor parsing (git-fixes). - Input: ims-pcu - fix use-after-free and double-free in disconnect (git-fixes). - Input: ims-pcu - release data interface on disconnect (git-fixes). - Input: ims-pcu - validate control endpoint type (git-fixes). - Input: maple_keyb - set driver data before registering input device (stable-fixes). - Input: maplecontrol - set driver data before registering input device (stable-fixes). - Input: maplemouse - set driver data before registering input device (stable-fixes). - Input: rmi4 - fix bit count in bitmap_copy() (git-fixes). - Input: rmi4 - fix limit in rmi_register_desc_has_subpacket() (git-fixes). - Input: rmi4 - fix memory leak in rmi_set_attn_data() (git-fixes). - Input: rmi4 - fix num_subpackets overflow in register descriptor (git-fixes). - Input: rmi4 - fix register descriptor address calculation (git-fixes). - Input: rmi4 - fix type overflow in register counts (git-fixes). - Input: rmi4 - initialize attn_fifo properly (stable-fixes). - Input: rmi4 - iterative IRQ handler (git-fixes). - Input: rmi4 - refactor F12 probe function (stable-fixes). - Input: rmi4 - refactor register descriptor parsing (git-fixes). - Input: rmi4 - tolerate short register descriptor structure (git-fixes). - Input: rmi4 - use local presence map in rmi_read_register_desc() (stable-fixes). - Input: serio - define serio_pause_rx guard to pause and resume serio ports (stable-fixes). - Input: synaptics-rmi4 - add support for querying DPM value (F12) (stable-fixes). - Input: synaptics-rmi4 - fix crash when DPM query is not supported (git-fixes). - Input: synaptics-rmi4 - unregister function handlers on physical driver registration failure (git-fixes). - Input: touchwin - reset the packet index on every complete packet (git-fixes). - intel_th: fix MSC output device reference leak (git-fixes). - io_uring/cancel: de-unionize file and user_data in struct io_cancel_data (bsc#1271283). - io_uring/filetable: clamp alloc_hint to the configured alloc range (bsc#1271285). - io_uring/timeout: add helper for parsing user time (bsc#1271291). - io_uring/timeout: honour caller's time namespace for IORING_TIMEOUT_ABS (bsc#1271291). - io_uring/timeout: migrate reqs from ts64 to ktime (bsc#1271291). - io_uring/wait: honour caller's time namespace for IORING_ENTER_ABS_TIMER (bsc#1271291). - KVM: nVMX: Hide shadow VMCS right after VMCLEAR (git-fixes). - KVM: SEV: Do not allow intra-host migration/mirroring of SNP VMs (git-fixes). - KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git-fixes). - KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). - KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug (git-fixes). - KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes). - KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes). - KVM: x86/mmu: Fix use-after-free on vendor module reload (git-fixes). - KVM: x86/mmu: Preserve nested TDP shadow page tables if they are used as roots (git-fixes). - KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes). - KVM: x86: Fix SRCU list traversal in kvm_fire_mask_notifiers() (git-fixes). - KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer (git-fixes). - KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git-fixes). - KVM: x86: hyper-v: Validate all GVAs during PV TLB flush (git-fixes). - KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs (git-fixes). - libbpf: Search /lib64 and /lib in resolve_full_path() (bsc#1271250). - mac802154: hold an interface reference across the scan worker (git-fixes). - mac802154: llsec: reject frames shorter than the authentication tag (git-fixes). - media: airspy: Return queued buffers on start_streaming() failure (git-fixes). - media: atomisp: Fix memory leak in atomisp_fixed_pattern_table() (git-fixes). - media: cedrus: clean up media device on probe failure (git-fixes). - media: cx231xx: fix devres lifetime (git-fixes). - media: cx23885: add ioremap return check and cleanup (git-fixes). - media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges (git-fixes). - media: meson: vdec: Fix memory leak in error path of vdec_open (git-fixes). - media: msi2500: Return queued buffers on start_streaming() failure (git-fixes). - media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe (git-fixes). - media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure (git-fixes). - media: nxp: imx8-isi: Convert to platform remove callback returning void (stable-fixes). - media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path (git-fixes). - media: nxp: imx8-isi: Fix potential out-of-bounds issues (git-fixes). - media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding (git-fixes). - media: nxp: imx8-isi: Fix use-after-free on remove (git-fixes). - media: nxp: imx8-isi: use devm_pm_runtime_enable() to simplify code (stable-fixes). - media: pwc: Drain fill_buf on start_streaming() failure (git-fixes). - media: pwc: Return queued buffers on start_streaming() failure (git-fixes). - media: qcom: venus: drop extra padding in NV12 raw size calculation (git-fixes). - media: qcom: venus: relax encoder frame/blur dimension steps on v4 (git-fixes). - media: qcom: venus: relax encoder frame/blur step size on v6 (git-fixes). - media: radio-si476x: Unregister v4l2_device on probe failure (git-fixes). - media: rockchip: rga: fix too small buffer size (git-fixes). - media: rtl2832: fix use-after-free in rtl2832_remove() (git-fixes). - media: rtl2832_sdr: Return queued buffers on start_streaming() failure (git-fixes). - media: saa7134: Fix a possible memory leak in saa7134_video_init1 (git-fixes). - media: staging: ipu3-imgu: Add range check for imgu_css_cfg_acc_stripe (git-fixes). - media: stm32: dcmi: unregister notifier on probe failure (git-fixes). - media: sun4i-csi: Return queued buffers on start_streaming() failure (git-fixes). - media: tegra-video: vi: fix invalid u32 return value in format lookup (git-fixes). - media: uvcvideo: Avoid partial metadata buffers (git-fixes). - media: uvcvideo: Fix buffer sequence in frame gaps (git-fixes). - media: uvcvideo: Fix sequence number when no EOF (git-fixes). - media: v4l2-common: Add YUV24 format info (git-fixes). - media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (git-fixes). - media: vivid: add vivid_update_reduced_fps() (git-fixes). - media: vivid: check for vb2_is_busy() when toggling caps (git-fixes). - mei: bus: access mei_device under device_lock on cleanup (git-fixes). - memstick: ms_block: reject a card that reports too many blocks (git-fixes). - mfd: cros_ec: Delay dev_set_drvdata() until probe success (git-fixes). - mfd: sm501: Fix reference leak on failed device registration (git-fixes). - mfd: tps6586x: Fix OF node refcount (git-fixes). - mkspec-dtb: Skip missing DTBs. - mm: convert pagecache_isize_extended to use a folio (bsc#1272920). - mm: fix the inaccurate memory statistics issue for users (bsc#1268648). - mm: list_lru: disable memcg_aware when cgroup.memory is set to 'nokmem' (bsc#1271402). - mm: zero range of eof folio exposed by inode size extension (bsc#1272920). - mmc: vub300: defer reset until cmd_mutex is unlocked (git-fixes). - mtd: mchp23k256: use SPI match data for chip caps (git-fixes). - mtd: mtdswap: remove debugfs stats file on teardown (git-fixes). - mtd: nand: mtk-ecc: stop on ECC idle timeouts (git-fixes). - mtd: onenand: samsung: report DMA completion timeouts (git-fixes). - mtd: rawnand: Add a helper for calculating a page index (stable-fixes). - mtd: rawnand: Ensure all continuous terms are always in sync (git-fixes). - mtd: rawnand: fsl_ifc: return errors for failed page reads (git-fixes). - mtd: rawnand: lpc32xx_mlc: fail DMA transfers on timeout (git-fixes). - mtd: rawnand: lpc32xx_slc: fail DMA transfer on completion timeout (git-fixes). - mtd: rawnand: Pause continuous reads at block boundaries (git-fixes). - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (bsc#1271866). - net/x25: fix use-after-free in x25_kill_by_neigh() (git-fixes). - net: mana: Add Interrupt Moderation support (bsc#1271368). - net: mana: Return error code from mana_create_rxq() (git-fixes). - net: thunderbolt: Fix frags overflow by bounding frame_count (git-fixes). - net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() (git-fixes). - net: usb: lan78xx: move functions to avoid forward definitions (stable-fixes). - net: wwan: t7xx: check skb_clone in control TX (git-fixes). - net: wwan: t7xx: destroy DMA pool on CLDMA late init failure (git-fixes). - phy: zynqmp: fix L0_TM_DISABLE_SCRAMBLE_ENCODER mask (git-fixes). - phy: zynqmp: keep SERDES scrambler and 8b/10b enabled for USB (git-fixes). - phy: zynqmp: use read-modify-write for SERDES scrambler bypass (git-fixes). - pinctrl-amd: Don't clear S4 wake bits at probe (git-fixes). - pinctrl: bm1880: add missing select GENERIC_PINCONF (git-fixes). - pinctrl: devicetree: don't free uninitialized dev_name on error path (git-fixes). - pinctrl: qcom: sc8280xp: Add missing wakeup entries for GPIO143/151 (git-fixes). - pkspec-dtb: Fix dtb-al rename. - platform/x86/amd/pmc: Add delay_suspend module parameter (stable-fixes). - platform/x86/amd/pmc: Avoid logging '(null)' for DMI values (git-fixes). - platform/x86/amd/pmc: Check for intermediate wakeup in function (stable-fixes). - platform/x86/amd/pmc: Delay suspend for some Lenovo Laptops (stable-fixes). - platform/x86/amd/pmc: Don't log during intermediate wakeups (stable-fixes). - platform/x86: dell-smbios: Move request functions for reuse (stable-fixes). - posix-cpu-timers: Cleanup the firing logic (bsc#1271912). - posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912). - posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912). - posix-cpu-timers: Handle interval timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set() (bsc#1271912). - posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912). - posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1271912). - posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912). - posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912). - posix-timers: Add proper state tracking (bsc#1271912). - posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912). - posix-timers: Clarify posix_timer_fn() comments (bsc#1271912). - posix-timers: Clear overrun in common_timer_set() (bsc#1271912). - posix-timers: Consolidate signal queueing (bsc#1271912). - posix-timers: Consolidate timer setup (bsc#1271912). - posix-timers: Cure si_sys_private race (bsc#1271912). - posix-timers: Document common_clock_get() correctly (bsc#1271912). - posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912). - posix-timers: Polish coding style in a few places (bsc#1271912). - posix-timers: Retrieve interval in common timer_settime() code (bsc#1271912). - power: supply: bq25890: fix the -10 C NTC lookup entry (git-fixes). - RDMA/mana_ib: initialize err for empty send WR lists (git-fixes). - regulator: ltc3676: Fix incorrect IRQSTAT bit offsets (git-fixes). - remoteproc: qcom: Fix leak when custom dump_segments addition fails (git-fixes). - reset: sunxi: fix memory region leak on ioremap failure (git-fixes). - Revert 'Input: rmi4 - fix register descriptor address calculation' (stable-fixes). - sched/psi: Create the psimon kthread outside of cgroup_mutex (bsc#1269134). - sctp: validate embedded address parameter length (git-fixes). - selftests: Disable dad for ipv6 in fcnal-test.sh (bsc#1272871). - selftests: Replace sleep with slowwait (bsc#1272871). - serial: 8250_mid: Disable DMA for selected platforms (git-fixes). - serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms (git-fixes). - serial: 8250_mid: Remove 8250_pci usage (stable-fixes). - serial: sc16is7xx: implement gpio get_direction() callback (git-fixes). - series.conf: disable failing patch. - slimbus: Convert to platform remove callback returning void (stable-fixes). - slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock (git-fixes). - slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD (git-fixes). - slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (git-fixes). - slimbus: qcom-ngd-ctrl: Fix probe error path ordering (git-fixes). - slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (git-fixes). - slimbus: qcom-ngd-ctrl: Initialize controller resources in controller (git-fixes). - slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (git-fixes). - staging: media: atomisp: reduce load_primary_binaries() stack usage (git-fixes). - staging: rtl8723bs: core: move constants to right side in comparison (stable-fixes). - staging: rtl8723bs: fix inverted HT40 secondary channel offset (git-fixes). - task_work: Fix NMI race condition (git-fixes). - time: Switch to hrtimer_setup() (bsc#1271912). - uio_hv_generic: Bind to FCopy device by default (git-fixes). - usb: cdc_acm: Add quirk for Uniden BC125AT scanner (stable-fixes). - usb: chipidea: fix usage_count leak when autosuspend_delay is negative (git-fixes). - USB: core: add USB_QUIRK_NO_LPM for VIA Labs USB 2.0 hub (stable-fixes). - usb: core: port: Deattach Type-C connector on component unbind (git-fixes). - usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback (git-fixes). - usb: gadget: f_midi: cancel pending IN work before freeing the midi object (git-fixes). - usb: gadget: f_ncm: validate datagram bounds in ncm_unwrap_ntb() (git-fixes). - USB: gadget: fsl-udc: fix dev_printk() device (git-fixes). - USB: gadget: fsl-udc: fix device name leak on probe failure (git-fixes). - usb: gadget: function: rndis: add length check for header (stable-fixes). - usb: gadget: function: rndis: add length check to response query (stable-fixes). - usb: gadget: printer: fix infinite loop in printer_read() (git-fixes). - USB: gadget: snps-udc: fix device name leak on probe failure (git-fixes). - usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown (git-fixes). - usb: gadget: udc: Fix use-after-free in gadget_match_driver (stable-fixes). - usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer (git-fixes). - USB: iowarrior: fix use-after-free on disconnect race (git-fixes). - usb: iowarrior: remove inherent race with minor number (stable-fixes). - USB: quirks: add NO_LPM for the Samsung T5 EVO Portable SSD (stable-fixes). - USB: serial: io_edgeport: cap received transmit credits (git-fixes). - USB: serial: io_ti: reject oversized boot-mode firmware (git-fixes). - USB: serial: keyspan_pda: fix data loss on receive throttling (git-fixes). - USB: serial: mxuport: validate firmware header size (git-fixes). - USB: serial: option: add Telit Cinterion FE990D50 compositions (stable-fixes). - wan: wanxl: Only reset hardware after BAR mapping (git-fixes). - watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (git-fixes). - wifi: at76c50x-usb: avoid length underflow in at76_guess_freq() (git-fixes). - wifi: ath6kl: fix OOB access from firmware ADDBA window size (git-fixes). - wifi: ath6kl: fix OOB read from firmware IE lengths in connect event (git-fixes). - wifi: ath6kl: fix OOB read from firmware num_msg in TX complete handler (git-fixes). - wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (git-fixes). - wifi: ath10k: fix skb leak on incomplete msdu during rx pop (git-fixes). - wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin (git-fixes). - wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() (git-fixes). - wifi: ath11k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (git-fixes). - wifi: ath12k: Flush the posted write after writing to PCIE_SOC_GLOBAL_RESET (git-fixes). - wifi: brcmfmac: fix 802.1X-SHA256 call trace warning (git-fixes). - wifi: brcmfmac: initialize SDIO data work before cleanup (git-fixes). - wifi: brcmfmac: make release_scratchbuffers idempotent (git-fixes). - wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (git-fixes). - wifi: carl9170: fix buffer overflow in rx_stream failover path (git-fixes). - wifi: carl9170: fix OOB read from off-by-two in TX status handler (git-fixes). - wifi: cfg80211: bound element ID read when checking non-inheritance (git-fixes). - wifi: cfg80211: cancel sched scan results work on unregister (git-fixes). - wifi: cfg80211: derive S1G beacon TSF from S1G fields (git-fixes). - wifi: cfg80211: reject unsupported PMSR FTM location requests (git-fixes). - wifi: cfg80211: validate PMSR FTM preamble range (git-fixes). - wifi: cfg80211: validate PMSR measurement type data (git-fixes). - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (git-fixes). - wifi: iwlwifi: mvm: fix flushing during quiet CSA (bsc#1272600). - wifi: iwlwifi: mvm: fix read in wake packet notification handler (git-fixes). - wifi: iwlwifi: mvm: validate SAR GEO response payload size (git-fixes). - wifi: libertas: fix memory leak in helper_firmware_cb() (git-fixes). - wifi: mac80211: fix fils_discovery double free on alloc failure (git-fixes). - wifi: mac80211: fix memory leak in ieee80211_register_hw() (git-fixes). - wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure (git-fixes). - wifi: mac80211: free ack status frame on TX header build failure (git-fixes). - wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (git-fixes). - wifi: mac80211: recalculate TIM when a station enters power save (git-fixes). - wifi: mac80211: tear down new links on vif update error path (git-fixes). - wifi: mac80211: validate individual TWT params before driver setup (git-fixes). - wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv() (git-fixes). - wifi: mt76: mt7615: drop TXRX_NOTIFY on non-mmio buses (git-fixes). - wifi: mt76: mt7915: guard HE capability lookups (git-fixes). - wifi: mt76: mt7921: drop TXRX_NOTIFY on non-mmio buses (git-fixes). - wifi: mt76: mt7925: drop TXRX_NOTIFY on non-mmio buses (git-fixes). - wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() (git-fixes). - wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() (git-fixes). - wifi: mwifiex: bound uAP association event IEs to the event buffer (git-fixes). - wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (git-fixes). - wifi: mwifiex: fix permanently busy scans after multiple roam iterations (git-fixes). - wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (git-fixes). - wifi: nl80211: free RNR data on MBSSID mismatch (git-fixes). - wifi: nl80211: validate nested MBSSID IE blobs (git-fixes). - wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (git-fixes). - wifi: rt2x00: avoid full teardown before work setup in probe (git-fixes). - wifi: wilc1000: validate assoc response length before subtracting header (git-fixes). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3798-1 Released: Tue Aug 25 14:40:59 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262632,1262633,1262635,1262636,1262638,1263440,1268412,CVE-2026-5545,CVE-2026-5773,CVE-2026-6253,CVE-2026-6276,CVE-2026-6429,CVE-2026-7168,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5545: wrong reuse of HTTP Negotiate connection (bsc#1262632). - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-6253: proxy credentials leak over redirect-to proxy (bsc#1262635). - CVE-2026-6276: stale custom cookie host causes cookie leak (bsc#1262636). - CVE-2026-6429: netrc credential leak with reused proxy connection (bsc#1262638). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3841-1 Released: Thu Aug 27 14:21:33 2026 Summary: Security update for wicked Type: security Severity: important References: 1274627,CVE-2026-71401,CVE-2026-71402 This update for wicked fixes the following issue: - CVE-2026-71401: out-of-bounds read due to IP length underflow in checksum handling of DHCPv4 capture parsing (bsc#1274627). - CVE-2026-71402: out-of-bounds read due to DHCP option reader being extended beyond provided allocation in DHCPv4 capture parsing (bsc#1274627). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3850-1 Released: Fri Aug 28 11:27:18 2026 Summary: Recommended update for ethtool Type: recommended Severity: moderate References: 1224590,1261256 This update for ethtool fixes the following issues: - backport Rx CQE coalescing support (bsc#1261256): * sync UAPI header copies with SLE15-SP7 * adds netlink support for configuring receive completion queue event (RX CQE) coalesce modes - backport post-6.4 upstream fixes (bsc#1224590): * Fix index calculation in RTTPT2C register dump loop * netlink: add NULL check for get_string in features.c * qsfp: Better handling of Page 03h netlink read failure * ethtool: + Fix argument check in do_srxfh function to prevent segmentation fault + Fix incorrect success return value on RX net + Fix JSON output for IRQ coalescing * netlink-rss: retrieve ring count using ETHTOOL_GRXRIN - update guards script (address a warning with new perl version) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3931-1 Released: Thu Sep 3 09:19:16 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). - CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: - Update to version 059+suse.576.g72b98359a: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3956-1 Released: Thu Sep 3 10:04:30 2026 Summary: Recommended update for perl-Bootloader Type: recommended Severity: moderate References: 1246013,1271602 This update for perl-Bootloader fixes the following issues: - Update to version 1.28: * fix test suite * adjust two tests * add test case * updated test results * fix command line parser (bsc#1271602) * fix and reenable ksh tests: ksh uses alts now * update ksh test results - Update to version 1.27: * adjust spec file for immutable mode: switch to using * systemd-tmpfiles (jsc#PED-14833) - Update to version 1.26: * adjust test cases - Implement config for BLS (bsc#1246013) The following package changes have been done: - NetworkManager-1.44.2-150600.3.7.1 updated - bash-sh-4.4-150400.27.6.1 updated - bash-4.4-150400.27.6.1 updated - ca-certificates-mozilla-2.84-150200.44.1 updated - container-suseconnect-2.5.6-150700.4.94.1 updated - coreutils-8.32-150400.9.12.1 updated - crypto-policies-20230920.570ea89-150600.3.19.1 updated - curl-8.14.1-150700.7.23.1 updated - device-mapper-2.03.24_1.02.198-150700.7.6.1 updated - dmidecode-3.7-150400.16.14.1 updated - dracut-059+suse.576.g72b98359a-150700.3.23.1 updated - elfutils-0.185-150400.5.8.3 updated - ethtool-6.4-150600.7.6.1 updated - gawk-4.2.1-150000.3.6.1 updated - glib2-tools-2.78.6-150600.4.38.1 updated - glibc-locale-base-2.38-150600.14.52.1 updated - glibc-2.38-150600.14.52.1 updated - gpg2-2.4.4-150600.3.18.1 updated - grub2-i386-pc-2.12-150700.19.34.1 updated - grub2-x86_64-efi-2.12-150700.19.34.1 updated - grub2-2.12-150700.19.34.1 updated - gzip-1.10-150200.16.1 updated - hwdata-0.406-150000.3.80.1 added - iproute2-6.4-150600.7.15.1 updated - jq-1.6-150000.3.20.1 updated - kbd-2.4.0-150700.15.6.1 updated - kernel-default-6.4.0-150700.53.78.1 updated - kmod-29-150600.13.6.1 updated - kpartx-0.10.7~1+211+suse.18f1559-150700.3.14.1 updated - krb5-1.20.1-150600.11.19.1 updated - libaio1-0.3.113-150600.15.3.1 updated - libapparmor1-3.1.7-150600.5.15.1 updated - libasm1-0.185-150400.5.8.3 updated - libblkid1-2.40.4-150700.4.18.1 updated - libbrotlicommon1-1.0.7-150200.3.5.1 updated - libbrotlidec1-1.0.7-150200.3.5.1 updated - libcap2-2.63-150400.3.6.1 updated - libcryptsetup12-2.8.4-150700.6.4.4 updated - libcurl4-8.14.1-150700.7.23.1 updated - libdevmapper-event1_03-2.03.24_1.02.198-150700.7.6.1 updated - libdevmapper1_03-2.03.24_1.02.198-150700.7.6.1 updated - libdw1-0.185-150400.5.8.3 updated - libelf1-0.185-150400.5.8.3 updated - libexpat1-2.7.1-150700.3.12.1 updated - libfdisk1-2.40.4-150700.4.18.1 updated - libfreebl3-3.112.5-150400.3.69.2 updated - libfreetype6-2.10.4-150000.4.25.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libgcrypt20-1.11.0-150700.5.10.1 updated - libgio-2_0-0-2.78.6-150600.4.38.1 updated - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libgmodule-2_0-0-2.78.6-150600.4.38.1 updated - libgobject-2_0-0-2.78.6-150600.4.38.1 updated - libgpgme11-1.23.0-150600.3.5.1 updated - libjq1-1.6-150000.3.20.1 updated - libkmod2-29-150600.13.6.1 updated - libldap-2_4-2-2.4.46-150600.25.3.1 updated - libldap-data-2.4.46-150600.25.3.1 updated - liblzma5-5.4.1-150600.3.6.1 updated - libmount1-2.40.4-150700.4.18.1 updated - libmpath0-0.10.7~1+211+suse.18f1559-150700.3.14.1 updated - libncurses6-6.1-150000.5.33.1 updated - libnfsidmap1-1.0-150600.28.19.1 updated - libnghttp2-14-1.64.0-150700.3.3.1 updated - libnm0-1.44.2-150600.3.7.1 updated - libopeniscsiusr0-0.2.0-150700.57.6.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libpci3-3.13.0-150300.13.12.1 updated - libpng16-16-1.6.58-150600.3.23.1 updated - libreadline7-7.0-150400.27.6.1 updated - libsasl2-3-2.1.28-150600.7.14.1 updated - libselinux1-3.5-150600.3.3.1 updated - libsgutils2-1_48-2-1.48+12.096114a9-150600.3.6.1 updated - libsmartcols1-2.40.4-150700.4.18.1 updated - libsoftokn3-3.112.5-150400.3.69.2 updated - libsolv-tools-base-0.7.39-150700.11.10.1 updated - libsqlite3-0-3.53.2-150000.3.42.1 updated - libssh-config-0.9.8-150600.11.15.1 updated - libssh4-0.9.8-150600.11.15.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - libsubid5-4.17.2-150600.17.24.1 added - libsystemd0-254.27-150600.4.71.2 updated - libtasn1-6-4.13-150000.4.14.1 updated - libtasn1-4.13-150000.4.14.1 updated - libudev1-254.27-150600.4.71.2 updated - libuuid1-2.40.4-150700.4.18.1 updated - libxml2-2-2.12.10-150700.4.14.1 updated - libz1-1.2.13-150500.4.6.1 updated - libzypp-17.38.13-150700.6.13.1 updated - login_defs-4.17.2-150600.17.24.1 updated - lsscsi-0.32-150700.17.3.1 updated - mdadm-4.4+40.g243a5d9f-150700.4.24.1 updated - mozilla-nspr-4.36.2-150000.3.36.1 updated - mozilla-nss-certs-3.112.5-150400.3.69.2 updated - mozilla-nss-3.112.5-150400.3.69.2 updated - multipath-tools-0.10.7~1+211+suse.18f1559-150700.3.14.1 updated - ncurses-utils-6.1-150000.5.33.1 updated - nfs-client-2.6.4-150600.28.19.1 updated - open-iscsi-2.1.12-150700.57.6.1 updated - openssh-clients-9.6p1-150600.6.49.1 updated - openssh-common-9.6p1-150600.6.49.1 updated - openssh-server-9.6p1-150600.6.49.1 updated - openssh-9.6p1-150600.6.49.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - openssl-3.5.0-150700.3.4.1 updated - pam-1.3.0-150000.6.89.1 updated - pciutils-3.13.0-150300.13.12.1 updated - perl-Bootloader-1.28-150700.3.6.1 updated - perl-base-5.26.1-150300.17.23.1 updated - rpcbind-0.2.3-150000.5.12.1 updated - rpm-ndb-4.14.3-150400.59.19.1 updated - rsync-3.2.7-150600.3.24.1 updated - sed-4.9-150600.3.3.1 updated - sg3_utils-1.48+12.096114a9-150600.3.6.1 updated - shadow-4.17.2-150600.17.24.1 updated - shim-16.1-150300.4.31.3 updated - sles-release-15.7-150700.67.6.1 updated - suse-build-key-12.0-150000.8.64.1 updated - suse-module-tools-15.7.10-150700.3.11.1 updated - sysconfig-netconfig-0.85.11-150200.18.1 updated - sysconfig-0.85.11-150200.18.1 updated - sysstat-12.0.2-150000.3.51.1 updated - systemd-presets-branding-SLE-15.1-150600.35.3.1 updated - systemd-rpm-macros-16-150000.7.42.1 updated - systemd-254.27-150600.4.71.2 updated - tar-1.34-150000.3.42.1 updated - terminfo-base-6.1-150000.5.33.1 updated - timezone-2026c-150600.91.12.1 updated - udev-254.27-150600.4.71.2 updated - util-linux-systemd-2.40.4-150700.4.18.1 updated - util-linux-2.40.4-150700.4.18.1 updated - vim-data-common-9.2.0957-150500.20.64.1 updated - vim-small-9.2.0957-150500.20.64.1 updated - wicked-service-0.6.79-150700.3.8.1 updated - wicked-0.6.79-150700.3.8.1 updated - wpa_supplicant-2.11-150700.3.3.1 updated - xz-5.4.1-150600.3.6.1 updated - zypper-1.14.98-150700.13.6.1 updated - libargon2-1-20190702-150600.1.4 removed - openslp-2.0.0-150600.19.5 removed - pciutils-ids-20200324-3.6.1 removed From sle-container-updates at lists.suse.com Sun Sep 6 07:30:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:30:04 +0200 (CEST) Subject: SUSE-CU-2026:9519-1: Security update of bci/bci-init Message-ID: <20260906073004.BB845FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9519-1 Container Tags : bci/bci-init:15.7 , bci/bci-init:15.7-53.39 , bci/bci-init:latest Container Release : 53.39 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259542 1259652 1261678 1266344 1266347 1275902 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:30:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:30:55 +0200 (CEST) Subject: SUSE-CU-2026:9520-1: Recommended update of suse/kea Message-ID: <20260906073055.7F326FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/kea ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9520-1 Container Tags : suse/kea:2.6 , suse/kea:2.6-79.17 Container Release : 79.17 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/kea was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:32:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:32:15 +0200 (CEST) Subject: SUSE-CU-2026:9521-1: Recommended update of suse/kiosk/firefox-esr Message-ID: <20260906073215.36900FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9521-1 Container Tags : suse/kiosk/firefox-esr:140.14 , suse/kiosk/firefox-esr:140.14-75.20 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.20 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:32:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:32:56 +0200 (CEST) Subject: SUSE-CU-2026:9522-1: Recommended update of bci/bci-micro-fips Message-ID: <20260906073256.01690FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9522-1 Container Tags : bci/bci-micro-fips:15.7 , bci/bci-micro-fips:15.7-27.5 , bci/bci-micro-fips:latest Container Release : 27.5 Severity : important Type : recommended References : 1242233 1243830 1277267 ----------------------------------------------------------------- The container bci/bci-micro-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:33:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:33:54 +0200 (CEST) Subject: SUSE-CU-2026:9523-1: Security update of bci/nodejs Message-ID: <20260906073354.440ABFCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9523-1 Container Tags : bci/node:22 , bci/node:22-sles15 , bci/node:22.23.2 , bci/node:22.23.2-24.39 , bci/nodejs:22 , bci/nodejs:22-sles15 , bci/nodejs:22.23.2 , bci/nodejs:22.23.2-24.39 Container Release : 24.39 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259542 1259652 1261678 1266344 1266347 1275902 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:35:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:35:01 +0200 (CEST) Subject: SUSE-CU-2026:9524-1: Security update of bci/openjdk-devel Message-ID: <20260906073501.37E28FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9524-1 Container Tags : bci/openjdk-devel:17 , bci/openjdk-devel:17-sles15 , bci/openjdk-devel:17.0.20.0 , bci/openjdk-devel:17.0.20.0-21.46 Container Release : 21.46 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259542 1259652 1261678 1266344 1266347 1275902 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - container:bci-openjdk-17-15.7.17-20.39 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:36:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:36:07 +0200 (CEST) Subject: SUSE-CU-2026:9525-1: Security update of bci/openjdk Message-ID: <20260906073607.0E539FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9525-1 Container Tags : bci/openjdk:17 , bci/openjdk:17-sles15 , bci/openjdk:17.0.20.0 , bci/openjdk:17.0.20.0-20.39 Container Release : 20.39 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:37:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:37:17 +0200 (CEST) Subject: SUSE-CU-2026:9526-1: Security update of bci/openjdk-devel Message-ID: <20260906073717.A1265FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9526-1 Container Tags : bci/openjdk-devel:21 , bci/openjdk-devel:21-sles15 , bci/openjdk-devel:21.0.12.0 , bci/openjdk-devel:21.0.12.0-25.46 Container Release : 25.46 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259542 1259652 1261678 1266344 1266347 1275902 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - container:bci-openjdk-21-15.7.21-24.38 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:38:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:38:19 +0200 (CEST) Subject: SUSE-CU-2026:9527-1: Security update of bci/openjdk Message-ID: <20260906073819.AE072FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9527-1 Container Tags : bci/openjdk:21 , bci/openjdk:21-sles15 , bci/openjdk:21.0.12.0 , bci/openjdk:21.0.12.0-24.38 Container Release : 24.38 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:39:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:39:08 +0200 (CEST) Subject: SUSE-CU-2026:9528-1: Security update of bci/openjdk-devel Message-ID: <20260906073908.668B5FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9528-1 Container Tags : bci/openjdk-devel:25 , bci/openjdk-devel:25-sles15 , bci/openjdk-devel:25.0.4.0 , bci/openjdk-devel:25.0.4.0-9.47 , bci/openjdk-devel:latest Container Release : 9.47 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259542 1259652 1261678 1266344 1266347 1275902 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - container:bci-openjdk-25-15.7.25-9.38 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:39:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:39:56 +0200 (CEST) Subject: SUSE-CU-2026:9529-1: Security update of bci/openjdk Message-ID: <20260906073956.701B1FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9529-1 Container Tags : bci/openjdk:25 , bci/openjdk:25-sles15 , bci/openjdk:25.0.4.0 , bci/openjdk:25.0.4.0-9.38 , bci/openjdk:latest Container Release : 9.38 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:41:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:41:05 +0200 (CEST) Subject: SUSE-CU-2026:9530-1: Security update of bci/php-apache Message-ID: <20260906074105.6B15CFCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/php-apache ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9530-1 Container Tags : bci/php-apache:8 , bci/php-apache:8-sles15 , bci/php-apache:8.3.33 , bci/php-apache:8.3.33-26.4 , bci/php-apache:latest Container Release : 26.4 Severity : critical Type : security References : 1207866 1274235 1274237 1274850 1274852 1274854 CVE-2022-25147 CVE-2025-49506 CVE-2026-32327 CVE-2026-34191 CVE-2026-34501 CVE-2026-34502 ----------------------------------------------------------------- The container bci/php-apache was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3938-1 Released: Thu Sep 3 09:29:58 2026 Summary: Security update for apr-util Type: security Severity: critical References: 1207866,1274235,1274237,1274850,1274852,1274854,CVE-2022-25147,CVE-2025-49506,CVE-2026-32327,CVE-2026-34191,CVE-2026-34501,CVE-2026-34502 This update for apr-util fixes the following issues: - CVE-2022-25147: buffer overflow possible with specially crafted input (bsc#1207866). - CVE-2025-49506: leaking content via side channel timing attack (bsc#1274237). - CVE-2026-32327: XML stack recursion crash (bsc#1274235). - CVE-2026-34191: SQL Injection via apr_dbd_oracle (bsc#1274850). - CVE-2026-34501: heap buffer overflow in redis client (bsc#1274852). - CVE-2026-34502: heap buffer overflow in APR memcached client (bsc#1274854). The following package changes have been done: - libapr-util1-1.6.1-150600.27.3.1 updated - container:bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:43:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:43:50 +0200 (CEST) Subject: SUSE-CU-2026:9533-1: Recommended update of suse/postgres Message-ID: <20260906074350.9656DFCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9533-1 Container Tags : suse/postgres:16-contrib , suse/postgres:16.14 , suse/postgres:16.14-contrib , suse/postgres:16.14-contrib-93.19 Container Release : 93.19 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 07:43:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 09:43:52 +0200 (CEST) Subject: SUSE-CU-2026:9534-1: Security update of suse/postgres Message-ID: <20260906074352.35278FDCF@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9534-1 Container Tags : suse/postgres:16-contrib , suse/postgres:16.15 , suse/postgres:16.15-contrib , suse/postgres:16.15-contrib-93.21 Container Release : 93.21 Severity : important Type : security References : 1275001 1275002 1275042 1275043 1275044 1275046 1275047 1275048 1275049 1275050 1275051 1275053 1275054 1275056 1275057 1275058 1275059 1275061 1275062 1275063 1275064 1275065 1275066 1275067 1275068 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-15741 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-19385 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3963-1 Released: Thu Sep 3 15:33:32 2026 Summary: Security update for postgresql16 Type: security Severity: important References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275053,1275054,1275056,1275057,1275058,1275059,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-15741,CVE-2026-15742,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471 This update for postgresql16 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql16: - Update to version 16.15: * https://www.postgresql.org/docs/16/release-16-15.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ The following package changes have been done: - postgresql16-16.15-150600.16.38.1 updated - postgresql16-server-16.15-150600.16.38.1 updated - postgresql16-contrib-16.15-150600.16.38.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:02:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:02:45 +0200 (CEST) Subject: SUSE-CU-2026:9534-1: Security update of suse/postgres Message-ID: <20260906110245.48A04FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9534-1 Container Tags : suse/postgres:16-contrib , suse/postgres:16.15 , suse/postgres:16.15-contrib , suse/postgres:16.15-contrib-93.21 Container Release : 93.21 Severity : important Type : security References : 1275001 1275002 1275042 1275043 1275044 1275046 1275047 1275048 1275049 1275050 1275051 1275053 1275054 1275056 1275057 1275058 1275059 1275061 1275062 1275063 1275064 1275065 1275066 1275067 1275068 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-15741 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-19385 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3963-1 Released: Thu Sep 3 15:33:32 2026 Summary: Security update for postgresql16 Type: security Severity: important References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275053,1275054,1275056,1275057,1275058,1275059,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-15741,CVE-2026-15742,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471 This update for postgresql16 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql16: - Update to version 16.15: * https://www.postgresql.org/docs/16/release-16-15.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ The following package changes have been done: - postgresql16-16.15-150600.16.38.1 updated - postgresql16-server-16.15-150600.16.38.1 updated - postgresql16-contrib-16.15-150600.16.38.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:03:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:03:09 +0200 (CEST) Subject: SUSE-CU-2026:9535-1: Security update of suse/postgres Message-ID: <20260906110309.2F6E9FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9535-1 Container Tags : suse/postgres:16 , suse/postgres:16.15 , suse/postgres:16.15 , suse/postgres:16.15-93.21 Container Release : 93.21 Severity : important Type : security References : 1242233 1243830 1259542 1275001 1275002 1275042 1275043 1275044 1275046 1275047 1275048 1275049 1275050 1275051 1275053 1275054 1275056 1275057 1275058 1275059 1275061 1275062 1275063 1275064 1275065 1275066 1275067 1275068 1275902 1277267 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-15741 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-19385 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3963-1 Released: Thu Sep 3 15:33:32 2026 Summary: Security update for postgresql16 Type: security Severity: important References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275053,1275054,1275056,1275057,1275058,1275059,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-15741,CVE-2026-15742,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471 This update for postgresql16 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql16: - Update to version 16.15: * https://www.postgresql.org/docs/16/release-16-15.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - postgresql16-16.15-150600.16.38.1 updated - shadow-4.17.2-150600.17.24.1 updated - postgresql16-server-16.15-150600.16.38.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:04:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:04:01 +0200 (CEST) Subject: SUSE-CU-2026:9441-1: Security update of suse/postgres Message-ID: <20260906110401.AF617FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9441-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.10 , suse/postgres:17.10-contrib , suse/postgres:17.10-contrib-83.17 Container Release : 83.17 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:04:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:04:04 +0200 (CEST) Subject: SUSE-CU-2026:9536-1: Recommended update of suse/postgres Message-ID: <20260906110404.0D661FDD4@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9536-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.10 , suse/postgres:17.10-contrib , suse/postgres:17.10-contrib-83.20 Container Release : 83.20 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:04:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:04:31 +0200 (CEST) Subject: SUSE-CU-2026:9538-1: Recommended update of suse/postgres Message-ID: <20260906110431.D88B7FDD4@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9538-1 Container Tags : suse/postgres:17 , suse/postgres:17.10 , suse/postgres:17.10 , suse/postgres:17.10-83.19 Container Release : 83.19 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:04:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:04:30 +0200 (CEST) Subject: SUSE-CU-2026:9537-1: Security update of suse/postgres Message-ID: <20260906110430.C1457FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9537-1 Container Tags : suse/postgres:17 , suse/postgres:17.10 , suse/postgres:17.10 , suse/postgres:17.10-83.17 Container Release : 83.17 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:05:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:05:13 +0200 (CEST) Subject: SUSE-CU-2026:9539-1: Security update of suse/postgres Message-ID: <20260906110513.23EFCFDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9539-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.4 , suse/postgres:18.4-contrib , suse/postgres:18.4-contrib-73.17 , suse/postgres:latest Container Release : 73.17 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:05:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:05:15 +0200 (CEST) Subject: SUSE-CU-2026:9540-1: Recommended update of suse/postgres Message-ID: <20260906110515.07436FDD4@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9540-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.4 , suse/postgres:18.4-contrib , suse/postgres:18.4-contrib-73.19 , suse/postgres:latest Container Release : 73.19 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:05:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:05:45 +0200 (CEST) Subject: SUSE-CU-2026:9541-1: Security update of suse/postgres Message-ID: <20260906110545.CB4C3FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9541-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-73.17 , suse/postgres:latest Container Release : 73.17 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:05:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:05:48 +0200 (CEST) Subject: SUSE-CU-2026:9542-1: Recommended update of suse/postgres Message-ID: <20260906110548.8713CFDD4@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9542-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-73.19 , suse/postgres:latest Container Release : 73.19 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:07:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:07:09 +0200 (CEST) Subject: SUSE-CU-2026:9543-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260906110709.BE74BFDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9543-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-73.17 , suse/kiosk/pulseaudio:latest Container Release : 73.17 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:07:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:07:10 +0200 (CEST) Subject: SUSE-CU-2026:9544-1: Recommended update of suse/kiosk/pulseaudio Message-ID: <20260906110710.BC2B5FDD4@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9544-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-73.19 , suse/kiosk/pulseaudio:latest Container Release : 73.19 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:08:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:08:29 +0200 (CEST) Subject: SUSE-CU-2026:9545-1: Security update of bci/python Message-ID: <20260906110829.C8E68FDCB@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9545-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.42 Container Release : 85.42 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:09:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:09:54 +0200 (CEST) Subject: SUSE-CU-2026:9546-1: Security update of bci/python Message-ID: <20260906110954.4CC57FDCB@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9546-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.14 , bci/python:3.13.14-88.38 , bci/python:latest Container Release : 88.38 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:11:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:11:14 +0200 (CEST) Subject: SUSE-CU-2026:9547-1: Security update of bci/python Message-ID: <20260906111114.E0ED5FDCB@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9547-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.36 Container Release : 84.36 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:11:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:11:53 +0200 (CEST) Subject: SUSE-CU-2026:9548-1: Security update of suse/mariadb-client Message-ID: <20260906111153.72D8FFDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9548-1 Container Tags : suse/mariadb-client:11.8 , suse/mariadb-client:11.8.8 , suse/mariadb-client:11.8.8-72.10 , suse/mariadb-client:latest Container Release : 72.10 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/mariadb-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:11:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:11:54 +0200 (CEST) Subject: SUSE-CU-2026:9549-1: Recommended update of suse/mariadb-client Message-ID: <20260906111154.A6F18FDD4@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9549-1 Container Tags : suse/mariadb-client:11.8 , suse/mariadb-client:11.8.8 , suse/mariadb-client:11.8.8-72.12 , suse/mariadb-client:latest Container Release : 72.12 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/mariadb-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:12:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:12:43 +0200 (CEST) Subject: SUSE-CU-2026:9550-1: Security update of suse/mariadb Message-ID: <20260906111243.25BD8FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9550-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-79.17 , suse/mariadb:latest Container Release : 79.17 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:12:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:12:44 +0200 (CEST) Subject: SUSE-CU-2026:9551-1: Recommended update of suse/mariadb Message-ID: <20260906111244.6E0E3FDD4@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9551-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-79.19 , suse/mariadb:latest Container Release : 79.19 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 11:14:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:14:00 +0200 (CEST) Subject: SUSE-CU-2026:9552-1: Security update of suse/rmt-server Message-ID: <20260906111400.E8109FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9552-1 Container Tags : suse/rmt-server:3 , suse/rmt-server:3.1 , suse/rmt-server:3.1-71.1 , suse/rmt-server:latest Container Release : 71.1 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1262632 1262633 1262635 1262636 1262638 1263440 1265369 1266344 1266347 1268011 1268337 1268338 1268339 1268412 1270034 1274715 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-61594 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42256 CVE-2026-42258 CVE-2026-42764 CVE-2026-47240 CVE-2026-47241 CVE-2026-47242 CVE-2026-5545 CVE-2026-5773 CVE-2026-6253 CVE-2026-6276 CVE-2026-6429 CVE-2026-7168 CVE-2026-8926 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3090-1 Released: Fri Jul 17 08:13:15 2026 Summary: Security update for ruby3.4 Type: security Severity: moderate References: 1268011,1268337,1268338,1268339,1270034,CVE-2025-61594,CVE-2026-42258,CVE-2026-47240,CVE-2026-47241,CVE-2026-47242 This update for ruby3.4 fixes the following issues - CVE-2026-42258: Net:IMAP: Command Injection via Symbol Arguments (bsc#1268011). - CVE-2026-47240: Net:IMAP: Command Injection via non-synchronizing literal in 'raw' argument (bsc#1268337). - CVE-2026-47241: Net:IMAP: Denial of Service via incomplete raw argument validation (bsc#1268338). - CVE-2026-47242: Net:IMAP: Command Injection via ID and ENABLE command arguments (bsc#1268339). - CVE-2025-61594: merging URIs using the + operator could expose sensitive user credentials (bsc#1270034). Changes for ruby3.4: - Update to 3.4.10: - bundling net-imap 0.5.15. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3792-1 Released: Tue Aug 25 14:31:18 2026 Summary: Security update for rmt-server Type: security Severity: important References: 1265369,1274715,CVE-2026-42256 This update for rmt-server fixes the following issue: Update to version 3.1 (bsc#1274715). - CVE-2026-42256: net-imap: hostile server can perform a DoS on client authenticating a connection with SCRAM-SHA1 or SCRAM-SHA2 (bsc#1265369). Changes for rmt-server: - Version 3.1: * Remove all errors and warnings due to new Ruby and Ruby on Rails versions - Version 3.0: * Split Rails meta-gem into individual components for better security control - Version 3.0.alpha: * Update Ruby to version 3.4.8 and Rails to version 7.1.6 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3798-1 Released: Tue Aug 25 14:40:59 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262632,1262633,1262635,1262636,1262638,1263440,1268412,CVE-2026-5545,CVE-2026-5773,CVE-2026-6253,CVE-2026-6276,CVE-2026-6429,CVE-2026-7168,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5545: wrong reuse of HTTP Negotiate connection (bsc#1262632). - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-6253: proxy credentials leak over redirect-to proxy (bsc#1262635). - CVE-2026-6276: stale custom cookie host causes cookie leak (bsc#1262636). - CVE-2026-6429: netrc credential leak with reused proxy connection (bsc#1262638). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libruby3_4-3_4-3.4.10-150700.3.4.1 added - libopenssl3-3.5.0-150700.5.45.2 updated - libcurl4-8.14.1-150700.7.23.1 updated - ruby3.4-3.4.10-150700.3.4.1 added - rmt-server-config-3.1.0-150700.3.28.1 updated - rmt-server-3.1.0-150700.3.28.1 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated - ruby2.5-rubygem-bundler-2.2.34-150700.21.3.1 removed From sle-container-updates at lists.suse.com Sun Sep 6 11:14:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 13:14:02 +0200 (CEST) Subject: SUSE-CU-2026:9553-1: Recommended update of suse/rmt-server Message-ID: <20260906111402.60516FDD4@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9553-1 Container Tags : suse/rmt-server:3 , suse/rmt-server:3.1 , suse/rmt-server:3.1-71.3 , suse/rmt-server:latest Container Release : 71.3 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:27:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:27:54 +0200 (CEST) Subject: SUSE-CU-2026:9553-1: Recommended update of suse/rmt-server Message-ID: <20260906122754.78982FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9553-1 Container Tags : suse/rmt-server:3 , suse/rmt-server:3.1 , suse/rmt-server:3.1-71.3 , suse/rmt-server:latest Container Release : 71.3 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:29:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:29:11 +0200 (CEST) Subject: SUSE-CU-2026:9554-1: Security update of bci/ruby Message-ID: <20260906122911.4B885FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9554-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-27.1 , bci/ruby:2.5-sles15 Container Release : 27.1 Severity : important Type : security References : 1208574 1238591 1239625 1239637 1244554 1244555 1244557 1244590 1244700 1246296 1247850 1247858 1250553 1250553 1250553 1251979 1256804 1256805 1256807 1256808 1256809 1256810 1256811 1256812 1257593 1257594 1257595 1269790 CVE-2021-30560 CVE-2023-40403 CVE-2024-55549 CVE-2025-10911 CVE-2025-10911 CVE-2025-10911 CVE-2025-11731 CVE-2025-24855 CVE-2025-49794 CVE-2025-49795 CVE-2025-49796 CVE-2025-6021 CVE-2025-6170 CVE-2025-7425 CVE-2025-8732 CVE-2026-0989 CVE-2026-0990 CVE-2026-0992 CVE-2026-11979 CVE-2026-1757 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:557-1 Released: Tue Feb 28 09:29:15 2023 Summary: Security update for libxslt Type: security Severity: important References: 1208574,CVE-2021-30560 This update for libxslt fixes the following issues: - CVE-2021-30560: Fixing a use after free vulnerability in Blink XSLT (bsc#1208574). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:1125-1 Released: Thu Apr 3 13:49:28 2025 Summary: Security update for libxslt Type: security Severity: important References: 1238591,1239625,1239637,CVE-2023-40403,CVE-2024-55549,CVE-2025-24855 This update for libxslt fixes the following issues: - CVE-2023-40403: Fixed sensitive information disclosure during processing web content (bsc#1238591) - CVE-2024-55549: Fixed use-after-free in xsltGetInheritedNsList (bsc#1239637) - CVE-2025-24855: Fixed use-after-free in numbers.c (bsc#1239625) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2260-1 Released: Wed Jul 9 19:04:24 2025 Summary: Security update for libxml2 Type: security Severity: important References: 1244554,1244555,1244557,1244590,1244700,CVE-2025-49794,CVE-2025-49795,CVE-2025-49796,CVE-2025-6021,CVE-2025-6170 This update for libxml2 fixes the following issues: - CVE-2025-49794: Fixed a heap use after free which could lead to denial of service. (bsc#1244554) - CVE-2025-49796: Fixed type confusion which could lead to denial of service. (bsc#1244557) - CVE-2025-49795: Fixed a null pointer dereference which could lead to denial of service. (bsc#1244555) - CVE-2025-6170: Fixed a stack buffer overflow which could lead to a crash. (bsc#1244700) - CVE-2025-6021: Fixed an integer overflow in xmlBuildQName() which could lead to stack buffer overflow. (bsc#1244590) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2617-1 Released: Mon Aug 4 09:04:59 2025 Summary: Security update for libxml2 Type: security Severity: important References: 1246296,CVE-2025-7425 This update for libxml2 fixes the following issues: - CVE-2025-7425: Fixed heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr (bsc#1246296) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3875-1 Released: Thu Oct 30 16:26:57 2025 Summary: Security update for libxslt Type: security Severity: important References: 1250553,1251979,CVE-2025-10911,CVE-2025-11731 This update for libxslt fixes the following issues: - CVE-2025-11731: fixed a type confusion in exsltFuncResultComp function leading to denial of service (bsc#1251979) - CVE-2025-10911: last fix caused a regression, patch was temporary disabled (bsc#1250553) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:605-1 Released: Tue Feb 24 12:19:11 2026 Summary: Security update for libxml2 Type: security Severity: moderate References: 1247850,1247858,1250553,1256804,1256805,1256807,1256808,1256809,1256810,1256811,1256812,1257593,1257594,1257595,CVE-2025-10911,CVE-2025-8732,CVE-2026-0989,CVE-2026-0990,CVE-2026-0992,CVE-2026-1757 This update for libxml2 fixes the following issues: - CVE-2026-0990: Fixed a call stack overflow leading to application crash due to infinite recursion in `xmlCatalogXMLResolveURI`. (bsc#1256807, bsc#1256811) - CVE-2026-0992: Fixed an excessive resource consumption when processing XML catalogs due to exponential behavior. (bsc#1256809, bsc#1256812) - CVE-2026-1757: Fixed a memory leak in the `xmllint` interactive shell. (bsc#1257594, bsc#1257595) - CVE-2025-10911: Fixed a use-after-free with key data stored cross-RVT. (bsc#1250553) - CVE-2025-8732: Fixed an infinite recursion in catalog parsing functions when processing malformed SGML catalog files. (bsc#1247858) - CVE-2026-0989: Fixe a call stack exhaustion leading to application crash due to RelaxNG parser not limiting the recursion depth. (bsc#1256805, bsc#1256810) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:801-1 Released: Wed Mar 4 13:33:26 2026 Summary: Security update for libxslt Type: security Severity: moderate References: 1250553,CVE-2025-10911 This update for libxslt fixes the following issues: - CVE-2025-10911: use-after-free will be fixed on libxml2 side instead (bsc#1250553). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). The following package changes have been done: - libxml2-2-2.12.10-150700.4.14.1 added - libxslt1-1.1.34-150400.3.16.1 added From sle-container-updates at lists.suse.com Sun Sep 6 12:29:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:29:12 +0200 (CEST) Subject: SUSE-CU-2026:9555-1: Security update of bci/ruby Message-ID: <20260906122912.7FFE6FDCF@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9555-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-27.4 , bci/ruby:2.5-sles15 Container Release : 27.4 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259542 1259652 1261678 1266344 1266347 1275902 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:30:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:30:59 +0200 (CEST) Subject: SUSE-CU-2026:9556-1: Security update of bci/ruby Message-ID: <20260906123059.79C7CFCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9556-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-26.1 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 26.1 Severity : important Type : security References : 1208574 1238591 1239625 1239637 1244554 1244555 1244557 1244590 1244700 1246296 1247850 1247858 1250553 1250553 1250553 1251979 1256804 1256805 1256807 1256808 1256809 1256810 1256811 1256812 1257593 1257594 1257595 1269790 CVE-2021-30560 CVE-2023-40403 CVE-2024-55549 CVE-2025-10911 CVE-2025-10911 CVE-2025-10911 CVE-2025-11731 CVE-2025-24855 CVE-2025-49794 CVE-2025-49795 CVE-2025-49796 CVE-2025-6021 CVE-2025-6170 CVE-2025-7425 CVE-2025-8732 CVE-2026-0989 CVE-2026-0990 CVE-2026-0992 CVE-2026-11979 CVE-2026-1757 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:557-1 Released: Tue Feb 28 09:29:15 2023 Summary: Security update for libxslt Type: security Severity: important References: 1208574,CVE-2021-30560 This update for libxslt fixes the following issues: - CVE-2021-30560: Fixing a use after free vulnerability in Blink XSLT (bsc#1208574). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:1125-1 Released: Thu Apr 3 13:49:28 2025 Summary: Security update for libxslt Type: security Severity: important References: 1238591,1239625,1239637,CVE-2023-40403,CVE-2024-55549,CVE-2025-24855 This update for libxslt fixes the following issues: - CVE-2023-40403: Fixed sensitive information disclosure during processing web content (bsc#1238591) - CVE-2024-55549: Fixed use-after-free in xsltGetInheritedNsList (bsc#1239637) - CVE-2025-24855: Fixed use-after-free in numbers.c (bsc#1239625) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2260-1 Released: Wed Jul 9 19:04:24 2025 Summary: Security update for libxml2 Type: security Severity: important References: 1244554,1244555,1244557,1244590,1244700,CVE-2025-49794,CVE-2025-49795,CVE-2025-49796,CVE-2025-6021,CVE-2025-6170 This update for libxml2 fixes the following issues: - CVE-2025-49794: Fixed a heap use after free which could lead to denial of service. (bsc#1244554) - CVE-2025-49796: Fixed type confusion which could lead to denial of service. (bsc#1244557) - CVE-2025-49795: Fixed a null pointer dereference which could lead to denial of service. (bsc#1244555) - CVE-2025-6170: Fixed a stack buffer overflow which could lead to a crash. (bsc#1244700) - CVE-2025-6021: Fixed an integer overflow in xmlBuildQName() which could lead to stack buffer overflow. (bsc#1244590) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2617-1 Released: Mon Aug 4 09:04:59 2025 Summary: Security update for libxml2 Type: security Severity: important References: 1246296,CVE-2025-7425 This update for libxml2 fixes the following issues: - CVE-2025-7425: Fixed heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr (bsc#1246296) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3875-1 Released: Thu Oct 30 16:26:57 2025 Summary: Security update for libxslt Type: security Severity: important References: 1250553,1251979,CVE-2025-10911,CVE-2025-11731 This update for libxslt fixes the following issues: - CVE-2025-11731: fixed a type confusion in exsltFuncResultComp function leading to denial of service (bsc#1251979) - CVE-2025-10911: last fix caused a regression, patch was temporary disabled (bsc#1250553) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:605-1 Released: Tue Feb 24 12:19:11 2026 Summary: Security update for libxml2 Type: security Severity: moderate References: 1247850,1247858,1250553,1256804,1256805,1256807,1256808,1256809,1256810,1256811,1256812,1257593,1257594,1257595,CVE-2025-10911,CVE-2025-8732,CVE-2026-0989,CVE-2026-0990,CVE-2026-0992,CVE-2026-1757 This update for libxml2 fixes the following issues: - CVE-2026-0990: Fixed a call stack overflow leading to application crash due to infinite recursion in `xmlCatalogXMLResolveURI`. (bsc#1256807, bsc#1256811) - CVE-2026-0992: Fixed an excessive resource consumption when processing XML catalogs due to exponential behavior. (bsc#1256809, bsc#1256812) - CVE-2026-1757: Fixed a memory leak in the `xmllint` interactive shell. (bsc#1257594, bsc#1257595) - CVE-2025-10911: Fixed a use-after-free with key data stored cross-RVT. (bsc#1250553) - CVE-2025-8732: Fixed an infinite recursion in catalog parsing functions when processing malformed SGML catalog files. (bsc#1247858) - CVE-2026-0989: Fixe a call stack exhaustion leading to application crash due to RelaxNG parser not limiting the recursion depth. (bsc#1256805, bsc#1256810) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:801-1 Released: Wed Mar 4 13:33:26 2026 Summary: Security update for libxslt Type: security Severity: moderate References: 1250553,CVE-2025-10911 This update for libxslt fixes the following issues: - CVE-2025-10911: use-after-free will be fixed on libxml2 side instead (bsc#1250553). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). The following package changes have been done: - libxml2-2-2.12.10-150700.4.14.1 added - libxslt1-1.1.34-150400.3.16.1 added From sle-container-updates at lists.suse.com Sun Sep 6 12:31:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:31:01 +0200 (CEST) Subject: SUSE-CU-2026:9557-1: Security update of bci/ruby Message-ID: <20260906123101.27ED7FDCF@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9557-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-26.4 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 26.4 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259542 1259652 1261678 1266344 1266347 1275902 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:32:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:32:18 +0200 (CEST) Subject: SUSE-CU-2026:9558-1: Security update of bci/rust Message-ID: <20260906123218.04314FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9558-1 Container Tags : bci/rust:1.96 , bci/rust:1.96-sles15 , bci/rust:1.96.1 , bci/rust:1.96.1-2.2.16 , bci/rust:oldstable Container Release : 2.16 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:33:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:33:31 +0200 (CEST) Subject: SUSE-CU-2026:9559-1: Security update of bci/rust Message-ID: <20260906123331.06100FCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9559-1 Container Tags : bci/rust:1.97 , bci/rust:1.97-sles15 , bci/rust:1.97.1 , bci/rust:1.97.1-1.2.16 , bci/rust:latest , bci/rust:stable Container Release : 2.16 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:34:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:34:27 +0200 (CEST) Subject: SUSE-CU-2026:9560-1: Security update of suse/samba-client Message-ID: <20260906123427.B3AF4FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9560-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-75.14 , suse/samba-client:latest Container Release : 75.14 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:34:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:34:28 +0200 (CEST) Subject: SUSE-CU-2026:9561-1: Recommended update of suse/samba-client Message-ID: <20260906123428.D44D6FDCF@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9561-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-75.15 , suse/samba-client:latest Container Release : 75.15 Severity : important Type : recommended References : 1242233 1243830 1277267 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:35:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:35:27 +0200 (CEST) Subject: SUSE-CU-2026:9562-1: Security update of suse/samba-server Message-ID: <20260906123527.7F141FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9562-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-76.14 , suse/samba-server:latest Container Release : 76.14 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:35:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:35:28 +0200 (CEST) Subject: SUSE-CU-2026:9563-1: Recommended update of suse/samba-server Message-ID: <20260906123528.AF2ADFDCF@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9563-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-76.16 , suse/samba-server:latest Container Release : 76.16 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:36:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:36:28 +0200 (CEST) Subject: SUSE-CU-2026:9564-1: Security update of suse/samba-toolbox Message-ID: <20260906123628.24E93FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9564-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-76.14 , suse/samba-toolbox:latest Container Release : 76.14 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:36:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:36:29 +0200 (CEST) Subject: SUSE-CU-2026:9565-1: Recommended update of suse/samba-toolbox Message-ID: <20260906123629.4DFF4FDCF@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9565-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-76.15 , suse/samba-toolbox:latest Container Release : 76.15 Severity : important Type : recommended References : 1242233 1243830 1277267 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:37:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:37:56 +0200 (CEST) Subject: SUSE-CU-2026:9566-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260906123756.E621EFCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9566-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-61.1 , bci/bci-sle15-kernel-module-devel:latest Container Release : 61.1 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259542 1259652 1261678 1266344 1266347 1275902 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:38:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:38:51 +0200 (CEST) Subject: SUSE-CU-2026:9567-1: Security update of suse/sle15 Message-ID: <20260906123851.1026FFCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9567-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.23.23 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.23.23 , suse/sle15:latest Container Release : 5.23.23 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259542 1259652 1261678 1266344 1266347 1275902 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libsubid5-4.17.2-150600.17.24.1 updated - login_defs-4.17.2-150600.17.24.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - openssl-3.5.0-150700.3.4.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:40:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:40:27 +0200 (CEST) Subject: SUSE-CU-2026:9568-1: Security update of bci/spack Message-ID: <20260906124027.1296EFCEE@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9568-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.46 , bci/spack:latest Container Release : 25.46 Severity : important Type : security References : 1216950 1236136 1236599 1242233 1243014 1243459 1243564 1243830 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259542 1259652 1261678 1266344 1266347 1275902 1277267 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libopenssl3-3.5.0-150700.5.45.2 updated - libopenssl-3-fips-provider-3.5.0-150700.5.45.2 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - libopenssl-3-devel-3.5.0-150700.5.45.2 updated - libopenssl-devel-3.5.0-150700.3.4.1 updated - container:registry.suse.com-bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:40:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:40:33 +0200 (CEST) Subject: SUSE-CU-2026:9569-1: Security update of suse/kiosk/tigervnc-x11vnc Message-ID: <20260906124033.73674FDCF@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/tigervnc-x11vnc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9569-1 Container Tags : suse/kiosk/tigervnc-x11vnc:1 , suse/kiosk/tigervnc-x11vnc:1.14 , suse/kiosk/tigervnc-x11vnc:1.14-63.19 , suse/kiosk/tigervnc-x11vnc:latest Container Release : 63.19 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/kiosk/tigervnc-x11vnc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - openssl-3.5.0-150700.3.4.1 updated - openssl-3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:40:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:40:35 +0200 (CEST) Subject: SUSE-CU-2026:9570-1: Recommended update of suse/kiosk/tigervnc-x11vnc Message-ID: <20260906124035.6E9DEFEC9@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/tigervnc-x11vnc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9570-1 Container Tags : suse/kiosk/tigervnc-x11vnc:1 , suse/kiosk/tigervnc-x11vnc:1.14 , suse/kiosk/tigervnc-x11vnc:1.14-63.21 , suse/kiosk/tigervnc-x11vnc:latest Container Release : 63.21 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/kiosk/tigervnc-x11vnc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:41:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:41:42 +0200 (CEST) Subject: SUSE-CU-2026:9571-1: Security update of suse/kiosk/xorg-client Message-ID: <20260906124142.AF0BEF771@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9571-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-79.15 , suse/kiosk/xorg-client:latest Container Release : 79.15 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:41:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:41:43 +0200 (CEST) Subject: SUSE-CU-2026:9572-1: Recommended update of suse/kiosk/xorg-client Message-ID: <20260906124143.C0901FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9572-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-79.17 , suse/kiosk/xorg-client:latest Container Release : 79.17 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Sun Sep 6 12:41:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 6 Sep 2026 14:41:45 +0200 (CEST) Subject: SUSE-CU-2026:9573-1: Security update of suse/kiosk/xorg-client Message-ID: <20260906124145.197D9FDD4@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9573-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-80.1 , suse/kiosk/xorg-client:latest Container Release : 80.1 Severity : critical Type : security References : 1029961 1081723 1081723 1096405 1096406 1096407 1096408 1097410 1105435 1106873 1114407 1115750 1118118 1119069 1119105 1119687 1124223 1125410 1126377 1130325 1130326 1131060 1131686 1141322 1141322 1146358 1146359 1150137 1157818 1158527 1158812 1158958 1158959 1158960 1159491 1159715 1159819 1159819 1159847 1159850 1160309 1160438 1160439 1164719 1168422 1169746 1170671 1171978 1172091 1172115 1172234 1172236 1172240 1172879 1173641 1174230 1174697 1175960 1176206 1176384 1176756 1176899 1176934 1177977 1179382 1180520 1183942 1184161 1185116 1185116 1188891 1189517 1189802 1191467 1191525 1191546 1191546 1191546 1191546 1192079 1192079 1192080 1192080 1192086 1192086 1192087 1192087 1192228 1192228 1195115 1195391 1195773 1196147 1196148 1196150 1198146 1198486 1198486 1198932 1198980 1198980 1198980 1199474 1200027 1200027 1200321 1201234 1201298 1201298 1201298 1201298 1201511 1201783 1202118 1202118 1202645 1202870 1202870 1203446 1204272 1204690 1204729 1204729 1206337 1207038 1207209 1208056 1208138 1208242 1208999 1210660 1211643 1212230 1212607 1214254 1214980 1214980 1215204 1216198 1216594 1216598 1217119 1218640 1219213 1219276 1219391 1221052 1222804 1222807 1222811 1222813 1222814 1222821 1222822 1222826 1222828 1222830 1222833 1222834 1222834 1223179 1223724 1223903 1224044 1224113 1224113 1224113 1224113 1224115 1224116 1224118 1225365 1226192 1226227 1226586 1226724 1226731 1226733 1227642 1227669 1227670 1227671 1227918 1228120 1228120 1228322 1228924 1230166 1230932 1231463 1231463 1233282 1233420 1233421 1234225 1236834 1236878 1236974 1237236 1237240 1237241 1237242 1237374 1237374 1240897 1241020 1241078 1241189 1241701 1242844 1243503 1243867 1244057 1244057 1244554 1244555 1244557 1244590 1244596 1244700 1245034 1245227 1246114 1246232 1246233 1246267 1246296 1246299 1246533 1246597 1247106 1247108 1247503 1247581 1247582 1247589 1247850 1247858 1247985 1248117 1248278 1248330 1248586 1249049 1249055 1249128 1250413 1250553 1250750 1251263 1253783 1254132 1254297 1254353 1254353 1254662 1254670 1254670 1254878 1255451 1256341 1256459 1256498 1256499 1256500 1256804 1256805 1256807 1256808 1256809 1256810 1256811 1256812 1257049 1257235 1257353 1257354 1257355 1257593 1257594 1257595 1257922 1257960 1258083 1258568 1259619 1260411 1261210 1261546 1261568 1261569 1261570 1261571 1261572 1261742 1261743 1261998 1263704 1263705 1263707 1263708 1263709 1263710 1263711 1263712 1263713 1263714 1263715 1263716 1267733 1268012 1268013 1268434 1268853 1269779 1269790 1270008 1270009 1270010 1270016 1270018 1270021 928700 928701 CVE-2015-3414 CVE-2015-3415 CVE-2018-0495 CVE-2018-1000654 CVE-2018-12384 CVE-2018-12404 CVE-2018-12405 CVE-2018-17466 CVE-2018-18492 CVE-2018-18493 CVE-2018-18494 CVE-2018-18498 CVE-2018-18508 CVE-2018-20346 CVE-2018-4180 CVE-2018-4181 CVE-2018-4182 CVE-2018-4183 CVE-2018-4700 CVE-2019-11745 CVE-2019-16168 CVE-2019-17006 CVE-2019-17006 CVE-2019-19244 CVE-2019-19317 CVE-2019-19603 CVE-2019-19645 CVE-2019-19646 CVE-2019-19880 CVE-2019-19923 CVE-2019-19924 CVE-2019-19925 CVE-2019-19926 CVE-2019-19959 CVE-2019-20218 CVE-2019-3880 CVE-2019-8675 CVE-2019-8696 CVE-2019-8842 CVE-2019-9936 CVE-2019-9937 CVE-2020-10001 CVE-2020-12399 CVE-2020-12400 CVE-2020-12401 CVE-2020-12403 CVE-2020-13434 CVE-2020-13435 CVE-2020-13630 CVE-2020-13631 CVE-2020-13632 CVE-2020-15358 CVE-2020-15673 CVE-2020-15676 CVE-2020-15677 CVE-2020-15678 CVE-2020-15683 CVE-2020-15969 CVE-2020-25648 CVE-2020-3898 CVE-2020-6829 CVE-2020-9327 CVE-2021-23981 CVE-2021-23982 CVE-2021-23984 CVE-2021-23987 CVE-2021-25317 CVE-2021-36690 CVE-2021-42523 CVE-2021-46848 CVE-2022-1210 CVE-2022-23491 CVE-2022-25308 CVE-2022-25309 CVE-2022-25310 CVE-2022-26691 CVE-2022-31741 CVE-2022-31741 CVE-2022-3479 CVE-2022-35737 CVE-2022-46908 CVE-2022-48622 CVE-2023-0767 CVE-2023-2137 CVE-2023-25435 CVE-2023-32324 CVE-2023-32360 CVE-2023-34241 CVE-2023-38469 CVE-2023-38471 CVE-2023-4504 CVE-2023-52356 CVE-2023-5388 CVE-2023-5388 CVE-2024-12133 CVE-2024-12224 CVE-2024-12243 CVE-2024-13978 CVE-2024-34397 CVE-2024-35235 CVE-2024-47175 CVE-2024-52533 CVE-2024-52615 CVE-2024-52616 CVE-2024-6655 CVE-2024-6655 CVE-2024-7006 CVE-2025-10911 CVE-2025-13151 CVE-2025-1352 CVE-2025-13601 CVE-2025-1372 CVE-2025-1376 CVE-2025-1377 CVE-2025-14087 CVE-2025-14512 CVE-2025-14831 CVE-2025-29087 CVE-2025-29088 CVE-2025-3277 CVE-2025-32988 CVE-2025-32989 CVE-2025-32990 CVE-2025-3360 CVE-2025-4373 CVE-2025-49794 CVE-2025-49795 CVE-2025-49796 CVE-2025-50422 CVE-2025-58060 CVE-2025-58364 CVE-2025-58436 CVE-2025-58436 CVE-2025-58436 CVE-2025-59529 CVE-2025-6021 CVE-2025-6052 CVE-2025-6170 CVE-2025-61915 CVE-2025-6199 CVE-2025-6395 CVE-2025-68276 CVE-2025-68468 CVE-2025-68471 CVE-2025-6965 CVE-2025-7039 CVE-2025-70873 CVE-2025-7345 CVE-2025-7425 CVE-2025-7709 CVE-2025-7709 CVE-2025-8176 CVE-2025-8177 CVE-2025-8534 CVE-2025-8732 CVE-2025-8851 CVE-2025-8961 CVE-2025-9165 CVE-2025-9187 CVE-2025-9820 CVE-2025-9900 CVE-2026-0988 CVE-2026-0989 CVE-2026-0990 CVE-2026-0992 CVE-2026-11822 CVE-2026-11824 CVE-2026-11979 CVE-2026-12912 CVE-2026-1484 CVE-2026-1485 CVE-2026-1489 CVE-2026-1757 CVE-2026-22693 CVE-2026-24401 CVE-2026-25727 CVE-2026-27447 CVE-2026-2781 CVE-2026-33845 CVE-2026-33846 CVE-2026-34933 CVE-2026-34978 CVE-2026-34979 CVE-2026-34980 CVE-2026-34990 CVE-2026-36849 CVE-2026-3833 CVE-2026-39314 CVE-2026-39316 CVE-2026-40393 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015 CVE-2026-4775 CVE-2026-4775 CVE-2026-50593 CVE-2026-5201 CVE-2026-5260 CVE-2026-5419 CVE-2026-56109 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2018:1476-1 Released: Thu Aug 2 14:20:03 2018 Summary: Security update for cups Type: security Severity: moderate References: 1096405,1096406,1096407,1096408,CVE-2018-4180,CVE-2018-4181,CVE-2018-4182,CVE-2018-4183 This update for cups fixes the following issues: The following security vulnerabilities were fixed: - Fixed a local privilege escalation to root and sandbox bypasses in the scheduler - CVE-2018-4180: Fixed a local privilege escalation to root in dnssd backend (bsc#1096405) - CVE-2018-4181: Limited local file reads as root via cupsd.conf include directive (bsc#1096406) - CVE-2018-4182: Fixed a sandbox bypass due to insecure error handling (bsc#1096407) - CVE-2018-4183: Fixed a sandbox bypass due to profile misconfiguration (bsc#1096408) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2018:2882-1 Released: Mon Dec 10 08:07:44 2018 Summary: Security update for cups Type: security Severity: important References: 1115750,CVE-2018-4700 This update for cups fixes the following issues: Security issue fixed: - CVE-2018-4700: Fixed extremely predictable cookie generation that is effectively breaking the CSRF protection of the CUPS web interface (bsc#1115750). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2018:3044-1 Released: Fri Dec 21 18:47:21 2018 Summary: Security update for MozillaFirefox, mozilla-nspr and mozilla-nss Type: security Severity: important References: 1097410,1106873,1119069,1119105,CVE-2018-0495,CVE-2018-12384,CVE-2018-12404,CVE-2018-12405,CVE-2018-17466,CVE-2018-18492,CVE-2018-18493,CVE-2018-18494,CVE-2018-18498 This update for MozillaFirefox, mozilla-nss and mozilla-nspr fixes the following issues: Issues fixed in MozillaFirefox: - Update to Firefox ESR 60.4 (bsc#1119105) - CVE-2018-17466: Fixed a buffer overflow and out-of-bounds read in ANGLE library with TextureStorage11 - CVE-2018-18492: Fixed a use-after-free with select element - CVE-2018-18493: Fixed a buffer overflow in accelerated 2D canvas with Skia - CVE-2018-18494: Fixed a Same-origin policy violation using location attribute and performance.getEntries to steal cross-origin URLs - CVE-2018-18498: Fixed a integer overflow when calculating buffer sizes for images - CVE-2018-12405: Fixed a few memory safety bugs Issues fixed in mozilla-nss: - Update to NSS 3.40.1 (bsc#1119105) - CVE-2018-12404: Fixed a cache side-channel variant of the Bleichenbacher attack (bsc#1119069) - CVE-2018-12384: Fixed an issue in the SSL handshake. NSS responded to an SSLv2-compatible ClientHello with a ServerHello that had an all-zero random. (bsc#1106873) - CVE-2018-0495: Fixed a memory-cache side-channel attack with ECDSA signatures (bsc#1097410) - Fixed a decryption failure during FFDHE key exchange - Various security fixes in the ASN.1 code Issues fixed in mozilla-nspr: - Update mozilla-nspr to 4.20 (bsc#1119105) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2019:608-1 Released: Wed Mar 13 15:21:02 2019 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1118118 This update for cups fixes the following issues: - Fixed validation of UTF-8 filenames to avoid crashes (bsc#1118118) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:788-1 Released: Thu Mar 28 11:55:06 2019 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1119687,CVE-2018-20346 This update for sqlite3 to version 3.27.2 fixes the following issue: Security issue fixed: - CVE-2018-20346: Fixed a remote code execution vulnerability in FTS3 (Magellan) (bsc#1119687). Release notes: https://www.sqlite.org/releaselog/3_27_2.html ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:1040-1 Released: Thu Apr 25 17:09:21 2019 Summary: Security update for samba Type: security Severity: important References: 1114407,1124223,1125410,1126377,1131060,1131686,CVE-2019-3880 This update for samba fixes the following issues: Security issue fixed: - CVE-2019-3880: Fixed a path/symlink traversal vulnerability, which allowed an unprivileged user to save registry files outside a share (bsc#1131060). ldb was updated to version 1.2.4 (bsc#1125410 bsc#1131686): - Out of bound read in ldb_wildcard_compare - Hold at most 10 outstanding paged result cookies - Put 'results_store' into a doubly linked list - Refuse to build Samba against a newer minor version of ldb Non-security issues fixed: - Fixed update-apparmor-samba-profile script after apparmor switched to using named profiles (bsc#1126377). - Abide to the load_printers parameter in smb.conf (bsc#1124223). - Provide the 32bit samba winbind PAM module and its dependend 32bit libraries. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:1127-1 Released: Thu May 2 09:39:24 2019 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1130325,1130326,CVE-2019-9936,CVE-2019-9937 This update for sqlite3 to version 3.28.0 fixes the following issues: Security issues fixed: - CVE-2019-9936: Fixed a heap-based buffer over-read, when running fts5 prefix queries inside transaction (bsc#1130326). - CVE-2019-9937: Fixed a denial of service related to interleaving reads and writes in a single transaction with an fts5 virtual table (bsc#1130325). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:1372-1 Released: Tue May 28 16:53:28 2019 Summary: Security update for libtasn1 Type: security Severity: moderate References: 1105435,CVE-2018-1000654 This update for libtasn1 fixes the following issues: Security issue fixed: - CVE-2018-1000654: Fixed a denial of service in the asn1 parser (bsc#1105435). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2019:2142-1 Released: Wed Aug 14 18:14:04 2019 Summary: Recommended update for mozilla-nspr, mozilla-nss Type: recommended Severity: moderate References: 1141322 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nss was updated to NSS 3.45 (bsc#1141322) : * New function in pk11pub.h: PK11_FindRawCertsWithSubject * The following CA certificates were Removed: CN = Certinomis - Root CA (bmo#1552374) * Implement Delegated Credentials (draft-ietf-tls-subcerts) (bmo#1540403) This adds a new experimental function SSL_DelegateCredential Note: In 3.45, selfserv does not yet support delegated credentials (See bmo#1548360). Note: In 3.45 the SSLChannelInfo is left unmodified, while an upcoming change in 3.46 will set SSLChannelInfo.authKeyBits to that of the delegated credential for better policy enforcement (See bmo#1563078). * Replace ARM32 Curve25519 implementation with one from fiat-crypto (bmo#1550579) * Expose a function PK11_FindRawCertsWithSubject for finding certificates with a given subject on a given slot (bmo#1552262) * Add IPSEC IKE support to softoken (bmo#1546229) * Add support for the Elbrus lcc compiler (<=1.23) (bmo#1554616) * Expose an external clock for SSL (bmo#1543874) This adds new experimental functions: SSL_SetTimeFunc, SSL_CreateAntiReplayContext, SSL_SetAntiReplayContext, and SSL_ReleaseAntiReplayContext. The experimental function SSL_InitAntiReplay is removed. * Various changes in response to the ongoing FIPS review (bmo#1546477) Note: The source package size has increased substantially due to the new FIPS test vectors. This will likely prompt follow-on work, but please accept our apologies in the meantime. mozilla-nspr was updated to version 4.21 * Changed prbit.h to use builtin function on aarch64. * Removed Gonk/B2G references. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:2533-1 Released: Thu Oct 3 15:02:50 2019 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1150137,CVE-2019-16168 This update for sqlite3 fixes the following issues: Security issue fixed: - CVE-2019-16168: Fixed improper validation of sqlite_stat1 field that could lead to denial of service (bsc#1150137). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:3030-1 Released: Thu Nov 21 19:11:25 2019 Summary: Security update for cups Type: security Severity: important References: 1146358,1146359,CVE-2019-8675,CVE-2019-8696 This update for cups fixes the following issues: - CVE-2019-8675: Fixed a stack buffer overflow in libcups's asn1_get_type function(bsc#1146358). - CVE-2019-8696: Fixed a stack buffer overflow in libcups's asn1_get_packed function (bsc#1146359). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:3395-1 Released: Mon Dec 30 14:05:06 2019 Summary: Security update for mozilla-nspr, mozilla-nss Type: security Severity: moderate References: 1141322,1158527,1159819,CVE-2018-18508,CVE-2019-11745,CVE-2019-17006 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nss was updated to NSS 3.47.1: Security issues fixed: - CVE-2019-17006: Added length checks for cryptographic primitives (bsc#1159819). - CVE-2019-11745: EncryptUpdate should use maxout, not block size (bsc#1158527). - CVE-2019-11727: Fixed vulnerability sign CertificateVerify with PKCS#1 v1.5 signatures issue (bsc#1141322). mozilla-nspr was updated to version 4.23: - Whitespace in C files was cleaned up and no longer uses tab characters for indenting. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2020:1083-1 Released: Thu Apr 23 11:31:23 2020 Summary: Security update for cups Type: security Severity: important References: 1168422,CVE-2020-3898 This update for cups fixes the following issues: - CVE-2020-3898: Fixed a heap buffer overflow in ppdFindOption() (bsc#1168422). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2020:1677-1 Released: Thu Jun 18 18:16:39 2020 Summary: Security update for mozilla-nspr, mozilla-nss Type: security Severity: important References: 1159819,1169746,1171978,CVE-2019-17006,CVE-2020-12399 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nss was updated to version 3.53 - CVE-2020-12399: Fixed a timing attack on DSA signature generation (bsc#1171978). - CVE-2019-17006: Added length checks for cryptographic primitives (bsc#1159819). Release notes: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.53_release_notes mozilla-nspr to version 4.25 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2020:3091-1 Released: Thu Oct 29 16:35:37 2020 Summary: Security update for MozillaThunderbird and mozilla-nspr Type: security Severity: important References: 1174230,1176384,1176756,1176899,1177977,CVE-2020-15673,CVE-2020-15676,CVE-2020-15677,CVE-2020-15678,CVE-2020-15683,CVE-2020-15969 This update for MozillaThunderbird and mozilla-nspr fixes the following issues: - Mozilla Thunderbird 78.4 * new: MailExtensions: browser.tabs.sendMessage API added * new: MailExtensions: messageDisplayScripts API added * changed: Yahoo and AOL mail users using password authentication will be migrated to OAuth2 * changed: MailExtensions: messageDisplay APIs extended to support multiple selected messages * changed: MailExtensions: compose.begin functions now support creating a message with attachments * fixed: Thunderbird could freeze when updating global search index * fixed: Multiple issues with handling of self-signed SSL certificates addressed * fixed: Recipient address fields in compose window could expand to fill all available space * fixed: Inserting emoji characters in message compose window caused unexpected behavior * fixed: Button to restore default folder icon color was not keyboard accessible * fixed: Various keyboard navigation fixes * fixed: Various color-related theme fixes * fixed: MailExtensions: Updating attachments with onBeforeSend.addListener() did not work MFSA 2020-47 (bsc#1177977) * CVE-2020-15969 Use-after-free in usersctp * CVE-2020-15683 Memory safety bugs fixed in Thunderbird 78.4 - Mozilla Thunderbird 78.3.3 * OpenPGP: Improved support for encrypting with subkeys * OpenPGP message status icons were not visible in message header pane * Creating a new calendar event did not require an event title - Mozilla Thunderbird 78.3.2 (bsc#1176899) * OpenPGP: Improved support for encrypting with subkeys * OpenPGP: Encrypted messages with international characters were sometimes displayed incorrectly * Single-click deletion of recipient pills with middle mouse button restored * Searching an address book list did not display results * Dark mode, high contrast, and Windows theming fixes - Mozilla Thunderbird 78.3.1 * fix crash in nsImapProtocol::CreateNewLineFromSocket - Mozilla Thunderbird 78.3.0 MFSA 2020-44 (bsc#1176756) * CVE-2020-15677 Download origin spoofing via redirect * CVE-2020-15676 XSS when pasting attacker-controlled data into a contenteditable element * CVE-2020-15678 When recursing through layers while scrolling, an iterator may have become invalid, resulting in a potential use-after- free scenario * CVE-2020-15673 Memory safety bugs fixed in Thunderbird 78.3 - update mozilla-nspr to version 4.25.1 * The macOS platform code for shared library loading was changed to support macOS 11. * Dependency needed for the MozillaThunderbird udpate ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:285-1 Released: Tue Feb 2 13:08:54 2021 Summary: Security update for cups Type: security Severity: moderate References: 1170671,1180520,CVE-2019-8842,CVE-2020-10001 This update for cups fixes the following issues: - CVE-2020-10001: Fixed an out-of-bounds read in the ippReadIO function (bsc#1180520). - CVE-2019-8842: Fixed an out-of-bounds read in an extension field (bsc#1170671). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:1007-1 Released: Thu Apr 1 17:47:20 2021 Summary: Security update for MozillaFirefox Type: security Severity: important References: 1183942,CVE-2021-23981,CVE-2021-23982,CVE-2021-23984,CVE-2021-23987 This update for MozillaFirefox fixes the following issues: - Firefox was updated to 78.9.0 ESR (MFSA 2021-11, bsc#1183942) * CVE-2021-23981: Texture upload into an unbound backing buffer resulted in an out-of-bound read * CVE-2021-23982: Internal network hosts could have been probed by a malicious webpage * CVE-2021-23984: Malicious extensions could have spoofed popup information * CVE-2021-23987: Memory safety bugs ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:1021-1 Released: Tue Apr 6 14:30:30 2021 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1175960 This update for cups fixes the following issues: - Fixed the web UI kerberos authentication (bsc#1175960) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:1454-1 Released: Fri Apr 30 09:22:26 2021 Summary: Security update for cups Type: security Severity: important References: 1184161,CVE-2021-25317 This update for cups fixes the following issues: - CVE-2021-25317: ownership of /var/log/cups could allow privilege escalation from lp user to root via symlink attacks (bsc#1184161) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:2320-1 Released: Wed Jul 14 17:01:06 2021 Summary: Security update for sqlite3 Type: security Severity: important References: 1157818,1158812,1158958,1158959,1158960,1159491,1159715,1159847,1159850,1160309,1160438,1160439,1164719,1172091,1172115,1172234,1172236,1172240,1173641,928700,928701,CVE-2015-3414,CVE-2015-3415,CVE-2019-19244,CVE-2019-19317,CVE-2019-19603,CVE-2019-19645,CVE-2019-19646,CVE-2019-19880,CVE-2019-19923,CVE-2019-19924,CVE-2019-19925,CVE-2019-19926,CVE-2019-19959,CVE-2019-20218,CVE-2020-13434,CVE-2020-13435,CVE-2020-13630,CVE-2020-13631,CVE-2020-13632,CVE-2020-15358,CVE-2020-9327 This update for sqlite3 fixes the following issues: - Update to version 3.36.0 - CVE-2020-15358: heap-based buffer overflow in multiSelectOrderBy due to mishandling of query-flattener optimization (bsc#1173641) - CVE-2020-9327: NULL pointer dereference and segmentation fault because of generated column optimizations in isAuxiliaryVtabOperator (bsc#1164719) - CVE-2019-20218: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error (bsc#1160439) - CVE-2019-19959: memory-management error via ext/misc/zipfile.c involving embedded '\0' input (bsc#1160438) - CVE-2019-19923: improper handling of certain uses of SELECT DISTINCT in flattenSubquery may lead to null pointer dereference (bsc#1160309) - CVE-2019-19924: improper error handling in sqlite3WindowRewrite() (bsc#1159850) - CVE-2019-19925: improper handling of NULL pathname during an update of a ZIP archive (bsc#1159847) - CVE-2019-19926: improper handling of certain errors during parsing multiSelect in select.c (bsc#1159715) - CVE-2019-19880: exprListAppendList in window.c allows attackers to trigger an invalid pointer dereference (bsc#1159491) - CVE-2019-19603: during handling of CREATE TABLE and CREATE VIEW statements, does not consider confusion with a shadow table name (bsc#1158960) - CVE-2019-19646: pragma.c mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns (bsc#1158959) - CVE-2019-19645: alter.c allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements (bsc#1158958) - CVE-2019-19317: lookupName in resolve.c omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service (bsc#1158812) - CVE-2019-19244: sqlite3,sqlite2,sqlite: The function sqlite3Select in select.c allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage (bsc#1157818) - CVE-2015-3415: sqlite3VdbeExec comparison operator vulnerability (bsc#928701) - CVE-2015-3414: sqlite3,sqlite2: dequoting of collation-sequence names (bsc#928700) - CVE-2020-13434: integer overflow in sqlite3_str_vappendf (bsc#1172115) - CVE-2020-13630: (bsc#1172234: use-after-free in fts3EvalNextRow - CVE-2020-13631: virtual table allowed to be renamed to one of its shadow tables (bsc#1172236) - CVE-2020-13632: NULL pointer dereference via crafted matchinfo() query (bsc#1172240) - CVE-2020-13435: Malicious SQL statements could have crashed the process that is running SQLite (bsc#1172091) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:3115-1 Released: Thu Sep 16 14:04:26 2021 Summary: Recommended update for mozilla-nspr, mozilla-nss Type: recommended Severity: moderate References: 1029961,1174697,1176206,1176934,1179382,1188891,CVE-2020-12400,CVE-2020-12401,CVE-2020-12403,CVE-2020-25648,CVE-2020-6829 This update for mozilla-nspr fixes the following issues: mozilla-nspr was updated to version 4.32: * implement new socket option PR_SockOpt_DontFrag * support larger DNS records by increasing the default buffer size for DNS queries * Lock access to PRCallOnceType members in PR_CallOnce* for thread safety bmo#1686138 * PR_GetSystemInfo supports a new flag PR_SI_RELEASE_BUILD to get information about the operating system build version. Mozilla NSS was updated to version 3.68: * bmo#1713562 - Fix test leak. * bmo#1717452 - NSS 3.68 should depend on NSPR 4.32. * bmo#1693206 - Implement PKCS8 export of ECDSA keys. * bmo#1712883 - DTLS 1.3 draft-43. * bmo#1655493 - Support SHA2 HW acceleration using Intel SHA Extension. * bmo#1713562 - Validate ECH public names. * bmo#1717610 - Add function to get seconds from epoch from pkix::Time. update to NSS 3.67 * bmo#1683710 - Add a means to disable ALPN. * bmo#1715720 - Fix nssckbi version number in NSS 3.67 (was supposed to be incremented in 3.66). * bmo#1714719 - Set NSS_USE_64 on riscv64 target when using GYP/Ninja. * bmo#1566124 - Fix counter increase in ppc-gcm-wrap.c. * bmo#1566124 - Fix AES_GCM mode on ppc64le for messages of length more than 255-byte. update to NSS 3.66 * bmo#1710716 - Remove Expired Sonera Class2 CA from NSS. * bmo#1710716 - Remove Expired Root Certificates from NSS - QuoVadis Root Certification Authority. * bmo#1708307 - Remove Trustis FPS Root CA from NSS. * bmo#1707097 - Add Certum Trusted Root CA to NSS. * bmo#1707097 - Add Certum EC-384 CA to NSS. * bmo#1703942 - Add ANF Secure Server Root CA to NSS. * bmo#1697071 - Add GLOBALTRUST 2020 root cert to NSS. * bmo#1712184 - NSS tools manpages need to be updated to reflect that sqlite is the default database. * bmo#1712230 - Don't build ppc-gcm.s with clang integrated assembler. * bmo#1712211 - Strict prototype error when trying to compile nss code that includes blapi.h. * bmo#1710773 - NSS needs FIPS 180-3 FIPS indicators. * bmo#1709291 - Add VerifyCodeSigningCertificateChain. update to NSS 3.65 * bmo#1709654 - Update for NetBSD configuration. * bmo#1709750 - Disable HPKE test when fuzzing. * bmo#1566124 - Optimize AES-GCM for ppc64le. * bmo#1699021 - Add AES-256-GCM to HPKE. * bmo#1698419 - ECH -10 updates. * bmo#1692930 - Update HPKE to final version. * bmo#1707130 - NSS should use modern algorithms in PKCS#12 files by default. * bmo#1703936 - New coverity/cpp scanner errors. * bmo#1697303 - NSS needs to update it's csp clearing to FIPS 180-3 standards. * bmo#1702663 - Need to support RSA PSS with Hashing PKCS #11 Mechanisms. * bmo#1705119 - Deadlock when using GCM and non-thread safe tokens. update to NSS 3.64 * bmo#1705286 - Properly detect mips64. * bmo#1687164 - Introduce NSS_DISABLE_CRYPTO_VSX and disable_crypto_vsx. * bmo#1698320 - replace __builtin_cpu_supports('vsx') with ppc_crypto_support() for clang. * bmo#1613235 - Add POWER ChaCha20 stream cipher vector acceleration. Fixed in 3.63 * bmo#1697380 - Make a clang-format run on top of helpful contributions. * bmo#1683520 - ECCKiila P384, change syntax of nested structs initialization to prevent build isses with GCC 4.8. * bmo#1683520 - [lib/freebl/ecl] P-384: allow zero scalars in dual scalar multiplication. * bmo#1683520 - ECCKiila P521, change syntax of nested structs initialization to prevent build isses with GCC 4.8. * bmo#1683520 - [lib/freebl/ecl] P-521: allow zero scalars in dual scalar multiplication. * bmo#1696800 - HACL* update March 2021 - c95ab70fcb2bc21025d8845281bc4bc8987ca683. * bmo#1694214 - tstclnt can't enable middlebox compat mode. * bmo#1694392 - NSS does not work with PKCS #11 modules not supporting profiles. * bmo#1685880 - Minor fix to prevent unused variable on early return. * bmo#1685880 - Fix for the gcc compiler version 7 to support setenv with nss build. * bmo#1693217 - Increase nssckbi.h version number for March 2021 batch of root CA changes, CA list version 2.48. * bmo#1692094 - Set email distrust after to 21-03-01 for Camerfirma's 'Chambers of Commerce' and 'Global Chambersign' roots. * bmo#1618407 - Symantec root certs - Set CKA_NSS_EMAIL_DISTRUST_AFTER. * bmo#1693173 - Add GlobalSign R45, E45, R46, and E46 root certs to NSS. * bmo#1683738 - Add AC RAIZ FNMT-RCM SERVIDORES SEGUROS root cert to NSS. * bmo#1686854 - Remove GeoTrust PCA-G2 and VeriSign Universal root certs from NSS. * bmo#1687822 - Turn off Websites trust bit for the ???Staat der Nederlanden Root CA - G3??? root cert in NSS. * bmo#1692094 - Turn off Websites Trust Bit for 'Chambers of Commerce Root - 2008' and 'Global Chambersign Root - 2008???. * bmo#1694291 - Tracing fixes for ECH. update to NSS 3.62 * bmo#1688374 - Fix parallel build NSS-3.61 with make * bmo#1682044 - pkix_Build_GatherCerts() + pkix_CacheCert_Add() can corrupt 'cachedCertTable' * bmo#1690583 - Fix CH padding extension size calculation * bmo#1690421 - Adjust 3.62 ABI report formatting for new libabigail * bmo#1690421 - Install packaged libabigail in docker-builds image * bmo#1689228 - Minor ECH -09 fixes for interop testing, fuzzing * bmo#1674819 - Fixup a51fae403328, enum type may be signed * bmo#1681585 - Add ECH support to selfserv * bmo#1681585 - Update ECH to Draft-09 * bmo#1678398 - Add Export/Import functions for HPKE context * bmo#1678398 - Update HPKE to draft-07 update to NSS 3.61 * bmo#1682071 - Fix issue with IKE Quick mode deriving incorrect key values under certain conditions. * bmo#1684300 - Fix default PBE iteration count when NSS is compiled with NSS_DISABLE_DBM. * bmo#1651411 - Improve constant-timeness in RSA operations. * bmo#1677207 - Upgrade Google Test version to latest release. * bmo#1654332 - Add aarch64-make target to nss-try. Update to NSS 3.60.1: Notable changes in NSS 3.60: * TLS 1.3 Encrypted Client Hello (draft-ietf-tls-esni-08) support has been added, replacing the previous ESNI (draft-ietf-tls-esni-01) implementation. See bmo#1654332 for more information. * December 2020 batch of Root CA changes, builtins library updated to version 2.46. See bmo#1678189, bmo#1678166, and bmo#1670769 for more information. Update to NSS 3.59.1: * bmo#1679290 - Fix potential deadlock with certain third-party PKCS11 modules Update to NSS 3.59: Notable changes: * Exported two existing functions from libnss: CERT_AddCertToListHeadWithData and CERT_AddCertToListTailWithData Bugfixes * bmo#1607449 - Lock cert->nssCertificate to prevent a potential data race * bmo#1672823 - Add Wycheproof test cases for HMAC, HKDF, and DSA * bmo#1663661 - Guard against NULL token in nssSlot_IsTokenPresent * bmo#1670835 - Support enabling and disabling signatures via Crypto Policy * bmo#1672291 - Resolve libpkix OCSP failures on SHA1 self-signed root certs when SHA1 signatures are disabled. * bmo#1644209 - Fix broken SelectedCipherSuiteReplacer filter to solve some test intermittents * bmo#1672703 - Tolerate the first CCS in TLS 1.3 to fix a regression in our CVE-2020-25648 fix that broke purple-discord (boo#1179382) * bmo#1666891 - Support key wrap/unwrap with RSA-OAEP * bmo#1667989 - Fix gyp linking on Solaris * bmo#1668123 - Export CERT_AddCertToListHeadWithData and CERT_AddCertToListTailWithData from libnss * bmo#1634584 - Set CKA_NSS_SERVER_DISTRUST_AFTER for Trustis FPS Root CA * bmo#1663091 - Remove unnecessary assertions in the streaming ASN.1 decoder that affected decoding certain PKCS8 private keys when using NSS debug builds * bmo#670839 - Use ARM crypto extension for AES, SHA1 and SHA2 on MacOS. update to NSS 3.58 Bugs fixed: * bmo#1641480 (CVE-2020-25648) Tighten CCS handling for middlebox compatibility mode. * bmo#1631890 - Add support for Hybrid Public Key Encryption (draft-irtf-cfrg-hpke) support for TLS Encrypted Client Hello (draft-ietf-tls-esni). * bmo#1657255 - Add CI tests that disable SHA1/SHA2 ARM crypto extensions. * bmo#1668328 - Handle spaces in the Python path name when using gyp on Windows. * bmo#1667153 - Add PK11_ImportDataKey for data object import. * bmo#1665715 - Pass the embedded SCT list extension (if present) to TrustDomain::CheckRevocation instead of the notBefore value. update to NSS 3.57 * The following CA certificates were Added: bmo#1663049 - CN=Trustwave Global Certification Authority SHA-256 Fingerprint: 97552015F5DDFC3C8788C006944555408894450084F100867086BC1A2BB58DC8 bmo#1663049 - CN=Trustwave Global ECC P256 Certification Authority SHA-256 Fingerprint: 945BBC825EA554F489D1FD51A73DDF2EA624AC7019A05205225C22A78CCFA8B4 bmo#1663049 - CN=Trustwave Global ECC P384 Certification Authority SHA-256 Fingerprint: 55903859C8C0C3EBB8759ECE4E2557225FF5758BBD38EBD48276601E1BD58097 * The following CA certificates were Removed: bmo#1651211 - CN=EE Certification Centre Root CA SHA-256 Fingerprint: 3E84BA4342908516E77573C0992F0979CA084E4685681FF195CCBA8A229B8A76 bmo#1656077 - O=Government Root Certification Authority; C=TW SHA-256 Fingerprint: 7600295EEFE85B9E1FD624DB76062AAAAE59818A54D2774CD4C0B2C01131E1B3 * Trust settings for the following CA certificates were Modified: bmo#1653092 - CN=OISTE WISeKey Global Root GA CA Websites (server authentication) trust bit removed. * https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes update to NSS 3.56 Notable changes * bmo#1650702 - Support SHA-1 HW acceleration on ARMv8 * bmo#1656981 - Use MPI comba and mulq optimizations on x86-64 MacOS. * bmo#1654142 - Add CPU feature detection for Intel SHA extension. * bmo#1648822 - Add stricter validation of DH keys in FIPS mode. * bmo#1656986 - Properly detect arm64 during GYP build architecture detection. * bmo#1652729 - Add build flag to disable RC2 and relocate to lib/freebl/deprecated. * bmo#1656429 - Correct RTT estimate used in 0-RTT anti-replay. * bmo#1588941 - Send empty certificate message when scheme selection fails. * bmo#1652032 - Fix failure to build in Windows arm64 makefile cross-compilation. * bmo#1625791 - Fix deadlock issue in nssSlot_IsTokenPresent. * bmo#1653975 - Fix 3.53 regression by setting 'all' as the default makefile target. * bmo#1659792 - Fix broken libpkix tests with unexpired PayPal cert. * bmo#1659814 - Fix interop.sh failures with newer tls-interop commit and dependencies. * bmo#1656519 - NSPR dependency updated to 4.28 update to NSS 3.55 Notable changes * P384 and P521 elliptic curve implementations are replaced with verifiable implementations from Fiat-Crypto [0] and ECCKiila [1]. * PK11_FindCertInSlot is added. With this function, a given slot can be queried with a DER-Encoded certificate, providing performance and usability improvements over other mechanisms. (bmo#1649633) * DTLS 1.3 implementation is updated to draft-38. (bmo#1647752) Relevant Bugfixes * bmo#1631583 (CVE-2020-6829, CVE-2020-12400) - Replace P384 and P521 with new, verifiable implementations from Fiat-Crypto and ECCKiila. * bmo#1649487 - Move overzealous assertion in VFY_EndWithSignature. * bmo#1631573 (CVE-2020-12401) - Remove unnecessary scalar padding. * bmo#1636771 (CVE-2020-12403) - Explicitly disable multi-part ChaCha20 (which was not functioning correctly) and more strictly enforce tag length. * bmo#1649648 - Don't memcpy zero bytes (sanitizer fix). * bmo#1649316 - Don't memcpy zero bytes (sanitizer fix). * bmo#1649322 - Don't memcpy zero bytes (sanitizer fix). * bmo#1653202 - Fix initialization bug in blapitest when compiled with NSS_DISABLE_DEPRECATED_SEED. * bmo#1646594 - Fix AVX2 detection in makefile builds. * bmo#1649633 - Add PK11_FindCertInSlot to search a given slot for a DER-encoded certificate. * bmo#1651520 - Fix slotLock race in NSC_GetTokenInfo. * bmo#1647752 - Update DTLS 1.3 implementation to draft-38. * bmo#1649190 - Run cipher, sdr, and ocsp tests under standard test cycle in CI. * bmo#1649226 - Add Wycheproof ECDSA tests. * bmo#1637222 - Consistently enforce IV requirements for DES and 3DES. * bmo#1067214 - Enforce minimum PKCS#1 v1.5 padding length in RSA_CheckSignRecover. * bmo#1646324 - Advertise PKCS#1 schemes for certificates in the signature_algorithms extension. update to NSS 3.54 Notable changes * Support for TLS 1.3 external pre-shared keys (bmo#1603042). * Use ARM Cryptography Extension for SHA256, when available (bmo#1528113) * The following CA certificates were Added: bmo#1645186 - certSIGN Root CA G2. bmo#1645174 - e-Szigno Root CA 2017. bmo#1641716 - Microsoft ECC Root Certificate Authority 2017. bmo#1641716 - Microsoft RSA Root Certificate Authority 2017. * The following CA certificates were Removed: bmo#1645199 - AddTrust Class 1 CA Root. bmo#1645199 - AddTrust External CA Root. bmo#1641718 - LuxTrust Global Root 2. bmo#1639987 - Staat der Nederlanden Root CA - G2. bmo#1618402 - Symantec Class 2 Public Primary Certification Authority - G4. bmo#1618402 - Symantec Class 1 Public Primary Certification Authority - G4. bmo#1618402 - VeriSign Class 3 Public Primary Certification Authority - G3. * A number of certificates had their Email trust bit disabled. See bmo#1618402 for a complete list. Bugs fixed * bmo#1528113 - Use ARM Cryptography Extension for SHA256. * bmo#1603042 - Add TLS 1.3 external PSK support. * bmo#1642802 - Add uint128 support for HACL* curve25519 on Windows. * bmo#1645186 - Add 'certSIGN Root CA G2' root certificate. * bmo#1645174 - Add Microsec's 'e-Szigno Root CA 2017' root certificate. * bmo#1641716 - Add Microsoft's non-EV root certificates. * bmo1621151 - Disable email trust bit for 'O=Government Root Certification Authority; C=TW' root. * bmo#1645199 - Remove AddTrust root certificates. * bmo#1641718 - Remove 'LuxTrust Global Root 2' root certificate. * bmo#1639987 - Remove 'Staat der Nederlanden Root CA - G2' root certificate. * bmo#1618402 - Remove Symantec root certificates and disable email trust bit. * bmo#1640516 - NSS 3.54 should depend on NSPR 4.26. * bmo#1642146 - Fix undefined reference to `PORT_ZAlloc_stub' in seed.c. * bmo#1642153 - Fix infinite recursion building NSS. * bmo#1642638 - Fix fuzzing assertion crash. * bmo#1642871 - Enable SSL_SendSessionTicket after resumption. * bmo#1643123 - Support SSL_ExportEarlyKeyingMaterial with External PSKs. * bmo#1643557 - Fix numerous compile warnings in NSS. * bmo#1644774 - SSL gtests to use ClearServerCache when resetting self-encrypt keys. * bmo#1645479 - Don't use SECITEM_MakeItem in secutil.c. * bmo#1646520 - Stricter enforcement of ASN.1 INTEGER encoding. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:1659-1 Released: Fri May 13 15:41:32 2022 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1189517,1195115 This update for cups fixes the following issues: - CUPS printservice takes much longer than before with a big number of printers (bsc#1189517) - CUPS PreserveJobHistory doesn't work with seconds (bsc#1195115) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1861-1 Released: Thu May 26 12:07:40 2022 Summary: Security update for cups Type: security Severity: important References: 1199474,CVE-2022-26691 This update for cups fixes the following issues: - CVE-2022-26691: Fixed an authentication bypass and code execution vulnerability (bsc#1199474) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1898-1 Released: Tue May 31 18:03:55 2022 Summary: Security update for fribidi Type: security Severity: moderate References: 1196147,1196148,1196150,CVE-2022-25308,CVE-2022-25309,CVE-2022-25310 This update for fribidi fixes the following issues: - CVE-2022-25308: Fixed stack out of bounds read (bsc#1196147). - CVE-2022-25309: Fixed heap-buffer-overflow in fribidi_cap_rtl_to_unicode (bsc#1196148). - CVE-2022-25310: Fixed NULL pointer dereference in fribidi_remove_bidi_marks (bsc#1196150). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2533-1 Released: Fri Jul 22 17:37:15 2022 Summary: Security update for mozilla-nss Type: security Severity: important References: 1192079,1192080,1192086,1192087,1192228,1198486,1200027,CVE-2022-31741 This update for mozilla-nss fixes the following issues: Various FIPS 140-3 related fixes were backported from SUSE Linux Enterprise 15 SP4: - Makes the PBKDF known answer test compliant with NIST SP800-132. (bsc#1192079). - FIPS: Add on-demand integrity tests through sftk_FIPSRepeatIntegrityCheck() (bsc#1198980). - FIPS: mark algorithms as approved/non-approved according to security policy (bsc#1191546, bsc#1201298). - FIPS: remove hard disabling of unapproved algorithms. This requirement is now fulfilled by the service level indicator (bsc#1200325). - Run test suite at build time, and make it pass (bsc#1198486). - FIPS: skip algorithms that are hard disabled in FIPS mode. - Prevent expired PayPalEE cert from failing the tests. - Allow checksumming to be disabled, but only if we entered FIPS mode due to NSS_FIPS being set, not if it came from /proc. - FIPS: Make the PBKDF known answer test compliant with NIST SP800-132. - Update FIPS validation string to version-release format. - FIPS: remove XCBC MAC from list of FIPS approved algorithms. - Enable NSS_ENABLE_FIPS_INDICATORS and set NSS_FIPS_MODULE_ID for build. - FIPS: claim 3DES unapproved in FIPS mode (bsc#1192080). - FIPS: allow testing of unapproved algorithms (bsc#1192228). - FIPS: add version indicators. (bmo#1729550, bsc#1192086). - FIPS: fix some secret clearing (bmo#1697303, bsc#1192087). Version update to NSS 3.79: - Use PK11_GetSlotInfo instead of raw C_GetSlotInfo calls. - Update mercurial in clang-format docker image. - Use of uninitialized pointer in lg_init after alloc fail. - selfserv and tstclnt should use PR_GetPrefLoopbackAddrInfo. - Add SECMOD_LockedModuleHasRemovableSlots. - Fix secasn1d parsing of indefinite SEQUENCE inside indefinite GROUP. - Added RFC8422 compliant TLS <= 1.2 undefined/compressed ECPointFormat extension alerts. - TLS 1.3 Server: Send protocol_version alert on unsupported ClientHello.legacy_version. - Correct invalid record inner and outer content type alerts. - NSS does not properly import or export pkcs12 files with large passwords and pkcs5v2 encoding. - improve error handling after nssCKFWInstance_CreateObjectHandle. - Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple. - NSS 3.79 should depend on NSPR 4.34 Version update to NSS 3.78.1: - Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple Version update to NSS 3.78: - Added TLS 1.3 zero-length inner plaintext checks and tests, zero-length record/fragment handling tests. - Reworked overlong record size checks and added TLS1.3 specific boundaries. - Add ECH Grease Support to tstclnt - Add a strict variant of moz::pkix::CheckCertHostname. - Change SSL_REUSE_SERVER_ECDHE_KEY default to false. - Make SEC_PKCS12EnableCipher succeed - Update zlib in NSS to 1.2.12. Version update to NSS 3.77: - Fix link to TLS page on wireshark wiki - Add two D-TRUST 2020 root certificates. - Add Telia Root CA v2 root certificate. - Remove expired explicitly distrusted certificates from certdata.txt. - support specific RSA-PSS parameters in mozilla::pkix - Remove obsolete stateEnd check in SEC_ASN1DecoderUpdate. - Remove token member from NSSSlot struct. - Provide secure variants of mpp_pprime and mpp_make_prime. - Support UTF-8 library path in the module spec string. - Update nssUTF8_Length to RFC 3629 and fix buffer overrun. - Update googletest to 1.11.0 - Add SetTls13GreaseEchSize to experimental API. - TLS 1.3 Illegal legacy_version handling/alerts. - Fix calculation of ECH HRR Transcript. - Allow ld path to be set as environment variable. - Ensure we don't read uninitialized memory in ssl gtests. - Fix DataBuffer Move Assignment. - internal_error alert on Certificate Request with sha1+ecdsa in TLS 1.3 - rework signature verification in mozilla::pkix Version update to NSS 3.76.1 - Remove token member from NSSSlot struct. - Hold tokensLock through nssToken_GetSlot calls in nssTrustDomain_GetActiveSlots. - Check return value of PK11Slot_GetNSSToken. - Use Wycheproof JSON for RSASSA-PSS - Add SHA256 fingerprint comments to old certdata.txt entries. - Avoid truncating files in nss-release-helper.py. - Throw illegal_parameter alert for illegal extensions in handshake message. Version update to NSS 3.75 - Make DottedOIDToCode.py compatible with python3. - Avoid undefined shift in SSL_CERT_IS while fuzzing. - Remove redundant key type check. - Update ABI expectations to match ECH changes. - Enable CKM_CHACHA20. - check return on NSS_NoDB_Init and NSS_Shutdown. - Run ECDSA test vectors from bltest as part of the CI tests. - Add ECDSA test vectors to the bltest command line tool. - Allow to build using clang's integrated assembler. - Allow to override python for the build. - test HKDF output rather than input. - Use ASSERT macros to end failed tests early. - move assignment operator for DataBuffer. - Add test cases for ECH compression and unexpected extensions in SH. - Update tests for ECH-13. - Tidy up error handling. - Add tests for ECH HRR Changes. - Server only sends GREASE HRR extension if enabled by preference. - Update generation of the Associated Data for ECH-13. - When ECH is accepted, reject extensions which were only advertised in the Outer Client Hello. - Allow for compressed, non-contiguous, extensions. - Scramble the PSK extension in CHOuter. - Split custom extension handling for ECH. - Add ECH-13 HRR Handling. - Client side ECH padding. - Stricter ClientHelloInner Decompression. - Remove ECH_inner extension, use new enum format. - Update the version number for ECH-13 and adjust the ECHConfig size. Version update to NSS 3.74 - mozilla::pkix: support SHA-2 hashes in CertIDs in OCSP responses - Ensure clients offer consistent ciphersuites after HRR - NSS does not properly restrict server keys based on policy - Set nssckbi version number to 2.54 - Replace Google Trust Services LLC (GTS) R4 root certificate - Replace Google Trust Services LLC (GTS) R3 root certificate - Replace Google Trust Services LLC (GTS) R2 root certificate - Replace Google Trust Services LLC (GTS) R1 root certificate - Replace GlobalSign ECC Root CA R4 - Remove Expired Root Certificates - DST Root CA X3 - Remove Expiring Cybertrust Global Root and GlobalSign root certificates - Add renewed Autoridad de Certificacion Firmaprofesional CIF A62634068 root certificate - Add iTrusChina ECC root certificate - Add iTrusChina RSA root certificate - Add ISRG Root X2 root certificate - Add Chunghwa Telecom's HiPKI Root CA - G1 root certificate - Avoid a clang 13 unused variable warning in opt build - Check for missing signedData field - Ensure DER encoded signatures are within size limits - enable key logging option (boo#1195040) Version update to NSS 3.73.1: - Add SHA-2 support to mozilla::pkix's OSCP implementation Version update to NSS 3.73 - check for missing signedData field. - Ensure DER encoded signatures are within size limits. - NSS needs FiPS 140-3 version indicators. - pkix_CacheCert_Lookup doesn't return cached certs - sunset Coverity from NSS Fixed MFSA 2021-51 (bsc#1193170) CVE-2021-43527: Memory corruption via DER-encoded DSA and RSA-PSS signatures Version update to NSS 3.72 - Fix nsinstall parallel failure. - Increase KDF cache size to mitigate perf regression in about:logins Version update to NSS 3.71 - Set nssckbi version number to 2.52. - Respect server requirements of tlsfuzzer/test-tls13-signature-algorithms.py - Import of PKCS#12 files with Camellia encryption is not supported - Add HARICA Client ECC Root CA 2021. - Add HARICA Client RSA Root CA 2021. - Add HARICA TLS ECC Root CA 2021. - Add HARICA TLS RSA Root CA 2021. - Add TunTrust Root CA certificate to NSS. Version update to NSS 3.70 - Update test case to verify fix. - Explicitly disable downgrade check in TlsConnectStreamTls13.EchOuterWith12Max - Explicitly disable downgrade check in TlsConnectTest.DisableFalseStartOnFallback - Avoid using a lookup table in nssb64d. - Use HW accelerated SHA2 on AArch64 Big Endian. - Change default value of enableHelloDowngradeCheck to true. - Cache additional PBE entries. - Read HPKE vectors from official JSON. Version update to NSS 3.69.1: - Disable DTLS 1.0 and 1.1 by default - integrity checks in key4.db not happening on private components with AES_CBC NSS 3.69: - Disable DTLS 1.0 and 1.1 by default (backed out again) - integrity checks in key4.db not happening on private components with AES_CBC (backed out again) - SSL handling of signature algorithms ignores environmental invalid algorithms. - sqlite 3.34 changed it's open semantics, causing nss failures. - Gtest update changed the gtest reports, losing gtest details in all.sh reports. - NSS incorrectly accepting 1536 bit DH primes in FIPS mode - SQLite calls could timeout in starvation situations. - Coverity/cpp scanner errors found in nss 3.67 - Import the NSS documentation from MDN in nss/doc. - NSS using a tempdir to measure sql performance not active Version Update to 3.68.4 (bsc#1200027) - CVE-2022-31741: Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple. (bmo#1767590) Mozilla NSPR was updated to version 4.34: * add an API that returns a preferred loopback IP on hosts that have two IP stacks available. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2595-1 Released: Fri Jul 29 16:00:42 2022 Summary: Security update for mozilla-nss Type: security Severity: important References: 1192079,1192080,1192086,1192087,1192228,1198486,1200027,CVE-2022-31741 This update for mozilla-nss fixes the following issues: Various FIPS 140-3 related fixes were backported from SUSE Linux Enterprise 15 SP4: - Makes the PBKDF known answer test compliant with NIST SP800-132. (bsc#1192079). - FIPS: Add on-demand integrity tests through sftk_FIPSRepeatIntegrityCheck() (bsc#1198980). - FIPS: mark algorithms as approved/non-approved according to security policy (bsc#1191546, bsc#1201298). - FIPS: remove hard disabling of unapproved algorithms. This requirement is now fulfilled by the service level indicator (bsc#1200325). - Run test suite at build time, and make it pass (bsc#1198486). - FIPS: skip algorithms that are hard disabled in FIPS mode. - Prevent expired PayPalEE cert from failing the tests. - Allow checksumming to be disabled, but only if we entered FIPS mode due to NSS_FIPS being set, not if it came from /proc. - FIPS: Make the PBKDF known answer test compliant with NIST SP800-132. - Update FIPS validation string to version-release format. - FIPS: remove XCBC MAC from list of FIPS approved algorithms. - Enable NSS_ENABLE_FIPS_INDICATORS and set NSS_FIPS_MODULE_ID for build. - FIPS: claim 3DES unapproved in FIPS mode (bsc#1192080). - FIPS: allow testing of unapproved algorithms (bsc#1192228). - FIPS: add version indicators. (bmo#1729550, bsc#1192086). - FIPS: fix some secret clearing (bmo#1697303, bsc#1192087). Version update to NSS 3.79: - Use PK11_GetSlotInfo instead of raw C_GetSlotInfo calls. - Update mercurial in clang-format docker image. - Use of uninitialized pointer in lg_init after alloc fail. - selfserv and tstclnt should use PR_GetPrefLoopbackAddrInfo. - Add SECMOD_LockedModuleHasRemovableSlots. - Fix secasn1d parsing of indefinite SEQUENCE inside indefinite GROUP. - Added RFC8422 compliant TLS <= 1.2 undefined/compressed ECPointFormat extension alerts. - TLS 1.3 Server: Send protocol_version alert on unsupported ClientHello.legacy_version. - Correct invalid record inner and outer content type alerts. - NSS does not properly import or export pkcs12 files with large passwords and pkcs5v2 encoding. - improve error handling after nssCKFWInstance_CreateObjectHandle. - Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple. - NSS 3.79 should depend on NSPR 4.34 Version update to NSS 3.78.1: - Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple Version update to NSS 3.78: - Added TLS 1.3 zero-length inner plaintext checks and tests, zero-length record/fragment handling tests. - Reworked overlong record size checks and added TLS1.3 specific boundaries. - Add ECH Grease Support to tstclnt - Add a strict variant of moz::pkix::CheckCertHostname. - Change SSL_REUSE_SERVER_ECDHE_KEY default to false. - Make SEC_PKCS12EnableCipher succeed - Update zlib in NSS to 1.2.12. Version update to NSS 3.77: - Fix link to TLS page on wireshark wiki - Add two D-TRUST 2020 root certificates. - Add Telia Root CA v2 root certificate. - Remove expired explicitly distrusted certificates from certdata.txt. - support specific RSA-PSS parameters in mozilla::pkix - Remove obsolete stateEnd check in SEC_ASN1DecoderUpdate. - Remove token member from NSSSlot struct. - Provide secure variants of mpp_pprime and mpp_make_prime. - Support UTF-8 library path in the module spec string. - Update nssUTF8_Length to RFC 3629 and fix buffer overrun. - Update googletest to 1.11.0 - Add SetTls13GreaseEchSize to experimental API. - TLS 1.3 Illegal legacy_version handling/alerts. - Fix calculation of ECH HRR Transcript. - Allow ld path to be set as environment variable. - Ensure we don't read uninitialized memory in ssl gtests. - Fix DataBuffer Move Assignment. - internal_error alert on Certificate Request with sha1+ecdsa in TLS 1.3 - rework signature verification in mozilla::pkix Version update to NSS 3.76.1 - Remove token member from NSSSlot struct. - Hold tokensLock through nssToken_GetSlot calls in nssTrustDomain_GetActiveSlots. - Check return value of PK11Slot_GetNSSToken. - Use Wycheproof JSON for RSASSA-PSS - Add SHA256 fingerprint comments to old certdata.txt entries. - Avoid truncating files in nss-release-helper.py. - Throw illegal_parameter alert for illegal extensions in handshake message. Version update to NSS 3.75 - Make DottedOIDToCode.py compatible with python3. - Avoid undefined shift in SSL_CERT_IS while fuzzing. - Remove redundant key type check. - Update ABI expectations to match ECH changes. - Enable CKM_CHACHA20. - check return on NSS_NoDB_Init and NSS_Shutdown. - Run ECDSA test vectors from bltest as part of the CI tests. - Add ECDSA test vectors to the bltest command line tool. - Allow to build using clang's integrated assembler. - Allow to override python for the build. - test HKDF output rather than input. - Use ASSERT macros to end failed tests early. - move assignment operator for DataBuffer. - Add test cases for ECH compression and unexpected extensions in SH. - Update tests for ECH-13. - Tidy up error handling. - Add tests for ECH HRR Changes. - Server only sends GREASE HRR extension if enabled by preference. - Update generation of the Associated Data for ECH-13. - When ECH is accepted, reject extensions which were only advertised in the Outer Client Hello. - Allow for compressed, non-contiguous, extensions. - Scramble the PSK extension in CHOuter. - Split custom extension handling for ECH. - Add ECH-13 HRR Handling. - Client side ECH padding. - Stricter ClientHelloInner Decompression. - Remove ECH_inner extension, use new enum format. - Update the version number for ECH-13 and adjust the ECHConfig size. Version update to NSS 3.74 - mozilla::pkix: support SHA-2 hashes in CertIDs in OCSP responses - Ensure clients offer consistent ciphersuites after HRR - NSS does not properly restrict server keys based on policy - Set nssckbi version number to 2.54 - Replace Google Trust Services LLC (GTS) R4 root certificate - Replace Google Trust Services LLC (GTS) R3 root certificate - Replace Google Trust Services LLC (GTS) R2 root certificate - Replace Google Trust Services LLC (GTS) R1 root certificate - Replace GlobalSign ECC Root CA R4 - Remove Expired Root Certificates - DST Root CA X3 - Remove Expiring Cybertrust Global Root and GlobalSign root certificates - Add renewed Autoridad de Certificacion Firmaprofesional CIF A62634068 root certificate - Add iTrusChina ECC root certificate - Add iTrusChina RSA root certificate - Add ISRG Root X2 root certificate - Add Chunghwa Telecom's HiPKI Root CA - G1 root certificate - Avoid a clang 13 unused variable warning in opt build - Check for missing signedData field - Ensure DER encoded signatures are within size limits - enable key logging option (boo#1195040) Version update to NSS 3.73.1: - Add SHA-2 support to mozilla::pkix's OSCP implementation Version update to NSS 3.73 - check for missing signedData field. - Ensure DER encoded signatures are within size limits. - NSS needs FiPS 140-3 version indicators. - pkix_CacheCert_Lookup doesn't return cached certs - sunset Coverity from NSS Fixed MFSA 2021-51 (bsc#1193170) CVE-2021-43527: Memory corruption via DER-encoded DSA and RSA-PSS signatures Version update to NSS 3.72 - Fix nsinstall parallel failure. - Increase KDF cache size to mitigate perf regression in about:logins Version update to NSS 3.71 - Set nssckbi version number to 2.52. - Respect server requirements of tlsfuzzer/test-tls13-signature-algorithms.py - Import of PKCS#12 files with Camellia encryption is not supported - Add HARICA Client ECC Root CA 2021. - Add HARICA Client RSA Root CA 2021. - Add HARICA TLS ECC Root CA 2021. - Add HARICA TLS RSA Root CA 2021. - Add TunTrust Root CA certificate to NSS. Version update to NSS 3.70 - Update test case to verify fix. - Explicitly disable downgrade check in TlsConnectStreamTls13.EchOuterWith12Max - Explicitly disable downgrade check in TlsConnectTest.DisableFalseStartOnFallback - Avoid using a lookup table in nssb64d. - Use HW accelerated SHA2 on AArch64 Big Endian. - Change default value of enableHelloDowngradeCheck to true. - Cache additional PBE entries. - Read HPKE vectors from official JSON. Version update to NSS 3.69.1: - Disable DTLS 1.0 and 1.1 by default - integrity checks in key4.db not happening on private components with AES_CBC NSS 3.69: - Disable DTLS 1.0 and 1.1 by default (backed out again) - integrity checks in key4.db not happening on private components with AES_CBC (backed out again) - SSL handling of signature algorithms ignores environmental invalid algorithms. - sqlite 3.34 changed it's open semantics, causing nss failures. - Gtest update changed the gtest reports, losing gtest details in all.sh reports. - NSS incorrectly accepting 1536 bit DH primes in FIPS mode - SQLite calls could timeout in starvation situations. - Coverity/cpp scanner errors found in nss 3.67 - Import the NSS documentation from MDN in nss/doc. - NSS using a tempdir to measure sql performance not active Version Update to 3.68.4 (bsc#1200027) - CVE-2022-31741: Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple. (bmo#1767590) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:2901-1 Released: Fri Aug 26 03:34:23 2022 Summary: Recommended update for elfutils Type: recommended Severity: moderate References: This update for elfutils fixes the following issues: - Fix runtime dependency for devel package ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:2939-1 Released: Mon Aug 29 14:49:17 2022 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1201298,1202645 This update for mozilla-nss fixes the following issues: Update to NSS 3.79.1 (bsc#1202645) * compare signature and signatureAlgorithm fields in legacy certificate verifier. * Uninitialized value in cert_ComputeCertType. * protect SFTKSlot needLogin with slotLock. * avoid data race on primary password change. * check for null template in sec_asn1{d,e}_push_state. - FIPS: unapprove the rest of the DSA ciphers, keeping signature verification only (bsc#1201298). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:3241-1 Released: Mon Sep 12 07:21:04 2022 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1201511 This update for cups fixes the following issues: - Stuck print jobs being cancelled immediately, despite MaxJobTime being set to 0 (bsc#1201511) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3307-1 Released: Mon Sep 19 13:26:51 2022 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1189802,1195773,1201783,CVE-2021-36690,CVE-2022-35737 This update for sqlite3 fixes the following issues: - CVE-2022-35737: Fixed an array-bounds overflow if billions of bytes are used in a string argument to a C API (bnc#1201783). - CVE-2021-36690: Fixed an issue with the SQLite Expert extension when a column has no collating sequence (bsc#1189802). - Package the Tcl bindings here again so that we only ship one copy of SQLite (bsc#1195773). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3784-1 Released: Wed Oct 26 18:03:28 2022 Summary: Security update for libtasn1 Type: security Severity: critical References: 1204690,CVE-2021-46848 This update for libtasn1 fixes the following issues: - CVE-2021-46848: Fixed off-by-one array size check that affects asn1_encode_simple_der (bsc#1204690) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:3873-1 Released: Fri Nov 4 14:58:08 2022 Summary: Recommended update for mozilla-nspr, mozilla-nss Type: recommended Severity: moderate References: 1191546,1198980,1201298,1202870,1204729 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nspr was updated to version 4.34.1: * add file descriptor sanity checks in the NSPR poll function. mozilla-nss was updated to NSS 3.79.2 (bsc#1204729): * Bump minimum NSPR version to 4.34.1. * Gracefully handle null nickname in CERT_GetCertNicknameWithValidity. Other fixes that were applied: - FIPS: Allow the use of DSA keys (verification only) (bsc#1201298). - FIPS: Add sftk_FIPSRepeatIntegrityCheck() to softoken's .def file (bsc#1198980). - FIPS: Allow the use of longer symmetric keys via the service level indicator (bsc#1191546). - FIPS: Prevent TLS sessions from getting flagged as non-FIPS (bsc#1191546). - FIPS: Mark DSA keygen unapproved (bsc#1191546, bsc#1201298). - FIPS: Use libjitterentropy for entropy (bsc#1202870). - FIPS: Fixed an abort() when both NSS_FIPS and /proc FIPS mode are enabled. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:3958-1 Released: Fri Nov 11 15:20:45 2022 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1191546,1198980,1201298,1202870,1204729 This update for mozilla-nss fixes the following issues: mozilla-nss was updated to NSS 3.79.2 (bsc#1204729) * Bump minimum NSPR version to 4.34.1. * Gracefully handle null nickname in CERT_GetCertNicknameWithValidity. - FIPS: Allow the use of DSA keys (verification only) (bsc#1201298). - FIPS: Add sftk_FIPSRepeatIntegrityCheck() to softoken's .def file (bsc#1198980). - FIPS: Allow the use of longer symmetric keys via the service level indicator (bsc#1191546). - FIPS: Export sftk_FIPSRepeatIntegrityCheck() correctly (bsc#1198980). - FIPS: Prevent sessions from getting flagged as non-FIPS (bsc#1191546). - FIPS: Mark DSA keygen unapproved (bsc#1191546, bsc#1201298). - FIPS: Enable userspace entropy gathering via libjitterentropy (bsc#1202870). - FIPS: Prevent keys from getting flagged as non-FIPS and add remaining TLS mechanisms. - FIPS: Use libjitterentropy for entropy. - FIPS: Fixed an abort() when both NSS_FIPS and /proc FIPS mode are enabled. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:4492-1 Released: Wed Dec 14 13:52:39 2022 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1191546,1198980,1201298 This update for mozilla-nss fixes the following issues: - FIPS: Disapprove the creation of DSA keys, i.e. mark them as not-fips (bsc#1201298) - FIPS: Allow the use SHA keygen mechs (bsc#1191546). - FIPS: ensure abort() is called when the repeat integrity check fails (bsc#1198980). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:4628-1 Released: Wed Dec 28 09:23:13 2022 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1206337,CVE-2022-46908 This update for sqlite3 fixes the following issues: - CVE-2022-46908: Properly implement the azProhibitedFunctions protection mechanism, when relying on --safe for execution of an untrusted CLI script (bsc#1206337). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:119-1 Released: Fri Jan 20 10:28:07 2023 Summary: Security update for mozilla-nss Type: security Severity: important References: 1204272,1207038,CVE-2022-23491,CVE-2022-3479 This update for mozilla-nss fixes the following issues: - CVE-2022-3479: Fixed a potential crash that could be triggered when a server requested a client authentication certificate, but the client had no certificates stored (bsc#1204272). - Updated to version 3.79.3 (bsc#1207038): - CVE-2022-23491: Removed trust for 3 root certificates from TrustCor. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:434-1 Released: Thu Feb 16 09:08:05 2023 Summary: Security update for mozilla-nss Type: security Severity: important References: 1208138,CVE-2023-0767 This update for mozilla-nss fixes the following issues: Updated to NSS 3.79.4 (bsc#1208138): - CVE-2023-0767: Fixed handling of unknown PKCS#12 safe bag types. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:1810-1 Released: Tue Apr 11 12:06:13 2023 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1191467,1191525,1198932,1200321,1201234,1203446 This update for cups fixes the following issues: - Fix print jobs on cups.sock return with EAGAIN (Resource temporarily unavailable) (bsc#1191525) - Fix '/usr/bin/lpr: Error - The printer or class does not exist (bsc#1203446) - Improves logging on 'IPP_STATUS_ERROR_NOT_FOUND' error (bsc#1191467, bsc#1198932) - Add 'After=network.target sssd.service' to the systemd unit (bsc#1201234, bsc#1200321) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:1939-1 Released: Fri Apr 21 11:14:30 2023 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1191546,1207209,1208242,1208999 This update for mozilla-nss fixes the following issues: - FIPS 140-3: Adjust SLI reporting for PBKDF2 parameter validation (bsc#1208999) - FIPS 140-3: Update session->lastOpWasFIPS before destroying the key after derivation in the CKM_TLS12_KEY_AND_MAC_DERIVE, CKM_NSS_TLS_KEY_AND_MAC_DERIVE_SHA256, CKM_TLS_KEY_AND_MAC_DERIVE and CKM_SSL3_KEY_AND_MAC_DERIVE cases. (bsc#1191546) - FIPS 140-3: more changes for pairwise consistency checks. (bsc#1207209) - Add manpages to mozilla-nss-tools (bsc#1208242) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2347-1 Released: Thu Jun 1 14:33:10 2023 Summary: Security update for cups Type: security Severity: important References: 1211643,CVE-2023-32324 This update for cups fixes the following issues: - CVE-2023-32324: Fixed a buffer overflow in format_log_line() which could cause a denial-of-service (bsc#1211643). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2616-1 Released: Thu Jun 22 16:47:50 2023 Summary: Security update for cups Type: security Severity: important References: 1212230,CVE-2023-34241 This update for cups fixes the following issues: - CVE-2023-34241: Fixed a use-after-free problem in cupsdAcceptClient() (bsc#1212230). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2788-1 Released: Thu Jul 6 11:51:02 2023 Summary: Recommended update for mozilla-nspr, mozilla-nss Type: recommended Severity: moderate References: 1185116,1202118 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nspr was updated to version 4.35 * fixes for building with clang * use the number of online processors for the PR_GetNumberOfProcessors() API on some platforms * fix build on mips+musl libc * Add support for the LoongArch 64-bit architecture mozilla-nss was update to NSS 3.90: * clang-format lib/freebl/stubs.c * Add a constant time select function * Updating an old dbm with lots of certs with keys to sql results in a database that is slow to access. * output early build errors by default * Update the technical constraints for KamuSM * Add BJCA Global Root CA1 and CA2 root certificates * Enable default UBSan Checks * Add explicit handling of zero length records * Tidy up DTLS ACK Error Handling Path * Refactor zero length record tests * Fix compiler warning via correct assert * run linux tests on nss-t/t-linux-xlarge-gcp * In FIPS mode, nss should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator * Fix reading raw negative numbers * Repairing unreachable code in clang built with gyp * Integrate Vale Curve25519 * Removing unused flags for Hacl* * Adding a better error message * Update HACL* till 51a72a953a4ee6f91e63b2816ae5c4e62edf35d6 * Fall back to the softokn when writing certificate trust * FIPS-104-3 requires we restart post programmatically * cmd/ecperf: fix dangling pointer warning on gcc 13 * Update ACVP dockerfile for compatibility with debian package changes * Add a CI task for tracking ECCKiila code status, update whitespace in ECCKiila files * Removed deprecated sprintf function and replaced with snprintf * fix rst warnings in nss doc * Fix incorrect pygment style * Change GYP directive to apply across platforms * Add libsmime3 abi-check exception for NSS_CMSSignerInfo_GetDigestAlgTag - Merge the libfreebl3-hmac and libsoftokn3-hmac packages into the respective libraries. (bsc#1185116) update to NSS 3.89.1 * Update the technical constraints for KamuSM. * Add BJCA Global Root CA1 and CA2 root certificates. update to NSS 3.89 * revert freebl/softoken RSA_MIN_MODULUS_BITS increase * PR_STATIC_ASSERT is cursed * Need to add policy control to keys lengths for signatures * Fix unreachable code warning in fuzz builds * Fix various compiler warnings in NSS * Enable various compiler warnings for clang builds * set PORT error after sftk_HMACCmp failure * Need to add policy control to keys lengths for signatures * remove data length assertion in sec_PKCS7Decrypt * Make high tag number assertion failure an error * CKM_SHA384_KEY_DERIVATION correction maximum key length from 284 to 384 * Tolerate certificate_authorities xtn in ClientHello * Fix build failure on Windows * migrate Win 2012 tasks to Azure * fix title length in doc * Add interop tests for HRR and PSK to GREASE suite * Add presence/absence tests for TLS GREASE * Correct addition of GREASE value to ALPN xtn * CH extension permutation * TLS GREASE (RFC8701) * improve handling of unknown PKCS#12 safe bag types * use a different treeherder symbol for each docker image build task * remove nested table in rst doc * Export NSS_CMSSignerInfo_GetDigestAlgTag * build failure while implicitly casting SECStatus to PRUInt32 update to NSS 3.88.1 * improve handling of unknown PKCS#12 safe bag types update to NSS 3.88 * remove nested table in rst doc * Export NSS_CMSSignerInfo_GetDigestAlgTag. * build failure while implicitly casting SECStatus to PRUInt32 * Add check for ClientHello SID max length * Added EarlyData ALPN test support to BoGo shim * ECH client - Discard resumption TLS < 1.3 Session(IDs|Tickets) if ECH configs are setup * On HRR skip PSK incompatible with negotiated ciphersuites hash algorithm * ECH client: Send ech_required alert on server negotiating TLS 1.2. Fixed misleading Gtest, enabled corresponding BoGo test * Added Bogo ECH rejection test support * Added ECH 0Rtt support to BoGo shim * RSA OAEP Wycheproof JSON * RSA decrypt Wycheproof JSON * ECDSA Wycheproof JSON * ECDH Wycheproof JSON * PKCS#1v1.5 wycheproof json * Use X25519 wycheproof json * Move scripts to python3 * Properly link FuzzingEngine for oss-fuzz. * Extending RSA-PSS bltest test coverage (Adding SHA-256 and SHA-384) * NSS needs to move off of DSA for integrity checks * Add initial testing with ACVP vector sets using acvp-rust * Don't clone libFuzzer, rely on clang instead update to NSS 3.87 * NULL password encoding incorrect * Fix rng stub signature for fuzzing builds * Updating the compiler parsing for build * Modification of supported compilers * tstclnt crashes when accessing gnutls server without a user cert in the database. * Add configuration option to enable source-based coverage sanitizer * Update ECCKiila generated files. * Add support for the LoongArch 64-bit architecture * add checks for zero-length RSA modulus to avoid memory errors and failed assertions later * Additional zero-length RSA modulus checks update to NSS 3.86 * conscious language removal in NSS * Set nssckbi version number to 2.60 * Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates * Remove Staat der Nederlanden EV Root CA from NSS * Remove EC-ACC root cert from NSS * Remove SwissSign Platinum CA - G2 from NSS * Remove Network Solutions Certificate Authority * compress docker image artifact with zstd * Migrate nss from AWS to GCP * Enable static builds in the CI * Removing SAW docker from the NSS build system * Initialising variables in the rsa blinding code * Implementation of the double-signing of the message for ECDSA * Adding exponent blinding for RSA. update to NSS 3.85 * Modification of the primes.c and dhe-params.c in order to have better looking tables * Update zlib in NSS to 1.2.13 * Skip building modutil and shlibsign when building in Firefox * Mark _nss_version_c unused on clang-cl * bmo#1795668 - Remove redundant variable definitions in lowhashtest * Add note about python executable to build instructions. update to NSS 3.84 * Bump minimum NSPR version to 4.35 * Add a flag to disable building libnssckbi. update to NSS 3.83 * Remove set-but-unused variables from SEC_PKCS12DecoderValidateBags * Set nssckbi version number to 2.58 * Add two SECOM root certificates to NSS * Add two DigitalSign root certificates to NSS * Remove Camerfirma Global Chambersign Root from NSS * Added bug reference and description to disabled UnsolicitedServerNameAck bogo ECH test * Removed skipping of ECH on equality of private and public server name * Added comment and bug reference to ECHRandomHRRExtension bogo test * Added Bogo shim client HRR test support. Fixed overwriting of CHInner.random on HRR * Added check for server only sending ECH extension with retry configs in EncryptedExtensions and if not accepting ECH. Changed config setting behavior to skip configs with unsupported mandatory extensions instead of failing * Added ECH client support to BoGo shim. Changed CHInner creation to skip TLS 1.2 only extensions to comply with BoGo * Added ECH server support to BoGo shim. Fixed NSS ECH server accept_confirmation bugs * Update BoGo tests to recent BoringSSL version * Bump minimum NSPR version to 4.34.1 update to NSS 3.82 * check for null template in sec_asn1{d,e}_push_state * QuickDER: Forbid NULL tags with non-zero length * Initialize local variables in TlsConnectTestBase::ConnectAndCheckCipherSuite * Cast the result of GetProcAddress * pk11wrap: Tighten certificate lookup based on PKCS #11 URI. update to NSS 3.81 * Enable aarch64 hardware crypto support on OpenBSD * make NSS_SecureMemcmp 0/1 valued * Add no_application_protocol alert handler and test client error code is set * Gracefully handle null nickname in CERT_GetCertNicknameWithValidity * required for Firefox 104 - raised NSPR requirement to 4.34.1 - changing some Requires from (pre) to generic as (pre) is not sufficient (bsc#1202118) update to NSS 3.80 * Fix SEC_ERROR_ALGORITHM_MISMATCH entry in SECerrs.h. * Add support for asynchronous client auth hooks. * nss-policy-check: make unknown keyword check optional. * GatherBuffer: Reduced plaintext buffer allocations by allocating it on initialization. Replaced redundant code with assert. Debug builds: Added buffer freeing/allocation for each record. * Mark 3.79 as an ESR release. * Bump nssckbi version number for June. * Remove Hellenic Academic 2011 Root. * Add E-Tugra Roots. * Add Certainly Roots. * Add DigitCert Roots. * Protect SFTKSlot needLogin with slotLock. * Compare signature and signatureAlgorithm fields in legacy certificate verifier. * Uninitialized value in cert_VerifyCertChainOld. * Unchecked return code in sec_DecodeSigAlg. * Uninitialized value in cert_ComputeCertType. * Avoid data race on primary password change. * Replace ppc64 dcbzl intrinisic. * Allow LDFLAGS override in makefile builds. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2814-1 Released: Wed Jul 12 22:05:25 2023 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1185116,1202118 This update for mozilla-nss fixes the following issues: mozilla-nss was updated to NSS 3.90: * Add a constant time select function * Updating an old dbm with lots of certs with keys to sql results in a database that is slow to access. * output early build errors by default * Update the technical constraints for KamuSM * Add BJCA Global Root CA1 and CA2 root certificates * Enable default UBSan Checks * Add explicit handling of zero length records * Tidy up DTLS ACK Error Handling Path * Refactor zero length record tests * Fix compiler warning via correct assert * run linux tests on nss-t/t-linux-xlarge-gcp * In FIPS mode, nss should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator * Fix reading raw negative numbers * Repairing unreachable code in clang built with gyp * Integrate Vale Curve25519 * Removing unused flags for Hacl* * Adding a better error message * Update HACL* till 51a72a953a4ee6f91e63b2816ae5c4e62edf35d6 * Fall back to the softokn when writing certificate trust * FIPS-104-3 requires we restart post programmatically * cmd/ecperf: fix dangling pointer warning on gcc 13 * Update ACVP dockerfile for compatibility with debian package changes * Add a CI task for tracking ECCKiila code status, update whitespace in ECCKiila files * Removed deprecated sprintf function and replaced with snprintf * fix rst warnings in nss doc * Fix incorrect pygment style * Change GYP directive to apply across platforms * Add libsmime3 abi-check exception for NSS_CMSSignerInfo_GetDigestAlgTag - Merge the libfreebl3-hmac and libsoftokn3-hmac packages into the respective libraries. (bsc#1185116) update to NSS 3.89.1 * Update the technical constraints for KamuSM. * Add BJCA Global Root CA1 and CA2 root certificates. update to NSS 3.89 * revert freebl/softoken RSA_MIN_MODULUS_BITS increase * PR_STATIC_ASSERT is cursed * Need to add policy control to keys lengths for signatures * Fix unreachable code warning in fuzz builds * Fix various compiler warnings in NSS * Enable various compiler warnings for clang builds * set PORT error after sftk_HMACCmp failure * Need to add policy control to keys lengths for signatures * remove data length assertion in sec_PKCS7Decrypt * Make high tag number assertion failure an error * CKM_SHA384_KEY_DERIVATION correction maximum key length from 284 to 384 * Tolerate certificate_authorities xtn in ClientHello * Fix build failure on Windows * migrate Win 2012 tasks to Azure * fix title length in doc * Add interop tests for HRR and PSK to GREASE suite * Add presence/absence tests for TLS GREASE * Correct addition of GREASE value to ALPN xtn * CH extension permutation * TLS GREASE (RFC8701) * improve handling of unknown PKCS#12 safe bag types * use a different treeherder symbol for each docker image build task * remove nested table in rst doc * Export NSS_CMSSignerInfo_GetDigestAlgTag * build failure while implicitly casting SECStatus to PRUInt32 update to NSS 3.88.1 * improve handling of unknown PKCS#12 safe bag types update to NSS 3.88 * remove nested table in rst doc * Export NSS_CMSSignerInfo_GetDigestAlgTag. * build failure while implicitly casting SECStatus to PRUInt32 * Add check for ClientHello SID max length * Added EarlyData ALPN test support to BoGo shim * ECH client - Discard resumption TLS < 1.3 Session(IDs|Tickets) if ECH configs are setup * On HRR skip PSK incompatible with negotiated ciphersuites hash algorithm * ECH client: Send ech_required alert on server negotiating TLS 1.2. Fixed misleading Gtest, enabled corresponding BoGo test * Added Bogo ECH rejection test support * Added ECH 0Rtt support to BoGo shim * RSA OAEP Wycheproof JSON * RSA decrypt Wycheproof JSON * ECDSA Wycheproof JSON * ECDH Wycheproof JSON * PKCS#1v1.5 wycheproof json * Use X25519 wycheproof json * Move scripts to python3 * Properly link FuzzingEngine for oss-fuzz. * Extending RSA-PSS bltest test coverage (Adding SHA-256 and SHA-384) * NSS needs to move off of DSA for integrity checks * Add initial testing with ACVP vector sets using acvp-rust * Don't clone libFuzzer, rely on clang instead update to NSS 3.87 * NULL password encoding incorrect * Fix rng stub signature for fuzzing builds * Updating the compiler parsing for build * Modification of supported compilers * tstclnt crashes when accessing gnutls server without a user cert in the database. * Add configuration option to enable source-based coverage sanitizer * Update ECCKiila generated files. * Add support for the LoongArch 64-bit architecture * add checks for zero-length RSA modulus to avoid memory errors and failed assertions later * Additional zero-length RSA modulus checks update to NSS 3.86 * conscious language removal in NSS * Set nssckbi version number to 2.60 * Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates * Remove Staat der Nederlanden EV Root CA from NSS * Remove EC-ACC root cert from NSS * Remove SwissSign Platinum CA - G2 from NSS * Remove Network Solutions Certificate Authority * compress docker image artifact with zstd * Migrate nss from AWS to GCP * Enable static builds in the CI * Removing SAW docker from the NSS build system * Initialising variables in the rsa blinding code * Implementation of the double-signing of the message for ECDSA * Adding exponent blinding for RSA. update to NSS 3.85 * Modification of the primes.c and dhe-params.c in order to have better looking tables * Update zlib in NSS to 1.2.13 * Skip building modutil and shlibsign when building in Firefox * Use __STDC_VERSION__ rather than __STDC__ as a guard * Remove redundant variable definitions in lowhashtest * Add note about python executable to build instructions. update to NSS 3.84 * Bump minimum NSPR version to 4.35 * Add a flag to disable building libnssckbi. update to NSS 3.83 * Remove set-but-unused variables from SEC_PKCS12DecoderValidateBags * Set nssckbi version number to 2.58 * Add two SECOM root certificates to NSS * Add two DigitalSign root certificates to NSS * Remove Camerfirma Global Chambersign Root from NSS * Added bug reference and description to disabled UnsolicitedServerNameAck bogo ECH test * Removed skipping of ECH on equality of private and public server name * Added comment and bug reference to ECHRandomHRRExtension bogo test * Added Bogo shim client HRR test support. Fixed overwriting of CHInner.random on HRR * Added check for server only sending ECH extension with retry configs in EncryptedExtensions and if not accepting ECH. Changed config setting behavior to skip configs with unsupported mandatory extensions instead of failing * Added ECH client support to BoGo shim. Changed CHInner creation to skip TLS 1.2 only extensions to comply with BoGo * Added ECH server support to BoGo shim. Fixed NSS ECH server accept_confirmation bugs * Update BoGo tests to recent BoringSSL version * Bump minimum NSPR version to 4.34.1 update to NSS 3.82 * check for null template in sec_asn1{d,e}_push_state * QuickDER: Forbid NULL tags with non-zero length * Initialize local variables in TlsConnectTestBase::ConnectAndCheckCipherSuite * Cast the result of GetProcAddress * pk11wrap: Tighten certificate lookup based on PKCS #11 URI. update to NSS 3.81 * Enable aarch64 hardware crypto support on OpenBSD * make NSS_SecureMemcmp 0/1 valued * Add no_application_protocol alert handler and test client error code is set * Gracefully handle null nickname in CERT_GetCertNicknameWithValidity * required for Firefox 104 - raised NSPR requirement to 4.34.1 - changing some Requires from (pre) to generic as (pre) is not sufficient (bsc#1202118) update to NSS 3.80 * Fix SEC_ERROR_ALGORITHM_MISMATCH entry in SECerrs.h. * Add support for asynchronous client auth hooks. * nss-policy-check: make unknown keyword check optional. * GatherBuffer: Reduced plaintext buffer allocations by allocating it on initialization. Replaced redundant code with assert. Debug builds: Added buffer freeing/allocation for each record. * Mark 3.79 as an ESR release. * Bump nssckbi version number for June. * Remove Hellenic Academic 2011 Root. * Add E-Tugra Roots. * Add Certainly Roots. * Add DigitCert Roots. * Protect SFTKSlot needLogin with slotLock. * Compare signature and signatureAlgorithm fields in legacy certificate verifier. * Uninitialized value in cert_VerifyCertChainOld. * Unchecked return code in sec_DecodeSigAlg. * Uninitialized value in cert_ComputeCertType. * Avoid data race on primary password change. * Replace ppc64 dcbzl intrinisic. * Allow LDFLAGS override in makefile builds. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3707-1 Released: Wed Sep 20 17:12:03 2023 Summary: Security update for cups Type: security Severity: important References: 1214254,1215204,CVE-2023-32360,CVE-2023-4504 This update for cups fixes the following issues: - CVE-2023-4504: Fixed heap overflow in OpenPrinting CUPS Postscript Parsing (bsc#1215204). - CVE-2023-32360: Fixed Information leak through Cups-Get-Document operation (bsc#1214254). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4619-1 Released: Thu Nov 30 10:13:52 2023 Summary: Security update for sqlite3 Type: security Severity: important References: 1210660,CVE-2023-2137 This update for sqlite3 fixes the following issues: - CVE-2023-2137: Fixed heap buffer overflow (bsc#1210660). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4700-1 Released: Mon Dec 11 07:03:27 2023 Summary: Recommended update for p11-kit Type: recommended Severity: moderate References: This update for p11-kit fixes the following issues: - Ensure that programs using can be compiled with CRYPTOKI_GNU. Fixes GnuTLS builds (jsc#PED-6705). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4968-1 Released: Mon Dec 25 09:12:49 2023 Summary: Security update for jbigkit Type: security Severity: low References: 1198146,CVE-2022-1210 This update for jbigkit fixes the following issues: - CVE-2022-1210: Fixed denial of service in TIFF File Handler (bsc#1198146). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:26-1 Released: Thu Jan 4 11:15:24 2024 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1214980 This update for mozilla-nss fixes the following issues: Mozilla NSS was updated to NSS 3.90.1 * regenerate NameConstraints test certificates. * add OSXSAVE and XCR0 tests to AVX2 detection. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:597-1 Released: Thu Feb 22 20:07:11 2024 Summary: Security update for mozilla-nss Type: security Severity: important References: 1216198,CVE-2023-5388 This update for mozilla-nss fixes the following issues: Update to NSS 3.90.2: - CVE-2023-5388: Fixed timing attack against RSA decryption in TLS (bsc#1216198) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:1474-1 Released: Tue Apr 30 06:21:02 2024 Summary: Recommended update for cups Type: recommended Severity: important References: 1217119 This update for cups fixes the following issues: - Fix occasional stuck on poll() loop (bsc#1217119) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:1950-1 Released: Fri Jun 7 17:20:14 2024 Summary: Security update for glib2 Type: security Severity: moderate References: 1224044,CVE-2024-34397 This update for glib2 fixes the following issues: Update to version 2.78.6: + Fix a regression with IBus caused by the fix for CVE-2024-34397 Changes in version 2.78.5: + Fix CVE-2024-34397: GDBus signal subscriptions for well-known names are vulnerable to unicast spoofing. (bsc#1224044) + Bugs fixed: - gvfs-udisks2-volume-monitor SIGSEGV in g_content_type_guess_for_tree() due to filename with bad encoding - gcontenttype: Make filename valid utf-8 string before processing. - gdbusconnection: Don't deliver signals if the sender doesn't match. Changes in version 2.78.4: + Bugs fixed: - Fix generated RST anchors for methods, signals and properties. - docs/reference: depend on a native gtk-doc. - gobject_gdb.py: Do not break bt on optimized build. - gregex: clean up usage of _GRegex.jit_status. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:2003-1 Released: Wed Jun 12 07:30:30 2024 Summary: Security update for cups Type: security Severity: important References: 1223179,1225365,CVE-2024-35235 This update for cups fixes the following issues: - CVE-2024-35235: Fixed a bug in cupsd that could allow an attacker to change the permissions of other files in the system. (bsc#1225365) - Handle local 'Negotiate' authentication response for cli clients (bsc#1223179) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:2076-1 Released: Wed Jun 19 05:25:07 2024 Summary: Security update for gdk-pixbuf Type: security Severity: important References: 1195391,1219276,1223903,CVE-2022-48622 This update for gdk-pixbuf fixes the following issues: gdk-pixbuf was updated to version 2.42.12: - Security issues fixed: * CVE-2022-48622: Fixed vulnerability where a crafted .ani file could allow an attacker to overwrite heap metadata, leading to a denial of service or code execution attack to a denial of service or code execution attack (bsc#1219276) - Changes in version 2.42.12: + ani: Reject files with multiple INA or IART chunks, + ani: validate chunk size, + Updated translations. - Enable other image loaders such as xpm and xbm (bsc#1223903) - Changes in version 2.42.11: + Disable fringe loaders by default. + Introspection fixes. + Updated translations. - Changes in version 2.42.10: + Search for rst2man.py. + Update the memory size limit for JPEG images. + Updated translations. - Fixed loading of larger images - Avoid Bash specific syntax in baselibs postscript (bsc#1195391) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:2200-1 Released: Tue Jun 25 13:53:17 2024 Summary: Security update for avahi Type: security Severity: moderate References: 1216594,1216598,1226586,CVE-2023-38469,CVE-2023-38471 This update for avahi fixes the following issues: - CVE-2023-38471: Fixed a reachable assertion in dbus_set_host_name. (bsc#1216594) - CVE-2023-38469: Fixed a reachable assertion in avahi_dns_packet_append_record. (bsc#1216598) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2340-1 Released: Tue Jul 9 07:33:29 2024 Summary: Recommended update for pixman Type: recommended Severity: moderate References: 1221052 This update for pixman fixes the following issues: - Update to version 0.43.4 + Fix incorrect compositing on big-endian architectures (bsc#1221052) + Allow building on clang/arm32 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:2633-1 Released: Tue Jul 30 09:13:34 2024 Summary: Security update for gtk3 Type: security Severity: important References: 1228120,CVE-2024-6655 This update for gtk3 fixes the following issues: - CVE-2024-6655: Fixed library injection from current working directory (bsc#1228120) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2667-1 Released: Tue Jul 30 16:14:00 2024 Summary: Recommended update for libxkbcommon Type: recommended Severity: moderate References: 1218640,1228322 This update of libxkbcommon fixes the following issue: - ship libxkbregistry0-32bit and libxbkregistry-devel-32bit for use by Wine. (bsc#1218640 bsc#1228322) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2671-1 Released: Tue Jul 30 21:10:57 2024 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1226192 This update for cups fixes the following issues: - Require the exact matching version-release of all libcups* sub-packages (bsc#1226192) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2684-1 Released: Wed Jul 31 20:04:41 2024 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1214980,1222804,1222807,1222811,1222813,1222814,1222821,1222822,1222826,1222828,1222830,1222833,1222834,1223724,1224113,1224115,1224116,1224118,1227918,CVE-2023-5388 This update for mozilla-nss fixes the following issues: - Fixed startup crash of Firefox when using FIPS-mode (bsc#1223724). - Added 'Provides: nss' so other RPMs that require 'nss' can be installed (jira PED-6358). - FIPS: added safe memsets (bsc#1222811) - FIPS: restrict AES-GCM (bsc#1222830) - FIPS: Updated FIPS approved cipher lists (bsc#1222813, bsc#1222814, bsc#1222821, bsc#1222822, bsc#1224118) - FIPS: Updated FIPS self tests (bsc#1222807, bsc#1222828, bsc#1222834) - FIPS: Updated FIPS approved cipher lists (bsc#1222804, bsc#1222826, bsc#1222833, bsc#1224113, bsc#1224115, bsc#1224116) - Require `sed` for mozilla-nss-sysinit, as setup-nsssysinit.sh depends on it and will create a broken, empty config, if sed is missing (bsc#1227918) Update to NSS 3.101.2: * bmo#1905691 - ChaChaXor to return after the function update to NSS 3.101.1: * GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME. update to NSS 3.101: * add diagnostic assertions for SFTKObject refcount. * freeing the slot in DeleteCertAndKey if authentication failed * fix formatting issues. * Add Firmaprofesional CA Root-A Web to NSS. * remove invalid acvp fuzz test vectors. * pad short P-384 and P-521 signatures gtests. * remove unused FreeBL ECC code. * pad short P-384 and P-521 signatures. * be less strict about ECDSA private key length. * Integrate HACL* P-521. * Integrate HACL* P-384. * memory leak in create_objects_from_handles. * ensure all input is consumed in a few places in mozilla::pkix * SMIME/CMS and PKCS #12 do not integrate with modern NSS policy * clean up escape handling * Use lib::pkix as default validator instead of the old-one * Need to add high level support for PQ signing. * Certificate Compression: changing the allocation/freeing of buffer + Improving the documentation * SMIME/CMS and PKCS #12 do not integrate with modern NSS policy * Allow for non-full length ecdsa signature when using softoken * Modification of .taskcluster.yml due to mozlint indent defects * Implement support for PBMAC1 in PKCS#12 * disable VLA warnings for fuzz builds. * remove redundant AllocItem implementation. * add PK11_ReadDistrustAfterAttribute. * - Clang-formatting of SEC_GetMgfTypeByOidTag update * Set SEC_ERROR_LIBRARY_FAILURE on self-test failure * sftk_getParameters(): Fix fallback to default variable after error with configfile. * Switch to the mozillareleases/image_builder image - switch from ec_field_GFp to ec_field_plain Update to NSS 3.100: * merge pk11_kyberSlotList into pk11_ecSlotList for faster Xyber operations. * remove ckcapi. * avoid a potential PK11GenericObject memory leak. * Remove incomplete ESDH code. * Decrypt RSA OAEP encrypted messages. * Fix certutil CRLDP URI code. * Don't set CKA_DERIVE for CKK_EC_EDWARDS private keys. * Add ability to encrypt and decrypt CMS messages using ECDH. * Correct Templates for key agreement in smime/cmsasn.c. * Moving the decodedCert allocation to NSS. * Allow developers to speed up repeated local execution of NSS tests that depend on certificates. Update to NSS 3.99: * Removing check for message len in ed25519 (bmo#1325335) * add ed25519 to SECU_ecName2params. (bmo#1884276) * add EdDSA wycheproof tests. (bmo#1325335) * nss/lib layer code for EDDSA. (bmo#1325335) * Adding EdDSA implementation. (bmo#1325335) * Exporting Certificate Compression types (bmo#1881027) * Updating ACVP docker to rust 1.74 (bmo#1880857) * Updating HACL* to 0f136f28935822579c244f287e1d2a1908a7e552 (bmo#1325335) * Add NSS_CMSRecipient_IsSupported. (bmo#1877730) Update to NSS 3.98: * (CVE-2023-5388) Timing attack against RSA decryption in TLS * Certificate Compression: enabling the check that the compression was advertised * Move Windows workers to nss-1/b-win2022-alpha * Remove Email trust bit from OISTE WISeKey Global Root GC CA * Replace `distutils.spawn.find_executable` with `shutil.which` within `mach` in `nss` * Certificate Compression: Updating nss_bogo_shim to support Certificate compression * TLS Certificate Compression (RFC 8879) Implementation * Add valgrind annotations to freebl kyber operations for constant-time execution tests * Set nssckbi version number to 2.66 * Add Telekom Security roots * Add D-Trust 2022 S/MIME roots * Remove expired Security Communication RootCA1 root * move keys to a slot that supports concatenation in PK11_ConcatSymKeys * remove unmaintained tls-interop tests * bogo: add support for the -ipv6 and -shim-id shim flags * bogo: add support for the -curves shim flag and update Kyber expectations * bogo: adjust expectation for a key usage bit test * mozpkix: add option to ignore invalid subject alternative names * Fix selfserv not stripping `publicname:` from -X value * take ownership of ecckilla shims * add valgrind annotations to freebl/ec.c * PR_INADDR_ANY needs PR_htonl before assignment to inet.ip * Update zlib to 1.3.1 Update to NSS 3.97: * make Xyber768d00 opt-in by policy * add libssl support for xyber768d00 * add PK11_ConcatSymKeys * add Kyber and a PKCS#11 KEM interface to softoken * add a FreeBL API for Kyber * part 2: vendor github.com/pq-crystals/kyber/commit/e0d1c6ff * part 1: add a script for vendoring kyber from pq-crystals repo * Removing the calls to RSA Blind from loader.* * fix worker type for level3 mac tasks * RSA Blind implementation * Remove DSA selftests * read KWP testvectors from JSON * Backed out changeset dcb174139e4f * Fix CKM_PBE_SHA1_DES2_EDE_CBC derivation * Wrap CC shell commands in gyp expansions Update to NSS 3.96.1: * Use pypi dependencies for MacOS worker in ./build_gyp.sh * p7sign: add -a hash and -u certusage (also p7verify cleanups) * add a defensive check for large ssl_DefSend return values * Add dependency to the taskcluster script for Darwin * Upgrade version of the MacOS worker for the CI Update to NSS 3.95: * Bump builtins version number. * Remove Email trust bit from Autoridad de Certificacion Firmaprofesional CIF A62634068 root cert. * Remove 4 DigiCert (Symantec/Verisign) Root Certificates * Remove 3 TrustCor Root Certificates from NSS. * Remove Camerfirma root certificates from NSS. * Remove old Autoridad de Certificacion Firmaprofesional Certificate. * Add four Commscope root certificates to NSS. * Add TrustAsia Global Root CA G3 and G4 root certificates. * Include P-384 and P-521 Scalar Validation from HACL* * Include P-256 Scalar Validation from HACL*. * After the HACL 256 ECC patch, NSS incorrectly encodes 256 ECC without DER wrapping at the softoken level * Add means to provide library parameters to C_Initialize * add OSXSAVE and XCR0 tests to AVX2 detection. * Typo in ssl3_AppendHandshakeNumber * Introducing input check of ssl3_AppendHandshakeNumber * Fix Invalid casts in instance.c Update to NSS 3.94: * Updated code and commit ID for HACL* * update ACVP fuzzed test vector: refuzzed with current NSS * Softoken C_ calls should use system FIPS setting to select NSC_ or FC_ variants * NSS needs a database tool that can dump the low level representation of the database * declare string literals using char in pkixnames_tests.cpp * avoid implicit conversion for ByteString * update rust version for acvp docker * Moving the init function of the mpi_ints before clean-up in ec.c * P-256 ECDH and ECDSA from HACL* * Add ACVP test vectors to the repository * Stop relying on std::basic_string * Transpose the PPC_ABI check from Makefile to gyp Update to NSS 3.93: * Update zlib in NSS to 1.3. * softoken: iterate hashUpdate calls for long inputs. * regenerate NameConstraints test certificates (bsc#1214980). Update to NSS 3.92: * Set nssckbi version number to 2.62 * Add 4 Atos TrustedRoot Root CA certificates to NSS * Add 4 SSL.com Root CA certificates * Add Sectigo E46 and R46 Root CA certificates * Add LAWtrust Root CA2 (4096) * Remove E-Tugra Certification Authority root * Remove Camerfirma Chambers of Commerce Root. * Remove Hongkong Post Root CA 1 * Remove E-Tugra Global Root CA ECC v3 and RSA v3 * Avoid redefining BYTE_ORDER on hppa Linux Update to NSS 3.91: * Implementation of the HW support check for ADX instruction * Removing the support of Curve25519 * Fix comment about the addition of ticketSupportsEarlyData * Adding args to enable-legacy-db build * dbtests.sh failure in 'certutil dump keys with explicit default trust flags' * Initialize flags in slot structures * Improve the length check of RSA input to avoid heap overflow * Followup Fixes * avoid processing unexpected inputs by checking for m_exptmod base sign * add a limit check on order_k to avoid infinite loop * Update HACL* to commit 5f6051d2 * add SHA3 to cryptohi and softoken * HACL SHA3 * Disabling ASM C25519 for A but X86_64 Update to NSS 3.90.3: * GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME. * clean up escape handling. * remove redundant AllocItem implementation. * Disable ASM support for Curve25519. * Disable ASM support for Curve25519 for all but X86_64. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:3117-1 Released: Tue Sep 3 17:07:39 2024 Summary: Security update for tiff Type: security Severity: moderate References: 1228924,CVE-2024-7006 This update for tiff fixes the following issues: - CVE-2024-7006: Fixed null pointer dereference in tif_dirinfo.c (bsc#1228924) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:3131-1 Released: Tue Sep 3 17:42:24 2024 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1224113 This update for mozilla-nss fixes the following issues: - FIPS: Enforce approved curves with the CKK_EC_MONTGOMERY key type (bsc#1224113). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:3185-1 Released: Tue Sep 10 08:15:38 2024 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1226227 This update for cups fixes the following issues: - Fixed cupsd failing to authenticate users when group membership is required (bsc#1226227) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:3219-1 Released: Thu Sep 12 13:16:33 2024 Summary: Security update for colord Type: security Severity: moderate References: 1208056 This update for colord fixes the following issues: - Fixed a potential local privilege escalation by removing the script in the specfile which changes the ownership of /var/lib/colord. (bsc#1208056) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:3846-1 Released: Thu Oct 31 11:07:10 2024 Summary: Recommended update for gnutls Type: recommended Severity: moderate References: 1226724,1226731,1226733,1227642,1227669,1227670,1227671,1230166 This update for gnutls fixes the following issues: - FIPS: Do not allow curve P-192 for signature or keypair verification [bsc#1227669] - FIPS: Allow to perform the integrity check with the hmac provided by each library [bsc#1226724] - FIPS: Mark gnutls_hash_fast operations as approved in SLI. [bsc#1230166] - FIPS: Run pairwise consistency test only in FIPS mode. [bsc#1226733] - FIPS: Use full hash+sign operations, not low level primitives in PCT test. [bsc#1226733] - FIPS: Mark SHA1 as not allowed for signature verification in both RSA and ECDSA sigVer. [bsc#1227642] - FIPS: Allow RSA signature verification with min of 2048 bit modulus. [bsc#1227670] - FIPS: Remove not needed DSA in selfchecks in FIPS mode. [bsc#1227671, bsc#1226731] ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:4196-1 Released: Thu Dec 5 13:56:06 2024 Summary: Security update for avahi Type: security Severity: moderate References: 1233420,CVE-2024-52616 This update for avahi fixes the following issues: - CVE-2024-52616: Fixed Avahi Wide-Area DNS Predictable Transaction IDs (bsc#1233420) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:4244-1 Released: Fri Dec 6 14:04:39 2024 Summary: Recommended update for shared-mime-info Type: recommended Severity: moderate References: 1231463 This update for shared-mime-info fixes the following issue: - Uninstall silently if update-mime-database is not present (bsc#1231463). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:4254-1 Released: Fri Dec 6 18:03:05 2024 Summary: Security update for glib2 Type: security Severity: important References: 1231463,1233282,CVE-2024-52533 This update for glib2 fixes the following issues: Security issues fixed: - CVE-2024-52533: Fix a single byte buffer overflow in set_connect_msg() (bsc#1233282). Non-security issue fixed: - Fix error when uninstalling packages (bsc#1231463). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:31-1 Released: Tue Jan 7 15:44:10 2025 Summary: Security update for gtk3 Type: security Severity: important References: 1172879,1228120,CVE-2024-6655 This update for gtk3 fixes the following issues: - CVE-2024-6655: Fixed library injection from current working directory (bsc#1228120). Other fixes: - Updated to version 3.24.43 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:548-1 Released: Fri Feb 14 11:19:24 2025 Summary: Security update for libtasn1 Type: security Severity: important References: 1236878,CVE-2024-12133 This update for libtasn1 fixes the following issues: - CVE-2024-12133: the processing of input DER data containing a large number of SEQUENCE OF or SET OF elements takes quadratic time to complete. (bsc#1236878) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:753-1 Released: Fri Feb 28 17:30:35 2025 Summary: Security update for tiff Type: security Severity: moderate References: 1212607,1219213,1236834,CVE-2023-25435,CVE-2023-52356 This update for tiff fixes the following issues: - CVE-2023-25435: Heap-buffer-overflow in extractContigSamplesShifted8bits() in tiffcrop.c (bsc#1212607). - CVE-2023-52356: Segment fault in libtiff in TIFFReadRGBATileExt() leading to denial of service (bsc#1219213). Other bugfixes: - Fixed tiff build issue on s390x as test 12 test_directory fails (bsc#1236834). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:764-1 Released: Mon Mar 3 09:43:37 2025 Summary: Security update for gnutls Type: security Severity: moderate References: 1236974,CVE-2024-12243 This update for gnutls fixes the following issues: - CVE-2024-12243: quadratic complexity of DER input decoding in libtasn1 can lead to a DoS (bsc#1236974). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:794-1 Released: Thu Mar 6 07:59:29 2025 Summary: Recommended update for pkg-config Type: recommended Severity: important References: 1237374 This update for pkg-config fixes the following issues: - Build with system GLib instead of bundled GLib (bsc#1237374). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:820-1 Released: Mon Mar 10 15:17:28 2025 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1222834 This update for mozilla-nss fixes the following issues: - FIPS: Do not pass in bad targetKeyLength parameters when checking for FIPS approval after keygen. This was causing false rejections. - FIPS: Approve RSA signature verification mechanisms with PKCS padding and legacy moduli (bsc#1222834). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:1245-1 Released: Mon Apr 14 13:31:49 2025 Summary: Recommended update for pkg-config Type: recommended Severity: moderate References: 1237374 This update for rsync fixes the following issues: - Security scan found old glib in pkg-config (bsc#1237374). - This update for pkg-config changes attribute to the author who actually makes the change ----------------------------------------------------------------- Advisory ID: SUSE-OU-2025:1258-1 Released: Mon Apr 14 18:49:52 2025 Summary: Recommended update for dpdk Type: optional Severity: low References: 1219391 This update for gnome-color-manager, colord, gnome-online-accounts, libnma, NetworkManager-applet fixes the following issues: - Add non x86_64 binaries to SUSE Package Hub, no source change in any package. (bsc#1219391) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:1367-1 Released: Thu Apr 24 16:38:48 2025 Summary: Security update for glib2 Type: security Severity: moderate References: 1240897,CVE-2025-3360 This update for glib2 fixes the following issues: - CVE-2025-3360: Fixed integer overflow and buffer underread when parsing a very long and invalid ISO 8601 timestamp with g_date_time_new_from_iso8601() (bsc#1240897) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:1456-1 Released: Wed May 7 17:13:32 2025 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1241020,1241078,1241189,CVE-2025-29087,CVE-2025-29088,CVE-2025-3277 This update for sqlite3 fixes the following issues: - CVE-2025-29087,CVE-2025-3277: Fixed integer overflow in sqlite concat function (bsc#1241020) - CVE-2025-29088: Fixed integer overflow through the SQLITE_DBCONFIG_LOOKASIDE component (bsc#1241078) Other fixes: - Updated to version 3.49.1 from Factory (jsc#SLE-16032) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2167-1 Released: Mon Jun 30 09:14:40 2025 Summary: Security update for glib2 Type: security Severity: important References: 1242844,1244596,CVE-2025-4373,CVE-2025-6052 This update for glib2 fixes the following issues: - CVE-2025-6052: Fixed integer overflow in g_string_maybe_expand() leads to potential buffer overflow in GString (bsc#1244596). - CVE-2025-4373: Fixed buffer underflow through glib/gstring.c via function g_string_insert_unichar (bsc#1242844). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2260-1 Released: Wed Jul 9 19:04:24 2025 Summary: Security update for libxml2 Type: security Severity: important References: 1244554,1244555,1244557,1244590,1244700,CVE-2025-49794,CVE-2025-49795,CVE-2025-49796,CVE-2025-6021,CVE-2025-6170 This update for libxml2 fixes the following issues: - CVE-2025-49794: Fixed a heap use after free which could lead to denial of service. (bsc#1244554) - CVE-2025-49796: Fixed type confusion which could lead to denial of service. (bsc#1244557) - CVE-2025-49795: Fixed a null pointer dereference which could lead to denial of service. (bsc#1244555) - CVE-2025-6170: Fixed a stack buffer overflow which could lead to a crash. (bsc#1244700) - CVE-2025-6021: Fixed an integer overflow in xmlBuildQName() which could lead to stack buffer overflow. (bsc#1244590) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2274-1 Released: Thu Jul 10 14:35:40 2025 Summary: Recommended update for mozilla-nspr, mozilla-nss Type: recommended Severity: moderate References: 1081723,1224113 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nss was updated to NSS 3.112: * Fix alias for mac workers on try * ensure all options can be configured with SSL_OptionSet and SSL_OptionSetDefault * ABI/API break in ssl certificate processing * remove unnecessary assertion in sec_asn1d_init_state_based_on_template * bmo#1965754 Update taskgraph to v14.2.1 * Workflow for automation of the release on GitHub when pushing a tag * fix faulty assertions in SEC_ASN1DecoderUpdate * Renegotiations should use a fresh ECH GREASE buffer * bmo#1951396 Update taskgraph to v14.1.1 * Partial fix for ACVP build CI job * Initialize find in sftk_searchDatabase * Add clang-18 to extra builds * Fault tolerant git fetch for fuzzing * Tolerate intermittent failures in ssl_policy_pkix_ocsp * fix compiler warnings when DEBUG_ASN1D_STATES or CMSDEBUG are set * fix content type tag check in NSS_CMSMessage_ContainsCertsOrCrls * Remove Cryptofuzz CI version check Update to NSS 3.111: * FIPS changes need to be upstreamed: force ems policy * Turn off Websites Trust Bit from CAs * Update nssckbi version following April 2025 Batch of Changes * Disable SMIME ???trust bit??? for GoDaddy CAs * Replaced deprecated sprintf function with snprintf in dbtool.c * Need up update NSS for PKCS 3.1 * avoid leaking localCert if it is already set in ssl3_FillInCachedSID * Decrease ASAN quarantine size for Cryptofuzz in CI * selfserv: Add support for zlib certificate compression Update to NSS 3.110: * FIPS changes need to be upstreamed: force ems policy * Prevent excess allocations in sslBuffer_Grow * Remove Crl templates from ASN1 fuzz target * Remove CERT_CrlTemplate from ASN1 fuzz target * Fix memory leak in NSS_CMSMessage_IsSigned * NSS policy updates * Improve locking in nssPKIObject_GetInstances * Fix race in sdb_GetMetaData * Fix member access within null pointer * Increase smime fuzzer memory limit * Enable resumption when using custom extensions * change CN of server12 test certificate * Part 2: Add missing check in NSS_CMSDigestContext_FinishSingle * Part 1: Fix smime UBSan errors * FIPS changes need to be upstreamed: updated key checks * Don't build libpkix in static builds * handle `-p all` in try syntax * fix opt-make builds to actually be opt * fix opt-static builds to actually be opt * Remove extraneous assert Update to NSS 3.109: * Call BL_Init before RNG_RNGInit() so that special SHA instructions can be used if available * NSS policy updates - fix inaccurate key policy issues * SMIME fuzz target * ASN1 decoder fuzz target * Part 2: Revert ???Extract testcases from ssl gtests for fuzzing??? * Add fuzz/README.md * Part 4: Fix tstclnt arguments script * Extend pkcs7 fuzz target * Extend certDN fuzz target * revert changes to HACL* files from bug 1866841 * Part 3: Package frida corpus script Update to NSS 3.108: * libclang-16 -> libclang-19 * Turn off Secure Email Trust Bit for Security Communication ECC RootCA1 * Turn off Secure Email Trust Bit for BJCA Global Root CA1 and BJCA Global Root CA2 * Remove SwissSign Silver CA ??? G2 * Add D-Trust 2023 TLS Roots to NSS * fix fips test failure on windows * change default sensitivity of KEM keys * Part 1: Introduce frida hooks and script * add missing arm_neon.h include to gcm.c * ci: update windows workers to win2022 * strip trailing carriage returns in tools tests * work around unix/windows path translation issues in cert test script * ci: let the windows setup script work without $m * detect msys * add a specialized CTR_Update variant for AES-GCM * NSS policy updates * FIPS changes need to be upstreamed: FIPS 140-3 RNG * FIPS changes need to be upstreamed: Add SafeZero * FIPS changes need to be upstreamed Updated POST * Segmentation fault in SECITEM_Hash during pkcs12 processing * Extending NSS with LoadModuleFromFunction functionality * Ensure zero-initialization of collectArgs.cert * pkcs7 fuzz target use CERT_DestroyCertificate * Fix actual underlying ODR violations issue * mozilla::pkix: allow reference ID labels to begin and/or end with hyphens * don't look for secmod.db in nssutil_ReadSecmodDB if NSS_DISABLE_DBM is set * Fix memory leak in pkcs7 fuzz target * Set -O2 for ASan builds in CI * Change branch of tlsfuzzer dependency * Run tests in CI for ASan builds with detect_odr_violation=1 * Fix coverage failure in CI * Add fuzzing for delegated credentials, DTLS short header and Tls13BackendEch * Add fuzzing for SSL_EnableTls13GreaseEch and SSL_SetDtls13VersionWorkaround * Part 3: Restructure fuzz/ * Extract testcases from ssl gtests for fuzzing * Force Cryptofuzz to use NSS in CI * Fix Cryptofuzz on 32 bit in CI * Update Cryptofuzz repository link * fix build error from 9505f79d * simplify error handling in get_token_objects_for_cache * nss doc: fix a warning * pkcs12 fixes from RHEL need to be picked up Update to NSS 3.107: * Remove MPI fuzz targets. * Remove globals `lockStatus` and `locksEverDisabled`. * Enable PKCS8 fuzz target. * Integrate Cryptofuzz in CI. * Part 2: Set tls server target socket options in config class * Part 1: Set tls client target socket options in config class * Support building with thread sanitizer. * set nssckbi version number to 2.72. * remove Websites Trust Bit from Entrust Root Certification Authority - G4. * remove Security Communication RootCA3 root cert. * remove SecureSign RootCA11 root cert. * Add distrust-after for TLS to Entrust Roots. * bmo#1927096 Update expected error code in pk12util pbmac1 tests. * Use random tstclnt args with handshake collection script * Remove extraneous assert in ssl3gthr.c. * Adding missing release notes for NSS_3_105. * Enable the disabled mlkem tests for dtls. * NSS gtests filter cleans up the constucted buffer before the use. * Make ssl_SetDefaultsFromEnvironment thread-safe. * Remove short circuit test from ssl_Init. Update to NSS 3.106: * NSS 3.106 should be distributed with NSPR 4.36. * pk12util: improve error handling in p12U_ReadPKCS12File. * Correctly destroy bulkkey in error scenario. * PKCS7 fuzz target, r=djackson,nss-reviewers. * Extract certificates with handshake collection script. * Specify len_control for fuzz targets. * Fix memory leak in dumpCertificatePEM. * Fix UBSan errors for SECU_PrintCertificate and SECU_PrintCertificateBasicInfo. * add new error codes to mozilla::pkix for Firefox to use. * allow null phKey in NSC_DeriveKey. * Only create seed corpus zip from existing corpus. * Use explicit allowlist for for KDF PRFS. * Increase optimization level for fuzz builds. * Remove incorrect assert. * Use libFuzzer options from fuzz/options/\*.options in CI. * Polish corpus collection for automation. * Detect new and unfuzzed SSL options. * PKCS12 fuzzing target. Update to NSS 3.105: * Allow importing PKCS#8 private EC keys missing public key * UBSAN fix: applying zero offset to null pointer in sslsnce.c * set KRML_MUSTINLINE=inline in makefile builds * Don't set CKA_SIGN for CKK_EC_MONTGOMERY private keys * override default definition of KRML_MUSTINLINE * libssl support for mlkem768x25519 * support for ML-KEM-768 in softoken and pk11wrap * Add Libcrux implementation of ML-KEM 768 to FreeBL * Avoid misuse of ctype(3) functions * part 2: run clang-format * part 1: upgrade to clang-format 13 * clang-format fuzz * DTLS client message buffer may not empty be on retransmit * Optionally print config for TLS client and server fuzz target * Fix some simple documentation issues in NSS. * improve performance of NSC_FindObjectsInit when template has CKA_TOKEN attr * define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN Update to NSS 3.104: * Copy original corpus to heap-allocated buffer * Fix min ssl version for DTLS client fuzzer * Remove OS2 support just like we did on NSPR * clang-format NSS improvements * Adding basicutil.h to use HexString2SECItem function * removing dirent.c from build * Allow handing in keymaterial to shlibsign to make the output reproducible * remove nec4.3, sunos4, riscos and SNI references * remove other old OS (BSDI, old HP UX, NCR, openunix, sco, unixware or reliantUnix * remove mentions of WIN95 * remove mentions of WIN16 * More explicit directory naming * Add more options to TLS server fuzz target * Add more options to TLS client fuzz target * Use OSS-Fuzz corpus in NSS CI * set nssckbi version number to 2.70. * Remove Email Trust bit from ACCVRAIZ1 root cert. * Remove Email Trust bit from certSIGN ROOT CA. * Add Cybertrust Japan Roots to NSS. * Add Taiwan CA Roots to NSS. * remove search by decoded serial in nssToken_FindCertificateByIssuerAndSerialNumber * Fix tstclnt CI build failure * vfyserv: ensure peer cert chain is in db for CERT_VerifyCertificateNow * Enable all supported protocol versions for UDP * Actually use random PSK hash type * Initialize NSS DB once * Additional ECH cipher suites and PSK hash types * Automate corpus file generation for TLS client Fuzzer * Fix crash with UNSAFE_FUZZER_MODE * clang-format shlibsign.c Update to NSS 3.103: * move list size check after lock acquisition in sftk_PutObjectToList. * Add fuzzing support for SSL_ENABLE_POST_HANDSHAKE_AUTH, * Adjust libFuzzer size limits * Add fuzzing support for SSL_SetCertificateCompressionAlgorithm, SSL_SetClientEchConfigs, SSL_VersionRangeSet and SSL_AddExternalPsk * Add fuzzing support for SSL_ENABLE_GREASE and SSL_ENABLE_CH_EXTENSION_PERMUTATION - Make the rpms reproducible, by using a hardcoded, static key to generate the checksums (*.chk-files) - FIPS: enforce approved curves with the CKK_EC_MONTGOMERY key type (bsc#1224113). Update to NSS 3.102.1: * ChaChaXor to return after the function Update to NSS 3.102: * Add Valgrind annotations to freebl Chacha20-Poly1305. * missing sqlite header. * GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME. * improve certutil keyUsage, extKeyUsage, and nsCertType keyword handling. * correct length of raw SPKI data before printing in pp utility. - Make NSS-build reproducible. Use key from openssl (bsc#1081723) - Exclude the SHA-1 hash from SLI approval. mozilla-nspr was updated to version 4.36: * renamed the prwin16.h header to prwin.h * various build, test and automation script fixes * major parts of the source code were reformatted ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2287-1 Released: Fri Jul 11 11:26:25 2025 Summary: Recommended update for Mesa Type: recommended Severity: important References: 1241701,1245034 This update for Mesa fixes the following issues: - Fixes Wayland session when using SP7 as vmware guest (bsc#1245034) - Fixes crash in libgallium on virtualbox (bsc#1241701) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2323-1 Released: Wed Jul 16 04:07:18 2025 Summary: Recommended update for mozilla-nspr, mozilla-nss Type: recommended Severity: moderate References: 1081723,1224113 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nss was updated to NSS 3.112: * Fix alias for mac workers on try * ensure all options can be configured with SSL_OptionSet and SSL_OptionSetDefault * ABI/API break in ssl certificate processing * remove unnecessary assertion in sec_asn1d_init_state_based_on_template * update taskgraph to v14.2.1 * Workflow for automation of the release on GitHub when pushing a tag * fix faulty assertions in SEC_ASN1DecoderUpdate * Renegotiations should use a fresh ECH GREASE buffer * update taskgraph to v14.1.1 * Partial fix for ACVP build CI job * Initialize find in sftk_searchDatabase * Add clang-18 to extra builds * Fault tolerant git fetch for fuzzing * Tolerate intermittent failures in ssl_policy_pkix_ocsp * fix compiler warnings when DEBUG_ASN1D_STATES or CMSDEBUG are set * fix content type tag check in NSS_CMSMessage_ContainsCertsOrCrls * Remove Cryptofuzz CI version check Update to NSS 3.111: * FIPS changes need to be upstreamed: force ems policy * Turn off Websites Trust Bit from CAs * Update nssckbi version following April 2025 Batch of Changes * Disable SMIME ???trust bit??? for GoDaddy CAs * Replaced deprecated sprintf function with snprintf in dbtool.c * Need up update NSS for PKCS 3.1 * avoid leaking localCert if it is already set in ssl3_FillInCachedSID * Decrease ASAN quarantine size for Cryptofuzz in CI * selfserv: Add support for zlib certificate compression Update to NSS 3.110: * FIPS changes need to be upstreamed: force ems policy * Prevent excess allocations in sslBuffer_Grow * Remove Crl templates from ASN1 fuzz target * Remove CERT_CrlTemplate from ASN1 fuzz target * Fix memory leak in NSS_CMSMessage_IsSigned * NSS policy updates * Improve locking in nssPKIObject_GetInstances * Fix race in sdb_GetMetaData * Fix member access within null pointer * Increase smime fuzzer memory limit * Enable resumption when using custom extensions * change CN of server12 test certificate * Part 2: Add missing check in NSS_CMSDigestContext_FinishSingle * Part 1: Fix smime UBSan errors * FIPS changes need to be upstreamed: updated key checks * Don't build libpkix in static builds * handle `-p all` in try syntax * fix opt-make builds to actually be opt * fix opt-static builds to actually be opt * Remove extraneous assert Update to NSS 3.109: * Call BL_Init before RNG_RNGInit() so that special SHA instructions can be used if available * NSS policy updates - fix inaccurate key policy issues * SMIME fuzz target * ASN1 decoder fuzz target * Part 2: Revert ???Extract testcases from ssl gtests for fuzzing??? * Add fuzz/README.md * Part 4: Fix tstclnt arguments script * Extend pkcs7 fuzz target * Extend certDN fuzz target * revert changes to HACL* files from bug 1866841 * Part 3: Package frida corpus script Update to NSS 3.108: * libclang-16 -> libclang-19 * Turn off Secure Email Trust Bit for Security Communication ECC RootCA1 * Turn off Secure Email Trust Bit for BJCA Global Root CA1 and BJCA Global Root CA2 * Remove SwissSign Silver CA ??? G2 * Add D-Trust 2023 TLS Roots to NSS * fix fips test failure on windows * change default sensitivity of KEM keys * Part 1: Introduce frida hooks and script * add missing arm_neon.h include to gcm.c * ci: update windows workers to win2022 * strip trailing carriage returns in tools tests * work around unix/windows path translation issues in cert test script * ci: let the windows setup script work without $m * detect msys * add a specialized CTR_Update variant for AES-GCM * NSS policy updates * FIPS changes need to be upstreamed: FIPS 140-3 RNG * FIPS changes need to be upstreamed: Add SafeZero * FIPS changes need to be upstreamed - updated POST * Segmentation fault in SECITEM_Hash during pkcs12 processing * Extending NSS with LoadModuleFromFunction functionality * Ensure zero-initialization of collectArgs.cert * pkcs7 fuzz target use CERT_DestroyCertificate * Fix actual underlying ODR violations issue * mozilla::pkix: allow reference ID labels to begin and/or end with hyphens * don't look for secmod.db in nssutil_ReadSecmodDB if NSS_DISABLE_DBM is set * Fix memory leak in pkcs7 fuzz target * Set -O2 for ASan builds in CI * Change branch of tlsfuzzer dependency * Run tests in CI for ASan builds with detect_odr_violation=1 * Fix coverage failure in CI * Add fuzzing for delegated credentials, DTLS short header and Tls13BackendEch * Add fuzzing for SSL_EnableTls13GreaseEch and SSL_SetDtls13VersionWorkaround * Part 3: Restructure fuzz/ * Extract testcases from ssl gtests for fuzzing * Force Cryptofuzz to use NSS in CI * Fix Cryptofuzz on 32 bit in CI * Update Cryptofuzz repository link * fix build error from 9505f79d * simplify error handling in get_token_objects_for_cache * nss doc: fix a warning * pkcs12 fixes from RHEL need to be picked up Update to NSS 3.107: * Remove MPI fuzz targets. * Remove globals `lockStatus` and `locksEverDisabled`. * Enable PKCS8 fuzz target. * Integrate Cryptofuzz in CI. * Part 2: Set tls server target socket options in config class * Part 1: Set tls client target socket options in config class * Support building with thread sanitizer. * set nssckbi version number to 2.72. * remove Websites Trust Bit from Entrust Root Certification Authority - G4. * remove Security Communication RootCA3 root cert. * remove SecureSign RootCA11 root cert. * Add distrust-after for TLS to Entrust Roots. * update expected error code in pk12util pbmac1 tests. * Use random tstclnt args with handshake collection script * Remove extraneous assert in ssl3gthr.c. * Adding missing release notes for NSS_3_105. * Enable the disabled mlkem tests for dtls. * NSS gtests filter cleans up the constucted buffer before the use. * Make ssl_SetDefaultsFromEnvironment thread-safe. * Remove short circuit test from ssl_Init. Update to NSS 3.106: * NSS 3.106 should be distributed with NSPR 4.36. * pk12util: improve error handling in p12U_ReadPKCS12File. * Correctly destroy bulkkey in error scenario. * PKCS7 fuzz target, r=djackson,nss-reviewers. * Extract certificates with handshake collection script. * Specify len_control for fuzz targets. * Fix memory leak in dumpCertificatePEM. * Fix UBSan errors for SECU_PrintCertificate and SECU_PrintCertificateBasicInfo. * add new error codes to mozilla::pkix for Firefox to use. * allow null phKey in NSC_DeriveKey. * Only create seed corpus zip from existing corpus. * Use explicit allowlist for for KDF PRFS. * Increase optimization level for fuzz builds. * Remove incorrect assert. * Use libFuzzer options from fuzz/options/\*.options in CI. * Polish corpus collection for automation. * Detect new and unfuzzed SSL options. * PKCS12 fuzzing target. Update to NSS 3.105: * Allow importing PKCS#8 private EC keys missing public key * UBSAN fix: applying zero offset to null pointer in sslsnce.c * set KRML_MUSTINLINE=inline in makefile builds * Don't set CKA_SIGN for CKK_EC_MONTGOMERY private keys * override default definition of KRML_MUSTINLINE * libssl support for mlkem768x25519 * support for ML-KEM-768 in softoken and pk11wrap * Add Libcrux implementation of ML-KEM 768 to FreeBL * Avoid misuse of ctype(3) functions * part 2: run clang-format * part 1: upgrade to clang-format 13 * clang-format fuzz * DTLS client message buffer may not empty be on retransmit * Optionally print config for TLS client and server fuzz target * Fix some simple documentation issues in NSS. * improve performance of NSC_FindObjectsInit when template has CKA_TOKEN attr * define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN Update to NSS 3.104: * Copy original corpus to heap-allocated buffer * Fix min ssl version for DTLS client fuzzer * Remove OS2 support just like we did on NSPR * clang-format NSS improvements * Adding basicutil.h to use HexString2SECItem function * removing dirent.c from build * Allow handing in keymaterial to shlibsign to make the output reproducible * remove nec4.3, sunos4, riscos and SNI references * remove other old OS (BSDI, old HP UX, NCR, openunix, sco, unixware or reliantUnix * remove mentions of WIN95 * remove mentions of WIN16 * More explicit directory naming * Add more options to TLS server fuzz target * Add more options to TLS client fuzz target * Use OSS-Fuzz corpus in NSS CI * set nssckbi version number to 2.70. * Remove Email Trust bit from ACCVRAIZ1 root cert. * Remove Email Trust bit from certSIGN ROOT CA. * Add Cybertrust Japan Roots to NSS. * Add Taiwan CA Roots to NSS. * remove search by decoded serial in nssToken_FindCertificateByIssuerAndSerialNumber * Fix tstclnt CI build failure * vfyserv: ensure peer cert chain is in db for CERT_VerifyCertificateNow * Enable all supported protocol versions for UDP * Actually use random PSK hash type * Initialize NSS DB once * Additional ECH cipher suites and PSK hash types * Automate corpus file generation for TLS client Fuzzer * Fix crash with UNSAFE_FUZZER_MODE * clang-format shlibsign.c Update to NSS 3.103: * move list size check after lock acquisition in sftk_PutObjectToList. * Add fuzzing support for SSL_ENABLE_POST_HANDSHAKE_AUTH, * Follow-up to fix test for presence of file nspr.patch. * Adjust libFuzzer size limits * Add fuzzing support for SSL_SetCertificateCompressionAlgorithm, SSL_SetClientEchConfigs, SSL_VersionRangeSet and SSL_AddExternalPsk * Add fuzzing support for SSL_ENABLE_GREASE and SSL_ENABLE_CH_EXTENSION_PERMUTATION - Make the rpms reproducible, by using a hardcoded, static key to generate the checksums (*.chk-files) - FIPS: enforce approved curves with the CKK_EC_MONTGOMERY key type (bsc#1224113). Update to NSS 3.102.1: * ChaChaXor to return after the function Update to NSS 3.102: * Add Valgrind annotations to freebl Chacha20-Poly1305. * missing sqlite header. * GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME. * improve certutil keyUsage, extKeyUsage, and nsCertType keyword handling. * correct length of raw SPKI data before printing in pp utility. - Make NSS-build reproducible Use key from openssl (bsc#1081723) - FIPS: exclude the SHA-1 hash from SLI approval. mozilla-nspr was updated to version 4.36: * renamed the prwin16.h header to prwin.h * configure was updated from 2.69 to 2.71 * various build, test and automation script fixes * major parts of the source code were reformatted ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2595-1 Released: Fri Aug 1 17:13:59 2025 Summary: Security update for gnutls Type: security Severity: important References: 1246232,1246233,1246267,1246299,CVE-2025-32988,CVE-2025-32989,CVE-2025-32990,CVE-2025-6395 This update for gnutls fixes the following issues: - CVE-2025-6395: Fix NULL pointer dereference when 2nd Client Hello omits PSK (bsc#1246299) - CVE-2025-32988: Fix double-free due to incorrect ownership handling in the export logic of SAN entries containing an otherName (bsc#1246232) - CVE-2025-32989: Fix heap buffer overread when handling the CT SCT extension during X.509 certificate parsing (bsc#1246233) - CVE-2025-32990: Fix 1-byte heap buffer overflow when parsing templates with certtool (bsc#1246267) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2617-1 Released: Mon Aug 4 09:04:59 2025 Summary: Security update for libxml2 Type: security Severity: important References: 1246296,CVE-2025-7425 This update for libxml2 fixes the following issues: - CVE-2025-7425: Fixed heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr (bsc#1246296) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2672-1 Released: Mon Aug 4 15:06:13 2025 Summary: Security update for sqlite3 Type: security Severity: important References: 1246597,CVE-2025-6965 This update for sqlite3 fixes the following issues: - Update to version 3.50.2 - CVE-2025-6965: Fixed an integer truncation to avoid assertion faults. (bsc#1246597) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2770-1 Released: Tue Aug 12 15:50:12 2025 Summary: Security update for tiff Type: security Severity: important References: 1243503,1247106,1247108,CVE-2025-8176,CVE-2025-8177 This update for tiff fixes the following issues: - Updated TIFFMergeFieldInfo() with read_count=write_count=0 for FIELD_IGNORE (bsc#1243503) - CVE-2025-8176: Fixed heap use-after-free in tools/tiffmedian.c (bsc#1247108) - CVE-2025-8177: Fixed possible buffer overflow in tools/thumbnail.c:setrow() when processing malformed TIFF files (bsc#1247106) - Add -DCMAKE_POLICY_VERSION_MINIMUM=3.5 to fix FTBFS with cmake4 - Add %check section - Remove Group: declarations, no longer used ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2954-1 Released: Thu Aug 21 15:42:53 2025 Summary: Security update for gdk-pixbuf Type: security Severity: important References: 1245227,1246114,CVE-2025-6199,CVE-2025-7345 This update for gdk-pixbuf fixes the following issues: - CVE-2025-6199: Fixed uninitialized memory leading to arbitrary memory contents leak (bsc#1245227) - CVE-2025-7345: Fixed heap buffer overflow within the gdk_pixbuf__jpeg_image_load_increment function (bsc#1246114) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3261-1 Released: Thu Sep 18 06:35:19 2025 Summary: Security update for cups Type: security Severity: important References: 1230932,1246533,1249049,1249128,CVE-2024-47175,CVE-2025-58060,CVE-2025-58364 This update for cups fixes the following issues: - CVE-2024-47175: no validation of IPP attributes in `ppdCreatePPDFromIPP2` when writing to a temporary PPD file allows for the injection of attacker-controlled data to the resulting PPD (bsc#1230932). - CVE-2025-58060: no password check when `AuthType` is set to anything but `Basic` and a request is made with an `Authorization: Basic` header (bsc#1249049). - CVE-2025-58364: unsafe deserialization and validation of printer attributes leads to NULL pointer dereference (bsc#1249128). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3286-1 Released: Mon Sep 22 08:02:27 2025 Summary: Recommended update for gtk3 Type: recommended Severity: moderate References: 1247503 This update for gtk3 fixes the following issues: - Fixed issue with window dimensions (bsc#1247503) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3333-1 Released: Wed Sep 24 08:55:10 2025 Summary: Security update for avahi Type: security Severity: moderate References: 1233421,CVE-2024-52615 This update for avahi fixes the following issues: - CVE-2024-52615: wide-area DNS uses constant source port for queries and can expose the Avahi-daemon to DNS spoofing attacks (bsc#1233421). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3348-1 Released: Wed Sep 24 16:05:03 2025 Summary: Security update for tiff Type: security Severity: moderate References: 1247581,1247582,1248117,1248330,CVE-2024-13978,CVE-2025-8534,CVE-2025-8961,CVE-2025-9165 This update for tiff fixes the following issues: - CVE-2025-9165: local execution manipulation leading to memory leak (bsc#1248330). - CVE-2024-13978: null pointer dereference in component fax2ps (bsc#1247581) - CVE-2025-8534: null pointer dereference in function PS_Lvl2page (bsc#1247582). - CVE-2025-8961: segmentation fault via main function of tiffcrop utility (bsc#1248117). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3449-1 Released: Thu Oct 2 09:15:17 2025 Summary: Security update for cairo Type: security Severity: low References: 1247589,CVE-2025-50422 This update for cairo fixes the following issues: - CVE-2025-50422: Fixed Poppler crash on malformed input (bsc#1247589) - Update to version 1.18.4: + The dependency on LZO has been made optional through a build time configuration toggle. + You can build Cairo against a Freetype installation that does not have the FT_Color type. + Cairo tests now build on Solaris 11.4 with GCC 14. + The DirectWrite backend now builds on MINGW 11. + The DirectWrite backend now supports font variations and proper glyph coverage. - Use tarball in lieu of source service due to freedesktop gitlab migration, will switch back at next release at the latest. - Add pkgconfig(lzo2) BuildRequires: New optional dependency, build lzo2 support feature. - Convert to source service: allows for easier upgrades by the GNOME team. - Update to version 1.18.2: + The malloc-stats code has been removed from the tests directory + Cairo now requires a version of pixman equal to, or newer than, 0.40. + There have been multiple build fixes for newer versions of GCC for MSVC; for Solaris; and on macOS 10.7. + PNG errors caused by loading malformed data are correctly propagated to callers, so they can handle the case. + Both stroke and fill colors are now set when showing glyphs on a PDF surface. + All the font options are copied when creating a fallback font object. + When drawing text on macOS, Cairo now tries harder to select the appropriate font name. + Cairo now prefers the COLRv1 table inside a font, if one is available. + Cairo requires a C11 toolchain when building. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3804-1 Released: Mon Oct 27 12:35:04 2025 Summary: Security update for mozilla-nss Type: security Severity: important References: 1251263,CVE-2025-9187 This update for mozilla-nss fixes the following issues: - Move NSS DB password hash away from SHA-1 Update to NSS 3.112.2: * Prevent leaks during pkcs12 decoding. * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates Update to NSS 3.112.1: * restore support for finding certificates by decoded serial number. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3949-1 Released: Wed Nov 5 11:04:35 2025 Summary: Security update for colord Type: security Severity: moderate References: 1250750,CVE-2021-42523 This update for colord fixes the following issues: - CVE-2021-42523: The original fix was wrong and did not properly free the error, resulting in a crash that has now been addressed (bsc#1250750). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3957-1 Released: Wed Nov 5 16:45:18 2025 Summary: Security update for tiff Type: security Severity: important References: 1248278,1250413,CVE-2025-8851,CVE-2025-9900 This update for tiff fixes the following issues: Update to 4.7.1: - CVE-2025-8851: Fixed stack-based buffer overflow (bsc#1248278). - CVE-2025-9900: Fixed write-what-where via TIFFReadRGBAImageOriented (bsc#1250413). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3982-1 Released: Thu Nov 6 19:21:10 2025 Summary: Recommended update for lcms2 Type: recommended Severity: moderate References: 1247985 This update for lcms2 fixes the following issue: - Enable threads support and avoid linker errors (bsc#1247985). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4179-1 Released: Mon Nov 24 08:27:54 2025 Summary: Recommended update for mozilla-nspr Type: recommended Severity: moderate References: This update for mozilla-nspr fixes the following issues: - update to NSPR 4.36.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.36.1 - update to NSPR 4.36.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4092-1 Released: Mon Nov 24 10:08:22 2025 Summary: Security update for elfutils Type: security Severity: moderate References: 1237236,1237240,1237241,1237242,CVE-2025-1352,CVE-2025-1372,CVE-2025-1376,CVE-2025-1377 This update for elfutils fixes the following issues: - Fixing build/testsuite for more recent glibc and kernels. - Fixing denial of service and general buffer overflow errors (bsc#1237236, bsc#1237240, bsc#1237241, bsc#1237242): - CVE-2025-1376: Fixed denial of service in function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip - CVE-2025-1377: Fixed denial of service in function gelf_getsymshndx of the file strip.c of the component eu-strip - CVE-2025-1372: Fixed buffer overflow in function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf - CVE-2025-1352: Fixed SEGV (illegal read access) in function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf - Fixing testsuite race conditions in run-debuginfod-find.sh. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4290-1 Released: Fri Nov 28 10:04:11 2025 Summary: Security update for cups Type: security Severity: moderate References: 1234225,1244057,1253783,CVE-2025-58436,CVE-2025-61915 This update for cups fixes the following issues: - CVE-2025-61915: Fixed a local denial-of-service via cupsd.conf update and related issues. (bsc#1253783) - CVE-2025-58436: Fixed an issue where a slow client communication leads to a possible DoS attack. (bsc#1244057) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4308-1 Released: Fri Nov 28 16:38:46 2025 Summary: Security update for glib2 Type: security Severity: moderate References: 1249055,CVE-2025-7039 This update for glib2 fixes the following issues: - CVE-2025-7039: Fixed buffer under-read on glib through glib/gfileutils.c via get_tmp_file() (bsc#1249055) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4319-1 Released: Wed Dec 3 13:34:00 2025 Summary: Security update for cups Type: security Severity: important References: 1254353,CVE-2025-58436 This update for cups fixes the following issues: - The fix for CVE-2025-58436 causes a regression where GTK applications will hang. (bsc#1254353) See also https://github.com/OpenPrinting/cups/issues/1429 The fix has been temporary disabled. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4323-1 Released: Mon Dec 8 19:14:15 2025 Summary: Security update for gnutls Type: security Severity: moderate References: 1254132,CVE-2025-9820 This update for gnutls fixes the following issues: - CVE-2025-9820: Fixed buffer overflow in gnutls_pkcs11_token_init. (bsc#1254132) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4425-1 Released: Wed Dec 17 12:20:02 2025 Summary: Security update for cups Type: security Severity: moderate References: 1244057,1254353,CVE-2025-58436 This update for cups fixes the following issues: Security issues fixed: - CVE-2025-58436: single client sending slow messages to cupsd can delay the application and make it unusable for other clients (bsc#1244057). Other issues fixed: - Update the CVE-2025-58436 patch to fix a regression that causes GTK applications to hang (bsc#1254353). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:18-1 Released: Mon Jan 5 11:52:25 2026 Summary: Security update for glib2 Type: security Severity: important References: 1254297,1254662,1254878,CVE-2025-13601,CVE-2025-14087,CVE-2025-14512 This update for glib2 fixes the following issues: - CVE-2025-14512: integer overflow in the GIO `escape_byte_string()` function when processing malicious files or remote filesystem attribute values can lead to denial-of-service (bsc#1254878). - CVE-2025-14087: buffer underflow in the GVariant parser `bytestring_parse()` and `string_parse()`functions when processing attacker-influenced data may lead to crash or code execution (bsc#1254662). - CVE-2025-13601: heap-based buffer overflow in the `g_escape_uri_string()` function when processing strings with a large number of unacceptable characters may lead to crash or code execution (bsc#1254297). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:224-1 Released: Thu Jan 22 13:18:20 2026 Summary: Security update for libtasn1 Type: security Severity: moderate References: 1256341,CVE-2025-13151 This update for libtasn1 fixes the following issues: - CVE-2025-13151: stack-based buffer overflow in `asn1_expend_octet_string` (bsc#1256341). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:243-1 Released: Thu Jan 22 14:57:36 2026 Summary: Security update for librsvg Type: security Severity: moderate References: 1243867,CVE-2024-12224 This update for librsvg fixes the following issues: Update to version 2.57.4 - bsc#1243867: + CVE-2024-12224: RUSTSEC-2024-0421 - idna accepts Punycode labels that do not produce any non-ASCII when decoded. + RUSTSEC-2024-0404 - Unsoundness in anstream. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:259-1 Released: Thu Jan 22 17:10:44 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1256498,1256499,1256500,CVE-2025-68276,CVE-2025-68468,CVE-2025-68471 This update for avahi fixes the following issues: - CVE-2025-68276: Fixed refuse to create wide-area record browsers when wide-area is off (bsc#1256498) - CVE-2025-68471: Fixed DoS bug by changing assert to return (bsc#1256500) - CVE-2025-68468: Fixed DoS bug by removing incorrect assertion (bsc#1256499) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:286-1 Released: Sat Jan 24 00:35:35 2026 Summary: Security update for glib2 Type: security Severity: low References: 1257049,CVE-2026-0988 This update for glib2 fixes the following issues: - CVE-2026-0988: Fixed a potential integer overflow in g_buffered_input_stream_peek (bsc#1257049). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:287-1 Released: Sat Jan 24 00:35:49 2026 Summary: Security update for harfbuzz Type: security Severity: moderate References: 1256459,CVE-2026-22693 This update for harfbuzz fixes the following issues: - CVE-2026-22693: Fixed a NULL pointer dereference in SubtableUnicodesCache::create (bsc#1256459). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:373-1 Released: Wed Feb 4 03:50:41 2026 Summary: Security update for glib2 Type: security Severity: important References: 1257353,1257354,1257355,CVE-2026-1484,CVE-2026-1485,CVE-2026-1489 This update for glib2 fixes the following issues: - CVE-2026-1485: Fixed buffer underflow and out-of-bounds access due to integer wraparound in content type parsing (bsc#1257354). - CVE-2026-1484: Fixed buffer underflow and out-of-bounds access due to miscalculated buffer boundaries in the Base64 encoding routine (bsc#1257355). - CVE-2026-1489: Fixed undersized heap allocation followed by out-of-bounds access due to integer overflow in Unicode case conversion (bsc#1257353). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:432-1 Released: Wed Feb 11 10:11:56 2026 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1248586,1254670,CVE-2025-7709 This update for sqlite3 fixes the following issues: - Update to v3.51.2: - CVE-2025-7709: Fixed an integer overflow in the FTS5 extension. (bsc#1254670) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:605-1 Released: Tue Feb 24 12:19:11 2026 Summary: Security update for libxml2 Type: security Severity: moderate References: 1247850,1247858,1250553,1256804,1256805,1256807,1256808,1256809,1256810,1256811,1256812,1257593,1257594,1257595,CVE-2025-10911,CVE-2025-8732,CVE-2026-0989,CVE-2026-0990,CVE-2026-0992,CVE-2026-1757 This update for libxml2 fixes the following issues: - CVE-2026-0990: Fixed a call stack overflow leading to application crash due to infinite recursion in `xmlCatalogXMLResolveURI`. (bsc#1256807, bsc#1256811) - CVE-2026-0992: Fixed an excessive resource consumption when processing XML catalogs due to exponential behavior. (bsc#1256809, bsc#1256812) - CVE-2026-1757: Fixed a memory leak in the `xmllint` interactive shell. (bsc#1257594, bsc#1257595) - CVE-2025-10911: Fixed a use-after-free with key data stored cross-RVT. (bsc#1250553) - CVE-2025-8732: Fixed an infinite recursion in catalog parsing functions when processing malformed SGML catalog files. (bsc#1247858) - CVE-2026-0989: Fixe a call stack exhaustion leading to application crash due to RelaxNG parser not limiting the recursion depth. (bsc#1256805, bsc#1256810) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:813-1 Released: Thu Mar 5 09:33:59 2026 Summary: Security update for mozilla-nss Type: security Severity: moderate References: 1258568,CVE-2026-2781 This update for mozilla-nss fixes the following issues: Update to NSS 3.112.3: * CVE-2026-2781: Avoid integer overflow in platform-independent ghash (bsc#1258568) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:829-1 Released: Thu Mar 5 16:17:08 2026 Summary: Security update for gnutls Type: security Severity: moderate References: 1257960,1258083,CVE-2025-14831 This update for gnutls fixes the following issues: Security issue: - CVE-2025-14831: excessive resource consumption when verifying specially crafted malicious certificates containing a large number of name constraints and subject alternative names (bsc#1257960). Other updates and bugfixes: - update libgnutls package to avoid binder getting calculated with SHA256 (bsc#1258083, jsc#PED-15752, jsc#PED-15753). - lib/psk: Add gnutls_psk_allocate_{client,server}_credentials2 - tests/psk-file: Add testing for _credentials2 functions - lib/psk: add null check for binder algo - pre_shared_key: fix memleak when retrying with different binder algo - pre_shared_key: add null check on pskcred ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1065-1 Released: Thu Mar 26 11:38:12 2026 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1254670,1259619,CVE-2025-70873,CVE-2025-7709 This update for sqlite3 fixes the following issues: Update sqlite3 to 3.51.3: - CVE-2025-7709: Integer Overflow in FTS5 Extension (bsc#1254670). - CVE-2025-70873: SQLite zipfile extension may disclose uninitialized heap memory during inflation (bsc#1259619). Changelog: * Fix the WAL-reset database corruption bug: https://sqlite.org/wal.html#walresetbug ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1399-1 Released: Thu Apr 16 12:44:14 2026 Summary: Security update for cups Type: security Severity: important References: 1261568,CVE-2026-34990 This update for cups fixes the following issue: - CVE-2026-34990: Local print admin token disclosure using temporary printers (bsc#1261568). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1441-1 Released: Fri Apr 17 16:18:19 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1257235,CVE-2026-24401 This update for avahi fixes the following issue: - CVE-2026-24401: avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record (bsc#1257235). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:1561-1 Released: Thu Apr 23 08:34:49 2026 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: This update for mozilla-nss fixes the following issues: Update to NSS 3.112.4: * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * RSA_EMSAEncodePSS should validate the length of mHash. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * Remove invalid PORT_Free(). * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * make ss->ssl3.hs.cookie an owned-copy of the cookie. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1576-1 Released: Thu Apr 23 17:53:21 2026 Summary: Security update for gdk-pixbuf Type: security Severity: important References: 1261210,CVE-2026-5201 This update for gdk-pixbuf fixes the following issue: - CVE-2026-5201: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image (bsc#1261210). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1750-1 Released: Thu May 7 13:52:09 2026 Summary: Security update for librsvg Type: security Severity: important References: 1257922,CVE-2026-25727 This update for librsvg fixes the following issue: - CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257922). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1845-1 Released: Wed May 13 17:26:41 2026 Summary: Security update for Mesa Type: security Severity: moderate References: 1261998,CVE-2026-40393 This update for Mesa fixes the following issue: - CVE-2026-40393: out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party (bsc#1261998). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1967-1 Released: Mon May 18 10:12:42 2026 Summary: Security update for tiff Type: security Severity: important References: 1260411,CVE-2026-4775 This update for tiff fixes the following issue - CVE-2026-4775: signed integer overflow in the `putcontig8bitYCbCr44tile` function (bsc#1260411). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2115-1 Released: Fri May 29 17:27:13 2026 Summary: Security update for gnutls Type: security Severity: important References: 1263704,1263705,1263707,1263708,1263709,1263710,1263711,1263712,1263713,1263714,1263715,1263716,CVE-2026-33845,CVE-2026-33846,CVE-2026-3833,CVE-2026-42009,CVE-2026-42010,CVE-2026-42011,CVE-2026-42012,CVE-2026-42013,CVE-2026-42014,CVE-2026-42015,CVE-2026-5260,CVE-2026-5419 This update for gnutls fixes the following issues - CVE-2026-3833: x509/name-constraints: compare domain names case-insensitive (bsc#1263707). - CVE-2026-5260: lib/pkcs11_privkey: guard against overreading on short ciphertexts (bsc#1263715). - CVE-2026-5419: gnutls_cipher_decrypt3: make PKCS#7 unpadding branch free (bsc#1263716). - CVE-2026-33845: buffers: switch from end_offset over to frag_length (bsc#1263704). - CVE-2026-33846: buffers: add more checks to DTLS reassembly (bsc#1263705). - CVE-2026-42009: lib/buffers: ensure packets have differing sequence numbers (bsc#1263708). - CVE-2026-42010: lib/auth/rsa_psk: fix binary PSK identity lookup (bsc#1263709). - CVE-2026-42011: x509/name_constraints: fix intersecting empty constraints (bsc#1263710). - CVE-2026-42012: x509/hostname-verify: make URI/SRV SAN preclude CN fallback (bsc#1263711). - CVE-2026-42013: x509: prevent fallback on oversized SAN (bsc#1263712). - CVE-2026-42014: pkcs11_write: fix UAF and leak in gnutls_pkcs11_token_set_pin (bsc#1263713). - CVE-2026-42015: x509/pkcs12_bag: fix off-by-one in bag element bounds chec (bsc#1263714). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2297-1 Released: Mon Jun 8 12:16:51 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1261546,CVE-2026-34933 This update for avahi fixes the following issue: - CVE-2026-34933: Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags (bsc#1261546). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2478-1 Released: Mon Jun 22 10:46:59 2026 Summary: Security update for graphite2 Type: security Severity: important References: 1267733,CVE-2026-50593 This update for graphite2 fixes the following issue: - CVE-2026-50593: Out-of-bounds write via Graphite actions (bsc#1267733). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2528-1 Released: Tue Jun 23 11:06:07 2026 Summary: Security update for sqlite3 Type: security Severity: important References: 1268012,1268013,CVE-2026-11822,CVE-2026-11824 This update for sqlite3 fixes the following issues Update to 3.53.2: - CVE-2026-11822: memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution (bsc#1268012). - CVE-2026-11824: heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code (bsc#1268013). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2637-1 Released: Thu Jun 25 17:42:10 2026 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: This update for mozilla-nss fixes the following issues: Update to NSS 3.112.5: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max. * update to version 2.84 of builtins module. - Added 'Suggests: p11-kit-nss-trust' to favor over mozilla-nss-certs (jsc#PED-15633) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2732-1 Released: Thu Jul 2 19:41:27 2026 Summary: Security update for cups Type: security Severity: moderate References: 1261569,1261570,1261571,1261572,1261742,1261743,CVE-2026-27447,CVE-2026-34978,CVE-2026-34979,CVE-2026-34980,CVE-2026-39314,CVE-2026-39316 This update for cups fixes the following issues - CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup (bsc#1261572). - CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (bsc#1261571). - CVE-2026-34979: Heap overflow in `get_options()` (bsc#1261570). - CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (bsc#1261569). - CVE-2026-39314: negative `job-password-supported` attribute can lead to a denial of service (bsc#1261743). - CVE-2026-39316: dangling subscription pointer can lead to a denial of service (1261742). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2853-1 Released: Fri Jul 10 19:54:25 2026 Summary: Security update for tiff Type: security Severity: important References: 1268434,1269779,CVE-2026-12912,CVE-2026-36849,CVE-2026-4775 This update for tiff fixes the following issues: Update to version 4.7.2. Security issues fixed: - CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog-compressed TIFF image (bsc#1269779). - CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). Other updates and bugfixes: - Version 4.7.2: - Software configuration changes: * cmake: Fix bundle identifiers to use reverse-DNS format * cmake: Fix and improve Apple framework build support * cmake: Use TurboJPEG CONFIG by default (issue #767) * cmake: changes related to 8-/12-bit modes * cmake: Replace CMath::CMath with direct link to avoid export. * Support for iOS-derived builds * Simplify cmake byte order version check * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions * configure.ac: Require bootstrap with at least Autoconf 2.71. - Library changes: * New/improved functionalities:: + Add TIFFGetMaxCompressionRatio() and use it in _TIFFReadEncoded[Tile|Strip)AndAllocBuffer() (issue #781) - Bug fixes: * Handle negative TIFFReadFile results before state updates (issue #854) * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777) * tif_dirwrite.c: add integer overflow checks to allocation size calculations * tif_print.c: add integer overflow checks to allocation size calculations * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop * DumpModeSeek: add bounds check to prevent OOB pointer advance * TIFFGrowStrips: fix use-after-free on partial realloc failure. * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it. * TIFFRGBAImage: avoid int overflows in put functions (issue #830) * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792) * tif_getimage: Widen pointer-offset arithmetic in tif_getimage * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798) * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753) * TIFFReadRGBAImage(): prevent integer overflow and later heap overflow (issue #787) * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831) * TIFFLinkDirectory() checks for IFD loops (issue #788) * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails. * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805) * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465) * tif_getimage: reject tile widths that would overflow toskew (issue #808) * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit. * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777). * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss-fuzz.com/issues/471328917) * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755). * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749) * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892) * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826) * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg-turbo 3.0.3 (issue #773) * JPEGDecode(): fix memory leak in error code path (https://issues.oss-fuzz.com/issues/471945501) * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850) * PixarLog: error out on invalid ABGR output buffer sizes. * PixarLog: complete ABGR bounds check for multi-row strip decoding. * PixarLog: fix heap-buffer-overflow in 8BITABGR decode with stride 3 (issue #824) * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789). * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797) * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072) * OJPEG: fix integer overflow in subsampling buffer allocation. * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795). * OJPEG fix potential integer overflow/out-of-bounds access (issue #796). * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b) * fix null pointer deference in issue #782. * fix stack-overflow in issue #784. - Other changes: * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739). * Harden integer size and offset calculations (issue #897) * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication * Move widening casts inside multiplication scope. * Lots of compiler warning fixes related to enabling more warning flags * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773) * TIFFFillStrip(): prevent harmless unsigned integer overflow ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3218-1 Released: Thu Jul 23 19:34:12 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1255451,CVE-2025-59529 This update for avahi fixes the following issue: - CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3270-1 Released: Mon Jul 27 13:01:22 2026 Summary: Security update for alsa Type: security Severity: moderate References: 1268853,CVE-2026-56109 This update for alsa fixes the following issue - CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that can allow attackers to corrupt memory (bsc#1268853). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - gtk3-data-3.24.43-150600.3.10.1 added - gtk3-schema-3.24.43-150600.3.10.1 added - hicolor-icon-theme-0.17-150600.19.2 added - libasound2-1.2.10-150600.4.3.1 added - libavahi-common3-0.8-150600.15.21.1 added - libdatrie1-0.2.9-1.25 added - libepoxy0-1.5.10-150500.1.2 added - libffi7-3.2.1.git259-10.8 added - libfribidi0-1.0.10-150400.3.3.1 added - libglib-2_0-0-2.78.6-150600.4.38.1 added - libgraphite2-3-1.3.14-150600.3.3.1 added - libjbig2-2.1-150000.3.5.1 added - libjpeg8-8.2.2-150600.22.5 added - liblcms2-2-2.15-150600.3.3.2 added - libnettle8-3.10.1-150700.2.16 added - libpixman-1-0-0.43.4-150600.3.3.1 added - libsqlite3-0-3.53.2-150000.3.42.1 added - libthai-data-0.1.29-150400.1.4 added - libudev1-254.27-150600.4.71.2 added - libunistring2-0.9.10-1.1 added - libwayland-egl1-99~1.23.1-150700.1.3 added - mozilla-nspr-4.36.2-150000.3.36.1 added - libgbm1-24.3.3-150700.93.8.1 added - libwayland-client0-1.23.1-150700.1.3 added - libp11-kit0-0.23.22-150500.8.3.1 added - pkg-config-0.29.2-150600.15.6.3 added - libgobject-2_0-0-2.78.6-150600.4.38.1 added - libgmodule-2_0-0-2.78.6-150600.4.38.1 added - libfreebl3-3.112.5-150400.3.69.2 added - libhogweed6-3.10.1-150700.2.16 added - libthai0-0.1.29-150400.1.4 added - libidn2-0-2.2.0-3.6.1 added - libxml2-2-2.12.10-150700.4.14.1 added - libelf1-0.185-150400.5.8.3 added - libtiff6-4.7.2-150600.3.29.1 added - mozilla-nss-certs-3.112.5-150400.3.69.2 added - libxcb-shm0-1.17.0-150700.1.2 added - libxcb-render0-1.17.0-150700.1.2 added - libwayland-cursor0-1.23.1-150700.1.3 added - xkeyboard-config-2.42-150700.1.1 added - libatk-1_0-0-2.50.0-150600.1.2 added - shared-mime-info-2.4-150600.3.3.2 added - libsoftokn3-3.112.5-150400.3.69.2 added - mozilla-nss-3.112.5-150400.3.69.2 added - libXrender1-0.9.10-1.30 added - libXfixes3-6.0.0-150400.1.4 added - libXdamage1-1.1.4-1.23 added - libXcomposite1-0.4.4-1.23 added - libxkbcommon0-1.5.0-150600.3.3.1 added - libtasn1-6-4.13-150000.4.14.1 added - libtasn1-4.13-150000.4.14.1 added - gio-branding-SLE-15-150600.35.2.1 added - libgio-2_0-0-2.78.6-150600.4.38.1 added - glib2-tools-2.78.6-150600.4.38.1 added - libharfbuzz0-8.3.0-150600.3.3.1 added - libXcursor1-1.1.15-1.18 added - libXrandr2-1.5.1-2.17 added - libXinerama1-1.1.3-1.22 added - libXi6-1.7.9-3.2.1 added - libavahi-client3-0.8-150600.15.21.1 added - libgnutls30-3.8.3-150600.4.20.1 added - libcolord2-1.4.6-150600.3.8.1 added - gdk-pixbuf-query-loaders-2.42.12-150600.3.11.1 added - libcairo2-1.18.4-150600.3.3.1 added - libXft2-2.3.2-1.33 added - libatspi0-2.50.0-150600.1.2 added - libgdk_pixbuf-2_0-0-2.42.12-150600.3.11.1 added - libcairo-gobject2-1.18.4-150600.3.3.1 added - libpango-1_0-0-1.51.1-150600.1.3 added - libatk-bridge-2_0-0-2.50.0-150600.1.2 added - librsvg-2-2-2.57.4-150600.3.8.2 added - gdk-pixbuf-loader-rsvg-2.57.4-150600.3.8.2 added - system-user-lp-20170617-150400.24.2.1 added - cups-config-2.2.7-150000.3.93.1 added - libcups2-2.2.7-150000.3.93.1 added - gtk3-tools-3.24.43-150600.3.10.1 added - libgtk-3-0-3.24.43-150600.3.10.1 added - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - coreutils-8.32-150400.9.12.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - sles-release-15.7-150700.67.6.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Mon Sep 7 07:07:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 09:07:53 +0200 (CEST) Subject: SUSE-IU-2026:6808-1: Recommended update of suse/sle-micro/base-5.5 Message-ID: <20260907070753.0980AFDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6808-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.312 , suse/sle-micro/base-5.5:latest Image Release : 5.8.312 Severity : important Type : recommended References : 1274740 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated From sle-container-updates at lists.suse.com Mon Sep 7 07:10:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 09:10:33 +0200 (CEST) Subject: SUSE-IU-2026:6809-1: Recommended update of suse/sle-micro/kvm-5.5 Message-ID: <20260907071033.4D8ABFDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/kvm-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6809-1 Image Tags : suse/sle-micro/kvm-5.5:2.0.4 , suse/sle-micro/kvm-5.5:2.0.4-3.5.601 , suse/sle-micro/kvm-5.5:latest Image Release : 3.5.601 Severity : important Type : recommended References : 1274740 ----------------------------------------------------------------- The container suse/sle-micro/kvm-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.312 updated From sle-container-updates at lists.suse.com Mon Sep 7 07:14:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 09:14:37 +0200 (CEST) Subject: SUSE-IU-2026:6810-1: Recommended update of suse/sle-micro/rt-5.5 Message-ID: <20260907071437.405D3FDCB@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6810-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.711 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.711 Severity : important Type : recommended References : 1274740 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.103 updated From sle-container-updates at lists.suse.com Mon Sep 7 07:17:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 09:17:37 +0200 (CEST) Subject: SUSE-IU-2026:6811-1: Recommended update of suse/sle-micro/5.5 Message-ID: <20260907071737.CDE1CFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6811-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.103 , suse/sle-micro/5.5:latest Image Release : 5.8.103 Severity : important Type : recommended References : 1274740 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.312 updated From sle-container-updates at lists.suse.com Mon Sep 7 07:27:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 09:27:24 +0200 (CEST) Subject: SUSE-CU-2026:9576-1: Recommended update of suse/sle-micro-rancher/5.4 Message-ID: <20260907072724.6CAF9FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9576-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.179 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.179 Severity : important Type : recommended References : 1274740 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated From sle-container-updates at lists.suse.com Mon Sep 7 07:29:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 09:29:49 +0200 (CEST) Subject: SUSE-CU-2026:9577-1: Recommended update of suse/sle-micro/5.4/toolbox Message-ID: <20260907072949.A5FF7FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9577-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.278 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.278 Severity : important Type : recommended References : 1274740 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3987-1 Released: Sun Sep 6 12:47:18 2026 Summary: Recommended update for container-suseconnect Type: recommended Severity: moderate References: This update for container-suseconnect fixes the following issues: Update to version 2.6.0: - simplify use_fips_mode conditional in specfile - Fix package for %suse_version bump (jsc#PED-15783) The following package changes have been done: - container-suseconnect-2.6.0-150000.4.95.2 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated From sle-container-updates at lists.suse.com Mon Sep 7 07:32:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 09:32:14 +0200 (CEST) Subject: SUSE-CU-2026:9578-1: Recommended update of suse/sle-micro/5.5/toolbox Message-ID: <20260907073214.DB645FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9578-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.189 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.189 Severity : important Type : recommended References : 1274740 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3987-1 Released: Sun Sep 6 12:47:18 2026 Summary: Recommended update for container-suseconnect Type: recommended Severity: moderate References: This update for container-suseconnect fixes the following issues: Update to version 2.6.0: - simplify use_fips_mode conditional in specfile - Fix package for %suse_version bump (jsc#PED-15783) The following package changes have been done: - container-suseconnect-2.6.0-150000.4.95.2 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated From sle-container-updates at lists.suse.com Mon Sep 7 07:36:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 09:36:04 +0200 (CEST) Subject: SUSE-IU-2026:6812-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260907073604.8A205FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6812-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.127 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.127 Severity : important Type : security References : 1262633 1263440 1267696 1268412 1272340 1276764 1277476 1277479 1277480 CVE-2026-10805 CVE-2026-13608 CVE-2026-16461 CVE-2026-19685 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1613 Released: Sun Sep 6 18:45:15 2026 Summary: Security update for rpcbind Type: security Severity: moderate References: 1272340,CVE-2026-16461 This update for rpcbind fixes the following issue: - CVE-2026-16461: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting (bsc#1272340). ----------------------------------------------------------------- Advisory ID: 1622 Released: Sun Sep 6 18:56:18 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: OpenLDAP SASL authentication bypass (bsc#1277476). - CVE-2026-80229: OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass (bsc#1277480). ----------------------------------------------------------------- Advisory ID: 1624 Released: Sun Sep 6 19:07:25 2026 Summary: Security update for NetworkManager Type: security Severity: important References: 1267696,1276764,CVE-2026-10805,CVE-2026-19685 This update for NetworkManager fixes the following issues: - CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). - CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). The following package changes have been done: - libcurl4-8.14.1-160000.9.1 updated - libnm0-1.52.0-160000.5.1 updated - NetworkManager-1.52.0-160000.5.1 updated - rpcbind-1.2.9-160000.2.1 updated - NetworkManager-wwan-1.52.0-160000.5.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-32ed223109487367583ec82984b3e6b1dbe306e52845b7249e94f584b283a0a9-0 updated From sle-container-updates at lists.suse.com Mon Sep 7 07:44:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 09:44:15 +0200 (CEST) Subject: SUSE-IU-2026:6815-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260907074415.67ED3FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6815-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.66 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.66 Severity : important Type : security References : 1262633 1263440 1267696 1268412 1276764 1277476 1277479 1277480 CVE-2026-10805 CVE-2026-13608 CVE-2026-19685 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1622 Released: Sun Sep 6 18:56:18 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: OpenLDAP SASL authentication bypass (bsc#1277476). - CVE-2026-80229: OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass (bsc#1277480). ----------------------------------------------------------------- Advisory ID: 1624 Released: Sun Sep 6 19:07:25 2026 Summary: Security update for NetworkManager Type: security Severity: important References: 1267696,1276764,CVE-2026-10805,CVE-2026-19685 This update for NetworkManager fixes the following issues: - CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). - CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). The following package changes have been done: - libcurl4-8.14.1-160000.9.1 updated - libnm0-1.52.0-160000.5.1 updated - curl-8.14.1-160000.9.1 updated - NetworkManager-1.52.0-160000.5.1 updated From sle-container-updates at lists.suse.com Mon Sep 7 07:51:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 09:51:30 +0200 (CEST) Subject: SUSE-IU-2026:6819-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260907075130.76B0DFCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6819-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.112 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.112 Severity : important Type : security References : 1262633 1263440 1267696 1268412 1276764 1277476 1277479 1277480 CVE-2026-10805 CVE-2026-13608 CVE-2026-19685 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1622 Released: Sun Sep 6 18:56:18 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: OpenLDAP SASL authentication bypass (bsc#1277476). - CVE-2026-80229: OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass (bsc#1277480). ----------------------------------------------------------------- Advisory ID: 1624 Released: Sun Sep 6 19:07:25 2026 Summary: Security update for NetworkManager Type: security Severity: important References: 1267696,1276764,CVE-2026-10805,CVE-2026-19685 This update for NetworkManager fixes the following issues: - CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). - CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). The following package changes have been done: - libcurl4-8.14.1-160000.9.1 updated - libnm0-1.52.0-160000.5.1 updated - NetworkManager-1.52.0-160000.5.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-32ed223109487367583ec82984b3e6b1dbe306e52845b7249e94f584b283a0a9-0 updated From sle-container-updates at lists.suse.com Mon Sep 7 07:59:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 09:59:27 +0200 (CEST) Subject: SUSE-IU-2026:6825-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260907075927.D7CD1FCEE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6825-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.146 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.146 Severity : important Type : security References : 1262633 1263440 1267696 1268412 1276764 1277476 1277479 1277480 CVE-2026-10805 CVE-2026-13608 CVE-2026-19685 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1622 Released: Sun Sep 6 18:56:18 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: OpenLDAP SASL authentication bypass (bsc#1277476). - CVE-2026-80229: OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass (bsc#1277480). ----------------------------------------------------------------- Advisory ID: 1624 Released: Sun Sep 6 19:07:25 2026 Summary: Security update for NetworkManager Type: security Severity: important References: 1267696,1276764,CVE-2026-10805,CVE-2026-19685 This update for NetworkManager fixes the following issues: - CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). - CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). The following package changes have been done: - libcurl4-8.14.1-160000.9.1 updated - libnm0-1.52.0-160000.5.1 updated - NetworkManager-1.52.0-160000.5.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-a3c5f6d9367f02dc0dc79dce0786469a7134140fe7d96d07c690f080c49acdbd-0 updated From sle-container-updates at lists.suse.com Mon Sep 7 08:08:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 10:08:03 +0200 (CEST) Subject: SUSE-CU-2026:9580-1: Recommended update of suse/ltss/sle15.4/sle15 Message-ID: <20260907080803.3E1BCFDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.4/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9580-1 Container Tags : suse/ltss/sle15.4/bci-base:15.4 , suse/ltss/sle15.4/bci-base:15.4-6.45 , suse/ltss/sle15.4/sle15:15.4 , suse/ltss/sle15.4/sle15:15.4-6.45 , suse/ltss/sle15.4/sle15:latest Container Release : 6.45 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/ltss/sle15.4/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3987-1 Released: Sun Sep 6 12:47:18 2026 Summary: Recommended update for container-suseconnect Type: recommended Severity: moderate References: This update for container-suseconnect fixes the following issues: Update to version 2.6.0: - simplify use_fips_mode conditional in specfile - Fix package for %suse_version bump (jsc#PED-15783) The following package changes have been done: - container-suseconnect-2.6.0-150000.4.95.2 updated From sle-container-updates at lists.suse.com Mon Sep 7 08:12:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 10:12:08 +0200 (CEST) Subject: SUSE-CU-2026:9581-1: Recommended update of suse/ltss/sle15.5/sle15 Message-ID: <20260907081208.2C6A4FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.5/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9581-1 Container Tags : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.68 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.68 , suse/ltss/sle15.5/sle15:latest Container Release : 8.68 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3987-1 Released: Sun Sep 6 12:47:18 2026 Summary: Recommended update for container-suseconnect Type: recommended Severity: moderate References: This update for container-suseconnect fixes the following issues: Update to version 2.6.0: - simplify use_fips_mode conditional in specfile - Fix package for %suse_version bump (jsc#PED-15783) The following package changes have been done: - container-suseconnect-2.6.0-150000.4.95.2 updated From sle-container-updates at lists.suse.com Mon Sep 7 08:14:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 10:14:35 +0200 (CEST) Subject: SUSE-CU-2026:9583-1: Recommended update of suse/ltss/sle15.6/sle15 Message-ID: <20260907081435.70326FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9583-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.88 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.88 , suse/ltss/sle15.6/sle15:latest Container Release : 5.88 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3987-1 Released: Sun Sep 6 12:47:18 2026 Summary: Recommended update for container-suseconnect Type: recommended Severity: moderate References: This update for container-suseconnect fixes the following issues: Update to version 2.6.0: - simplify use_fips_mode conditional in specfile - Fix package for %suse_version bump (jsc#PED-15783) The following package changes have been done: - container-suseconnect-2.6.0-150000.4.95.2 updated From sle-container-updates at lists.suse.com Mon Sep 7 08:17:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 10:17:32 +0200 (CEST) Subject: SUSE-CU-2026:9573-1: Security update of suse/kiosk/xorg-client Message-ID: <20260907081732.1BB17FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9573-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-80.1 , suse/kiosk/xorg-client:latest Container Release : 80.1 Severity : critical Type : security References : 1029961 1081723 1081723 1096405 1096406 1096407 1096408 1097410 1105435 1106873 1114407 1115750 1118118 1119069 1119105 1119687 1124223 1125410 1126377 1130325 1130326 1131060 1131686 1141322 1141322 1146358 1146359 1150137 1157818 1158527 1158812 1158958 1158959 1158960 1159491 1159715 1159819 1159819 1159847 1159850 1160309 1160438 1160439 1164719 1168422 1169746 1170671 1171978 1172091 1172115 1172234 1172236 1172240 1172879 1173641 1174230 1174697 1175960 1176206 1176384 1176756 1176899 1176934 1177977 1179382 1180520 1183942 1184161 1185116 1185116 1188891 1189517 1189802 1191467 1191525 1191546 1191546 1191546 1191546 1192079 1192079 1192080 1192080 1192086 1192086 1192087 1192087 1192228 1192228 1195115 1195391 1195773 1196147 1196148 1196150 1198146 1198486 1198486 1198932 1198980 1198980 1198980 1199474 1200027 1200027 1200321 1201234 1201298 1201298 1201298 1201298 1201511 1201783 1202118 1202118 1202645 1202870 1202870 1203446 1204272 1204690 1204729 1204729 1206337 1207038 1207209 1208056 1208138 1208242 1208999 1210660 1211643 1212230 1212607 1214254 1214980 1214980 1215204 1216198 1216594 1216598 1217119 1218640 1219213 1219276 1219391 1221052 1222804 1222807 1222811 1222813 1222814 1222821 1222822 1222826 1222828 1222830 1222833 1222834 1222834 1223179 1223724 1223903 1224044 1224113 1224113 1224113 1224113 1224115 1224116 1224118 1225365 1226192 1226227 1226586 1226724 1226731 1226733 1227642 1227669 1227670 1227671 1227918 1228120 1228120 1228322 1228924 1230166 1230932 1231463 1231463 1233282 1233420 1233421 1234225 1236834 1236878 1236974 1237236 1237240 1237241 1237242 1237374 1237374 1240897 1241020 1241078 1241189 1241701 1242844 1243503 1243867 1244057 1244057 1244554 1244555 1244557 1244590 1244596 1244700 1245034 1245227 1246114 1246232 1246233 1246267 1246296 1246299 1246533 1246597 1247106 1247108 1247503 1247581 1247582 1247589 1247850 1247858 1247985 1248117 1248278 1248330 1248586 1249049 1249055 1249128 1250413 1250553 1250750 1251263 1253783 1254132 1254297 1254353 1254353 1254662 1254670 1254670 1254878 1255451 1256341 1256459 1256498 1256499 1256500 1256804 1256805 1256807 1256808 1256809 1256810 1256811 1256812 1257049 1257235 1257353 1257354 1257355 1257593 1257594 1257595 1257922 1257960 1258083 1258568 1259619 1260411 1261210 1261546 1261568 1261569 1261570 1261571 1261572 1261742 1261743 1261998 1263704 1263705 1263707 1263708 1263709 1263710 1263711 1263712 1263713 1263714 1263715 1263716 1267733 1268012 1268013 1268434 1268853 1269779 1269790 1270008 1270009 1270010 1270016 1270018 1270021 928700 928701 CVE-2015-3414 CVE-2015-3415 CVE-2018-0495 CVE-2018-1000654 CVE-2018-12384 CVE-2018-12404 CVE-2018-12405 CVE-2018-17466 CVE-2018-18492 CVE-2018-18493 CVE-2018-18494 CVE-2018-18498 CVE-2018-18508 CVE-2018-20346 CVE-2018-4180 CVE-2018-4181 CVE-2018-4182 CVE-2018-4183 CVE-2018-4700 CVE-2019-11745 CVE-2019-16168 CVE-2019-17006 CVE-2019-17006 CVE-2019-19244 CVE-2019-19317 CVE-2019-19603 CVE-2019-19645 CVE-2019-19646 CVE-2019-19880 CVE-2019-19923 CVE-2019-19924 CVE-2019-19925 CVE-2019-19926 CVE-2019-19959 CVE-2019-20218 CVE-2019-3880 CVE-2019-8675 CVE-2019-8696 CVE-2019-8842 CVE-2019-9936 CVE-2019-9937 CVE-2020-10001 CVE-2020-12399 CVE-2020-12400 CVE-2020-12401 CVE-2020-12403 CVE-2020-13434 CVE-2020-13435 CVE-2020-13630 CVE-2020-13631 CVE-2020-13632 CVE-2020-15358 CVE-2020-15673 CVE-2020-15676 CVE-2020-15677 CVE-2020-15678 CVE-2020-15683 CVE-2020-15969 CVE-2020-25648 CVE-2020-3898 CVE-2020-6829 CVE-2020-9327 CVE-2021-23981 CVE-2021-23982 CVE-2021-23984 CVE-2021-23987 CVE-2021-25317 CVE-2021-36690 CVE-2021-42523 CVE-2021-46848 CVE-2022-1210 CVE-2022-23491 CVE-2022-25308 CVE-2022-25309 CVE-2022-25310 CVE-2022-26691 CVE-2022-31741 CVE-2022-31741 CVE-2022-3479 CVE-2022-35737 CVE-2022-46908 CVE-2022-48622 CVE-2023-0767 CVE-2023-2137 CVE-2023-25435 CVE-2023-32324 CVE-2023-32360 CVE-2023-34241 CVE-2023-38469 CVE-2023-38471 CVE-2023-4504 CVE-2023-52356 CVE-2023-5388 CVE-2023-5388 CVE-2024-12133 CVE-2024-12224 CVE-2024-12243 CVE-2024-13978 CVE-2024-34397 CVE-2024-35235 CVE-2024-47175 CVE-2024-52533 CVE-2024-52615 CVE-2024-52616 CVE-2024-6655 CVE-2024-6655 CVE-2024-7006 CVE-2025-10911 CVE-2025-13151 CVE-2025-1352 CVE-2025-13601 CVE-2025-1372 CVE-2025-1376 CVE-2025-1377 CVE-2025-14087 CVE-2025-14512 CVE-2025-14831 CVE-2025-29087 CVE-2025-29088 CVE-2025-3277 CVE-2025-32988 CVE-2025-32989 CVE-2025-32990 CVE-2025-3360 CVE-2025-4373 CVE-2025-49794 CVE-2025-49795 CVE-2025-49796 CVE-2025-50422 CVE-2025-58060 CVE-2025-58364 CVE-2025-58436 CVE-2025-58436 CVE-2025-58436 CVE-2025-59529 CVE-2025-6021 CVE-2025-6052 CVE-2025-6170 CVE-2025-61915 CVE-2025-6199 CVE-2025-6395 CVE-2025-68276 CVE-2025-68468 CVE-2025-68471 CVE-2025-6965 CVE-2025-7039 CVE-2025-70873 CVE-2025-7345 CVE-2025-7425 CVE-2025-7709 CVE-2025-7709 CVE-2025-8176 CVE-2025-8177 CVE-2025-8534 CVE-2025-8732 CVE-2025-8851 CVE-2025-8961 CVE-2025-9165 CVE-2025-9187 CVE-2025-9820 CVE-2025-9900 CVE-2026-0988 CVE-2026-0989 CVE-2026-0990 CVE-2026-0992 CVE-2026-11822 CVE-2026-11824 CVE-2026-11979 CVE-2026-12912 CVE-2026-1484 CVE-2026-1485 CVE-2026-1489 CVE-2026-1757 CVE-2026-22693 CVE-2026-24401 CVE-2026-25727 CVE-2026-27447 CVE-2026-2781 CVE-2026-33845 CVE-2026-33846 CVE-2026-34933 CVE-2026-34978 CVE-2026-34979 CVE-2026-34980 CVE-2026-34990 CVE-2026-36849 CVE-2026-3833 CVE-2026-39314 CVE-2026-39316 CVE-2026-40393 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015 CVE-2026-4775 CVE-2026-4775 CVE-2026-50593 CVE-2026-5201 CVE-2026-5260 CVE-2026-5419 CVE-2026-56109 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2018:1476-1 Released: Thu Aug 2 14:20:03 2018 Summary: Security update for cups Type: security Severity: moderate References: 1096405,1096406,1096407,1096408,CVE-2018-4180,CVE-2018-4181,CVE-2018-4182,CVE-2018-4183 This update for cups fixes the following issues: The following security vulnerabilities were fixed: - Fixed a local privilege escalation to root and sandbox bypasses in the scheduler - CVE-2018-4180: Fixed a local privilege escalation to root in dnssd backend (bsc#1096405) - CVE-2018-4181: Limited local file reads as root via cupsd.conf include directive (bsc#1096406) - CVE-2018-4182: Fixed a sandbox bypass due to insecure error handling (bsc#1096407) - CVE-2018-4183: Fixed a sandbox bypass due to profile misconfiguration (bsc#1096408) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2018:2882-1 Released: Mon Dec 10 08:07:44 2018 Summary: Security update for cups Type: security Severity: important References: 1115750,CVE-2018-4700 This update for cups fixes the following issues: Security issue fixed: - CVE-2018-4700: Fixed extremely predictable cookie generation that is effectively breaking the CSRF protection of the CUPS web interface (bsc#1115750). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2018:3044-1 Released: Fri Dec 21 18:47:21 2018 Summary: Security update for MozillaFirefox, mozilla-nspr and mozilla-nss Type: security Severity: important References: 1097410,1106873,1119069,1119105,CVE-2018-0495,CVE-2018-12384,CVE-2018-12404,CVE-2018-12405,CVE-2018-17466,CVE-2018-18492,CVE-2018-18493,CVE-2018-18494,CVE-2018-18498 This update for MozillaFirefox, mozilla-nss and mozilla-nspr fixes the following issues: Issues fixed in MozillaFirefox: - Update to Firefox ESR 60.4 (bsc#1119105) - CVE-2018-17466: Fixed a buffer overflow and out-of-bounds read in ANGLE library with TextureStorage11 - CVE-2018-18492: Fixed a use-after-free with select element - CVE-2018-18493: Fixed a buffer overflow in accelerated 2D canvas with Skia - CVE-2018-18494: Fixed a Same-origin policy violation using location attribute and performance.getEntries to steal cross-origin URLs - CVE-2018-18498: Fixed a integer overflow when calculating buffer sizes for images - CVE-2018-12405: Fixed a few memory safety bugs Issues fixed in mozilla-nss: - Update to NSS 3.40.1 (bsc#1119105) - CVE-2018-12404: Fixed a cache side-channel variant of the Bleichenbacher attack (bsc#1119069) - CVE-2018-12384: Fixed an issue in the SSL handshake. NSS responded to an SSLv2-compatible ClientHello with a ServerHello that had an all-zero random. (bsc#1106873) - CVE-2018-0495: Fixed a memory-cache side-channel attack with ECDSA signatures (bsc#1097410) - Fixed a decryption failure during FFDHE key exchange - Various security fixes in the ASN.1 code Issues fixed in mozilla-nspr: - Update mozilla-nspr to 4.20 (bsc#1119105) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2019:608-1 Released: Wed Mar 13 15:21:02 2019 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1118118 This update for cups fixes the following issues: - Fixed validation of UTF-8 filenames to avoid crashes (bsc#1118118) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:788-1 Released: Thu Mar 28 11:55:06 2019 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1119687,CVE-2018-20346 This update for sqlite3 to version 3.27.2 fixes the following issue: Security issue fixed: - CVE-2018-20346: Fixed a remote code execution vulnerability in FTS3 (Magellan) (bsc#1119687). Release notes: https://www.sqlite.org/releaselog/3_27_2.html ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:1040-1 Released: Thu Apr 25 17:09:21 2019 Summary: Security update for samba Type: security Severity: important References: 1114407,1124223,1125410,1126377,1131060,1131686,CVE-2019-3880 This update for samba fixes the following issues: Security issue fixed: - CVE-2019-3880: Fixed a path/symlink traversal vulnerability, which allowed an unprivileged user to save registry files outside a share (bsc#1131060). ldb was updated to version 1.2.4 (bsc#1125410 bsc#1131686): - Out of bound read in ldb_wildcard_compare - Hold at most 10 outstanding paged result cookies - Put 'results_store' into a doubly linked list - Refuse to build Samba against a newer minor version of ldb Non-security issues fixed: - Fixed update-apparmor-samba-profile script after apparmor switched to using named profiles (bsc#1126377). - Abide to the load_printers parameter in smb.conf (bsc#1124223). - Provide the 32bit samba winbind PAM module and its dependend 32bit libraries. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:1127-1 Released: Thu May 2 09:39:24 2019 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1130325,1130326,CVE-2019-9936,CVE-2019-9937 This update for sqlite3 to version 3.28.0 fixes the following issues: Security issues fixed: - CVE-2019-9936: Fixed a heap-based buffer over-read, when running fts5 prefix queries inside transaction (bsc#1130326). - CVE-2019-9937: Fixed a denial of service related to interleaving reads and writes in a single transaction with an fts5 virtual table (bsc#1130325). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:1372-1 Released: Tue May 28 16:53:28 2019 Summary: Security update for libtasn1 Type: security Severity: moderate References: 1105435,CVE-2018-1000654 This update for libtasn1 fixes the following issues: Security issue fixed: - CVE-2018-1000654: Fixed a denial of service in the asn1 parser (bsc#1105435). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2019:2142-1 Released: Wed Aug 14 18:14:04 2019 Summary: Recommended update for mozilla-nspr, mozilla-nss Type: recommended Severity: moderate References: 1141322 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nss was updated to NSS 3.45 (bsc#1141322) : * New function in pk11pub.h: PK11_FindRawCertsWithSubject * The following CA certificates were Removed: CN = Certinomis - Root CA (bmo#1552374) * Implement Delegated Credentials (draft-ietf-tls-subcerts) (bmo#1540403) This adds a new experimental function SSL_DelegateCredential Note: In 3.45, selfserv does not yet support delegated credentials (See bmo#1548360). Note: In 3.45 the SSLChannelInfo is left unmodified, while an upcoming change in 3.46 will set SSLChannelInfo.authKeyBits to that of the delegated credential for better policy enforcement (See bmo#1563078). * Replace ARM32 Curve25519 implementation with one from fiat-crypto (bmo#1550579) * Expose a function PK11_FindRawCertsWithSubject for finding certificates with a given subject on a given slot (bmo#1552262) * Add IPSEC IKE support to softoken (bmo#1546229) * Add support for the Elbrus lcc compiler (<=1.23) (bmo#1554616) * Expose an external clock for SSL (bmo#1543874) This adds new experimental functions: SSL_SetTimeFunc, SSL_CreateAntiReplayContext, SSL_SetAntiReplayContext, and SSL_ReleaseAntiReplayContext. The experimental function SSL_InitAntiReplay is removed. * Various changes in response to the ongoing FIPS review (bmo#1546477) Note: The source package size has increased substantially due to the new FIPS test vectors. This will likely prompt follow-on work, but please accept our apologies in the meantime. mozilla-nspr was updated to version 4.21 * Changed prbit.h to use builtin function on aarch64. * Removed Gonk/B2G references. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:2533-1 Released: Thu Oct 3 15:02:50 2019 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1150137,CVE-2019-16168 This update for sqlite3 fixes the following issues: Security issue fixed: - CVE-2019-16168: Fixed improper validation of sqlite_stat1 field that could lead to denial of service (bsc#1150137). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:3030-1 Released: Thu Nov 21 19:11:25 2019 Summary: Security update for cups Type: security Severity: important References: 1146358,1146359,CVE-2019-8675,CVE-2019-8696 This update for cups fixes the following issues: - CVE-2019-8675: Fixed a stack buffer overflow in libcups's asn1_get_type function(bsc#1146358). - CVE-2019-8696: Fixed a stack buffer overflow in libcups's asn1_get_packed function (bsc#1146359). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2019:3395-1 Released: Mon Dec 30 14:05:06 2019 Summary: Security update for mozilla-nspr, mozilla-nss Type: security Severity: moderate References: 1141322,1158527,1159819,CVE-2018-18508,CVE-2019-11745,CVE-2019-17006 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nss was updated to NSS 3.47.1: Security issues fixed: - CVE-2019-17006: Added length checks for cryptographic primitives (bsc#1159819). - CVE-2019-11745: EncryptUpdate should use maxout, not block size (bsc#1158527). - CVE-2019-11727: Fixed vulnerability sign CertificateVerify with PKCS#1 v1.5 signatures issue (bsc#1141322). mozilla-nspr was updated to version 4.23: - Whitespace in C files was cleaned up and no longer uses tab characters for indenting. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2020:1083-1 Released: Thu Apr 23 11:31:23 2020 Summary: Security update for cups Type: security Severity: important References: 1168422,CVE-2020-3898 This update for cups fixes the following issues: - CVE-2020-3898: Fixed a heap buffer overflow in ppdFindOption() (bsc#1168422). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2020:1677-1 Released: Thu Jun 18 18:16:39 2020 Summary: Security update for mozilla-nspr, mozilla-nss Type: security Severity: important References: 1159819,1169746,1171978,CVE-2019-17006,CVE-2020-12399 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nss was updated to version 3.53 - CVE-2020-12399: Fixed a timing attack on DSA signature generation (bsc#1171978). - CVE-2019-17006: Added length checks for cryptographic primitives (bsc#1159819). Release notes: https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.53_release_notes mozilla-nspr to version 4.25 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2020:3091-1 Released: Thu Oct 29 16:35:37 2020 Summary: Security update for MozillaThunderbird and mozilla-nspr Type: security Severity: important References: 1174230,1176384,1176756,1176899,1177977,CVE-2020-15673,CVE-2020-15676,CVE-2020-15677,CVE-2020-15678,CVE-2020-15683,CVE-2020-15969 This update for MozillaThunderbird and mozilla-nspr fixes the following issues: - Mozilla Thunderbird 78.4 * new: MailExtensions: browser.tabs.sendMessage API added * new: MailExtensions: messageDisplayScripts API added * changed: Yahoo and AOL mail users using password authentication will be migrated to OAuth2 * changed: MailExtensions: messageDisplay APIs extended to support multiple selected messages * changed: MailExtensions: compose.begin functions now support creating a message with attachments * fixed: Thunderbird could freeze when updating global search index * fixed: Multiple issues with handling of self-signed SSL certificates addressed * fixed: Recipient address fields in compose window could expand to fill all available space * fixed: Inserting emoji characters in message compose window caused unexpected behavior * fixed: Button to restore default folder icon color was not keyboard accessible * fixed: Various keyboard navigation fixes * fixed: Various color-related theme fixes * fixed: MailExtensions: Updating attachments with onBeforeSend.addListener() did not work MFSA 2020-47 (bsc#1177977) * CVE-2020-15969 Use-after-free in usersctp * CVE-2020-15683 Memory safety bugs fixed in Thunderbird 78.4 - Mozilla Thunderbird 78.3.3 * OpenPGP: Improved support for encrypting with subkeys * OpenPGP message status icons were not visible in message header pane * Creating a new calendar event did not require an event title - Mozilla Thunderbird 78.3.2 (bsc#1176899) * OpenPGP: Improved support for encrypting with subkeys * OpenPGP: Encrypted messages with international characters were sometimes displayed incorrectly * Single-click deletion of recipient pills with middle mouse button restored * Searching an address book list did not display results * Dark mode, high contrast, and Windows theming fixes - Mozilla Thunderbird 78.3.1 * fix crash in nsImapProtocol::CreateNewLineFromSocket - Mozilla Thunderbird 78.3.0 MFSA 2020-44 (bsc#1176756) * CVE-2020-15677 Download origin spoofing via redirect * CVE-2020-15676 XSS when pasting attacker-controlled data into a contenteditable element * CVE-2020-15678 When recursing through layers while scrolling, an iterator may have become invalid, resulting in a potential use-after- free scenario * CVE-2020-15673 Memory safety bugs fixed in Thunderbird 78.3 - update mozilla-nspr to version 4.25.1 * The macOS platform code for shared library loading was changed to support macOS 11. * Dependency needed for the MozillaThunderbird udpate ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:285-1 Released: Tue Feb 2 13:08:54 2021 Summary: Security update for cups Type: security Severity: moderate References: 1170671,1180520,CVE-2019-8842,CVE-2020-10001 This update for cups fixes the following issues: - CVE-2020-10001: Fixed an out-of-bounds read in the ippReadIO function (bsc#1180520). - CVE-2019-8842: Fixed an out-of-bounds read in an extension field (bsc#1170671). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:1007-1 Released: Thu Apr 1 17:47:20 2021 Summary: Security update for MozillaFirefox Type: security Severity: important References: 1183942,CVE-2021-23981,CVE-2021-23982,CVE-2021-23984,CVE-2021-23987 This update for MozillaFirefox fixes the following issues: - Firefox was updated to 78.9.0 ESR (MFSA 2021-11, bsc#1183942) * CVE-2021-23981: Texture upload into an unbound backing buffer resulted in an out-of-bound read * CVE-2021-23982: Internal network hosts could have been probed by a malicious webpage * CVE-2021-23984: Malicious extensions could have spoofed popup information * CVE-2021-23987: Memory safety bugs ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:1021-1 Released: Tue Apr 6 14:30:30 2021 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1175960 This update for cups fixes the following issues: - Fixed the web UI kerberos authentication (bsc#1175960) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:1454-1 Released: Fri Apr 30 09:22:26 2021 Summary: Security update for cups Type: security Severity: important References: 1184161,CVE-2021-25317 This update for cups fixes the following issues: - CVE-2021-25317: ownership of /var/log/cups could allow privilege escalation from lp user to root via symlink attacks (bsc#1184161) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:2320-1 Released: Wed Jul 14 17:01:06 2021 Summary: Security update for sqlite3 Type: security Severity: important References: 1157818,1158812,1158958,1158959,1158960,1159491,1159715,1159847,1159850,1160309,1160438,1160439,1164719,1172091,1172115,1172234,1172236,1172240,1173641,928700,928701,CVE-2015-3414,CVE-2015-3415,CVE-2019-19244,CVE-2019-19317,CVE-2019-19603,CVE-2019-19645,CVE-2019-19646,CVE-2019-19880,CVE-2019-19923,CVE-2019-19924,CVE-2019-19925,CVE-2019-19926,CVE-2019-19959,CVE-2019-20218,CVE-2020-13434,CVE-2020-13435,CVE-2020-13630,CVE-2020-13631,CVE-2020-13632,CVE-2020-15358,CVE-2020-9327 This update for sqlite3 fixes the following issues: - Update to version 3.36.0 - CVE-2020-15358: heap-based buffer overflow in multiSelectOrderBy due to mishandling of query-flattener optimization (bsc#1173641) - CVE-2020-9327: NULL pointer dereference and segmentation fault because of generated column optimizations in isAuxiliaryVtabOperator (bsc#1164719) - CVE-2019-20218: selectExpander in select.c proceeds with WITH stack unwinding even after a parsing error (bsc#1160439) - CVE-2019-19959: memory-management error via ext/misc/zipfile.c involving embedded '\0' input (bsc#1160438) - CVE-2019-19923: improper handling of certain uses of SELECT DISTINCT in flattenSubquery may lead to null pointer dereference (bsc#1160309) - CVE-2019-19924: improper error handling in sqlite3WindowRewrite() (bsc#1159850) - CVE-2019-19925: improper handling of NULL pathname during an update of a ZIP archive (bsc#1159847) - CVE-2019-19926: improper handling of certain errors during parsing multiSelect in select.c (bsc#1159715) - CVE-2019-19880: exprListAppendList in window.c allows attackers to trigger an invalid pointer dereference (bsc#1159491) - CVE-2019-19603: during handling of CREATE TABLE and CREATE VIEW statements, does not consider confusion with a shadow table name (bsc#1158960) - CVE-2019-19646: pragma.c mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns (bsc#1158959) - CVE-2019-19645: alter.c allows attackers to trigger infinite recursion via certain types of self-referential views in conjunction with ALTER TABLE statements (bsc#1158958) - CVE-2019-19317: lookupName in resolve.c omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service (bsc#1158812) - CVE-2019-19244: sqlite3,sqlite2,sqlite: The function sqlite3Select in select.c allows a crash if a sub-select uses both DISTINCT and window functions, and also has certain ORDER BY usage (bsc#1157818) - CVE-2015-3415: sqlite3VdbeExec comparison operator vulnerability (bsc#928701) - CVE-2015-3414: sqlite3,sqlite2: dequoting of collation-sequence names (bsc#928700) - CVE-2020-13434: integer overflow in sqlite3_str_vappendf (bsc#1172115) - CVE-2020-13630: (bsc#1172234: use-after-free in fts3EvalNextRow - CVE-2020-13631: virtual table allowed to be renamed to one of its shadow tables (bsc#1172236) - CVE-2020-13632: NULL pointer dereference via crafted matchinfo() query (bsc#1172240) - CVE-2020-13435: Malicious SQL statements could have crashed the process that is running SQLite (bsc#1172091) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:3115-1 Released: Thu Sep 16 14:04:26 2021 Summary: Recommended update for mozilla-nspr, mozilla-nss Type: recommended Severity: moderate References: 1029961,1174697,1176206,1176934,1179382,1188891,CVE-2020-12400,CVE-2020-12401,CVE-2020-12403,CVE-2020-25648,CVE-2020-6829 This update for mozilla-nspr fixes the following issues: mozilla-nspr was updated to version 4.32: * implement new socket option PR_SockOpt_DontFrag * support larger DNS records by increasing the default buffer size for DNS queries * Lock access to PRCallOnceType members in PR_CallOnce* for thread safety bmo#1686138 * PR_GetSystemInfo supports a new flag PR_SI_RELEASE_BUILD to get information about the operating system build version. Mozilla NSS was updated to version 3.68: * bmo#1713562 - Fix test leak. * bmo#1717452 - NSS 3.68 should depend on NSPR 4.32. * bmo#1693206 - Implement PKCS8 export of ECDSA keys. * bmo#1712883 - DTLS 1.3 draft-43. * bmo#1655493 - Support SHA2 HW acceleration using Intel SHA Extension. * bmo#1713562 - Validate ECH public names. * bmo#1717610 - Add function to get seconds from epoch from pkix::Time. update to NSS 3.67 * bmo#1683710 - Add a means to disable ALPN. * bmo#1715720 - Fix nssckbi version number in NSS 3.67 (was supposed to be incremented in 3.66). * bmo#1714719 - Set NSS_USE_64 on riscv64 target when using GYP/Ninja. * bmo#1566124 - Fix counter increase in ppc-gcm-wrap.c. * bmo#1566124 - Fix AES_GCM mode on ppc64le for messages of length more than 255-byte. update to NSS 3.66 * bmo#1710716 - Remove Expired Sonera Class2 CA from NSS. * bmo#1710716 - Remove Expired Root Certificates from NSS - QuoVadis Root Certification Authority. * bmo#1708307 - Remove Trustis FPS Root CA from NSS. * bmo#1707097 - Add Certum Trusted Root CA to NSS. * bmo#1707097 - Add Certum EC-384 CA to NSS. * bmo#1703942 - Add ANF Secure Server Root CA to NSS. * bmo#1697071 - Add GLOBALTRUST 2020 root cert to NSS. * bmo#1712184 - NSS tools manpages need to be updated to reflect that sqlite is the default database. * bmo#1712230 - Don't build ppc-gcm.s with clang integrated assembler. * bmo#1712211 - Strict prototype error when trying to compile nss code that includes blapi.h. * bmo#1710773 - NSS needs FIPS 180-3 FIPS indicators. * bmo#1709291 - Add VerifyCodeSigningCertificateChain. update to NSS 3.65 * bmo#1709654 - Update for NetBSD configuration. * bmo#1709750 - Disable HPKE test when fuzzing. * bmo#1566124 - Optimize AES-GCM for ppc64le. * bmo#1699021 - Add AES-256-GCM to HPKE. * bmo#1698419 - ECH -10 updates. * bmo#1692930 - Update HPKE to final version. * bmo#1707130 - NSS should use modern algorithms in PKCS#12 files by default. * bmo#1703936 - New coverity/cpp scanner errors. * bmo#1697303 - NSS needs to update it's csp clearing to FIPS 180-3 standards. * bmo#1702663 - Need to support RSA PSS with Hashing PKCS #11 Mechanisms. * bmo#1705119 - Deadlock when using GCM and non-thread safe tokens. update to NSS 3.64 * bmo#1705286 - Properly detect mips64. * bmo#1687164 - Introduce NSS_DISABLE_CRYPTO_VSX and disable_crypto_vsx. * bmo#1698320 - replace __builtin_cpu_supports('vsx') with ppc_crypto_support() for clang. * bmo#1613235 - Add POWER ChaCha20 stream cipher vector acceleration. Fixed in 3.63 * bmo#1697380 - Make a clang-format run on top of helpful contributions. * bmo#1683520 - ECCKiila P384, change syntax of nested structs initialization to prevent build isses with GCC 4.8. * bmo#1683520 - [lib/freebl/ecl] P-384: allow zero scalars in dual scalar multiplication. * bmo#1683520 - ECCKiila P521, change syntax of nested structs initialization to prevent build isses with GCC 4.8. * bmo#1683520 - [lib/freebl/ecl] P-521: allow zero scalars in dual scalar multiplication. * bmo#1696800 - HACL* update March 2021 - c95ab70fcb2bc21025d8845281bc4bc8987ca683. * bmo#1694214 - tstclnt can't enable middlebox compat mode. * bmo#1694392 - NSS does not work with PKCS #11 modules not supporting profiles. * bmo#1685880 - Minor fix to prevent unused variable on early return. * bmo#1685880 - Fix for the gcc compiler version 7 to support setenv with nss build. * bmo#1693217 - Increase nssckbi.h version number for March 2021 batch of root CA changes, CA list version 2.48. * bmo#1692094 - Set email distrust after to 21-03-01 for Camerfirma's 'Chambers of Commerce' and 'Global Chambersign' roots. * bmo#1618407 - Symantec root certs - Set CKA_NSS_EMAIL_DISTRUST_AFTER. * bmo#1693173 - Add GlobalSign R45, E45, R46, and E46 root certs to NSS. * bmo#1683738 - Add AC RAIZ FNMT-RCM SERVIDORES SEGUROS root cert to NSS. * bmo#1686854 - Remove GeoTrust PCA-G2 and VeriSign Universal root certs from NSS. * bmo#1687822 - Turn off Websites trust bit for the ???Staat der Nederlanden Root CA - G3??? root cert in NSS. * bmo#1692094 - Turn off Websites Trust Bit for 'Chambers of Commerce Root - 2008' and 'Global Chambersign Root - 2008???. * bmo#1694291 - Tracing fixes for ECH. update to NSS 3.62 * bmo#1688374 - Fix parallel build NSS-3.61 with make * bmo#1682044 - pkix_Build_GatherCerts() + pkix_CacheCert_Add() can corrupt 'cachedCertTable' * bmo#1690583 - Fix CH padding extension size calculation * bmo#1690421 - Adjust 3.62 ABI report formatting for new libabigail * bmo#1690421 - Install packaged libabigail in docker-builds image * bmo#1689228 - Minor ECH -09 fixes for interop testing, fuzzing * bmo#1674819 - Fixup a51fae403328, enum type may be signed * bmo#1681585 - Add ECH support to selfserv * bmo#1681585 - Update ECH to Draft-09 * bmo#1678398 - Add Export/Import functions for HPKE context * bmo#1678398 - Update HPKE to draft-07 update to NSS 3.61 * bmo#1682071 - Fix issue with IKE Quick mode deriving incorrect key values under certain conditions. * bmo#1684300 - Fix default PBE iteration count when NSS is compiled with NSS_DISABLE_DBM. * bmo#1651411 - Improve constant-timeness in RSA operations. * bmo#1677207 - Upgrade Google Test version to latest release. * bmo#1654332 - Add aarch64-make target to nss-try. Update to NSS 3.60.1: Notable changes in NSS 3.60: * TLS 1.3 Encrypted Client Hello (draft-ietf-tls-esni-08) support has been added, replacing the previous ESNI (draft-ietf-tls-esni-01) implementation. See bmo#1654332 for more information. * December 2020 batch of Root CA changes, builtins library updated to version 2.46. See bmo#1678189, bmo#1678166, and bmo#1670769 for more information. Update to NSS 3.59.1: * bmo#1679290 - Fix potential deadlock with certain third-party PKCS11 modules Update to NSS 3.59: Notable changes: * Exported two existing functions from libnss: CERT_AddCertToListHeadWithData and CERT_AddCertToListTailWithData Bugfixes * bmo#1607449 - Lock cert->nssCertificate to prevent a potential data race * bmo#1672823 - Add Wycheproof test cases for HMAC, HKDF, and DSA * bmo#1663661 - Guard against NULL token in nssSlot_IsTokenPresent * bmo#1670835 - Support enabling and disabling signatures via Crypto Policy * bmo#1672291 - Resolve libpkix OCSP failures on SHA1 self-signed root certs when SHA1 signatures are disabled. * bmo#1644209 - Fix broken SelectedCipherSuiteReplacer filter to solve some test intermittents * bmo#1672703 - Tolerate the first CCS in TLS 1.3 to fix a regression in our CVE-2020-25648 fix that broke purple-discord (boo#1179382) * bmo#1666891 - Support key wrap/unwrap with RSA-OAEP * bmo#1667989 - Fix gyp linking on Solaris * bmo#1668123 - Export CERT_AddCertToListHeadWithData and CERT_AddCertToListTailWithData from libnss * bmo#1634584 - Set CKA_NSS_SERVER_DISTRUST_AFTER for Trustis FPS Root CA * bmo#1663091 - Remove unnecessary assertions in the streaming ASN.1 decoder that affected decoding certain PKCS8 private keys when using NSS debug builds * bmo#670839 - Use ARM crypto extension for AES, SHA1 and SHA2 on MacOS. update to NSS 3.58 Bugs fixed: * bmo#1641480 (CVE-2020-25648) Tighten CCS handling for middlebox compatibility mode. * bmo#1631890 - Add support for Hybrid Public Key Encryption (draft-irtf-cfrg-hpke) support for TLS Encrypted Client Hello (draft-ietf-tls-esni). * bmo#1657255 - Add CI tests that disable SHA1/SHA2 ARM crypto extensions. * bmo#1668328 - Handle spaces in the Python path name when using gyp on Windows. * bmo#1667153 - Add PK11_ImportDataKey for data object import. * bmo#1665715 - Pass the embedded SCT list extension (if present) to TrustDomain::CheckRevocation instead of the notBefore value. update to NSS 3.57 * The following CA certificates were Added: bmo#1663049 - CN=Trustwave Global Certification Authority SHA-256 Fingerprint: 97552015F5DDFC3C8788C006944555408894450084F100867086BC1A2BB58DC8 bmo#1663049 - CN=Trustwave Global ECC P256 Certification Authority SHA-256 Fingerprint: 945BBC825EA554F489D1FD51A73DDF2EA624AC7019A05205225C22A78CCFA8B4 bmo#1663049 - CN=Trustwave Global ECC P384 Certification Authority SHA-256 Fingerprint: 55903859C8C0C3EBB8759ECE4E2557225FF5758BBD38EBD48276601E1BD58097 * The following CA certificates were Removed: bmo#1651211 - CN=EE Certification Centre Root CA SHA-256 Fingerprint: 3E84BA4342908516E77573C0992F0979CA084E4685681FF195CCBA8A229B8A76 bmo#1656077 - O=Government Root Certification Authority; C=TW SHA-256 Fingerprint: 7600295EEFE85B9E1FD624DB76062AAAAE59818A54D2774CD4C0B2C01131E1B3 * Trust settings for the following CA certificates were Modified: bmo#1653092 - CN=OISTE WISeKey Global Root GA CA Websites (server authentication) trust bit removed. * https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes update to NSS 3.56 Notable changes * bmo#1650702 - Support SHA-1 HW acceleration on ARMv8 * bmo#1656981 - Use MPI comba and mulq optimizations on x86-64 MacOS. * bmo#1654142 - Add CPU feature detection for Intel SHA extension. * bmo#1648822 - Add stricter validation of DH keys in FIPS mode. * bmo#1656986 - Properly detect arm64 during GYP build architecture detection. * bmo#1652729 - Add build flag to disable RC2 and relocate to lib/freebl/deprecated. * bmo#1656429 - Correct RTT estimate used in 0-RTT anti-replay. * bmo#1588941 - Send empty certificate message when scheme selection fails. * bmo#1652032 - Fix failure to build in Windows arm64 makefile cross-compilation. * bmo#1625791 - Fix deadlock issue in nssSlot_IsTokenPresent. * bmo#1653975 - Fix 3.53 regression by setting 'all' as the default makefile target. * bmo#1659792 - Fix broken libpkix tests with unexpired PayPal cert. * bmo#1659814 - Fix interop.sh failures with newer tls-interop commit and dependencies. * bmo#1656519 - NSPR dependency updated to 4.28 update to NSS 3.55 Notable changes * P384 and P521 elliptic curve implementations are replaced with verifiable implementations from Fiat-Crypto [0] and ECCKiila [1]. * PK11_FindCertInSlot is added. With this function, a given slot can be queried with a DER-Encoded certificate, providing performance and usability improvements over other mechanisms. (bmo#1649633) * DTLS 1.3 implementation is updated to draft-38. (bmo#1647752) Relevant Bugfixes * bmo#1631583 (CVE-2020-6829, CVE-2020-12400) - Replace P384 and P521 with new, verifiable implementations from Fiat-Crypto and ECCKiila. * bmo#1649487 - Move overzealous assertion in VFY_EndWithSignature. * bmo#1631573 (CVE-2020-12401) - Remove unnecessary scalar padding. * bmo#1636771 (CVE-2020-12403) - Explicitly disable multi-part ChaCha20 (which was not functioning correctly) and more strictly enforce tag length. * bmo#1649648 - Don't memcpy zero bytes (sanitizer fix). * bmo#1649316 - Don't memcpy zero bytes (sanitizer fix). * bmo#1649322 - Don't memcpy zero bytes (sanitizer fix). * bmo#1653202 - Fix initialization bug in blapitest when compiled with NSS_DISABLE_DEPRECATED_SEED. * bmo#1646594 - Fix AVX2 detection in makefile builds. * bmo#1649633 - Add PK11_FindCertInSlot to search a given slot for a DER-encoded certificate. * bmo#1651520 - Fix slotLock race in NSC_GetTokenInfo. * bmo#1647752 - Update DTLS 1.3 implementation to draft-38. * bmo#1649190 - Run cipher, sdr, and ocsp tests under standard test cycle in CI. * bmo#1649226 - Add Wycheproof ECDSA tests. * bmo#1637222 - Consistently enforce IV requirements for DES and 3DES. * bmo#1067214 - Enforce minimum PKCS#1 v1.5 padding length in RSA_CheckSignRecover. * bmo#1646324 - Advertise PKCS#1 schemes for certificates in the signature_algorithms extension. update to NSS 3.54 Notable changes * Support for TLS 1.3 external pre-shared keys (bmo#1603042). * Use ARM Cryptography Extension for SHA256, when available (bmo#1528113) * The following CA certificates were Added: bmo#1645186 - certSIGN Root CA G2. bmo#1645174 - e-Szigno Root CA 2017. bmo#1641716 - Microsoft ECC Root Certificate Authority 2017. bmo#1641716 - Microsoft RSA Root Certificate Authority 2017. * The following CA certificates were Removed: bmo#1645199 - AddTrust Class 1 CA Root. bmo#1645199 - AddTrust External CA Root. bmo#1641718 - LuxTrust Global Root 2. bmo#1639987 - Staat der Nederlanden Root CA - G2. bmo#1618402 - Symantec Class 2 Public Primary Certification Authority - G4. bmo#1618402 - Symantec Class 1 Public Primary Certification Authority - G4. bmo#1618402 - VeriSign Class 3 Public Primary Certification Authority - G3. * A number of certificates had their Email trust bit disabled. See bmo#1618402 for a complete list. Bugs fixed * bmo#1528113 - Use ARM Cryptography Extension for SHA256. * bmo#1603042 - Add TLS 1.3 external PSK support. * bmo#1642802 - Add uint128 support for HACL* curve25519 on Windows. * bmo#1645186 - Add 'certSIGN Root CA G2' root certificate. * bmo#1645174 - Add Microsec's 'e-Szigno Root CA 2017' root certificate. * bmo#1641716 - Add Microsoft's non-EV root certificates. * bmo1621151 - Disable email trust bit for 'O=Government Root Certification Authority; C=TW' root. * bmo#1645199 - Remove AddTrust root certificates. * bmo#1641718 - Remove 'LuxTrust Global Root 2' root certificate. * bmo#1639987 - Remove 'Staat der Nederlanden Root CA - G2' root certificate. * bmo#1618402 - Remove Symantec root certificates and disable email trust bit. * bmo#1640516 - NSS 3.54 should depend on NSPR 4.26. * bmo#1642146 - Fix undefined reference to `PORT_ZAlloc_stub' in seed.c. * bmo#1642153 - Fix infinite recursion building NSS. * bmo#1642638 - Fix fuzzing assertion crash. * bmo#1642871 - Enable SSL_SendSessionTicket after resumption. * bmo#1643123 - Support SSL_ExportEarlyKeyingMaterial with External PSKs. * bmo#1643557 - Fix numerous compile warnings in NSS. * bmo#1644774 - SSL gtests to use ClearServerCache when resetting self-encrypt keys. * bmo#1645479 - Don't use SECITEM_MakeItem in secutil.c. * bmo#1646520 - Stricter enforcement of ASN.1 INTEGER encoding. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:1659-1 Released: Fri May 13 15:41:32 2022 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1189517,1195115 This update for cups fixes the following issues: - CUPS printservice takes much longer than before with a big number of printers (bsc#1189517) - CUPS PreserveJobHistory doesn't work with seconds (bsc#1195115) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1861-1 Released: Thu May 26 12:07:40 2022 Summary: Security update for cups Type: security Severity: important References: 1199474,CVE-2022-26691 This update for cups fixes the following issues: - CVE-2022-26691: Fixed an authentication bypass and code execution vulnerability (bsc#1199474) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:1898-1 Released: Tue May 31 18:03:55 2022 Summary: Security update for fribidi Type: security Severity: moderate References: 1196147,1196148,1196150,CVE-2022-25308,CVE-2022-25309,CVE-2022-25310 This update for fribidi fixes the following issues: - CVE-2022-25308: Fixed stack out of bounds read (bsc#1196147). - CVE-2022-25309: Fixed heap-buffer-overflow in fribidi_cap_rtl_to_unicode (bsc#1196148). - CVE-2022-25310: Fixed NULL pointer dereference in fribidi_remove_bidi_marks (bsc#1196150). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2533-1 Released: Fri Jul 22 17:37:15 2022 Summary: Security update for mozilla-nss Type: security Severity: important References: 1192079,1192080,1192086,1192087,1192228,1198486,1200027,CVE-2022-31741 This update for mozilla-nss fixes the following issues: Various FIPS 140-3 related fixes were backported from SUSE Linux Enterprise 15 SP4: - Makes the PBKDF known answer test compliant with NIST SP800-132. (bsc#1192079). - FIPS: Add on-demand integrity tests through sftk_FIPSRepeatIntegrityCheck() (bsc#1198980). - FIPS: mark algorithms as approved/non-approved according to security policy (bsc#1191546, bsc#1201298). - FIPS: remove hard disabling of unapproved algorithms. This requirement is now fulfilled by the service level indicator (bsc#1200325). - Run test suite at build time, and make it pass (bsc#1198486). - FIPS: skip algorithms that are hard disabled in FIPS mode. - Prevent expired PayPalEE cert from failing the tests. - Allow checksumming to be disabled, but only if we entered FIPS mode due to NSS_FIPS being set, not if it came from /proc. - FIPS: Make the PBKDF known answer test compliant with NIST SP800-132. - Update FIPS validation string to version-release format. - FIPS: remove XCBC MAC from list of FIPS approved algorithms. - Enable NSS_ENABLE_FIPS_INDICATORS and set NSS_FIPS_MODULE_ID for build. - FIPS: claim 3DES unapproved in FIPS mode (bsc#1192080). - FIPS: allow testing of unapproved algorithms (bsc#1192228). - FIPS: add version indicators. (bmo#1729550, bsc#1192086). - FIPS: fix some secret clearing (bmo#1697303, bsc#1192087). Version update to NSS 3.79: - Use PK11_GetSlotInfo instead of raw C_GetSlotInfo calls. - Update mercurial in clang-format docker image. - Use of uninitialized pointer in lg_init after alloc fail. - selfserv and tstclnt should use PR_GetPrefLoopbackAddrInfo. - Add SECMOD_LockedModuleHasRemovableSlots. - Fix secasn1d parsing of indefinite SEQUENCE inside indefinite GROUP. - Added RFC8422 compliant TLS <= 1.2 undefined/compressed ECPointFormat extension alerts. - TLS 1.3 Server: Send protocol_version alert on unsupported ClientHello.legacy_version. - Correct invalid record inner and outer content type alerts. - NSS does not properly import or export pkcs12 files with large passwords and pkcs5v2 encoding. - improve error handling after nssCKFWInstance_CreateObjectHandle. - Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple. - NSS 3.79 should depend on NSPR 4.34 Version update to NSS 3.78.1: - Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple Version update to NSS 3.78: - Added TLS 1.3 zero-length inner plaintext checks and tests, zero-length record/fragment handling tests. - Reworked overlong record size checks and added TLS1.3 specific boundaries. - Add ECH Grease Support to tstclnt - Add a strict variant of moz::pkix::CheckCertHostname. - Change SSL_REUSE_SERVER_ECDHE_KEY default to false. - Make SEC_PKCS12EnableCipher succeed - Update zlib in NSS to 1.2.12. Version update to NSS 3.77: - Fix link to TLS page on wireshark wiki - Add two D-TRUST 2020 root certificates. - Add Telia Root CA v2 root certificate. - Remove expired explicitly distrusted certificates from certdata.txt. - support specific RSA-PSS parameters in mozilla::pkix - Remove obsolete stateEnd check in SEC_ASN1DecoderUpdate. - Remove token member from NSSSlot struct. - Provide secure variants of mpp_pprime and mpp_make_prime. - Support UTF-8 library path in the module spec string. - Update nssUTF8_Length to RFC 3629 and fix buffer overrun. - Update googletest to 1.11.0 - Add SetTls13GreaseEchSize to experimental API. - TLS 1.3 Illegal legacy_version handling/alerts. - Fix calculation of ECH HRR Transcript. - Allow ld path to be set as environment variable. - Ensure we don't read uninitialized memory in ssl gtests. - Fix DataBuffer Move Assignment. - internal_error alert on Certificate Request with sha1+ecdsa in TLS 1.3 - rework signature verification in mozilla::pkix Version update to NSS 3.76.1 - Remove token member from NSSSlot struct. - Hold tokensLock through nssToken_GetSlot calls in nssTrustDomain_GetActiveSlots. - Check return value of PK11Slot_GetNSSToken. - Use Wycheproof JSON for RSASSA-PSS - Add SHA256 fingerprint comments to old certdata.txt entries. - Avoid truncating files in nss-release-helper.py. - Throw illegal_parameter alert for illegal extensions in handshake message. Version update to NSS 3.75 - Make DottedOIDToCode.py compatible with python3. - Avoid undefined shift in SSL_CERT_IS while fuzzing. - Remove redundant key type check. - Update ABI expectations to match ECH changes. - Enable CKM_CHACHA20. - check return on NSS_NoDB_Init and NSS_Shutdown. - Run ECDSA test vectors from bltest as part of the CI tests. - Add ECDSA test vectors to the bltest command line tool. - Allow to build using clang's integrated assembler. - Allow to override python for the build. - test HKDF output rather than input. - Use ASSERT macros to end failed tests early. - move assignment operator for DataBuffer. - Add test cases for ECH compression and unexpected extensions in SH. - Update tests for ECH-13. - Tidy up error handling. - Add tests for ECH HRR Changes. - Server only sends GREASE HRR extension if enabled by preference. - Update generation of the Associated Data for ECH-13. - When ECH is accepted, reject extensions which were only advertised in the Outer Client Hello. - Allow for compressed, non-contiguous, extensions. - Scramble the PSK extension in CHOuter. - Split custom extension handling for ECH. - Add ECH-13 HRR Handling. - Client side ECH padding. - Stricter ClientHelloInner Decompression. - Remove ECH_inner extension, use new enum format. - Update the version number for ECH-13 and adjust the ECHConfig size. Version update to NSS 3.74 - mozilla::pkix: support SHA-2 hashes in CertIDs in OCSP responses - Ensure clients offer consistent ciphersuites after HRR - NSS does not properly restrict server keys based on policy - Set nssckbi version number to 2.54 - Replace Google Trust Services LLC (GTS) R4 root certificate - Replace Google Trust Services LLC (GTS) R3 root certificate - Replace Google Trust Services LLC (GTS) R2 root certificate - Replace Google Trust Services LLC (GTS) R1 root certificate - Replace GlobalSign ECC Root CA R4 - Remove Expired Root Certificates - DST Root CA X3 - Remove Expiring Cybertrust Global Root and GlobalSign root certificates - Add renewed Autoridad de Certificacion Firmaprofesional CIF A62634068 root certificate - Add iTrusChina ECC root certificate - Add iTrusChina RSA root certificate - Add ISRG Root X2 root certificate - Add Chunghwa Telecom's HiPKI Root CA - G1 root certificate - Avoid a clang 13 unused variable warning in opt build - Check for missing signedData field - Ensure DER encoded signatures are within size limits - enable key logging option (boo#1195040) Version update to NSS 3.73.1: - Add SHA-2 support to mozilla::pkix's OSCP implementation Version update to NSS 3.73 - check for missing signedData field. - Ensure DER encoded signatures are within size limits. - NSS needs FiPS 140-3 version indicators. - pkix_CacheCert_Lookup doesn't return cached certs - sunset Coverity from NSS Fixed MFSA 2021-51 (bsc#1193170) CVE-2021-43527: Memory corruption via DER-encoded DSA and RSA-PSS signatures Version update to NSS 3.72 - Fix nsinstall parallel failure. - Increase KDF cache size to mitigate perf regression in about:logins Version update to NSS 3.71 - Set nssckbi version number to 2.52. - Respect server requirements of tlsfuzzer/test-tls13-signature-algorithms.py - Import of PKCS#12 files with Camellia encryption is not supported - Add HARICA Client ECC Root CA 2021. - Add HARICA Client RSA Root CA 2021. - Add HARICA TLS ECC Root CA 2021. - Add HARICA TLS RSA Root CA 2021. - Add TunTrust Root CA certificate to NSS. Version update to NSS 3.70 - Update test case to verify fix. - Explicitly disable downgrade check in TlsConnectStreamTls13.EchOuterWith12Max - Explicitly disable downgrade check in TlsConnectTest.DisableFalseStartOnFallback - Avoid using a lookup table in nssb64d. - Use HW accelerated SHA2 on AArch64 Big Endian. - Change default value of enableHelloDowngradeCheck to true. - Cache additional PBE entries. - Read HPKE vectors from official JSON. Version update to NSS 3.69.1: - Disable DTLS 1.0 and 1.1 by default - integrity checks in key4.db not happening on private components with AES_CBC NSS 3.69: - Disable DTLS 1.0 and 1.1 by default (backed out again) - integrity checks in key4.db not happening on private components with AES_CBC (backed out again) - SSL handling of signature algorithms ignores environmental invalid algorithms. - sqlite 3.34 changed it's open semantics, causing nss failures. - Gtest update changed the gtest reports, losing gtest details in all.sh reports. - NSS incorrectly accepting 1536 bit DH primes in FIPS mode - SQLite calls could timeout in starvation situations. - Coverity/cpp scanner errors found in nss 3.67 - Import the NSS documentation from MDN in nss/doc. - NSS using a tempdir to measure sql performance not active Version Update to 3.68.4 (bsc#1200027) - CVE-2022-31741: Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple. (bmo#1767590) Mozilla NSPR was updated to version 4.34: * add an API that returns a preferred loopback IP on hosts that have two IP stacks available. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:2595-1 Released: Fri Jul 29 16:00:42 2022 Summary: Security update for mozilla-nss Type: security Severity: important References: 1192079,1192080,1192086,1192087,1192228,1198486,1200027,CVE-2022-31741 This update for mozilla-nss fixes the following issues: Various FIPS 140-3 related fixes were backported from SUSE Linux Enterprise 15 SP4: - Makes the PBKDF known answer test compliant with NIST SP800-132. (bsc#1192079). - FIPS: Add on-demand integrity tests through sftk_FIPSRepeatIntegrityCheck() (bsc#1198980). - FIPS: mark algorithms as approved/non-approved according to security policy (bsc#1191546, bsc#1201298). - FIPS: remove hard disabling of unapproved algorithms. This requirement is now fulfilled by the service level indicator (bsc#1200325). - Run test suite at build time, and make it pass (bsc#1198486). - FIPS: skip algorithms that are hard disabled in FIPS mode. - Prevent expired PayPalEE cert from failing the tests. - Allow checksumming to be disabled, but only if we entered FIPS mode due to NSS_FIPS being set, not if it came from /proc. - FIPS: Make the PBKDF known answer test compliant with NIST SP800-132. - Update FIPS validation string to version-release format. - FIPS: remove XCBC MAC from list of FIPS approved algorithms. - Enable NSS_ENABLE_FIPS_INDICATORS and set NSS_FIPS_MODULE_ID for build. - FIPS: claim 3DES unapproved in FIPS mode (bsc#1192080). - FIPS: allow testing of unapproved algorithms (bsc#1192228). - FIPS: add version indicators. (bmo#1729550, bsc#1192086). - FIPS: fix some secret clearing (bmo#1697303, bsc#1192087). Version update to NSS 3.79: - Use PK11_GetSlotInfo instead of raw C_GetSlotInfo calls. - Update mercurial in clang-format docker image. - Use of uninitialized pointer in lg_init after alloc fail. - selfserv and tstclnt should use PR_GetPrefLoopbackAddrInfo. - Add SECMOD_LockedModuleHasRemovableSlots. - Fix secasn1d parsing of indefinite SEQUENCE inside indefinite GROUP. - Added RFC8422 compliant TLS <= 1.2 undefined/compressed ECPointFormat extension alerts. - TLS 1.3 Server: Send protocol_version alert on unsupported ClientHello.legacy_version. - Correct invalid record inner and outer content type alerts. - NSS does not properly import or export pkcs12 files with large passwords and pkcs5v2 encoding. - improve error handling after nssCKFWInstance_CreateObjectHandle. - Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple. - NSS 3.79 should depend on NSPR 4.34 Version update to NSS 3.78.1: - Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple Version update to NSS 3.78: - Added TLS 1.3 zero-length inner plaintext checks and tests, zero-length record/fragment handling tests. - Reworked overlong record size checks and added TLS1.3 specific boundaries. - Add ECH Grease Support to tstclnt - Add a strict variant of moz::pkix::CheckCertHostname. - Change SSL_REUSE_SERVER_ECDHE_KEY default to false. - Make SEC_PKCS12EnableCipher succeed - Update zlib in NSS to 1.2.12. Version update to NSS 3.77: - Fix link to TLS page on wireshark wiki - Add two D-TRUST 2020 root certificates. - Add Telia Root CA v2 root certificate. - Remove expired explicitly distrusted certificates from certdata.txt. - support specific RSA-PSS parameters in mozilla::pkix - Remove obsolete stateEnd check in SEC_ASN1DecoderUpdate. - Remove token member from NSSSlot struct. - Provide secure variants of mpp_pprime and mpp_make_prime. - Support UTF-8 library path in the module spec string. - Update nssUTF8_Length to RFC 3629 and fix buffer overrun. - Update googletest to 1.11.0 - Add SetTls13GreaseEchSize to experimental API. - TLS 1.3 Illegal legacy_version handling/alerts. - Fix calculation of ECH HRR Transcript. - Allow ld path to be set as environment variable. - Ensure we don't read uninitialized memory in ssl gtests. - Fix DataBuffer Move Assignment. - internal_error alert on Certificate Request with sha1+ecdsa in TLS 1.3 - rework signature verification in mozilla::pkix Version update to NSS 3.76.1 - Remove token member from NSSSlot struct. - Hold tokensLock through nssToken_GetSlot calls in nssTrustDomain_GetActiveSlots. - Check return value of PK11Slot_GetNSSToken. - Use Wycheproof JSON for RSASSA-PSS - Add SHA256 fingerprint comments to old certdata.txt entries. - Avoid truncating files in nss-release-helper.py. - Throw illegal_parameter alert for illegal extensions in handshake message. Version update to NSS 3.75 - Make DottedOIDToCode.py compatible with python3. - Avoid undefined shift in SSL_CERT_IS while fuzzing. - Remove redundant key type check. - Update ABI expectations to match ECH changes. - Enable CKM_CHACHA20. - check return on NSS_NoDB_Init and NSS_Shutdown. - Run ECDSA test vectors from bltest as part of the CI tests. - Add ECDSA test vectors to the bltest command line tool. - Allow to build using clang's integrated assembler. - Allow to override python for the build. - test HKDF output rather than input. - Use ASSERT macros to end failed tests early. - move assignment operator for DataBuffer. - Add test cases for ECH compression and unexpected extensions in SH. - Update tests for ECH-13. - Tidy up error handling. - Add tests for ECH HRR Changes. - Server only sends GREASE HRR extension if enabled by preference. - Update generation of the Associated Data for ECH-13. - When ECH is accepted, reject extensions which were only advertised in the Outer Client Hello. - Allow for compressed, non-contiguous, extensions. - Scramble the PSK extension in CHOuter. - Split custom extension handling for ECH. - Add ECH-13 HRR Handling. - Client side ECH padding. - Stricter ClientHelloInner Decompression. - Remove ECH_inner extension, use new enum format. - Update the version number for ECH-13 and adjust the ECHConfig size. Version update to NSS 3.74 - mozilla::pkix: support SHA-2 hashes in CertIDs in OCSP responses - Ensure clients offer consistent ciphersuites after HRR - NSS does not properly restrict server keys based on policy - Set nssckbi version number to 2.54 - Replace Google Trust Services LLC (GTS) R4 root certificate - Replace Google Trust Services LLC (GTS) R3 root certificate - Replace Google Trust Services LLC (GTS) R2 root certificate - Replace Google Trust Services LLC (GTS) R1 root certificate - Replace GlobalSign ECC Root CA R4 - Remove Expired Root Certificates - DST Root CA X3 - Remove Expiring Cybertrust Global Root and GlobalSign root certificates - Add renewed Autoridad de Certificacion Firmaprofesional CIF A62634068 root certificate - Add iTrusChina ECC root certificate - Add iTrusChina RSA root certificate - Add ISRG Root X2 root certificate - Add Chunghwa Telecom's HiPKI Root CA - G1 root certificate - Avoid a clang 13 unused variable warning in opt build - Check for missing signedData field - Ensure DER encoded signatures are within size limits - enable key logging option (boo#1195040) Version update to NSS 3.73.1: - Add SHA-2 support to mozilla::pkix's OSCP implementation Version update to NSS 3.73 - check for missing signedData field. - Ensure DER encoded signatures are within size limits. - NSS needs FiPS 140-3 version indicators. - pkix_CacheCert_Lookup doesn't return cached certs - sunset Coverity from NSS Fixed MFSA 2021-51 (bsc#1193170) CVE-2021-43527: Memory corruption via DER-encoded DSA and RSA-PSS signatures Version update to NSS 3.72 - Fix nsinstall parallel failure. - Increase KDF cache size to mitigate perf regression in about:logins Version update to NSS 3.71 - Set nssckbi version number to 2.52. - Respect server requirements of tlsfuzzer/test-tls13-signature-algorithms.py - Import of PKCS#12 files with Camellia encryption is not supported - Add HARICA Client ECC Root CA 2021. - Add HARICA Client RSA Root CA 2021. - Add HARICA TLS ECC Root CA 2021. - Add HARICA TLS RSA Root CA 2021. - Add TunTrust Root CA certificate to NSS. Version update to NSS 3.70 - Update test case to verify fix. - Explicitly disable downgrade check in TlsConnectStreamTls13.EchOuterWith12Max - Explicitly disable downgrade check in TlsConnectTest.DisableFalseStartOnFallback - Avoid using a lookup table in nssb64d. - Use HW accelerated SHA2 on AArch64 Big Endian. - Change default value of enableHelloDowngradeCheck to true. - Cache additional PBE entries. - Read HPKE vectors from official JSON. Version update to NSS 3.69.1: - Disable DTLS 1.0 and 1.1 by default - integrity checks in key4.db not happening on private components with AES_CBC NSS 3.69: - Disable DTLS 1.0 and 1.1 by default (backed out again) - integrity checks in key4.db not happening on private components with AES_CBC (backed out again) - SSL handling of signature algorithms ignores environmental invalid algorithms. - sqlite 3.34 changed it's open semantics, causing nss failures. - Gtest update changed the gtest reports, losing gtest details in all.sh reports. - NSS incorrectly accepting 1536 bit DH primes in FIPS mode - SQLite calls could timeout in starvation situations. - Coverity/cpp scanner errors found in nss 3.67 - Import the NSS documentation from MDN in nss/doc. - NSS using a tempdir to measure sql performance not active Version Update to 3.68.4 (bsc#1200027) - CVE-2022-31741: Initialize pointers passed to NSS_CMSDigestContext_FinishMultiple. (bmo#1767590) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:2901-1 Released: Fri Aug 26 03:34:23 2022 Summary: Recommended update for elfutils Type: recommended Severity: moderate References: This update for elfutils fixes the following issues: - Fix runtime dependency for devel package ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:2939-1 Released: Mon Aug 29 14:49:17 2022 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1201298,1202645 This update for mozilla-nss fixes the following issues: Update to NSS 3.79.1 (bsc#1202645) * compare signature and signatureAlgorithm fields in legacy certificate verifier. * Uninitialized value in cert_ComputeCertType. * protect SFTKSlot needLogin with slotLock. * avoid data race on primary password change. * check for null template in sec_asn1{d,e}_push_state. - FIPS: unapprove the rest of the DSA ciphers, keeping signature verification only (bsc#1201298). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:3241-1 Released: Mon Sep 12 07:21:04 2022 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1201511 This update for cups fixes the following issues: - Stuck print jobs being cancelled immediately, despite MaxJobTime being set to 0 (bsc#1201511) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3307-1 Released: Mon Sep 19 13:26:51 2022 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1189802,1195773,1201783,CVE-2021-36690,CVE-2022-35737 This update for sqlite3 fixes the following issues: - CVE-2022-35737: Fixed an array-bounds overflow if billions of bytes are used in a string argument to a C API (bnc#1201783). - CVE-2021-36690: Fixed an issue with the SQLite Expert extension when a column has no collating sequence (bsc#1189802). - Package the Tcl bindings here again so that we only ship one copy of SQLite (bsc#1195773). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3784-1 Released: Wed Oct 26 18:03:28 2022 Summary: Security update for libtasn1 Type: security Severity: critical References: 1204690,CVE-2021-46848 This update for libtasn1 fixes the following issues: - CVE-2021-46848: Fixed off-by-one array size check that affects asn1_encode_simple_der (bsc#1204690) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:3873-1 Released: Fri Nov 4 14:58:08 2022 Summary: Recommended update for mozilla-nspr, mozilla-nss Type: recommended Severity: moderate References: 1191546,1198980,1201298,1202870,1204729 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nspr was updated to version 4.34.1: * add file descriptor sanity checks in the NSPR poll function. mozilla-nss was updated to NSS 3.79.2 (bsc#1204729): * Bump minimum NSPR version to 4.34.1. * Gracefully handle null nickname in CERT_GetCertNicknameWithValidity. Other fixes that were applied: - FIPS: Allow the use of DSA keys (verification only) (bsc#1201298). - FIPS: Add sftk_FIPSRepeatIntegrityCheck() to softoken's .def file (bsc#1198980). - FIPS: Allow the use of longer symmetric keys via the service level indicator (bsc#1191546). - FIPS: Prevent TLS sessions from getting flagged as non-FIPS (bsc#1191546). - FIPS: Mark DSA keygen unapproved (bsc#1191546, bsc#1201298). - FIPS: Use libjitterentropy for entropy (bsc#1202870). - FIPS: Fixed an abort() when both NSS_FIPS and /proc FIPS mode are enabled. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:3958-1 Released: Fri Nov 11 15:20:45 2022 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1191546,1198980,1201298,1202870,1204729 This update for mozilla-nss fixes the following issues: mozilla-nss was updated to NSS 3.79.2 (bsc#1204729) * Bump minimum NSPR version to 4.34.1. * Gracefully handle null nickname in CERT_GetCertNicknameWithValidity. - FIPS: Allow the use of DSA keys (verification only) (bsc#1201298). - FIPS: Add sftk_FIPSRepeatIntegrityCheck() to softoken's .def file (bsc#1198980). - FIPS: Allow the use of longer symmetric keys via the service level indicator (bsc#1191546). - FIPS: Export sftk_FIPSRepeatIntegrityCheck() correctly (bsc#1198980). - FIPS: Prevent sessions from getting flagged as non-FIPS (bsc#1191546). - FIPS: Mark DSA keygen unapproved (bsc#1191546, bsc#1201298). - FIPS: Enable userspace entropy gathering via libjitterentropy (bsc#1202870). - FIPS: Prevent keys from getting flagged as non-FIPS and add remaining TLS mechanisms. - FIPS: Use libjitterentropy for entropy. - FIPS: Fixed an abort() when both NSS_FIPS and /proc FIPS mode are enabled. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:4492-1 Released: Wed Dec 14 13:52:39 2022 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1191546,1198980,1201298 This update for mozilla-nss fixes the following issues: - FIPS: Disapprove the creation of DSA keys, i.e. mark them as not-fips (bsc#1201298) - FIPS: Allow the use SHA keygen mechs (bsc#1191546). - FIPS: ensure abort() is called when the repeat integrity check fails (bsc#1198980). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:4628-1 Released: Wed Dec 28 09:23:13 2022 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1206337,CVE-2022-46908 This update for sqlite3 fixes the following issues: - CVE-2022-46908: Properly implement the azProhibitedFunctions protection mechanism, when relying on --safe for execution of an untrusted CLI script (bsc#1206337). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:119-1 Released: Fri Jan 20 10:28:07 2023 Summary: Security update for mozilla-nss Type: security Severity: important References: 1204272,1207038,CVE-2022-23491,CVE-2022-3479 This update for mozilla-nss fixes the following issues: - CVE-2022-3479: Fixed a potential crash that could be triggered when a server requested a client authentication certificate, but the client had no certificates stored (bsc#1204272). - Updated to version 3.79.3 (bsc#1207038): - CVE-2022-23491: Removed trust for 3 root certificates from TrustCor. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:434-1 Released: Thu Feb 16 09:08:05 2023 Summary: Security update for mozilla-nss Type: security Severity: important References: 1208138,CVE-2023-0767 This update for mozilla-nss fixes the following issues: Updated to NSS 3.79.4 (bsc#1208138): - CVE-2023-0767: Fixed handling of unknown PKCS#12 safe bag types. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:1810-1 Released: Tue Apr 11 12:06:13 2023 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1191467,1191525,1198932,1200321,1201234,1203446 This update for cups fixes the following issues: - Fix print jobs on cups.sock return with EAGAIN (Resource temporarily unavailable) (bsc#1191525) - Fix '/usr/bin/lpr: Error - The printer or class does not exist (bsc#1203446) - Improves logging on 'IPP_STATUS_ERROR_NOT_FOUND' error (bsc#1191467, bsc#1198932) - Add 'After=network.target sssd.service' to the systemd unit (bsc#1201234, bsc#1200321) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:1939-1 Released: Fri Apr 21 11:14:30 2023 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1191546,1207209,1208242,1208999 This update for mozilla-nss fixes the following issues: - FIPS 140-3: Adjust SLI reporting for PBKDF2 parameter validation (bsc#1208999) - FIPS 140-3: Update session->lastOpWasFIPS before destroying the key after derivation in the CKM_TLS12_KEY_AND_MAC_DERIVE, CKM_NSS_TLS_KEY_AND_MAC_DERIVE_SHA256, CKM_TLS_KEY_AND_MAC_DERIVE and CKM_SSL3_KEY_AND_MAC_DERIVE cases. (bsc#1191546) - FIPS 140-3: more changes for pairwise consistency checks. (bsc#1207209) - Add manpages to mozilla-nss-tools (bsc#1208242) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2347-1 Released: Thu Jun 1 14:33:10 2023 Summary: Security update for cups Type: security Severity: important References: 1211643,CVE-2023-32324 This update for cups fixes the following issues: - CVE-2023-32324: Fixed a buffer overflow in format_log_line() which could cause a denial-of-service (bsc#1211643). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2616-1 Released: Thu Jun 22 16:47:50 2023 Summary: Security update for cups Type: security Severity: important References: 1212230,CVE-2023-34241 This update for cups fixes the following issues: - CVE-2023-34241: Fixed a use-after-free problem in cupsdAcceptClient() (bsc#1212230). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2788-1 Released: Thu Jul 6 11:51:02 2023 Summary: Recommended update for mozilla-nspr, mozilla-nss Type: recommended Severity: moderate References: 1185116,1202118 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nspr was updated to version 4.35 * fixes for building with clang * use the number of online processors for the PR_GetNumberOfProcessors() API on some platforms * fix build on mips+musl libc * Add support for the LoongArch 64-bit architecture mozilla-nss was update to NSS 3.90: * clang-format lib/freebl/stubs.c * Add a constant time select function * Updating an old dbm with lots of certs with keys to sql results in a database that is slow to access. * output early build errors by default * Update the technical constraints for KamuSM * Add BJCA Global Root CA1 and CA2 root certificates * Enable default UBSan Checks * Add explicit handling of zero length records * Tidy up DTLS ACK Error Handling Path * Refactor zero length record tests * Fix compiler warning via correct assert * run linux tests on nss-t/t-linux-xlarge-gcp * In FIPS mode, nss should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator * Fix reading raw negative numbers * Repairing unreachable code in clang built with gyp * Integrate Vale Curve25519 * Removing unused flags for Hacl* * Adding a better error message * Update HACL* till 51a72a953a4ee6f91e63b2816ae5c4e62edf35d6 * Fall back to the softokn when writing certificate trust * FIPS-104-3 requires we restart post programmatically * cmd/ecperf: fix dangling pointer warning on gcc 13 * Update ACVP dockerfile for compatibility with debian package changes * Add a CI task for tracking ECCKiila code status, update whitespace in ECCKiila files * Removed deprecated sprintf function and replaced with snprintf * fix rst warnings in nss doc * Fix incorrect pygment style * Change GYP directive to apply across platforms * Add libsmime3 abi-check exception for NSS_CMSSignerInfo_GetDigestAlgTag - Merge the libfreebl3-hmac and libsoftokn3-hmac packages into the respective libraries. (bsc#1185116) update to NSS 3.89.1 * Update the technical constraints for KamuSM. * Add BJCA Global Root CA1 and CA2 root certificates. update to NSS 3.89 * revert freebl/softoken RSA_MIN_MODULUS_BITS increase * PR_STATIC_ASSERT is cursed * Need to add policy control to keys lengths for signatures * Fix unreachable code warning in fuzz builds * Fix various compiler warnings in NSS * Enable various compiler warnings for clang builds * set PORT error after sftk_HMACCmp failure * Need to add policy control to keys lengths for signatures * remove data length assertion in sec_PKCS7Decrypt * Make high tag number assertion failure an error * CKM_SHA384_KEY_DERIVATION correction maximum key length from 284 to 384 * Tolerate certificate_authorities xtn in ClientHello * Fix build failure on Windows * migrate Win 2012 tasks to Azure * fix title length in doc * Add interop tests for HRR and PSK to GREASE suite * Add presence/absence tests for TLS GREASE * Correct addition of GREASE value to ALPN xtn * CH extension permutation * TLS GREASE (RFC8701) * improve handling of unknown PKCS#12 safe bag types * use a different treeherder symbol for each docker image build task * remove nested table in rst doc * Export NSS_CMSSignerInfo_GetDigestAlgTag * build failure while implicitly casting SECStatus to PRUInt32 update to NSS 3.88.1 * improve handling of unknown PKCS#12 safe bag types update to NSS 3.88 * remove nested table in rst doc * Export NSS_CMSSignerInfo_GetDigestAlgTag. * build failure while implicitly casting SECStatus to PRUInt32 * Add check for ClientHello SID max length * Added EarlyData ALPN test support to BoGo shim * ECH client - Discard resumption TLS < 1.3 Session(IDs|Tickets) if ECH configs are setup * On HRR skip PSK incompatible with negotiated ciphersuites hash algorithm * ECH client: Send ech_required alert on server negotiating TLS 1.2. Fixed misleading Gtest, enabled corresponding BoGo test * Added Bogo ECH rejection test support * Added ECH 0Rtt support to BoGo shim * RSA OAEP Wycheproof JSON * RSA decrypt Wycheproof JSON * ECDSA Wycheproof JSON * ECDH Wycheproof JSON * PKCS#1v1.5 wycheproof json * Use X25519 wycheproof json * Move scripts to python3 * Properly link FuzzingEngine for oss-fuzz. * Extending RSA-PSS bltest test coverage (Adding SHA-256 and SHA-384) * NSS needs to move off of DSA for integrity checks * Add initial testing with ACVP vector sets using acvp-rust * Don't clone libFuzzer, rely on clang instead update to NSS 3.87 * NULL password encoding incorrect * Fix rng stub signature for fuzzing builds * Updating the compiler parsing for build * Modification of supported compilers * tstclnt crashes when accessing gnutls server without a user cert in the database. * Add configuration option to enable source-based coverage sanitizer * Update ECCKiila generated files. * Add support for the LoongArch 64-bit architecture * add checks for zero-length RSA modulus to avoid memory errors and failed assertions later * Additional zero-length RSA modulus checks update to NSS 3.86 * conscious language removal in NSS * Set nssckbi version number to 2.60 * Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates * Remove Staat der Nederlanden EV Root CA from NSS * Remove EC-ACC root cert from NSS * Remove SwissSign Platinum CA - G2 from NSS * Remove Network Solutions Certificate Authority * compress docker image artifact with zstd * Migrate nss from AWS to GCP * Enable static builds in the CI * Removing SAW docker from the NSS build system * Initialising variables in the rsa blinding code * Implementation of the double-signing of the message for ECDSA * Adding exponent blinding for RSA. update to NSS 3.85 * Modification of the primes.c and dhe-params.c in order to have better looking tables * Update zlib in NSS to 1.2.13 * Skip building modutil and shlibsign when building in Firefox * Mark _nss_version_c unused on clang-cl * bmo#1795668 - Remove redundant variable definitions in lowhashtest * Add note about python executable to build instructions. update to NSS 3.84 * Bump minimum NSPR version to 4.35 * Add a flag to disable building libnssckbi. update to NSS 3.83 * Remove set-but-unused variables from SEC_PKCS12DecoderValidateBags * Set nssckbi version number to 2.58 * Add two SECOM root certificates to NSS * Add two DigitalSign root certificates to NSS * Remove Camerfirma Global Chambersign Root from NSS * Added bug reference and description to disabled UnsolicitedServerNameAck bogo ECH test * Removed skipping of ECH on equality of private and public server name * Added comment and bug reference to ECHRandomHRRExtension bogo test * Added Bogo shim client HRR test support. Fixed overwriting of CHInner.random on HRR * Added check for server only sending ECH extension with retry configs in EncryptedExtensions and if not accepting ECH. Changed config setting behavior to skip configs with unsupported mandatory extensions instead of failing * Added ECH client support to BoGo shim. Changed CHInner creation to skip TLS 1.2 only extensions to comply with BoGo * Added ECH server support to BoGo shim. Fixed NSS ECH server accept_confirmation bugs * Update BoGo tests to recent BoringSSL version * Bump minimum NSPR version to 4.34.1 update to NSS 3.82 * check for null template in sec_asn1{d,e}_push_state * QuickDER: Forbid NULL tags with non-zero length * Initialize local variables in TlsConnectTestBase::ConnectAndCheckCipherSuite * Cast the result of GetProcAddress * pk11wrap: Tighten certificate lookup based on PKCS #11 URI. update to NSS 3.81 * Enable aarch64 hardware crypto support on OpenBSD * make NSS_SecureMemcmp 0/1 valued * Add no_application_protocol alert handler and test client error code is set * Gracefully handle null nickname in CERT_GetCertNicknameWithValidity * required for Firefox 104 - raised NSPR requirement to 4.34.1 - changing some Requires from (pre) to generic as (pre) is not sufficient (bsc#1202118) update to NSS 3.80 * Fix SEC_ERROR_ALGORITHM_MISMATCH entry in SECerrs.h. * Add support for asynchronous client auth hooks. * nss-policy-check: make unknown keyword check optional. * GatherBuffer: Reduced plaintext buffer allocations by allocating it on initialization. Replaced redundant code with assert. Debug builds: Added buffer freeing/allocation for each record. * Mark 3.79 as an ESR release. * Bump nssckbi version number for June. * Remove Hellenic Academic 2011 Root. * Add E-Tugra Roots. * Add Certainly Roots. * Add DigitCert Roots. * Protect SFTKSlot needLogin with slotLock. * Compare signature and signatureAlgorithm fields in legacy certificate verifier. * Uninitialized value in cert_VerifyCertChainOld. * Unchecked return code in sec_DecodeSigAlg. * Uninitialized value in cert_ComputeCertType. * Avoid data race on primary password change. * Replace ppc64 dcbzl intrinisic. * Allow LDFLAGS override in makefile builds. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:2814-1 Released: Wed Jul 12 22:05:25 2023 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1185116,1202118 This update for mozilla-nss fixes the following issues: mozilla-nss was updated to NSS 3.90: * Add a constant time select function * Updating an old dbm with lots of certs with keys to sql results in a database that is slow to access. * output early build errors by default * Update the technical constraints for KamuSM * Add BJCA Global Root CA1 and CA2 root certificates * Enable default UBSan Checks * Add explicit handling of zero length records * Tidy up DTLS ACK Error Handling Path * Refactor zero length record tests * Fix compiler warning via correct assert * run linux tests on nss-t/t-linux-xlarge-gcp * In FIPS mode, nss should reject RSASSA-PSS salt lengths larger than the output size of the hash function used, or provide an indicator * Fix reading raw negative numbers * Repairing unreachable code in clang built with gyp * Integrate Vale Curve25519 * Removing unused flags for Hacl* * Adding a better error message * Update HACL* till 51a72a953a4ee6f91e63b2816ae5c4e62edf35d6 * Fall back to the softokn when writing certificate trust * FIPS-104-3 requires we restart post programmatically * cmd/ecperf: fix dangling pointer warning on gcc 13 * Update ACVP dockerfile for compatibility with debian package changes * Add a CI task for tracking ECCKiila code status, update whitespace in ECCKiila files * Removed deprecated sprintf function and replaced with snprintf * fix rst warnings in nss doc * Fix incorrect pygment style * Change GYP directive to apply across platforms * Add libsmime3 abi-check exception for NSS_CMSSignerInfo_GetDigestAlgTag - Merge the libfreebl3-hmac and libsoftokn3-hmac packages into the respective libraries. (bsc#1185116) update to NSS 3.89.1 * Update the technical constraints for KamuSM. * Add BJCA Global Root CA1 and CA2 root certificates. update to NSS 3.89 * revert freebl/softoken RSA_MIN_MODULUS_BITS increase * PR_STATIC_ASSERT is cursed * Need to add policy control to keys lengths for signatures * Fix unreachable code warning in fuzz builds * Fix various compiler warnings in NSS * Enable various compiler warnings for clang builds * set PORT error after sftk_HMACCmp failure * Need to add policy control to keys lengths for signatures * remove data length assertion in sec_PKCS7Decrypt * Make high tag number assertion failure an error * CKM_SHA384_KEY_DERIVATION correction maximum key length from 284 to 384 * Tolerate certificate_authorities xtn in ClientHello * Fix build failure on Windows * migrate Win 2012 tasks to Azure * fix title length in doc * Add interop tests for HRR and PSK to GREASE suite * Add presence/absence tests for TLS GREASE * Correct addition of GREASE value to ALPN xtn * CH extension permutation * TLS GREASE (RFC8701) * improve handling of unknown PKCS#12 safe bag types * use a different treeherder symbol for each docker image build task * remove nested table in rst doc * Export NSS_CMSSignerInfo_GetDigestAlgTag * build failure while implicitly casting SECStatus to PRUInt32 update to NSS 3.88.1 * improve handling of unknown PKCS#12 safe bag types update to NSS 3.88 * remove nested table in rst doc * Export NSS_CMSSignerInfo_GetDigestAlgTag. * build failure while implicitly casting SECStatus to PRUInt32 * Add check for ClientHello SID max length * Added EarlyData ALPN test support to BoGo shim * ECH client - Discard resumption TLS < 1.3 Session(IDs|Tickets) if ECH configs are setup * On HRR skip PSK incompatible with negotiated ciphersuites hash algorithm * ECH client: Send ech_required alert on server negotiating TLS 1.2. Fixed misleading Gtest, enabled corresponding BoGo test * Added Bogo ECH rejection test support * Added ECH 0Rtt support to BoGo shim * RSA OAEP Wycheproof JSON * RSA decrypt Wycheproof JSON * ECDSA Wycheproof JSON * ECDH Wycheproof JSON * PKCS#1v1.5 wycheproof json * Use X25519 wycheproof json * Move scripts to python3 * Properly link FuzzingEngine for oss-fuzz. * Extending RSA-PSS bltest test coverage (Adding SHA-256 and SHA-384) * NSS needs to move off of DSA for integrity checks * Add initial testing with ACVP vector sets using acvp-rust * Don't clone libFuzzer, rely on clang instead update to NSS 3.87 * NULL password encoding incorrect * Fix rng stub signature for fuzzing builds * Updating the compiler parsing for build * Modification of supported compilers * tstclnt crashes when accessing gnutls server without a user cert in the database. * Add configuration option to enable source-based coverage sanitizer * Update ECCKiila generated files. * Add support for the LoongArch 64-bit architecture * add checks for zero-length RSA modulus to avoid memory errors and failed assertions later * Additional zero-length RSA modulus checks update to NSS 3.86 * conscious language removal in NSS * Set nssckbi version number to 2.60 * Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates * Remove Staat der Nederlanden EV Root CA from NSS * Remove EC-ACC root cert from NSS * Remove SwissSign Platinum CA - G2 from NSS * Remove Network Solutions Certificate Authority * compress docker image artifact with zstd * Migrate nss from AWS to GCP * Enable static builds in the CI * Removing SAW docker from the NSS build system * Initialising variables in the rsa blinding code * Implementation of the double-signing of the message for ECDSA * Adding exponent blinding for RSA. update to NSS 3.85 * Modification of the primes.c and dhe-params.c in order to have better looking tables * Update zlib in NSS to 1.2.13 * Skip building modutil and shlibsign when building in Firefox * Use __STDC_VERSION__ rather than __STDC__ as a guard * Remove redundant variable definitions in lowhashtest * Add note about python executable to build instructions. update to NSS 3.84 * Bump minimum NSPR version to 4.35 * Add a flag to disable building libnssckbi. update to NSS 3.83 * Remove set-but-unused variables from SEC_PKCS12DecoderValidateBags * Set nssckbi version number to 2.58 * Add two SECOM root certificates to NSS * Add two DigitalSign root certificates to NSS * Remove Camerfirma Global Chambersign Root from NSS * Added bug reference and description to disabled UnsolicitedServerNameAck bogo ECH test * Removed skipping of ECH on equality of private and public server name * Added comment and bug reference to ECHRandomHRRExtension bogo test * Added Bogo shim client HRR test support. Fixed overwriting of CHInner.random on HRR * Added check for server only sending ECH extension with retry configs in EncryptedExtensions and if not accepting ECH. Changed config setting behavior to skip configs with unsupported mandatory extensions instead of failing * Added ECH client support to BoGo shim. Changed CHInner creation to skip TLS 1.2 only extensions to comply with BoGo * Added ECH server support to BoGo shim. Fixed NSS ECH server accept_confirmation bugs * Update BoGo tests to recent BoringSSL version * Bump minimum NSPR version to 4.34.1 update to NSS 3.82 * check for null template in sec_asn1{d,e}_push_state * QuickDER: Forbid NULL tags with non-zero length * Initialize local variables in TlsConnectTestBase::ConnectAndCheckCipherSuite * Cast the result of GetProcAddress * pk11wrap: Tighten certificate lookup based on PKCS #11 URI. update to NSS 3.81 * Enable aarch64 hardware crypto support on OpenBSD * make NSS_SecureMemcmp 0/1 valued * Add no_application_protocol alert handler and test client error code is set * Gracefully handle null nickname in CERT_GetCertNicknameWithValidity * required for Firefox 104 - raised NSPR requirement to 4.34.1 - changing some Requires from (pre) to generic as (pre) is not sufficient (bsc#1202118) update to NSS 3.80 * Fix SEC_ERROR_ALGORITHM_MISMATCH entry in SECerrs.h. * Add support for asynchronous client auth hooks. * nss-policy-check: make unknown keyword check optional. * GatherBuffer: Reduced plaintext buffer allocations by allocating it on initialization. Replaced redundant code with assert. Debug builds: Added buffer freeing/allocation for each record. * Mark 3.79 as an ESR release. * Bump nssckbi version number for June. * Remove Hellenic Academic 2011 Root. * Add E-Tugra Roots. * Add Certainly Roots. * Add DigitCert Roots. * Protect SFTKSlot needLogin with slotLock. * Compare signature and signatureAlgorithm fields in legacy certificate verifier. * Uninitialized value in cert_VerifyCertChainOld. * Unchecked return code in sec_DecodeSigAlg. * Uninitialized value in cert_ComputeCertType. * Avoid data race on primary password change. * Replace ppc64 dcbzl intrinisic. * Allow LDFLAGS override in makefile builds. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3707-1 Released: Wed Sep 20 17:12:03 2023 Summary: Security update for cups Type: security Severity: important References: 1214254,1215204,CVE-2023-32360,CVE-2023-4504 This update for cups fixes the following issues: - CVE-2023-4504: Fixed heap overflow in OpenPrinting CUPS Postscript Parsing (bsc#1215204). - CVE-2023-32360: Fixed Information leak through Cups-Get-Document operation (bsc#1214254). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4619-1 Released: Thu Nov 30 10:13:52 2023 Summary: Security update for sqlite3 Type: security Severity: important References: 1210660,CVE-2023-2137 This update for sqlite3 fixes the following issues: - CVE-2023-2137: Fixed heap buffer overflow (bsc#1210660). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:4700-1 Released: Mon Dec 11 07:03:27 2023 Summary: Recommended update for p11-kit Type: recommended Severity: moderate References: This update for p11-kit fixes the following issues: - Ensure that programs using can be compiled with CRYPTOKI_GNU. Fixes GnuTLS builds (jsc#PED-6705). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4968-1 Released: Mon Dec 25 09:12:49 2023 Summary: Security update for jbigkit Type: security Severity: low References: 1198146,CVE-2022-1210 This update for jbigkit fixes the following issues: - CVE-2022-1210: Fixed denial of service in TIFF File Handler (bsc#1198146). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:26-1 Released: Thu Jan 4 11:15:24 2024 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1214980 This update for mozilla-nss fixes the following issues: Mozilla NSS was updated to NSS 3.90.1 * regenerate NameConstraints test certificates. * add OSXSAVE and XCR0 tests to AVX2 detection. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:597-1 Released: Thu Feb 22 20:07:11 2024 Summary: Security update for mozilla-nss Type: security Severity: important References: 1216198,CVE-2023-5388 This update for mozilla-nss fixes the following issues: Update to NSS 3.90.2: - CVE-2023-5388: Fixed timing attack against RSA decryption in TLS (bsc#1216198) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:1474-1 Released: Tue Apr 30 06:21:02 2024 Summary: Recommended update for cups Type: recommended Severity: important References: 1217119 This update for cups fixes the following issues: - Fix occasional stuck on poll() loop (bsc#1217119) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:1950-1 Released: Fri Jun 7 17:20:14 2024 Summary: Security update for glib2 Type: security Severity: moderate References: 1224044,CVE-2024-34397 This update for glib2 fixes the following issues: Update to version 2.78.6: + Fix a regression with IBus caused by the fix for CVE-2024-34397 Changes in version 2.78.5: + Fix CVE-2024-34397: GDBus signal subscriptions for well-known names are vulnerable to unicast spoofing. (bsc#1224044) + Bugs fixed: - gvfs-udisks2-volume-monitor SIGSEGV in g_content_type_guess_for_tree() due to filename with bad encoding - gcontenttype: Make filename valid utf-8 string before processing. - gdbusconnection: Don't deliver signals if the sender doesn't match. Changes in version 2.78.4: + Bugs fixed: - Fix generated RST anchors for methods, signals and properties. - docs/reference: depend on a native gtk-doc. - gobject_gdb.py: Do not break bt on optimized build. - gregex: clean up usage of _GRegex.jit_status. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:2003-1 Released: Wed Jun 12 07:30:30 2024 Summary: Security update for cups Type: security Severity: important References: 1223179,1225365,CVE-2024-35235 This update for cups fixes the following issues: - CVE-2024-35235: Fixed a bug in cupsd that could allow an attacker to change the permissions of other files in the system. (bsc#1225365) - Handle local 'Negotiate' authentication response for cli clients (bsc#1223179) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:2076-1 Released: Wed Jun 19 05:25:07 2024 Summary: Security update for gdk-pixbuf Type: security Severity: important References: 1195391,1219276,1223903,CVE-2022-48622 This update for gdk-pixbuf fixes the following issues: gdk-pixbuf was updated to version 2.42.12: - Security issues fixed: * CVE-2022-48622: Fixed vulnerability where a crafted .ani file could allow an attacker to overwrite heap metadata, leading to a denial of service or code execution attack to a denial of service or code execution attack (bsc#1219276) - Changes in version 2.42.12: + ani: Reject files with multiple INA or IART chunks, + ani: validate chunk size, + Updated translations. - Enable other image loaders such as xpm and xbm (bsc#1223903) - Changes in version 2.42.11: + Disable fringe loaders by default. + Introspection fixes. + Updated translations. - Changes in version 2.42.10: + Search for rst2man.py. + Update the memory size limit for JPEG images. + Updated translations. - Fixed loading of larger images - Avoid Bash specific syntax in baselibs postscript (bsc#1195391) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:2200-1 Released: Tue Jun 25 13:53:17 2024 Summary: Security update for avahi Type: security Severity: moderate References: 1216594,1216598,1226586,CVE-2023-38469,CVE-2023-38471 This update for avahi fixes the following issues: - CVE-2023-38471: Fixed a reachable assertion in dbus_set_host_name. (bsc#1216594) - CVE-2023-38469: Fixed a reachable assertion in avahi_dns_packet_append_record. (bsc#1216598) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2340-1 Released: Tue Jul 9 07:33:29 2024 Summary: Recommended update for pixman Type: recommended Severity: moderate References: 1221052 This update for pixman fixes the following issues: - Update to version 0.43.4 + Fix incorrect compositing on big-endian architectures (bsc#1221052) + Allow building on clang/arm32 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:2633-1 Released: Tue Jul 30 09:13:34 2024 Summary: Security update for gtk3 Type: security Severity: important References: 1228120,CVE-2024-6655 This update for gtk3 fixes the following issues: - CVE-2024-6655: Fixed library injection from current working directory (bsc#1228120) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2667-1 Released: Tue Jul 30 16:14:00 2024 Summary: Recommended update for libxkbcommon Type: recommended Severity: moderate References: 1218640,1228322 This update of libxkbcommon fixes the following issue: - ship libxkbregistry0-32bit and libxbkregistry-devel-32bit for use by Wine. (bsc#1218640 bsc#1228322) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2671-1 Released: Tue Jul 30 21:10:57 2024 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1226192 This update for cups fixes the following issues: - Require the exact matching version-release of all libcups* sub-packages (bsc#1226192) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2684-1 Released: Wed Jul 31 20:04:41 2024 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1214980,1222804,1222807,1222811,1222813,1222814,1222821,1222822,1222826,1222828,1222830,1222833,1222834,1223724,1224113,1224115,1224116,1224118,1227918,CVE-2023-5388 This update for mozilla-nss fixes the following issues: - Fixed startup crash of Firefox when using FIPS-mode (bsc#1223724). - Added 'Provides: nss' so other RPMs that require 'nss' can be installed (jira PED-6358). - FIPS: added safe memsets (bsc#1222811) - FIPS: restrict AES-GCM (bsc#1222830) - FIPS: Updated FIPS approved cipher lists (bsc#1222813, bsc#1222814, bsc#1222821, bsc#1222822, bsc#1224118) - FIPS: Updated FIPS self tests (bsc#1222807, bsc#1222828, bsc#1222834) - FIPS: Updated FIPS approved cipher lists (bsc#1222804, bsc#1222826, bsc#1222833, bsc#1224113, bsc#1224115, bsc#1224116) - Require `sed` for mozilla-nss-sysinit, as setup-nsssysinit.sh depends on it and will create a broken, empty config, if sed is missing (bsc#1227918) Update to NSS 3.101.2: * bmo#1905691 - ChaChaXor to return after the function update to NSS 3.101.1: * GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME. update to NSS 3.101: * add diagnostic assertions for SFTKObject refcount. * freeing the slot in DeleteCertAndKey if authentication failed * fix formatting issues. * Add Firmaprofesional CA Root-A Web to NSS. * remove invalid acvp fuzz test vectors. * pad short P-384 and P-521 signatures gtests. * remove unused FreeBL ECC code. * pad short P-384 and P-521 signatures. * be less strict about ECDSA private key length. * Integrate HACL* P-521. * Integrate HACL* P-384. * memory leak in create_objects_from_handles. * ensure all input is consumed in a few places in mozilla::pkix * SMIME/CMS and PKCS #12 do not integrate with modern NSS policy * clean up escape handling * Use lib::pkix as default validator instead of the old-one * Need to add high level support for PQ signing. * Certificate Compression: changing the allocation/freeing of buffer + Improving the documentation * SMIME/CMS and PKCS #12 do not integrate with modern NSS policy * Allow for non-full length ecdsa signature when using softoken * Modification of .taskcluster.yml due to mozlint indent defects * Implement support for PBMAC1 in PKCS#12 * disable VLA warnings for fuzz builds. * remove redundant AllocItem implementation. * add PK11_ReadDistrustAfterAttribute. * - Clang-formatting of SEC_GetMgfTypeByOidTag update * Set SEC_ERROR_LIBRARY_FAILURE on self-test failure * sftk_getParameters(): Fix fallback to default variable after error with configfile. * Switch to the mozillareleases/image_builder image - switch from ec_field_GFp to ec_field_plain Update to NSS 3.100: * merge pk11_kyberSlotList into pk11_ecSlotList for faster Xyber operations. * remove ckcapi. * avoid a potential PK11GenericObject memory leak. * Remove incomplete ESDH code. * Decrypt RSA OAEP encrypted messages. * Fix certutil CRLDP URI code. * Don't set CKA_DERIVE for CKK_EC_EDWARDS private keys. * Add ability to encrypt and decrypt CMS messages using ECDH. * Correct Templates for key agreement in smime/cmsasn.c. * Moving the decodedCert allocation to NSS. * Allow developers to speed up repeated local execution of NSS tests that depend on certificates. Update to NSS 3.99: * Removing check for message len in ed25519 (bmo#1325335) * add ed25519 to SECU_ecName2params. (bmo#1884276) * add EdDSA wycheproof tests. (bmo#1325335) * nss/lib layer code for EDDSA. (bmo#1325335) * Adding EdDSA implementation. (bmo#1325335) * Exporting Certificate Compression types (bmo#1881027) * Updating ACVP docker to rust 1.74 (bmo#1880857) * Updating HACL* to 0f136f28935822579c244f287e1d2a1908a7e552 (bmo#1325335) * Add NSS_CMSRecipient_IsSupported. (bmo#1877730) Update to NSS 3.98: * (CVE-2023-5388) Timing attack against RSA decryption in TLS * Certificate Compression: enabling the check that the compression was advertised * Move Windows workers to nss-1/b-win2022-alpha * Remove Email trust bit from OISTE WISeKey Global Root GC CA * Replace `distutils.spawn.find_executable` with `shutil.which` within `mach` in `nss` * Certificate Compression: Updating nss_bogo_shim to support Certificate compression * TLS Certificate Compression (RFC 8879) Implementation * Add valgrind annotations to freebl kyber operations for constant-time execution tests * Set nssckbi version number to 2.66 * Add Telekom Security roots * Add D-Trust 2022 S/MIME roots * Remove expired Security Communication RootCA1 root * move keys to a slot that supports concatenation in PK11_ConcatSymKeys * remove unmaintained tls-interop tests * bogo: add support for the -ipv6 and -shim-id shim flags * bogo: add support for the -curves shim flag and update Kyber expectations * bogo: adjust expectation for a key usage bit test * mozpkix: add option to ignore invalid subject alternative names * Fix selfserv not stripping `publicname:` from -X value * take ownership of ecckilla shims * add valgrind annotations to freebl/ec.c * PR_INADDR_ANY needs PR_htonl before assignment to inet.ip * Update zlib to 1.3.1 Update to NSS 3.97: * make Xyber768d00 opt-in by policy * add libssl support for xyber768d00 * add PK11_ConcatSymKeys * add Kyber and a PKCS#11 KEM interface to softoken * add a FreeBL API for Kyber * part 2: vendor github.com/pq-crystals/kyber/commit/e0d1c6ff * part 1: add a script for vendoring kyber from pq-crystals repo * Removing the calls to RSA Blind from loader.* * fix worker type for level3 mac tasks * RSA Blind implementation * Remove DSA selftests * read KWP testvectors from JSON * Backed out changeset dcb174139e4f * Fix CKM_PBE_SHA1_DES2_EDE_CBC derivation * Wrap CC shell commands in gyp expansions Update to NSS 3.96.1: * Use pypi dependencies for MacOS worker in ./build_gyp.sh * p7sign: add -a hash and -u certusage (also p7verify cleanups) * add a defensive check for large ssl_DefSend return values * Add dependency to the taskcluster script for Darwin * Upgrade version of the MacOS worker for the CI Update to NSS 3.95: * Bump builtins version number. * Remove Email trust bit from Autoridad de Certificacion Firmaprofesional CIF A62634068 root cert. * Remove 4 DigiCert (Symantec/Verisign) Root Certificates * Remove 3 TrustCor Root Certificates from NSS. * Remove Camerfirma root certificates from NSS. * Remove old Autoridad de Certificacion Firmaprofesional Certificate. * Add four Commscope root certificates to NSS. * Add TrustAsia Global Root CA G3 and G4 root certificates. * Include P-384 and P-521 Scalar Validation from HACL* * Include P-256 Scalar Validation from HACL*. * After the HACL 256 ECC patch, NSS incorrectly encodes 256 ECC without DER wrapping at the softoken level * Add means to provide library parameters to C_Initialize * add OSXSAVE and XCR0 tests to AVX2 detection. * Typo in ssl3_AppendHandshakeNumber * Introducing input check of ssl3_AppendHandshakeNumber * Fix Invalid casts in instance.c Update to NSS 3.94: * Updated code and commit ID for HACL* * update ACVP fuzzed test vector: refuzzed with current NSS * Softoken C_ calls should use system FIPS setting to select NSC_ or FC_ variants * NSS needs a database tool that can dump the low level representation of the database * declare string literals using char in pkixnames_tests.cpp * avoid implicit conversion for ByteString * update rust version for acvp docker * Moving the init function of the mpi_ints before clean-up in ec.c * P-256 ECDH and ECDSA from HACL* * Add ACVP test vectors to the repository * Stop relying on std::basic_string * Transpose the PPC_ABI check from Makefile to gyp Update to NSS 3.93: * Update zlib in NSS to 1.3. * softoken: iterate hashUpdate calls for long inputs. * regenerate NameConstraints test certificates (bsc#1214980). Update to NSS 3.92: * Set nssckbi version number to 2.62 * Add 4 Atos TrustedRoot Root CA certificates to NSS * Add 4 SSL.com Root CA certificates * Add Sectigo E46 and R46 Root CA certificates * Add LAWtrust Root CA2 (4096) * Remove E-Tugra Certification Authority root * Remove Camerfirma Chambers of Commerce Root. * Remove Hongkong Post Root CA 1 * Remove E-Tugra Global Root CA ECC v3 and RSA v3 * Avoid redefining BYTE_ORDER on hppa Linux Update to NSS 3.91: * Implementation of the HW support check for ADX instruction * Removing the support of Curve25519 * Fix comment about the addition of ticketSupportsEarlyData * Adding args to enable-legacy-db build * dbtests.sh failure in 'certutil dump keys with explicit default trust flags' * Initialize flags in slot structures * Improve the length check of RSA input to avoid heap overflow * Followup Fixes * avoid processing unexpected inputs by checking for m_exptmod base sign * add a limit check on order_k to avoid infinite loop * Update HACL* to commit 5f6051d2 * add SHA3 to cryptohi and softoken * HACL SHA3 * Disabling ASM C25519 for A but X86_64 Update to NSS 3.90.3: * GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME. * clean up escape handling. * remove redundant AllocItem implementation. * Disable ASM support for Curve25519. * Disable ASM support for Curve25519 for all but X86_64. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:3117-1 Released: Tue Sep 3 17:07:39 2024 Summary: Security update for tiff Type: security Severity: moderate References: 1228924,CVE-2024-7006 This update for tiff fixes the following issues: - CVE-2024-7006: Fixed null pointer dereference in tif_dirinfo.c (bsc#1228924) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:3131-1 Released: Tue Sep 3 17:42:24 2024 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1224113 This update for mozilla-nss fixes the following issues: - FIPS: Enforce approved curves with the CKK_EC_MONTGOMERY key type (bsc#1224113). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:3185-1 Released: Tue Sep 10 08:15:38 2024 Summary: Recommended update for cups Type: recommended Severity: moderate References: 1226227 This update for cups fixes the following issues: - Fixed cupsd failing to authenticate users when group membership is required (bsc#1226227) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:3219-1 Released: Thu Sep 12 13:16:33 2024 Summary: Security update for colord Type: security Severity: moderate References: 1208056 This update for colord fixes the following issues: - Fixed a potential local privilege escalation by removing the script in the specfile which changes the ownership of /var/lib/colord. (bsc#1208056) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:3846-1 Released: Thu Oct 31 11:07:10 2024 Summary: Recommended update for gnutls Type: recommended Severity: moderate References: 1226724,1226731,1226733,1227642,1227669,1227670,1227671,1230166 This update for gnutls fixes the following issues: - FIPS: Do not allow curve P-192 for signature or keypair verification [bsc#1227669] - FIPS: Allow to perform the integrity check with the hmac provided by each library [bsc#1226724] - FIPS: Mark gnutls_hash_fast operations as approved in SLI. [bsc#1230166] - FIPS: Run pairwise consistency test only in FIPS mode. [bsc#1226733] - FIPS: Use full hash+sign operations, not low level primitives in PCT test. [bsc#1226733] - FIPS: Mark SHA1 as not allowed for signature verification in both RSA and ECDSA sigVer. [bsc#1227642] - FIPS: Allow RSA signature verification with min of 2048 bit modulus. [bsc#1227670] - FIPS: Remove not needed DSA in selfchecks in FIPS mode. [bsc#1227671, bsc#1226731] ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:4196-1 Released: Thu Dec 5 13:56:06 2024 Summary: Security update for avahi Type: security Severity: moderate References: 1233420,CVE-2024-52616 This update for avahi fixes the following issues: - CVE-2024-52616: Fixed Avahi Wide-Area DNS Predictable Transaction IDs (bsc#1233420) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:4244-1 Released: Fri Dec 6 14:04:39 2024 Summary: Recommended update for shared-mime-info Type: recommended Severity: moderate References: 1231463 This update for shared-mime-info fixes the following issue: - Uninstall silently if update-mime-database is not present (bsc#1231463). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:4254-1 Released: Fri Dec 6 18:03:05 2024 Summary: Security update for glib2 Type: security Severity: important References: 1231463,1233282,CVE-2024-52533 This update for glib2 fixes the following issues: Security issues fixed: - CVE-2024-52533: Fix a single byte buffer overflow in set_connect_msg() (bsc#1233282). Non-security issue fixed: - Fix error when uninstalling packages (bsc#1231463). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:31-1 Released: Tue Jan 7 15:44:10 2025 Summary: Security update for gtk3 Type: security Severity: important References: 1172879,1228120,CVE-2024-6655 This update for gtk3 fixes the following issues: - CVE-2024-6655: Fixed library injection from current working directory (bsc#1228120). Other fixes: - Updated to version 3.24.43 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:548-1 Released: Fri Feb 14 11:19:24 2025 Summary: Security update for libtasn1 Type: security Severity: important References: 1236878,CVE-2024-12133 This update for libtasn1 fixes the following issues: - CVE-2024-12133: the processing of input DER data containing a large number of SEQUENCE OF or SET OF elements takes quadratic time to complete. (bsc#1236878) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:753-1 Released: Fri Feb 28 17:30:35 2025 Summary: Security update for tiff Type: security Severity: moderate References: 1212607,1219213,1236834,CVE-2023-25435,CVE-2023-52356 This update for tiff fixes the following issues: - CVE-2023-25435: Heap-buffer-overflow in extractContigSamplesShifted8bits() in tiffcrop.c (bsc#1212607). - CVE-2023-52356: Segment fault in libtiff in TIFFReadRGBATileExt() leading to denial of service (bsc#1219213). Other bugfixes: - Fixed tiff build issue on s390x as test 12 test_directory fails (bsc#1236834). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:764-1 Released: Mon Mar 3 09:43:37 2025 Summary: Security update for gnutls Type: security Severity: moderate References: 1236974,CVE-2024-12243 This update for gnutls fixes the following issues: - CVE-2024-12243: quadratic complexity of DER input decoding in libtasn1 can lead to a DoS (bsc#1236974). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:794-1 Released: Thu Mar 6 07:59:29 2025 Summary: Recommended update for pkg-config Type: recommended Severity: important References: 1237374 This update for pkg-config fixes the following issues: - Build with system GLib instead of bundled GLib (bsc#1237374). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:820-1 Released: Mon Mar 10 15:17:28 2025 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1222834 This update for mozilla-nss fixes the following issues: - FIPS: Do not pass in bad targetKeyLength parameters when checking for FIPS approval after keygen. This was causing false rejections. - FIPS: Approve RSA signature verification mechanisms with PKCS padding and legacy moduli (bsc#1222834). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:1245-1 Released: Mon Apr 14 13:31:49 2025 Summary: Recommended update for pkg-config Type: recommended Severity: moderate References: 1237374 This update for rsync fixes the following issues: - Security scan found old glib in pkg-config (bsc#1237374). - This update for pkg-config changes attribute to the author who actually makes the change ----------------------------------------------------------------- Advisory ID: SUSE-OU-2025:1258-1 Released: Mon Apr 14 18:49:52 2025 Summary: Recommended update for dpdk Type: optional Severity: low References: 1219391 This update for gnome-color-manager, colord, gnome-online-accounts, libnma, NetworkManager-applet fixes the following issues: - Add non x86_64 binaries to SUSE Package Hub, no source change in any package. (bsc#1219391) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:1367-1 Released: Thu Apr 24 16:38:48 2025 Summary: Security update for glib2 Type: security Severity: moderate References: 1240897,CVE-2025-3360 This update for glib2 fixes the following issues: - CVE-2025-3360: Fixed integer overflow and buffer underread when parsing a very long and invalid ISO 8601 timestamp with g_date_time_new_from_iso8601() (bsc#1240897) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:1456-1 Released: Wed May 7 17:13:32 2025 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1241020,1241078,1241189,CVE-2025-29087,CVE-2025-29088,CVE-2025-3277 This update for sqlite3 fixes the following issues: - CVE-2025-29087,CVE-2025-3277: Fixed integer overflow in sqlite concat function (bsc#1241020) - CVE-2025-29088: Fixed integer overflow through the SQLITE_DBCONFIG_LOOKASIDE component (bsc#1241078) Other fixes: - Updated to version 3.49.1 from Factory (jsc#SLE-16032) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2167-1 Released: Mon Jun 30 09:14:40 2025 Summary: Security update for glib2 Type: security Severity: important References: 1242844,1244596,CVE-2025-4373,CVE-2025-6052 This update for glib2 fixes the following issues: - CVE-2025-6052: Fixed integer overflow in g_string_maybe_expand() leads to potential buffer overflow in GString (bsc#1244596). - CVE-2025-4373: Fixed buffer underflow through glib/gstring.c via function g_string_insert_unichar (bsc#1242844). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2260-1 Released: Wed Jul 9 19:04:24 2025 Summary: Security update for libxml2 Type: security Severity: important References: 1244554,1244555,1244557,1244590,1244700,CVE-2025-49794,CVE-2025-49795,CVE-2025-49796,CVE-2025-6021,CVE-2025-6170 This update for libxml2 fixes the following issues: - CVE-2025-49794: Fixed a heap use after free which could lead to denial of service. (bsc#1244554) - CVE-2025-49796: Fixed type confusion which could lead to denial of service. (bsc#1244557) - CVE-2025-49795: Fixed a null pointer dereference which could lead to denial of service. (bsc#1244555) - CVE-2025-6170: Fixed a stack buffer overflow which could lead to a crash. (bsc#1244700) - CVE-2025-6021: Fixed an integer overflow in xmlBuildQName() which could lead to stack buffer overflow. (bsc#1244590) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2274-1 Released: Thu Jul 10 14:35:40 2025 Summary: Recommended update for mozilla-nspr, mozilla-nss Type: recommended Severity: moderate References: 1081723,1224113 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nss was updated to NSS 3.112: * Fix alias for mac workers on try * ensure all options can be configured with SSL_OptionSet and SSL_OptionSetDefault * ABI/API break in ssl certificate processing * remove unnecessary assertion in sec_asn1d_init_state_based_on_template * bmo#1965754 Update taskgraph to v14.2.1 * Workflow for automation of the release on GitHub when pushing a tag * fix faulty assertions in SEC_ASN1DecoderUpdate * Renegotiations should use a fresh ECH GREASE buffer * bmo#1951396 Update taskgraph to v14.1.1 * Partial fix for ACVP build CI job * Initialize find in sftk_searchDatabase * Add clang-18 to extra builds * Fault tolerant git fetch for fuzzing * Tolerate intermittent failures in ssl_policy_pkix_ocsp * fix compiler warnings when DEBUG_ASN1D_STATES or CMSDEBUG are set * fix content type tag check in NSS_CMSMessage_ContainsCertsOrCrls * Remove Cryptofuzz CI version check Update to NSS 3.111: * FIPS changes need to be upstreamed: force ems policy * Turn off Websites Trust Bit from CAs * Update nssckbi version following April 2025 Batch of Changes * Disable SMIME ???trust bit??? for GoDaddy CAs * Replaced deprecated sprintf function with snprintf in dbtool.c * Need up update NSS for PKCS 3.1 * avoid leaking localCert if it is already set in ssl3_FillInCachedSID * Decrease ASAN quarantine size for Cryptofuzz in CI * selfserv: Add support for zlib certificate compression Update to NSS 3.110: * FIPS changes need to be upstreamed: force ems policy * Prevent excess allocations in sslBuffer_Grow * Remove Crl templates from ASN1 fuzz target * Remove CERT_CrlTemplate from ASN1 fuzz target * Fix memory leak in NSS_CMSMessage_IsSigned * NSS policy updates * Improve locking in nssPKIObject_GetInstances * Fix race in sdb_GetMetaData * Fix member access within null pointer * Increase smime fuzzer memory limit * Enable resumption when using custom extensions * change CN of server12 test certificate * Part 2: Add missing check in NSS_CMSDigestContext_FinishSingle * Part 1: Fix smime UBSan errors * FIPS changes need to be upstreamed: updated key checks * Don't build libpkix in static builds * handle `-p all` in try syntax * fix opt-make builds to actually be opt * fix opt-static builds to actually be opt * Remove extraneous assert Update to NSS 3.109: * Call BL_Init before RNG_RNGInit() so that special SHA instructions can be used if available * NSS policy updates - fix inaccurate key policy issues * SMIME fuzz target * ASN1 decoder fuzz target * Part 2: Revert ???Extract testcases from ssl gtests for fuzzing??? * Add fuzz/README.md * Part 4: Fix tstclnt arguments script * Extend pkcs7 fuzz target * Extend certDN fuzz target * revert changes to HACL* files from bug 1866841 * Part 3: Package frida corpus script Update to NSS 3.108: * libclang-16 -> libclang-19 * Turn off Secure Email Trust Bit for Security Communication ECC RootCA1 * Turn off Secure Email Trust Bit for BJCA Global Root CA1 and BJCA Global Root CA2 * Remove SwissSign Silver CA ??? G2 * Add D-Trust 2023 TLS Roots to NSS * fix fips test failure on windows * change default sensitivity of KEM keys * Part 1: Introduce frida hooks and script * add missing arm_neon.h include to gcm.c * ci: update windows workers to win2022 * strip trailing carriage returns in tools tests * work around unix/windows path translation issues in cert test script * ci: let the windows setup script work without $m * detect msys * add a specialized CTR_Update variant for AES-GCM * NSS policy updates * FIPS changes need to be upstreamed: FIPS 140-3 RNG * FIPS changes need to be upstreamed: Add SafeZero * FIPS changes need to be upstreamed Updated POST * Segmentation fault in SECITEM_Hash during pkcs12 processing * Extending NSS with LoadModuleFromFunction functionality * Ensure zero-initialization of collectArgs.cert * pkcs7 fuzz target use CERT_DestroyCertificate * Fix actual underlying ODR violations issue * mozilla::pkix: allow reference ID labels to begin and/or end with hyphens * don't look for secmod.db in nssutil_ReadSecmodDB if NSS_DISABLE_DBM is set * Fix memory leak in pkcs7 fuzz target * Set -O2 for ASan builds in CI * Change branch of tlsfuzzer dependency * Run tests in CI for ASan builds with detect_odr_violation=1 * Fix coverage failure in CI * Add fuzzing for delegated credentials, DTLS short header and Tls13BackendEch * Add fuzzing for SSL_EnableTls13GreaseEch and SSL_SetDtls13VersionWorkaround * Part 3: Restructure fuzz/ * Extract testcases from ssl gtests for fuzzing * Force Cryptofuzz to use NSS in CI * Fix Cryptofuzz on 32 bit in CI * Update Cryptofuzz repository link * fix build error from 9505f79d * simplify error handling in get_token_objects_for_cache * nss doc: fix a warning * pkcs12 fixes from RHEL need to be picked up Update to NSS 3.107: * Remove MPI fuzz targets. * Remove globals `lockStatus` and `locksEverDisabled`. * Enable PKCS8 fuzz target. * Integrate Cryptofuzz in CI. * Part 2: Set tls server target socket options in config class * Part 1: Set tls client target socket options in config class * Support building with thread sanitizer. * set nssckbi version number to 2.72. * remove Websites Trust Bit from Entrust Root Certification Authority - G4. * remove Security Communication RootCA3 root cert. * remove SecureSign RootCA11 root cert. * Add distrust-after for TLS to Entrust Roots. * bmo#1927096 Update expected error code in pk12util pbmac1 tests. * Use random tstclnt args with handshake collection script * Remove extraneous assert in ssl3gthr.c. * Adding missing release notes for NSS_3_105. * Enable the disabled mlkem tests for dtls. * NSS gtests filter cleans up the constucted buffer before the use. * Make ssl_SetDefaultsFromEnvironment thread-safe. * Remove short circuit test from ssl_Init. Update to NSS 3.106: * NSS 3.106 should be distributed with NSPR 4.36. * pk12util: improve error handling in p12U_ReadPKCS12File. * Correctly destroy bulkkey in error scenario. * PKCS7 fuzz target, r=djackson,nss-reviewers. * Extract certificates with handshake collection script. * Specify len_control for fuzz targets. * Fix memory leak in dumpCertificatePEM. * Fix UBSan errors for SECU_PrintCertificate and SECU_PrintCertificateBasicInfo. * add new error codes to mozilla::pkix for Firefox to use. * allow null phKey in NSC_DeriveKey. * Only create seed corpus zip from existing corpus. * Use explicit allowlist for for KDF PRFS. * Increase optimization level for fuzz builds. * Remove incorrect assert. * Use libFuzzer options from fuzz/options/\*.options in CI. * Polish corpus collection for automation. * Detect new and unfuzzed SSL options. * PKCS12 fuzzing target. Update to NSS 3.105: * Allow importing PKCS#8 private EC keys missing public key * UBSAN fix: applying zero offset to null pointer in sslsnce.c * set KRML_MUSTINLINE=inline in makefile builds * Don't set CKA_SIGN for CKK_EC_MONTGOMERY private keys * override default definition of KRML_MUSTINLINE * libssl support for mlkem768x25519 * support for ML-KEM-768 in softoken and pk11wrap * Add Libcrux implementation of ML-KEM 768 to FreeBL * Avoid misuse of ctype(3) functions * part 2: run clang-format * part 1: upgrade to clang-format 13 * clang-format fuzz * DTLS client message buffer may not empty be on retransmit * Optionally print config for TLS client and server fuzz target * Fix some simple documentation issues in NSS. * improve performance of NSC_FindObjectsInit when template has CKA_TOKEN attr * define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN Update to NSS 3.104: * Copy original corpus to heap-allocated buffer * Fix min ssl version for DTLS client fuzzer * Remove OS2 support just like we did on NSPR * clang-format NSS improvements * Adding basicutil.h to use HexString2SECItem function * removing dirent.c from build * Allow handing in keymaterial to shlibsign to make the output reproducible * remove nec4.3, sunos4, riscos and SNI references * remove other old OS (BSDI, old HP UX, NCR, openunix, sco, unixware or reliantUnix * remove mentions of WIN95 * remove mentions of WIN16 * More explicit directory naming * Add more options to TLS server fuzz target * Add more options to TLS client fuzz target * Use OSS-Fuzz corpus in NSS CI * set nssckbi version number to 2.70. * Remove Email Trust bit from ACCVRAIZ1 root cert. * Remove Email Trust bit from certSIGN ROOT CA. * Add Cybertrust Japan Roots to NSS. * Add Taiwan CA Roots to NSS. * remove search by decoded serial in nssToken_FindCertificateByIssuerAndSerialNumber * Fix tstclnt CI build failure * vfyserv: ensure peer cert chain is in db for CERT_VerifyCertificateNow * Enable all supported protocol versions for UDP * Actually use random PSK hash type * Initialize NSS DB once * Additional ECH cipher suites and PSK hash types * Automate corpus file generation for TLS client Fuzzer * Fix crash with UNSAFE_FUZZER_MODE * clang-format shlibsign.c Update to NSS 3.103: * move list size check after lock acquisition in sftk_PutObjectToList. * Add fuzzing support for SSL_ENABLE_POST_HANDSHAKE_AUTH, * Adjust libFuzzer size limits * Add fuzzing support for SSL_SetCertificateCompressionAlgorithm, SSL_SetClientEchConfigs, SSL_VersionRangeSet and SSL_AddExternalPsk * Add fuzzing support for SSL_ENABLE_GREASE and SSL_ENABLE_CH_EXTENSION_PERMUTATION - Make the rpms reproducible, by using a hardcoded, static key to generate the checksums (*.chk-files) - FIPS: enforce approved curves with the CKK_EC_MONTGOMERY key type (bsc#1224113). Update to NSS 3.102.1: * ChaChaXor to return after the function Update to NSS 3.102: * Add Valgrind annotations to freebl Chacha20-Poly1305. * missing sqlite header. * GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME. * improve certutil keyUsage, extKeyUsage, and nsCertType keyword handling. * correct length of raw SPKI data before printing in pp utility. - Make NSS-build reproducible. Use key from openssl (bsc#1081723) - Exclude the SHA-1 hash from SLI approval. mozilla-nspr was updated to version 4.36: * renamed the prwin16.h header to prwin.h * various build, test and automation script fixes * major parts of the source code were reformatted ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2287-1 Released: Fri Jul 11 11:26:25 2025 Summary: Recommended update for Mesa Type: recommended Severity: important References: 1241701,1245034 This update for Mesa fixes the following issues: - Fixes Wayland session when using SP7 as vmware guest (bsc#1245034) - Fixes crash in libgallium on virtualbox (bsc#1241701) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2323-1 Released: Wed Jul 16 04:07:18 2025 Summary: Recommended update for mozilla-nspr, mozilla-nss Type: recommended Severity: moderate References: 1081723,1224113 This update for mozilla-nspr, mozilla-nss fixes the following issues: mozilla-nss was updated to NSS 3.112: * Fix alias for mac workers on try * ensure all options can be configured with SSL_OptionSet and SSL_OptionSetDefault * ABI/API break in ssl certificate processing * remove unnecessary assertion in sec_asn1d_init_state_based_on_template * update taskgraph to v14.2.1 * Workflow for automation of the release on GitHub when pushing a tag * fix faulty assertions in SEC_ASN1DecoderUpdate * Renegotiations should use a fresh ECH GREASE buffer * update taskgraph to v14.1.1 * Partial fix for ACVP build CI job * Initialize find in sftk_searchDatabase * Add clang-18 to extra builds * Fault tolerant git fetch for fuzzing * Tolerate intermittent failures in ssl_policy_pkix_ocsp * fix compiler warnings when DEBUG_ASN1D_STATES or CMSDEBUG are set * fix content type tag check in NSS_CMSMessage_ContainsCertsOrCrls * Remove Cryptofuzz CI version check Update to NSS 3.111: * FIPS changes need to be upstreamed: force ems policy * Turn off Websites Trust Bit from CAs * Update nssckbi version following April 2025 Batch of Changes * Disable SMIME ???trust bit??? for GoDaddy CAs * Replaced deprecated sprintf function with snprintf in dbtool.c * Need up update NSS for PKCS 3.1 * avoid leaking localCert if it is already set in ssl3_FillInCachedSID * Decrease ASAN quarantine size for Cryptofuzz in CI * selfserv: Add support for zlib certificate compression Update to NSS 3.110: * FIPS changes need to be upstreamed: force ems policy * Prevent excess allocations in sslBuffer_Grow * Remove Crl templates from ASN1 fuzz target * Remove CERT_CrlTemplate from ASN1 fuzz target * Fix memory leak in NSS_CMSMessage_IsSigned * NSS policy updates * Improve locking in nssPKIObject_GetInstances * Fix race in sdb_GetMetaData * Fix member access within null pointer * Increase smime fuzzer memory limit * Enable resumption when using custom extensions * change CN of server12 test certificate * Part 2: Add missing check in NSS_CMSDigestContext_FinishSingle * Part 1: Fix smime UBSan errors * FIPS changes need to be upstreamed: updated key checks * Don't build libpkix in static builds * handle `-p all` in try syntax * fix opt-make builds to actually be opt * fix opt-static builds to actually be opt * Remove extraneous assert Update to NSS 3.109: * Call BL_Init before RNG_RNGInit() so that special SHA instructions can be used if available * NSS policy updates - fix inaccurate key policy issues * SMIME fuzz target * ASN1 decoder fuzz target * Part 2: Revert ???Extract testcases from ssl gtests for fuzzing??? * Add fuzz/README.md * Part 4: Fix tstclnt arguments script * Extend pkcs7 fuzz target * Extend certDN fuzz target * revert changes to HACL* files from bug 1866841 * Part 3: Package frida corpus script Update to NSS 3.108: * libclang-16 -> libclang-19 * Turn off Secure Email Trust Bit for Security Communication ECC RootCA1 * Turn off Secure Email Trust Bit for BJCA Global Root CA1 and BJCA Global Root CA2 * Remove SwissSign Silver CA ??? G2 * Add D-Trust 2023 TLS Roots to NSS * fix fips test failure on windows * change default sensitivity of KEM keys * Part 1: Introduce frida hooks and script * add missing arm_neon.h include to gcm.c * ci: update windows workers to win2022 * strip trailing carriage returns in tools tests * work around unix/windows path translation issues in cert test script * ci: let the windows setup script work without $m * detect msys * add a specialized CTR_Update variant for AES-GCM * NSS policy updates * FIPS changes need to be upstreamed: FIPS 140-3 RNG * FIPS changes need to be upstreamed: Add SafeZero * FIPS changes need to be upstreamed - updated POST * Segmentation fault in SECITEM_Hash during pkcs12 processing * Extending NSS with LoadModuleFromFunction functionality * Ensure zero-initialization of collectArgs.cert * pkcs7 fuzz target use CERT_DestroyCertificate * Fix actual underlying ODR violations issue * mozilla::pkix: allow reference ID labels to begin and/or end with hyphens * don't look for secmod.db in nssutil_ReadSecmodDB if NSS_DISABLE_DBM is set * Fix memory leak in pkcs7 fuzz target * Set -O2 for ASan builds in CI * Change branch of tlsfuzzer dependency * Run tests in CI for ASan builds with detect_odr_violation=1 * Fix coverage failure in CI * Add fuzzing for delegated credentials, DTLS short header and Tls13BackendEch * Add fuzzing for SSL_EnableTls13GreaseEch and SSL_SetDtls13VersionWorkaround * Part 3: Restructure fuzz/ * Extract testcases from ssl gtests for fuzzing * Force Cryptofuzz to use NSS in CI * Fix Cryptofuzz on 32 bit in CI * Update Cryptofuzz repository link * fix build error from 9505f79d * simplify error handling in get_token_objects_for_cache * nss doc: fix a warning * pkcs12 fixes from RHEL need to be picked up Update to NSS 3.107: * Remove MPI fuzz targets. * Remove globals `lockStatus` and `locksEverDisabled`. * Enable PKCS8 fuzz target. * Integrate Cryptofuzz in CI. * Part 2: Set tls server target socket options in config class * Part 1: Set tls client target socket options in config class * Support building with thread sanitizer. * set nssckbi version number to 2.72. * remove Websites Trust Bit from Entrust Root Certification Authority - G4. * remove Security Communication RootCA3 root cert. * remove SecureSign RootCA11 root cert. * Add distrust-after for TLS to Entrust Roots. * update expected error code in pk12util pbmac1 tests. * Use random tstclnt args with handshake collection script * Remove extraneous assert in ssl3gthr.c. * Adding missing release notes for NSS_3_105. * Enable the disabled mlkem tests for dtls. * NSS gtests filter cleans up the constucted buffer before the use. * Make ssl_SetDefaultsFromEnvironment thread-safe. * Remove short circuit test from ssl_Init. Update to NSS 3.106: * NSS 3.106 should be distributed with NSPR 4.36. * pk12util: improve error handling in p12U_ReadPKCS12File. * Correctly destroy bulkkey in error scenario. * PKCS7 fuzz target, r=djackson,nss-reviewers. * Extract certificates with handshake collection script. * Specify len_control for fuzz targets. * Fix memory leak in dumpCertificatePEM. * Fix UBSan errors for SECU_PrintCertificate and SECU_PrintCertificateBasicInfo. * add new error codes to mozilla::pkix for Firefox to use. * allow null phKey in NSC_DeriveKey. * Only create seed corpus zip from existing corpus. * Use explicit allowlist for for KDF PRFS. * Increase optimization level for fuzz builds. * Remove incorrect assert. * Use libFuzzer options from fuzz/options/\*.options in CI. * Polish corpus collection for automation. * Detect new and unfuzzed SSL options. * PKCS12 fuzzing target. Update to NSS 3.105: * Allow importing PKCS#8 private EC keys missing public key * UBSAN fix: applying zero offset to null pointer in sslsnce.c * set KRML_MUSTINLINE=inline in makefile builds * Don't set CKA_SIGN for CKK_EC_MONTGOMERY private keys * override default definition of KRML_MUSTINLINE * libssl support for mlkem768x25519 * support for ML-KEM-768 in softoken and pk11wrap * Add Libcrux implementation of ML-KEM 768 to FreeBL * Avoid misuse of ctype(3) functions * part 2: run clang-format * part 1: upgrade to clang-format 13 * clang-format fuzz * DTLS client message buffer may not empty be on retransmit * Optionally print config for TLS client and server fuzz target * Fix some simple documentation issues in NSS. * improve performance of NSC_FindObjectsInit when template has CKA_TOKEN attr * define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN Update to NSS 3.104: * Copy original corpus to heap-allocated buffer * Fix min ssl version for DTLS client fuzzer * Remove OS2 support just like we did on NSPR * clang-format NSS improvements * Adding basicutil.h to use HexString2SECItem function * removing dirent.c from build * Allow handing in keymaterial to shlibsign to make the output reproducible * remove nec4.3, sunos4, riscos and SNI references * remove other old OS (BSDI, old HP UX, NCR, openunix, sco, unixware or reliantUnix * remove mentions of WIN95 * remove mentions of WIN16 * More explicit directory naming * Add more options to TLS server fuzz target * Add more options to TLS client fuzz target * Use OSS-Fuzz corpus in NSS CI * set nssckbi version number to 2.70. * Remove Email Trust bit from ACCVRAIZ1 root cert. * Remove Email Trust bit from certSIGN ROOT CA. * Add Cybertrust Japan Roots to NSS. * Add Taiwan CA Roots to NSS. * remove search by decoded serial in nssToken_FindCertificateByIssuerAndSerialNumber * Fix tstclnt CI build failure * vfyserv: ensure peer cert chain is in db for CERT_VerifyCertificateNow * Enable all supported protocol versions for UDP * Actually use random PSK hash type * Initialize NSS DB once * Additional ECH cipher suites and PSK hash types * Automate corpus file generation for TLS client Fuzzer * Fix crash with UNSAFE_FUZZER_MODE * clang-format shlibsign.c Update to NSS 3.103: * move list size check after lock acquisition in sftk_PutObjectToList. * Add fuzzing support for SSL_ENABLE_POST_HANDSHAKE_AUTH, * Follow-up to fix test for presence of file nspr.patch. * Adjust libFuzzer size limits * Add fuzzing support for SSL_SetCertificateCompressionAlgorithm, SSL_SetClientEchConfigs, SSL_VersionRangeSet and SSL_AddExternalPsk * Add fuzzing support for SSL_ENABLE_GREASE and SSL_ENABLE_CH_EXTENSION_PERMUTATION - Make the rpms reproducible, by using a hardcoded, static key to generate the checksums (*.chk-files) - FIPS: enforce approved curves with the CKK_EC_MONTGOMERY key type (bsc#1224113). Update to NSS 3.102.1: * ChaChaXor to return after the function Update to NSS 3.102: * Add Valgrind annotations to freebl Chacha20-Poly1305. * missing sqlite header. * GLOBALTRUST 2020: Set Distrust After for TLS and S/MIME. * improve certutil keyUsage, extKeyUsage, and nsCertType keyword handling. * correct length of raw SPKI data before printing in pp utility. - Make NSS-build reproducible Use key from openssl (bsc#1081723) - FIPS: exclude the SHA-1 hash from SLI approval. mozilla-nspr was updated to version 4.36: * renamed the prwin16.h header to prwin.h * configure was updated from 2.69 to 2.71 * various build, test and automation script fixes * major parts of the source code were reformatted ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2595-1 Released: Fri Aug 1 17:13:59 2025 Summary: Security update for gnutls Type: security Severity: important References: 1246232,1246233,1246267,1246299,CVE-2025-32988,CVE-2025-32989,CVE-2025-32990,CVE-2025-6395 This update for gnutls fixes the following issues: - CVE-2025-6395: Fix NULL pointer dereference when 2nd Client Hello omits PSK (bsc#1246299) - CVE-2025-32988: Fix double-free due to incorrect ownership handling in the export logic of SAN entries containing an otherName (bsc#1246232) - CVE-2025-32989: Fix heap buffer overread when handling the CT SCT extension during X.509 certificate parsing (bsc#1246233) - CVE-2025-32990: Fix 1-byte heap buffer overflow when parsing templates with certtool (bsc#1246267) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2617-1 Released: Mon Aug 4 09:04:59 2025 Summary: Security update for libxml2 Type: security Severity: important References: 1246296,CVE-2025-7425 This update for libxml2 fixes the following issues: - CVE-2025-7425: Fixed heap Use-After-Free in libxslt caused by atype corruption in xmlAttrPtr (bsc#1246296) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2672-1 Released: Mon Aug 4 15:06:13 2025 Summary: Security update for sqlite3 Type: security Severity: important References: 1246597,CVE-2025-6965 This update for sqlite3 fixes the following issues: - Update to version 3.50.2 - CVE-2025-6965: Fixed an integer truncation to avoid assertion faults. (bsc#1246597) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2770-1 Released: Tue Aug 12 15:50:12 2025 Summary: Security update for tiff Type: security Severity: important References: 1243503,1247106,1247108,CVE-2025-8176,CVE-2025-8177 This update for tiff fixes the following issues: - Updated TIFFMergeFieldInfo() with read_count=write_count=0 for FIELD_IGNORE (bsc#1243503) - CVE-2025-8176: Fixed heap use-after-free in tools/tiffmedian.c (bsc#1247108) - CVE-2025-8177: Fixed possible buffer overflow in tools/thumbnail.c:setrow() when processing malformed TIFF files (bsc#1247106) - Add -DCMAKE_POLICY_VERSION_MINIMUM=3.5 to fix FTBFS with cmake4 - Add %check section - Remove Group: declarations, no longer used ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2954-1 Released: Thu Aug 21 15:42:53 2025 Summary: Security update for gdk-pixbuf Type: security Severity: important References: 1245227,1246114,CVE-2025-6199,CVE-2025-7345 This update for gdk-pixbuf fixes the following issues: - CVE-2025-6199: Fixed uninitialized memory leading to arbitrary memory contents leak (bsc#1245227) - CVE-2025-7345: Fixed heap buffer overflow within the gdk_pixbuf__jpeg_image_load_increment function (bsc#1246114) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3261-1 Released: Thu Sep 18 06:35:19 2025 Summary: Security update for cups Type: security Severity: important References: 1230932,1246533,1249049,1249128,CVE-2024-47175,CVE-2025-58060,CVE-2025-58364 This update for cups fixes the following issues: - CVE-2024-47175: no validation of IPP attributes in `ppdCreatePPDFromIPP2` when writing to a temporary PPD file allows for the injection of attacker-controlled data to the resulting PPD (bsc#1230932). - CVE-2025-58060: no password check when `AuthType` is set to anything but `Basic` and a request is made with an `Authorization: Basic` header (bsc#1249049). - CVE-2025-58364: unsafe deserialization and validation of printer attributes leads to NULL pointer dereference (bsc#1249128). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3286-1 Released: Mon Sep 22 08:02:27 2025 Summary: Recommended update for gtk3 Type: recommended Severity: moderate References: 1247503 This update for gtk3 fixes the following issues: - Fixed issue with window dimensions (bsc#1247503) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3333-1 Released: Wed Sep 24 08:55:10 2025 Summary: Security update for avahi Type: security Severity: moderate References: 1233421,CVE-2024-52615 This update for avahi fixes the following issues: - CVE-2024-52615: wide-area DNS uses constant source port for queries and can expose the Avahi-daemon to DNS spoofing attacks (bsc#1233421). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3348-1 Released: Wed Sep 24 16:05:03 2025 Summary: Security update for tiff Type: security Severity: moderate References: 1247581,1247582,1248117,1248330,CVE-2024-13978,CVE-2025-8534,CVE-2025-8961,CVE-2025-9165 This update for tiff fixes the following issues: - CVE-2025-9165: local execution manipulation leading to memory leak (bsc#1248330). - CVE-2024-13978: null pointer dereference in component fax2ps (bsc#1247581) - CVE-2025-8534: null pointer dereference in function PS_Lvl2page (bsc#1247582). - CVE-2025-8961: segmentation fault via main function of tiffcrop utility (bsc#1248117). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3449-1 Released: Thu Oct 2 09:15:17 2025 Summary: Security update for cairo Type: security Severity: low References: 1247589,CVE-2025-50422 This update for cairo fixes the following issues: - CVE-2025-50422: Fixed Poppler crash on malformed input (bsc#1247589) - Update to version 1.18.4: + The dependency on LZO has been made optional through a build time configuration toggle. + You can build Cairo against a Freetype installation that does not have the FT_Color type. + Cairo tests now build on Solaris 11.4 with GCC 14. + The DirectWrite backend now builds on MINGW 11. + The DirectWrite backend now supports font variations and proper glyph coverage. - Use tarball in lieu of source service due to freedesktop gitlab migration, will switch back at next release at the latest. - Add pkgconfig(lzo2) BuildRequires: New optional dependency, build lzo2 support feature. - Convert to source service: allows for easier upgrades by the GNOME team. - Update to version 1.18.2: + The malloc-stats code has been removed from the tests directory + Cairo now requires a version of pixman equal to, or newer than, 0.40. + There have been multiple build fixes for newer versions of GCC for MSVC; for Solaris; and on macOS 10.7. + PNG errors caused by loading malformed data are correctly propagated to callers, so they can handle the case. + Both stroke and fill colors are now set when showing glyphs on a PDF surface. + All the font options are copied when creating a fallback font object. + When drawing text on macOS, Cairo now tries harder to select the appropriate font name. + Cairo now prefers the COLRv1 table inside a font, if one is available. + Cairo requires a C11 toolchain when building. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3804-1 Released: Mon Oct 27 12:35:04 2025 Summary: Security update for mozilla-nss Type: security Severity: important References: 1251263,CVE-2025-9187 This update for mozilla-nss fixes the following issues: - Move NSS DB password hash away from SHA-1 Update to NSS 3.112.2: * Prevent leaks during pkcs12 decoding. * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates Update to NSS 3.112.1: * restore support for finding certificates by decoded serial number. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3949-1 Released: Wed Nov 5 11:04:35 2025 Summary: Security update for colord Type: security Severity: moderate References: 1250750,CVE-2021-42523 This update for colord fixes the following issues: - CVE-2021-42523: The original fix was wrong and did not properly free the error, resulting in a crash that has now been addressed (bsc#1250750). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3957-1 Released: Wed Nov 5 16:45:18 2025 Summary: Security update for tiff Type: security Severity: important References: 1248278,1250413,CVE-2025-8851,CVE-2025-9900 This update for tiff fixes the following issues: Update to 4.7.1: - CVE-2025-8851: Fixed stack-based buffer overflow (bsc#1248278). - CVE-2025-9900: Fixed write-what-where via TIFFReadRGBAImageOriented (bsc#1250413). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3982-1 Released: Thu Nov 6 19:21:10 2025 Summary: Recommended update for lcms2 Type: recommended Severity: moderate References: 1247985 This update for lcms2 fixes the following issue: - Enable threads support and avoid linker errors (bsc#1247985). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4179-1 Released: Mon Nov 24 08:27:54 2025 Summary: Recommended update for mozilla-nspr Type: recommended Severity: moderate References: This update for mozilla-nspr fixes the following issues: - update to NSPR 4.36.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.36.1 - update to NSPR 4.36.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4092-1 Released: Mon Nov 24 10:08:22 2025 Summary: Security update for elfutils Type: security Severity: moderate References: 1237236,1237240,1237241,1237242,CVE-2025-1352,CVE-2025-1372,CVE-2025-1376,CVE-2025-1377 This update for elfutils fixes the following issues: - Fixing build/testsuite for more recent glibc and kernels. - Fixing denial of service and general buffer overflow errors (bsc#1237236, bsc#1237240, bsc#1237241, bsc#1237242): - CVE-2025-1376: Fixed denial of service in function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip - CVE-2025-1377: Fixed denial of service in function gelf_getsymshndx of the file strip.c of the component eu-strip - CVE-2025-1372: Fixed buffer overflow in function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf - CVE-2025-1352: Fixed SEGV (illegal read access) in function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf - Fixing testsuite race conditions in run-debuginfod-find.sh. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4290-1 Released: Fri Nov 28 10:04:11 2025 Summary: Security update for cups Type: security Severity: moderate References: 1234225,1244057,1253783,CVE-2025-58436,CVE-2025-61915 This update for cups fixes the following issues: - CVE-2025-61915: Fixed a local denial-of-service via cupsd.conf update and related issues. (bsc#1253783) - CVE-2025-58436: Fixed an issue where a slow client communication leads to a possible DoS attack. (bsc#1244057) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4308-1 Released: Fri Nov 28 16:38:46 2025 Summary: Security update for glib2 Type: security Severity: moderate References: 1249055,CVE-2025-7039 This update for glib2 fixes the following issues: - CVE-2025-7039: Fixed buffer under-read on glib through glib/gfileutils.c via get_tmp_file() (bsc#1249055) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4319-1 Released: Wed Dec 3 13:34:00 2025 Summary: Security update for cups Type: security Severity: important References: 1254353,CVE-2025-58436 This update for cups fixes the following issues: - The fix for CVE-2025-58436 causes a regression where GTK applications will hang. (bsc#1254353) See also https://github.com/OpenPrinting/cups/issues/1429 The fix has been temporary disabled. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4323-1 Released: Mon Dec 8 19:14:15 2025 Summary: Security update for gnutls Type: security Severity: moderate References: 1254132,CVE-2025-9820 This update for gnutls fixes the following issues: - CVE-2025-9820: Fixed buffer overflow in gnutls_pkcs11_token_init. (bsc#1254132) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4425-1 Released: Wed Dec 17 12:20:02 2025 Summary: Security update for cups Type: security Severity: moderate References: 1244057,1254353,CVE-2025-58436 This update for cups fixes the following issues: Security issues fixed: - CVE-2025-58436: single client sending slow messages to cupsd can delay the application and make it unusable for other clients (bsc#1244057). Other issues fixed: - Update the CVE-2025-58436 patch to fix a regression that causes GTK applications to hang (bsc#1254353). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:18-1 Released: Mon Jan 5 11:52:25 2026 Summary: Security update for glib2 Type: security Severity: important References: 1254297,1254662,1254878,CVE-2025-13601,CVE-2025-14087,CVE-2025-14512 This update for glib2 fixes the following issues: - CVE-2025-14512: integer overflow in the GIO `escape_byte_string()` function when processing malicious files or remote filesystem attribute values can lead to denial-of-service (bsc#1254878). - CVE-2025-14087: buffer underflow in the GVariant parser `bytestring_parse()` and `string_parse()`functions when processing attacker-influenced data may lead to crash or code execution (bsc#1254662). - CVE-2025-13601: heap-based buffer overflow in the `g_escape_uri_string()` function when processing strings with a large number of unacceptable characters may lead to crash or code execution (bsc#1254297). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:224-1 Released: Thu Jan 22 13:18:20 2026 Summary: Security update for libtasn1 Type: security Severity: moderate References: 1256341,CVE-2025-13151 This update for libtasn1 fixes the following issues: - CVE-2025-13151: stack-based buffer overflow in `asn1_expend_octet_string` (bsc#1256341). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:243-1 Released: Thu Jan 22 14:57:36 2026 Summary: Security update for librsvg Type: security Severity: moderate References: 1243867,CVE-2024-12224 This update for librsvg fixes the following issues: Update to version 2.57.4 - bsc#1243867: + CVE-2024-12224: RUSTSEC-2024-0421 - idna accepts Punycode labels that do not produce any non-ASCII when decoded. + RUSTSEC-2024-0404 - Unsoundness in anstream. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:259-1 Released: Thu Jan 22 17:10:44 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1256498,1256499,1256500,CVE-2025-68276,CVE-2025-68468,CVE-2025-68471 This update for avahi fixes the following issues: - CVE-2025-68276: Fixed refuse to create wide-area record browsers when wide-area is off (bsc#1256498) - CVE-2025-68471: Fixed DoS bug by changing assert to return (bsc#1256500) - CVE-2025-68468: Fixed DoS bug by removing incorrect assertion (bsc#1256499) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:286-1 Released: Sat Jan 24 00:35:35 2026 Summary: Security update for glib2 Type: security Severity: low References: 1257049,CVE-2026-0988 This update for glib2 fixes the following issues: - CVE-2026-0988: Fixed a potential integer overflow in g_buffered_input_stream_peek (bsc#1257049). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:287-1 Released: Sat Jan 24 00:35:49 2026 Summary: Security update for harfbuzz Type: security Severity: moderate References: 1256459,CVE-2026-22693 This update for harfbuzz fixes the following issues: - CVE-2026-22693: Fixed a NULL pointer dereference in SubtableUnicodesCache::create (bsc#1256459). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:373-1 Released: Wed Feb 4 03:50:41 2026 Summary: Security update for glib2 Type: security Severity: important References: 1257353,1257354,1257355,CVE-2026-1484,CVE-2026-1485,CVE-2026-1489 This update for glib2 fixes the following issues: - CVE-2026-1485: Fixed buffer underflow and out-of-bounds access due to integer wraparound in content type parsing (bsc#1257354). - CVE-2026-1484: Fixed buffer underflow and out-of-bounds access due to miscalculated buffer boundaries in the Base64 encoding routine (bsc#1257355). - CVE-2026-1489: Fixed undersized heap allocation followed by out-of-bounds access due to integer overflow in Unicode case conversion (bsc#1257353). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:432-1 Released: Wed Feb 11 10:11:56 2026 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1248586,1254670,CVE-2025-7709 This update for sqlite3 fixes the following issues: - Update to v3.51.2: - CVE-2025-7709: Fixed an integer overflow in the FTS5 extension. (bsc#1254670) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:605-1 Released: Tue Feb 24 12:19:11 2026 Summary: Security update for libxml2 Type: security Severity: moderate References: 1247850,1247858,1250553,1256804,1256805,1256807,1256808,1256809,1256810,1256811,1256812,1257593,1257594,1257595,CVE-2025-10911,CVE-2025-8732,CVE-2026-0989,CVE-2026-0990,CVE-2026-0992,CVE-2026-1757 This update for libxml2 fixes the following issues: - CVE-2026-0990: Fixed a call stack overflow leading to application crash due to infinite recursion in `xmlCatalogXMLResolveURI`. (bsc#1256807, bsc#1256811) - CVE-2026-0992: Fixed an excessive resource consumption when processing XML catalogs due to exponential behavior. (bsc#1256809, bsc#1256812) - CVE-2026-1757: Fixed a memory leak in the `xmllint` interactive shell. (bsc#1257594, bsc#1257595) - CVE-2025-10911: Fixed a use-after-free with key data stored cross-RVT. (bsc#1250553) - CVE-2025-8732: Fixed an infinite recursion in catalog parsing functions when processing malformed SGML catalog files. (bsc#1247858) - CVE-2026-0989: Fixe a call stack exhaustion leading to application crash due to RelaxNG parser not limiting the recursion depth. (bsc#1256805, bsc#1256810) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:813-1 Released: Thu Mar 5 09:33:59 2026 Summary: Security update for mozilla-nss Type: security Severity: moderate References: 1258568,CVE-2026-2781 This update for mozilla-nss fixes the following issues: Update to NSS 3.112.3: * CVE-2026-2781: Avoid integer overflow in platform-independent ghash (bsc#1258568) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:829-1 Released: Thu Mar 5 16:17:08 2026 Summary: Security update for gnutls Type: security Severity: moderate References: 1257960,1258083,CVE-2025-14831 This update for gnutls fixes the following issues: Security issue: - CVE-2025-14831: excessive resource consumption when verifying specially crafted malicious certificates containing a large number of name constraints and subject alternative names (bsc#1257960). Other updates and bugfixes: - update libgnutls package to avoid binder getting calculated with SHA256 (bsc#1258083, jsc#PED-15752, jsc#PED-15753). - lib/psk: Add gnutls_psk_allocate_{client,server}_credentials2 - tests/psk-file: Add testing for _credentials2 functions - lib/psk: add null check for binder algo - pre_shared_key: fix memleak when retrying with different binder algo - pre_shared_key: add null check on pskcred ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1065-1 Released: Thu Mar 26 11:38:12 2026 Summary: Security update for sqlite3 Type: security Severity: moderate References: 1254670,1259619,CVE-2025-70873,CVE-2025-7709 This update for sqlite3 fixes the following issues: Update sqlite3 to 3.51.3: - CVE-2025-7709: Integer Overflow in FTS5 Extension (bsc#1254670). - CVE-2025-70873: SQLite zipfile extension may disclose uninitialized heap memory during inflation (bsc#1259619). Changelog: * Fix the WAL-reset database corruption bug: https://sqlite.org/wal.html#walresetbug ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1399-1 Released: Thu Apr 16 12:44:14 2026 Summary: Security update for cups Type: security Severity: important References: 1261568,CVE-2026-34990 This update for cups fixes the following issue: - CVE-2026-34990: Local print admin token disclosure using temporary printers (bsc#1261568). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1441-1 Released: Fri Apr 17 16:18:19 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1257235,CVE-2026-24401 This update for avahi fixes the following issue: - CVE-2026-24401: avahi-daemon can be crashed via a segmentation fault by sending an unsolicited mDNS response containing a recursive CNAME record (bsc#1257235). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:1561-1 Released: Thu Apr 23 08:34:49 2026 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: This update for mozilla-nss fixes the following issues: Update to NSS 3.112.4: * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * RSA_EMSAEncodePSS should validate the length of mHash. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * Remove invalid PORT_Free(). * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * make ss->ssl3.hs.cookie an owned-copy of the cookie. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1576-1 Released: Thu Apr 23 17:53:21 2026 Summary: Security update for gdk-pixbuf Type: security Severity: important References: 1261210,CVE-2026-5201 This update for gdk-pixbuf fixes the following issue: - CVE-2026-5201: Denial of Service via heap-based buffer overflow when processing a specially crafted JPEG image (bsc#1261210). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1750-1 Released: Thu May 7 13:52:09 2026 Summary: Security update for librsvg Type: security Severity: important References: 1257922,CVE-2026-25727 This update for librsvg fixes the following issue: - CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257922). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1845-1 Released: Wed May 13 17:26:41 2026 Summary: Security update for Mesa Type: security Severity: moderate References: 1261998,CVE-2026-40393 This update for Mesa fixes the following issue: - CVE-2026-40393: out-of-bounds memory access can occur in WebGPU because the amount of to-be-allocated data depends on an untrusted party (bsc#1261998). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1967-1 Released: Mon May 18 10:12:42 2026 Summary: Security update for tiff Type: security Severity: important References: 1260411,CVE-2026-4775 This update for tiff fixes the following issue - CVE-2026-4775: signed integer overflow in the `putcontig8bitYCbCr44tile` function (bsc#1260411). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2115-1 Released: Fri May 29 17:27:13 2026 Summary: Security update for gnutls Type: security Severity: important References: 1263704,1263705,1263707,1263708,1263709,1263710,1263711,1263712,1263713,1263714,1263715,1263716,CVE-2026-33845,CVE-2026-33846,CVE-2026-3833,CVE-2026-42009,CVE-2026-42010,CVE-2026-42011,CVE-2026-42012,CVE-2026-42013,CVE-2026-42014,CVE-2026-42015,CVE-2026-5260,CVE-2026-5419 This update for gnutls fixes the following issues - CVE-2026-3833: x509/name-constraints: compare domain names case-insensitive (bsc#1263707). - CVE-2026-5260: lib/pkcs11_privkey: guard against overreading on short ciphertexts (bsc#1263715). - CVE-2026-5419: gnutls_cipher_decrypt3: make PKCS#7 unpadding branch free (bsc#1263716). - CVE-2026-33845: buffers: switch from end_offset over to frag_length (bsc#1263704). - CVE-2026-33846: buffers: add more checks to DTLS reassembly (bsc#1263705). - CVE-2026-42009: lib/buffers: ensure packets have differing sequence numbers (bsc#1263708). - CVE-2026-42010: lib/auth/rsa_psk: fix binary PSK identity lookup (bsc#1263709). - CVE-2026-42011: x509/name_constraints: fix intersecting empty constraints (bsc#1263710). - CVE-2026-42012: x509/hostname-verify: make URI/SRV SAN preclude CN fallback (bsc#1263711). - CVE-2026-42013: x509: prevent fallback on oversized SAN (bsc#1263712). - CVE-2026-42014: pkcs11_write: fix UAF and leak in gnutls_pkcs11_token_set_pin (bsc#1263713). - CVE-2026-42015: x509/pkcs12_bag: fix off-by-one in bag element bounds chec (bsc#1263714). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2297-1 Released: Mon Jun 8 12:16:51 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1261546,CVE-2026-34933 This update for avahi fixes the following issue: - CVE-2026-34933: Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags (bsc#1261546). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2478-1 Released: Mon Jun 22 10:46:59 2026 Summary: Security update for graphite2 Type: security Severity: important References: 1267733,CVE-2026-50593 This update for graphite2 fixes the following issue: - CVE-2026-50593: Out-of-bounds write via Graphite actions (bsc#1267733). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2528-1 Released: Tue Jun 23 11:06:07 2026 Summary: Security update for sqlite3 Type: security Severity: important References: 1268012,1268013,CVE-2026-11822,CVE-2026-11824 This update for sqlite3 fixes the following issues Update to 3.53.2: - CVE-2026-11822: memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution (bsc#1268012). - CVE-2026-11824: heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code (bsc#1268013). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2637-1 Released: Thu Jun 25 17:42:10 2026 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: This update for mozilla-nss fixes the following issues: Update to NSS 3.112.5: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max. * update to version 2.84 of builtins module. - Added 'Suggests: p11-kit-nss-trust' to favor over mozilla-nss-certs (jsc#PED-15633) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2732-1 Released: Thu Jul 2 19:41:27 2026 Summary: Security update for cups Type: security Severity: moderate References: 1261569,1261570,1261571,1261572,1261742,1261743,CVE-2026-27447,CVE-2026-34978,CVE-2026-34979,CVE-2026-34980,CVE-2026-39314,CVE-2026-39316 This update for cups fixes the following issues - CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup (bsc#1261572). - CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (bsc#1261571). - CVE-2026-34979: Heap overflow in `get_options()` (bsc#1261570). - CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (bsc#1261569). - CVE-2026-39314: negative `job-password-supported` attribute can lead to a denial of service (bsc#1261743). - CVE-2026-39316: dangling subscription pointer can lead to a denial of service (1261742). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2853-1 Released: Fri Jul 10 19:54:25 2026 Summary: Security update for tiff Type: security Severity: important References: 1268434,1269779,CVE-2026-12912,CVE-2026-36849,CVE-2026-4775 This update for tiff fixes the following issues: Update to version 4.7.2. Security issues fixed: - CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog-compressed TIFF image (bsc#1269779). - CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). Other updates and bugfixes: - Version 4.7.2: - Software configuration changes: * cmake: Fix bundle identifiers to use reverse-DNS format * cmake: Fix and improve Apple framework build support * cmake: Use TurboJPEG CONFIG by default (issue #767) * cmake: changes related to 8-/12-bit modes * cmake: Replace CMath::CMath with direct link to avoid export. * Support for iOS-derived builds * Simplify cmake byte order version check * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions * configure.ac: Require bootstrap with at least Autoconf 2.71. - Library changes: * New/improved functionalities:: + Add TIFFGetMaxCompressionRatio() and use it in _TIFFReadEncoded[Tile|Strip)AndAllocBuffer() (issue #781) - Bug fixes: * Handle negative TIFFReadFile results before state updates (issue #854) * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777) * tif_dirwrite.c: add integer overflow checks to allocation size calculations * tif_print.c: add integer overflow checks to allocation size calculations * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop * DumpModeSeek: add bounds check to prevent OOB pointer advance * TIFFGrowStrips: fix use-after-free on partial realloc failure. * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it. * TIFFRGBAImage: avoid int overflows in put functions (issue #830) * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792) * tif_getimage: Widen pointer-offset arithmetic in tif_getimage * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798) * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753) * TIFFReadRGBAImage(): prevent integer overflow and later heap overflow (issue #787) * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831) * TIFFLinkDirectory() checks for IFD loops (issue #788) * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails. * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805) * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465) * tif_getimage: reject tile widths that would overflow toskew (issue #808) * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit. * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777). * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss-fuzz.com/issues/471328917) * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755). * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749) * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892) * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826) * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg-turbo 3.0.3 (issue #773) * JPEGDecode(): fix memory leak in error code path (https://issues.oss-fuzz.com/issues/471945501) * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850) * PixarLog: error out on invalid ABGR output buffer sizes. * PixarLog: complete ABGR bounds check for multi-row strip decoding. * PixarLog: fix heap-buffer-overflow in 8BITABGR decode with stride 3 (issue #824) * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789). * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797) * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072) * OJPEG: fix integer overflow in subsampling buffer allocation. * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795). * OJPEG fix potential integer overflow/out-of-bounds access (issue #796). * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b) * fix null pointer deference in issue #782. * fix stack-overflow in issue #784. - Other changes: * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739). * Harden integer size and offset calculations (issue #897) * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication * Move widening casts inside multiplication scope. * Lots of compiler warning fixes related to enabling more warning flags * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773) * TIFFFillStrip(): prevent harmless unsigned integer overflow ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3218-1 Released: Thu Jul 23 19:34:12 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1255451,CVE-2025-59529 This update for avahi fixes the following issue: - CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3270-1 Released: Mon Jul 27 13:01:22 2026 Summary: Security update for alsa Type: security Severity: moderate References: 1268853,CVE-2026-56109 This update for alsa fixes the following issue - CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that can allow attackers to corrupt memory (bsc#1268853). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - gtk3-data-3.24.43-150600.3.10.1 added - gtk3-schema-3.24.43-150600.3.10.1 added - hicolor-icon-theme-0.17-150600.19.2 added - libasound2-1.2.10-150600.4.3.1 added - libavahi-common3-0.8-150600.15.21.1 added - libdatrie1-0.2.9-1.25 added - libepoxy0-1.5.10-150500.1.2 added - libffi7-3.2.1.git259-10.8 added - libfribidi0-1.0.10-150400.3.3.1 added - libglib-2_0-0-2.78.6-150600.4.38.1 added - libgraphite2-3-1.3.14-150600.3.3.1 added - libjbig2-2.1-150000.3.5.1 added - libjpeg8-8.2.2-150600.22.5 added - liblcms2-2-2.15-150600.3.3.2 added - libnettle8-3.10.1-150700.2.16 added - libpixman-1-0-0.43.4-150600.3.3.1 added - libsqlite3-0-3.53.2-150000.3.42.1 added - libthai-data-0.1.29-150400.1.4 added - libudev1-254.27-150600.4.71.2 added - libunistring2-0.9.10-1.1 added - libwayland-egl1-99~1.23.1-150700.1.3 added - mozilla-nspr-4.36.2-150000.3.36.1 added - libgbm1-24.3.3-150700.93.8.1 added - libwayland-client0-1.23.1-150700.1.3 added - libp11-kit0-0.23.22-150500.8.3.1 added - pkg-config-0.29.2-150600.15.6.3 added - libgobject-2_0-0-2.78.6-150600.4.38.1 added - libgmodule-2_0-0-2.78.6-150600.4.38.1 added - libfreebl3-3.112.5-150400.3.69.2 added - libhogweed6-3.10.1-150700.2.16 added - libthai0-0.1.29-150400.1.4 added - libidn2-0-2.2.0-3.6.1 added - libxml2-2-2.12.10-150700.4.14.1 added - libelf1-0.185-150400.5.8.3 added - libtiff6-4.7.2-150600.3.29.1 added - mozilla-nss-certs-3.112.5-150400.3.69.2 added - libxcb-shm0-1.17.0-150700.1.2 added - libxcb-render0-1.17.0-150700.1.2 added - libwayland-cursor0-1.23.1-150700.1.3 added - xkeyboard-config-2.42-150700.1.1 added - libatk-1_0-0-2.50.0-150600.1.2 added - shared-mime-info-2.4-150600.3.3.2 added - libsoftokn3-3.112.5-150400.3.69.2 added - mozilla-nss-3.112.5-150400.3.69.2 added - libXrender1-0.9.10-1.30 added - libXfixes3-6.0.0-150400.1.4 added - libXdamage1-1.1.4-1.23 added - libXcomposite1-0.4.4-1.23 added - libxkbcommon0-1.5.0-150600.3.3.1 added - libtasn1-6-4.13-150000.4.14.1 added - libtasn1-4.13-150000.4.14.1 added - gio-branding-SLE-15-150600.35.2.1 added - libgio-2_0-0-2.78.6-150600.4.38.1 added - glib2-tools-2.78.6-150600.4.38.1 added - libharfbuzz0-8.3.0-150600.3.3.1 added - libXcursor1-1.1.15-1.18 added - libXrandr2-1.5.1-2.17 added - libXinerama1-1.1.3-1.22 added - libXi6-1.7.9-3.2.1 added - libavahi-client3-0.8-150600.15.21.1 added - libgnutls30-3.8.3-150600.4.20.1 added - libcolord2-1.4.6-150600.3.8.1 added - gdk-pixbuf-query-loaders-2.42.12-150600.3.11.1 added - libcairo2-1.18.4-150600.3.3.1 added - libXft2-2.3.2-1.33 added - libatspi0-2.50.0-150600.1.2 added - libgdk_pixbuf-2_0-0-2.42.12-150600.3.11.1 added - libcairo-gobject2-1.18.4-150600.3.3.1 added - libpango-1_0-0-1.51.1-150600.1.3 added - libatk-bridge-2_0-0-2.50.0-150600.1.2 added - librsvg-2-2-2.57.4-150600.3.8.2 added - gdk-pixbuf-loader-rsvg-2.57.4-150600.3.8.2 added - system-user-lp-20170617-150400.24.2.1 added - cups-config-2.2.7-150000.3.93.1 added - libcups2-2.2.7-150000.3.93.1 added - gtk3-tools-3.24.43-150600.3.10.1 added - libgtk-3-0-3.24.43-150600.3.10.1 added - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - coreutils-8.32-150400.9.12.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - sles-release-15.7-150700.67.6.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Mon Sep 7 08:18:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 10:18:29 +0200 (CEST) Subject: SUSE-CU-2026:9584-1: Security update of suse/kiosk/xorg Message-ID: <20260907081829.D1251FCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9584-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-83.17 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 83.17 Severity : important Type : security References : 1216950 1236136 1236599 1243014 1243459 1243564 1247463 1250233 1250234 1256829 1256831 1256832 1256833 1257274 1259652 1261678 1266344 1266347 CVE-2024-12797 CVE-2024-13176 CVE-2024-9143 CVE-2025-11187 CVE-2025-15468 CVE-2025-15469 CVE-2025-27587 CVE-2025-4575 CVE-2025-66199 CVE-2025-9231 CVE-2025-9232 CVE-2026-2673 CVE-2026-28390 CVE-2026-34182 CVE-2026-42764 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3835-1 Released: Thu Aug 27 13:53:51 2026 Summary: Security update for openssl, openssl-3 Type: security Severity: important References: 1216950,1236136,1236599,1243014,1243459,1243564,1247463,1250233,1250234,1256829,1256831,1256832,1256833,1257274,1259652,1261678,1266344,1266347,CVE-2024-12797,CVE-2024-13176,CVE-2024-9143,CVE-2025-11187,CVE-2025-15468,CVE-2025-15469,CVE-2025-27587,CVE-2025-4575,CVE-2025-66199,CVE-2025-9231,CVE-2025-9232,CVE-2026-2673,CVE-2026-28390,CVE-2026-34182,CVE-2026-42764 This update for openssl, openssl-3 fixes the following issues: OpenSSL is updated to 3.5.0 in SLE-15-SP7: (jsc#PED-16072) * Enables Post-Quantum Cryptography (PQC) TLS support Security issues fixed: * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347) * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344) * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678) * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652) * CVE-2025-66199: TLS 1.3 CompressedCertificate excessive memory allocation (bsc#1256833) * CVE-2025-15469: 'openssl dgst' one-shot codepath silently truncates inputs greater than 16MB (bsc#1256832) * CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256829) * CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256831) * CVE-2025-9231: Fix timing side-channel in SM2 algorithm on 64 bit ARM (bsc#1250233) * CVE-2025-9232: Fix out-of-bounds read in HTTP client no_proxy handling (bsc#1250234) * CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use (bsc#1243564) * CVE-2025-27587: Minerva side channel vulnerability in P-384 (bsc#1243459) * CVE-2024-12797: Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. (bsc#1236599) * CVE-2024-13176: Fixed timing side-channel in ECDSA signature computation. * CVE-2024-9143: Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic curve parameters. * CVE-2024-13176: Fix timing side-channel in ECDSA signature computation (bsc#1236136) POWER performance enhancements: * Optimized MLDSA NTT, supports p8 and above architectures (jsc#PED-14569) - Adapt spec file for immutability via systemd-tmpfiles (jsc#PED-14813) - Fix check %{suse_version} > 1600 (jsc#PED-15816) - Fix NULL pointer dereference when processing an OCSP response - Remove showciphers.c in favor of openssl ciphers - Use %ldconfig_scriptlets - Enable livepatching support for ppc64le [bsc#1257274] - Move ssl configuration files to the libopenssl package [bsc#1247463] - Don't install unneeded NOTES - Disable LTO for userspace livepatching [jsc#PED-13245] - Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014] - FIPS: Fix the speed command in FIPS mode for KMAC - FIPS: Restore the check to deny SHA1 signatures in FIPS mode and the functionality to allow/deny via crypto-policies. [jsc#PED-12224] Update to 3.5.0: * Changes: - Default encryption cipher for the req, cms, and smime applications changed from des-ede3-cbc to aes-256-cbc. - The default TLS supported groups list has been changed to include and prefer hybrid PQC KEM groups. Some practically unused groups were removed from the default list. - The default TLS keyshares have been changed to offer X25519MLKEM768 and and X25519. - All BIO_meth_get_*() functions were deprecated. * New features: - Support for server side QUIC (RFC 9000) - Support for 3rd party QUIC stacks including 0-RTT support - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA) - A new configuration option no-tls-deprecated-ec to disable support for TLS groups deprecated in RFC8422 - A new configuration option enable-fips-jitter to make the FIPS provider to use the JITTER seed source - Support for central key generation in CMP - Support added for opaque symmetric key objects (EVP_SKEY) - Support for multiple TLS keyshares and improved TLS key establishment group configurability - API support for pipelining in provided cipher algorithms Changes between 3.3.0 and 3.4.0: * Changes: - Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_* functions with improved semantics - The X25519 and X448 key exchange implementation in the FIPS provider is unapproved and has fips=no property. - SHAKE-128 and SHAKE-256 implementations have no default digest length anymore. That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before. - Setting config_diagnostics=1 in the config file will cause errors to be returned from SSL_CTX_new() and SSL_CTX_new_ex() if there is an error in the ssl module configuration. - An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for all connections with a minimum TLS version > 1.0. - Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t * New features: - Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions - FIPS indicators support in the FIPS provider and various updates of the FIPS provider required for future FIPS 140-3 validations - Implementation of RFC 9579 (PBMAC1) in PKCS#12 - An optional additional random seed source RNG JITTER using a statically linked jitterentropy library - New options -not_before and -not_after for explicit setting start and end dates of certificates created with the req and x509 apps - Support for integrity-only cipher suites TLS_SHA256_SHA256 and TLS_SHA384_SHA384 in TLS 1.3, as defined in RFC 9150 - Support for retrieving certificate request templates and CRLs in CMP - Support for additional X.509v3 extensions related to Attribute Certificates - Initial Attribute Certificate (RFC 5755) support - Possibility to customize ECC groups initialization to use precomputed values to save CPU time and use of this feature by the P-256 implementation Changes between 3.2.0 and 3.3.0: * Changes: - Optimized AES-CTR for ARM Neoverse V1 and V2 - Various optimizations for cryptographic routines using RISC-V vector crypto extensions - Added assembly implementation for md5 on loongarch64 - Accept longer context for TLS 1.2 exporters - The activate and soft_load configuration settings for providers in openssl.cnf have been updated to require a value of [1|yes|true|on] (in lower or UPPER case) to enable the setting. Conversely a value of [0|no|false|off] will disable the setting. - In openssl speed, changed the default hash function used with hmac from md5 to sha256. - The -verify option to the openssl crl and openssl req will make the program exit with 1 on failure. - The d2i_ASN1_GENERALIZEDTIME(), d2i_ASN1_UTCTIME(), ASN1_TIME_check(), and related functions have been augmented to check for a minimum length of the input string, in accordance with ITU-T X.690 section 11.7 and 11.8. - OPENSSL_sk_push() and sk__push() functions now return 0 instead of -1 if called with a NULL stack argument. - New limit on HTTP response headers is introduced to HTTP client. The default limit is set to 256 header lines. * Bug fixes and mitigations: - The BIO_get_new_index() function can only be called 127 times before it reaches its upper bound of BIO_TYPE_MASK and will now return -1 once its exhausted. * new features: - Support for qlog for tracing QUIC connections has been added - Added APIs to allow configuring the negotiated idle timeout for QUIC connections, and to allow determining the number of additional streams that can currently be created for a QUIC connection. - Added APIs to allow disabling implicit QUIC event processing for QUIC SSL objects - Added APIs to allow querying the size and utilisation of a QUIC stream's write buffer - New API SSL_write_ex2, which can be used to send an end-of-stream (FIN) condition in an optimised way when using QUIC. - Limited support for polling of QUIC connection and stream objects in a non-blocking manner. - Added a new EVP_DigestSqueeze() API. This allows SHAKE to squeeze multiple times with different output sizes. - The BLAKE2s hash algorithm matches BLAKE2b's support for configurable output length. - The EVP_PKEY_fromdata function has been augmented to allow for the derivation of CRT (Chinese Remainder Theorem) parameters when requested - Added API functions SSL_SESSION_get_time_ex(), SSL_SESSION_set_time_ex() using time_t which is Y2038 safe on 32 bit systems when 64 bit time is enabled. - Unknown entries in TLS SignatureAlgorithms, ClientSignatureAlgorithms config options and the respective calls to SSL[_CTX]_set1_sigalgs() and SSL[_CTX]_set1_client_sigalgs() that start with ? character are ignored and the configuration will still be used. - Added -set_issuer and -set_subject options to openssl x509 to override the Issuer and Subject when creating a certificate. The -subj option now is an alias for -set_subject. - Added several new features of CMPv3 defined in RFC 9480 and RFC 9483 - New option SSL_OP_PREFER_NO_DHE_KEX, which allows configuring a TLS1.3 server to prefer session resumption using PSK-only key exchange over PSK with DHE, if both are available. - New atexit configuration switch, which controls whether the OPENSSL_cleanup is registered when libcrypto is unloaded. - Added X509_STORE_get1_objects to avoid issues with the existing X509_STORE_get0_objects API in multi-threaded applications. - Support for using certificate profiles and extened delayed delivery in CMP - FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224] - Introduce --without lto. When %{optflags} contains -flto=*, tests cases are also built using -flto=* which significantly increases build times, this option disables lto which improve iteration times when developing. Update to 3.2.4: - Remove the engines' directories and symlinks that were added to allow parallel installations with openssl-1_1. - Add ktls capability [bsc#1216950] The following package changes have been done: - libopenssl3-3.5.0-150700.5.45.2 updated - container:suse-sle15-15.7-6d092dacdf017aa78c53ef98ac927ac162c0c984db97d6bb93e40a9045ef2e6d-0 updated From sle-container-updates at lists.suse.com Mon Sep 7 08:18:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 10:18:30 +0200 (CEST) Subject: SUSE-CU-2026:9585-1: Recommended update of suse/kiosk/xorg Message-ID: <20260907081830.E5198FDCF@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9585-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-83.19 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 83.19 Severity : important Type : recommended References : 1242233 1243830 1259542 1275902 1277267 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - login_defs-4.17.2-150600.17.24.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - shadow-4.17.2-150600.17.24.1 updated From sle-container-updates at lists.suse.com Mon Sep 7 08:35:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 10:35:17 +0200 (CEST) Subject: SUSE-CU-2026:9651-1: Recommended update of suse/sles/16.0/toolbox Message-ID: <20260907083517.19DF1FDCB@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9651-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.111 , suse/sles/16.0/toolbox:latest Container Release : 1.111 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1534 Released: Sun Aug 30 15:09:44 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-160000.1.1 updated From sle-container-updates at lists.suse.com Mon Sep 7 08:35:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 10:35:18 +0200 (CEST) Subject: SUSE-CU-2026:9652-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260907083518.1876DFDD4@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9652-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.112 , suse/sles/16.0/toolbox:latest Container Release : 1.112 Severity : moderate Type : security References : 1263078 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1562 Released: Mon Aug 31 07:56:37 2026 Summary: Security update for libgpg-error Type: security Severity: moderate References: 1263078 This update for libgpg-error fixes the following issue: - Out-of-bounds read in `_gpgrt_vfnameconcat` of `stringutils.c` when the `GPGRT_FCONCAT_SYSCONF` flag is used (bsc#1263078). The following package changes have been done: - libgpg-error0-1.58-160000.2.1 updated From sle-container-updates at lists.suse.com Mon Sep 7 08:35:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 10:35:19 +0200 (CEST) Subject: SUSE-CU-2026:9654-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260907083519.B966BFEDB@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9654-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.114 , suse/sles/16.0/toolbox:latest Container Release : 1.114 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1592 Released: Wed Sep 2 17:55:21 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl-3-fips-provider-3.5.0-160000.10.1 updated - libopenssl3-3.5.0-160000.10.1 updated From sle-container-updates at lists.suse.com Mon Sep 7 08:35:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 10:35:21 +0200 (CEST) Subject: SUSE-CU-2026:9655-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260907083521.33168FF48@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9655-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.115 , suse/sles/16.0/toolbox:latest Container Release : 1.115 Severity : moderate Type : security References : 1237515 1254924 1259418 1259650 1261400 1271444 CVE-2026-16742 CVE-2026-29111 CVE-2026-40226 CVE-2026-4105 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1602 Released: Thu Sep 3 22:41:28 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1237515,1254924,1259418,1259650,1261400,1271444,CVE-2026-16742,CVE-2026-29111,CVE-2026-40226,CVE-2026-4105 This update for systemd fixes the following issue: Security issue fixed: - CVE-2026-16742: `systemd-homed`: local privilege escalation due to missing home record signature verification on the authentication path (bsc#1271444). Non security issue fixed: - `systemd-resolved` fails to start due to write access to `tmpfs` denied (bsc#1237515). The following package changes have been done: - libsystemd0-257.13-160000.4.1 updated - libudev1-257.13-160000.4.1 updated From sle-container-updates at lists.suse.com Mon Sep 7 09:12:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 11:12:24 +0200 (CEST) Subject: SUSE-CU-2026:9655-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260907091224.CC7BAFCEE@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9655-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.115 , suse/sles/16.0/toolbox:latest Container Release : 1.115 Severity : moderate Type : security References : 1237515 1254924 1259418 1259650 1261400 1271444 CVE-2026-16742 CVE-2026-29111 CVE-2026-40226 CVE-2026-4105 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1602 Released: Thu Sep 3 22:41:28 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1237515,1254924,1259418,1259650,1261400,1271444,CVE-2026-16742,CVE-2026-29111,CVE-2026-40226,CVE-2026-4105 This update for systemd fixes the following issue: Security issue fixed: - CVE-2026-16742: `systemd-homed`: local privilege escalation due to missing home record signature verification on the authentication path (bsc#1271444). Non security issue fixed: - `systemd-resolved` fails to start due to write access to `tmpfs` denied (bsc#1237515). The following package changes have been done: - libsystemd0-257.13-160000.4.1 updated - libudev1-257.13-160000.4.1 updated From sle-container-updates at lists.suse.com Mon Sep 7 09:12:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 11:12:27 +0200 (CEST) Subject: SUSE-CU-2026:9657-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260907091227.19115FEC9@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9657-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.117 , suse/sles/16.0/toolbox:latest Container Release : 1.117 Severity : moderate Type : security References : 1262633 1263440 1268412 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1622 Released: Sun Sep 6 18:56:18 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: OpenLDAP SASL authentication bypass (bsc#1277476). - CVE-2026-80229: OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass (bsc#1277480). The following package changes have been done: - curl-8.14.1-160000.9.1 updated - libcurl-mini4-8.14.1-160000.9.1 updated From sle-container-updates at lists.suse.com Mon Sep 7 09:12:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 11:12:25 +0200 (CEST) Subject: SUSE-CU-2026:9656-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260907091225.E3872FDCF@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9656-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.116 , suse/sles/16.0/toolbox:latest Container Release : 1.116 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1610 Released: Fri Sep 4 15:48:44 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the `bzip2recover` utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-160000.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 7 09:20:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 7 Sep 2026 11:20:24 +0200 (CEST) Subject: SUSE-CU-2026:9715-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260907092024.0D366F771@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9715-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.27 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.27 Severity : critical Type : security References : 1207866 1274235 1274237 1274850 1274852 1274854 CVE-2022-25147 CVE-2025-49506 CVE-2026-32327 CVE-2026-34191 CVE-2026-34501 CVE-2026-34502 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3937-1 Released: Thu Sep 3 09:28:23 2026 Summary: Security update for apr-util Type: security Severity: critical References: 1207866,1274235,1274237,1274850,1274852,1274854,CVE-2022-25147,CVE-2025-49506,CVE-2026-32327,CVE-2026-34191,CVE-2026-34501,CVE-2026-34502 This update for apr-util fixes the following issues: - CVE-2022-25147: buffer overflow possible with specially crafted input (bsc#1207866). - CVE-2025-49506: leaking content via side channel timing attack (bsc#1274237). - CVE-2026-32327: XML stack recursion crash (bsc#1274235). - CVE-2026-34191: SQL Injection via apr_dbd_oracle (bsc#1274850). - CVE-2026-34501: heap buffer overflow in redis client (bsc#1274852). - CVE-2026-34502: heap buffer overflow in APR memcached client (bsc#1274854). The following package changes have been done: - libapr-util1-1.6.1-150300.18.8.1 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:09:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:09:45 +0200 (CEST) Subject: SUSE-IU-2026:6845-1: Security update of suse/sle-micro/base-5.5 Message-ID: <20260908070945.CF3B4FCCD@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6845-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.314 , suse/sle-micro/base-5.5:latest Image Release : 5.8.314 Severity : moderate Type : security References : 1266664 1266786 1274856 1274857 1274858 CVE-2026-23679 CVE-2026-42250 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - cpio-2.13-150400.3.10.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:12:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:12:21 +0200 (CEST) Subject: SUSE-IU-2026:6846-1: Security update of suse/sle-micro/kvm-5.5 Message-ID: <20260908071221.8D075FCCD@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/kvm-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6846-1 Image Tags : suse/sle-micro/kvm-5.5:2.0.4 , suse/sle-micro/kvm-5.5:2.0.4-3.5.605 , suse/sle-micro/kvm-5.5:latest Image Release : 3.5.605 Severity : moderate Type : security References : 1266786 1274856 1274857 1274858 CVE-2026-42250 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 ----------------------------------------------------------------- The container suse/sle-micro/kvm-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - cpio-2.13-150400.3.10.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.314 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:15:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:15:41 +0200 (CEST) Subject: SUSE-IU-2026:6847-1: Security update of suse/sle-micro/rt-5.5 Message-ID: <20260908071541.72356FCCD@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6847-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.714 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.714 Severity : moderate Type : security References : 1266786 1274856 1274857 1274858 CVE-2026-42250 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - cpio-2.13-150400.3.10.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.107 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:18:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:18:20 +0200 (CEST) Subject: SUSE-IU-2026:6848-1: Security update of suse/sle-micro/5.5 Message-ID: <20260908071820.6652EFCC7@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6848-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.107 , suse/sle-micro/5.5:latest Image Release : 5.8.107 Severity : moderate Type : security References : 1266664 1266786 1273100 1274856 1274857 1274858 CVE-2026-23679 CVE-2026-42250 CVE-2026-52791 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4026-1 Released: Mon Sep 7 09:44:09 2026 Summary: Security update for fuse-overlayfs Type: security Severity: moderate References: 1273100,CVE-2026-52791 This update for fuse-overlayfs fixes the following issue: - CVE-2026-52791: Privilege Escalation Vulnerability via SUID/SGID Bit Preservation (bsc#1273100). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - cpio-2.13-150400.3.10.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated - fuse-overlayfs-1.1.2-150100.3.14.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.314 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:24:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:24:19 +0200 (CEST) Subject: SUSE-CU-2026:9730-1: Security update of private-registry/1.2/harbor-core Message-ID: <20260908072419.7D55EFCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9730-1 Container Tags : private-registry/1.2/harbor-core:1.2.1 , private-registry/1.2/harbor-core:1.2.1-1.90 , private-registry/1.2/harbor-core:latest Container Release : 1.90 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/1.2/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.15.2-150700.1.10 updated - harbor-core-2.15.2-150700.1.10 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:24:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:24:37 +0200 (CEST) Subject: SUSE-CU-2026:9731-1: Security update of private-registry/1.2/harbor-exporter Message-ID: <20260908072437.72EA1FCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9731-1 Container Tags : private-registry/1.2/harbor-exporter:1.2.1 , private-registry/1.2/harbor-exporter:1.2.1-1.90 , private-registry/1.2/harbor-exporter:latest Container Release : 1.90 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/1.2/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - harbor-exporter-2.15.2-150700.1.10 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.15.2-150700.1.10 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:24:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:24:56 +0200 (CEST) Subject: SUSE-CU-2026:9732-1: Security update of private-registry/1.2/harbor-jobservice Message-ID: <20260908072456.1C584FCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9732-1 Container Tags : private-registry/1.2/harbor-jobservice:1.2.1 , private-registry/1.2/harbor-jobservice:1.2.1-1.88 , private-registry/1.2/harbor-jobservice:latest Container Release : 1.88 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/1.2/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.15.2-150700.1.10 updated - harbor-jobservice-2.15.2-150700.1.10 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:25:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:25:18 +0200 (CEST) Subject: SUSE-CU-2026:9733-1: Security update of private-registry/1.2/harbor-portal Message-ID: <20260908072518.8AD91FCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9733-1 Container Tags : private-registry/1.2/harbor-portal:1.2.1 , private-registry/1.2/harbor-portal:1.2.1-1.99 , private-registry/1.2/harbor-portal:latest Container Release : 1.99 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.15.2-150700.1.10 updated - harbor-portal-2.15.2-150700.1.10 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:25:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:25:38 +0200 (CEST) Subject: SUSE-CU-2026:9734-1: Security update of private-registry/1.2/harbor-registry Message-ID: <20260908072538.391FAFCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9734-1 Container Tags : private-registry/1.2/harbor-registry:1.2.1 , private-registry/1.2/harbor-registry:1.2.1-1.90 , private-registry/1.2/harbor-registry:latest Container Release : 1.90 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.15.2-150700.1.10 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:25:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:25:59 +0200 (CEST) Subject: SUSE-CU-2026:9735-1: Security update of private-registry/1.2/harbor-registryctl Message-ID: <20260908072559.79200FCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9735-1 Container Tags : private-registry/1.2/harbor-registryctl:1.2.1 , private-registry/1.2/harbor-registryctl:1.2.1-1.90 , private-registry/1.2/harbor-registryctl:latest Container Release : 1.90 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.15.2-150700.1.10 updated - harbor-registryctl-2.15.2-150700.1.10 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:26:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:26:23 +0200 (CEST) Subject: SUSE-CU-2026:9736-1: Security update of private-registry/1.2/harbor-trivy-adapter Message-ID: <20260908072623.85B92FCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9736-1 Container Tags : private-registry/1.2/harbor-trivy-adapter:1.2.1 , private-registry/1.2/harbor-trivy-adapter:1.2.1-1.99 , private-registry/1.2/harbor-trivy-adapter:latest Container Release : 1.99 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container private-registry/1.2/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - harbor-scanner-trivy-0.38.0-150700.1.10 updated - system-user-harbor-2.15.2-150700.1.10 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:27:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:27:25 +0200 (CEST) Subject: SUSE-CU-2026:9737-1: Security update of private-registry/harbor-core Message-ID: <20260908072725.6C68EFCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9737-1 Container Tags : private-registry/harbor-core:1.1.3 , private-registry/harbor-core:1.1.3-2.104 , private-registry/harbor-core:latest Container Release : 2.104 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.14.4-150700.1.41 updated - harbor-core-2.14.4-150700.1.41 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:28:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:28:29 +0200 (CEST) Subject: SUSE-CU-2026:9738-1: Security update of private-registry/harbor-exporter Message-ID: <20260908072829.BE439FCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9738-1 Container Tags : private-registry/harbor-exporter:1.1.3 , private-registry/harbor-exporter:1.1.3-2.105 , private-registry/harbor-exporter:latest Container Release : 2.105 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - harbor-exporter-2.14.4-150700.1.41 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.14.4-150700.1.41 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:29:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:29:37 +0200 (CEST) Subject: SUSE-CU-2026:9739-1: Security update of private-registry/harbor-jobservice Message-ID: <20260908072937.DCEBBFCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9739-1 Container Tags : private-registry/harbor-jobservice:1.1.3 , private-registry/harbor-jobservice:1.1.3-2.104 , private-registry/harbor-jobservice:latest Container Release : 2.104 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.14.4-150700.1.41 updated - harbor-jobservice-2.14.4-150700.1.41 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:30:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:30:46 +0200 (CEST) Subject: SUSE-CU-2026:9740-1: Security update of private-registry/harbor-portal Message-ID: <20260908073046.93EFBFCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9740-1 Container Tags : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.117 , private-registry/harbor-portal:latest Container Release : 2.117 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.14.4-150700.1.41 updated - harbor-portal-2.14.4-150700.1.41 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:31:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:31:18 +0200 (CEST) Subject: SUSE-CU-2026:9741-1: Security update of private-registry/harbor-registry Message-ID: <20260908073118.860B9FCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9741-1 Container Tags : private-registry/harbor-registry:1.1.3 , private-registry/harbor-registry:1.1.3-2.105 , private-registry/harbor-registry:latest Container Release : 2.105 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.14.4-150700.1.41 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:32:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:32:21 +0200 (CEST) Subject: SUSE-CU-2026:9742-1: Security update of private-registry/harbor-registryctl Message-ID: <20260908073221.91F5FFCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9742-1 Container Tags : private-registry/harbor-registryctl:1.1.3 , private-registry/harbor-registryctl:1.1.3-2.106 , private-registry/harbor-registryctl:latest Container Release : 2.106 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.14.4-150700.1.41 updated - harbor-registryctl-2.14.4-150700.1.41 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:33:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:33:30 +0200 (CEST) Subject: SUSE-CU-2026:9743-1: Security update of private-registry/harbor-trivy-adapter Message-ID: <20260908073330.B6D16FCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9743-1 Container Tags : private-registry/harbor-trivy-adapter:1.1.3 , private-registry/harbor-trivy-adapter:1.1.3-2.117 , private-registry/harbor-trivy-adapter:latest Container Release : 2.117 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - harbor-scanner-trivy-0.36.0-150700.1.26 updated - system-user-harbor-2.14.4-150700.1.41 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:33:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:33:43 +0200 (CEST) Subject: SUSE-CU-2026:9744-1: Security update of private-registry/harbor-core Message-ID: <20260908073343.D5686FCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9744-1 Container Tags : private-registry/harbor-core:2.13 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5-1.56 , private-registry/harbor-core:2.13.5-1.56 , private-registry/harbor-core:latest Container Release : 1.56 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.13.5-150700.1.30 updated - harbor213-core-2.13.5-150700.1.30 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:33:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:33:57 +0200 (CEST) Subject: SUSE-CU-2026:9745-1: Security update of private-registry/harbor-exporter Message-ID: <20260908073357.676AEFCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9745-1 Container Tags : private-registry/harbor-exporter:2.13 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5-1.56 , private-registry/harbor-exporter:2.13.5-1.56 , private-registry/harbor-exporter:latest Container Release : 1.56 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - harbor213-exporter-2.13.5-150700.1.30 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.13.5-150700.1.30 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 07:34:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 09:34:11 +0200 (CEST) Subject: SUSE-CU-2026:9746-1: Security update of private-registry/harbor-jobservice Message-ID: <20260908073411.0B3B3FCC7@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9746-1 Container Tags : private-registry/harbor-jobservice:2.13 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5-1.56 , private-registry/harbor-jobservice:2.13.5-1.56 , private-registry/harbor-jobservice:latest Container Release : 1.56 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.13.5-150700.1.30 updated - harbor213-jobservice-2.13.5-150700.1.30 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:33:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:33:24 +0200 (CEST) Subject: SUSE-IU-2026:6849-1: Security update of suse/sle-micro/base-5.5 Message-ID: <20260908183324.D77CAFCCD@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6849-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.315 , suse/sle-micro/base-5.5:latest Image Release : 5.8.315 Severity : important Type : security References : 1224868 1267696 1268322 1273580 1276764 CVE-2026-10805 CVE-2026-16445 CVE-2026-19685 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4063-1 Released: Tue Sep 8 09:01:59 2026 Summary: Security update for NetworkManager Type: security Severity: important References: 1224868,1267696,1276764,CVE-2026-10805,CVE-2026-19685 This update for NetworkManager fixes the following issues: - CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). - CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). Changes for NetworkManager: - Add config-server subpackage (bsc#1224868). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4079-1 Released: Tue Sep 8 09:13:46 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). - CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: - Update to version 055+suse.408.g34171a9: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset The following package changes have been done: - dracut-055+suse.408.g34171a9-150500.3.47.1 updated - libnm0-1.38.6-150500.3.10.1 updated - NetworkManager-1.38.6-150500.3.10.1 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:37:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:37:04 +0200 (CEST) Subject: SUSE-IU-2026:6850-1: Security update of suse/sle-micro/kvm-5.5 Message-ID: <20260908183704.EF2BFFCCD@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/kvm-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6850-1 Image Tags : suse/sle-micro/kvm-5.5:2.0.4 , suse/sle-micro/kvm-5.5:2.0.4-3.5.607 , suse/sle-micro/kvm-5.5:latest Image Release : 3.5.607 Severity : important Type : security References : 1224868 1267696 1276764 CVE-2026-10805 CVE-2026-19685 ----------------------------------------------------------------- The container suse/sle-micro/kvm-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4063-1 Released: Tue Sep 8 09:01:59 2026 Summary: Security update for NetworkManager Type: security Severity: important References: 1224868,1267696,1276764,CVE-2026-10805,CVE-2026-19685 This update for NetworkManager fixes the following issues: - CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). - CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). Changes for NetworkManager: - Add config-server subpackage (bsc#1224868). The following package changes have been done: - libnm0-1.38.6-150500.3.10.1 updated - NetworkManager-1.38.6-150500.3.10.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.315 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:42:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:42:31 +0200 (CEST) Subject: SUSE-IU-2026:6851-1: Security update of suse/sle-micro/rt-5.5 Message-ID: <20260908184231.094A2FCCD@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6851-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.717 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.717 Severity : important Type : security References : 1224868 1267696 1276764 CVE-2026-10805 CVE-2026-19685 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4063-1 Released: Tue Sep 8 09:01:59 2026 Summary: Security update for NetworkManager Type: security Severity: important References: 1224868,1267696,1276764,CVE-2026-10805,CVE-2026-19685 This update for NetworkManager fixes the following issues: - CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). - CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). Changes for NetworkManager: - Add config-server subpackage (bsc#1224868). The following package changes have been done: - libnm0-1.38.6-150500.3.10.1 updated - NetworkManager-1.38.6-150500.3.10.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.109 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:46:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:46:39 +0200 (CEST) Subject: SUSE-IU-2026:6852-1: Security update of suse/sle-micro/5.5 Message-ID: <20260908184639.036B9FCC7@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6852-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.109 , suse/sle-micro/5.5:latest Image Release : 5.8.109 Severity : important Type : security References : 1224868 1267696 1268322 1273580 1276764 1277199 1277203 1277205 1277208 1277209 1277210 1277212 CVE-2026-10805 CVE-2026-16445 CVE-2026-19685 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4063-1 Released: Tue Sep 8 09:01:59 2026 Summary: Security update for NetworkManager Type: security Severity: important References: 1224868,1267696,1276764,CVE-2026-10805,CVE-2026-19685 This update for NetworkManager fixes the following issues: - CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). - CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). Changes for NetworkManager: - Add config-server subpackage (bsc#1224868). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4064-1 Released: Tue Sep 8 09:02:39 2026 Summary: Security update for multipath-tools Type: security Severity: moderate References: 1277199,1277203,1277205,1277208,1277209,1277210,1277212 This update for multipath-tools fixes the following issues: - Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). - Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). - SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). - Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). - Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). - DoS on multipathd socket by exhausting connections (bsc#1277203). - Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: - Update to version 0.9.4+153+suse.eec9ef1. - Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4079-1 Released: Tue Sep 8 09:13:46 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). - CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: - Update to version 055+suse.408.g34171a9: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset The following package changes have been done: - dracut-055+suse.408.g34171a9-150500.3.47.1 updated - libnm0-1.38.6-150500.3.10.1 updated - NetworkManager-1.38.6-150500.3.10.1 updated - kpartx-0.9.4+153+suse.eec9ef1-150500.3.15.1 updated - libmpath0-0.9.4+153+suse.eec9ef1-150500.3.15.1 updated - multipath-tools-0.9.4+153+suse.eec9ef1-150500.3.15.1 updated - NetworkManager-wwan-1.38.6-150500.3.10.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.315 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:53:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:53:17 +0200 (CEST) Subject: SUSE-CU-2026:9749-1: Security update of rancher/elemental-channel/sl-micro Message-ID: <20260908185317.1C500FCC7@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-channel/sl-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9749-1 Container Tags : rancher/elemental-channel/sl-micro:6.0-baremetal , rancher/elemental-channel/sl-micro:6.0-baremetal-15.1 Container Release : 15.1 Severity : moderate Type : security References : 1217586 1263656 1263658 1271544 1271545 1271547 1271548 CVE-2023-42366 CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-channel/sl-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 784 Released: Mon Jul 6 15:38:37 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: 875 Released: Wed Sep 2 11:40:31 2026 Summary: Security update for busybox Type: security Severity: moderate References: 1217586,1271544,1271545,1271547,1271548,CVE-2023-42366,CVE-2026-38752,CVE-2026-38753,CVE-2026-38754,CVE-2026-38755 This update for busybox fixes the following issues: - CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586). - CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544). - CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545). - CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547). - CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548). The following package changes have been done: - glibc-2.38-14.1 updated - busybox-1.36.1-5.1 updated - container:suse-toolbox-image-1.0.0-9.163 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:53:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:53:27 +0200 (CEST) Subject: SUSE-CU-2026:9750-1: Security update of rancher/elemental-channel/sl-micro Message-ID: <20260908185327.EC028FCC7@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-channel/sl-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9750-1 Container Tags : rancher/elemental-channel/sl-micro:6.0-base , rancher/elemental-channel/sl-micro:6.0-base-15.1 Container Release : 15.1 Severity : moderate Type : security References : 1217586 1263656 1263658 1271544 1271545 1271547 1271548 CVE-2023-42366 CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-channel/sl-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 784 Released: Mon Jul 6 15:38:37 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: 875 Released: Wed Sep 2 11:40:31 2026 Summary: Security update for busybox Type: security Severity: moderate References: 1217586,1271544,1271545,1271547,1271548,CVE-2023-42366,CVE-2026-38752,CVE-2026-38753,CVE-2026-38754,CVE-2026-38755 This update for busybox fixes the following issues: - CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586). - CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544). - CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545). - CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547). - CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548). The following package changes have been done: - glibc-2.38-14.1 updated - busybox-1.36.1-5.1 updated - container:suse-toolbox-image-1.0.0-9.163 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:53:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:53:39 +0200 (CEST) Subject: SUSE-CU-2026:9751-1: Security update of rancher/elemental-channel/sl-micro Message-ID: <20260908185339.8E190FCC7@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-channel/sl-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9751-1 Container Tags : rancher/elemental-channel/sl-micro:6.0-kvm , rancher/elemental-channel/sl-micro:6.0-kvm-15.1 Container Release : 15.1 Severity : moderate Type : security References : 1217586 1263656 1263658 1271544 1271545 1271547 1271548 CVE-2023-42366 CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-channel/sl-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 784 Released: Mon Jul 6 15:38:37 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: 875 Released: Wed Sep 2 11:40:31 2026 Summary: Security update for busybox Type: security Severity: moderate References: 1217586,1271544,1271545,1271547,1271548,CVE-2023-42366,CVE-2026-38752,CVE-2026-38753,CVE-2026-38754,CVE-2026-38755 This update for busybox fixes the following issues: - CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586). - CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544). - CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545). - CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547). - CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548). The following package changes have been done: - glibc-2.38-14.1 updated - busybox-1.36.1-5.1 updated - container:suse-toolbox-image-1.0.0-9.163 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:53:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:53:50 +0200 (CEST) Subject: SUSE-CU-2026:9752-1: Security update of rancher/elemental-channel/sl-micro Message-ID: <20260908185350.833BAFCC7@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-channel/sl-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9752-1 Container Tags : rancher/elemental-channel/sl-micro:6.0-rt , rancher/elemental-channel/sl-micro:6.0-rt-15.1 Container Release : 15.1 Severity : moderate Type : security References : 1217586 1263656 1263658 1271544 1271545 1271547 1271548 CVE-2023-42366 CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-channel/sl-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 784 Released: Mon Jul 6 15:38:37 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: 875 Released: Wed Sep 2 11:40:31 2026 Summary: Security update for busybox Type: security Severity: moderate References: 1217586,1271544,1271545,1271547,1271548,CVE-2023-42366,CVE-2026-38752,CVE-2026-38753,CVE-2026-38754,CVE-2026-38755 This update for busybox fixes the following issues: - CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586). - CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544). - CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545). - CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547). - CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548). The following package changes have been done: - glibc-2.38-14.1 updated - busybox-1.36.1-5.1 updated - container:suse-toolbox-image-1.0.0-9.163 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:54:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:54:00 +0200 (CEST) Subject: SUSE-CU-2026:9753-1: Security update of rancher/elemental-channel/sl-micro Message-ID: <20260908185400.3C28DFCC7@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-channel/sl-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9753-1 Container Tags : rancher/elemental-channel/sl-micro:6.1-baremetal , rancher/elemental-channel/sl-micro:6.1-baremetal-15.1 Container Release : 15.1 Severity : moderate Type : security References : 1240751 1252555 1258120 1258170 1258508 1263656 1263658 CVE-2025-12105 CVE-2025-32049 CVE-2026-2369 CVE-2026-2443 CVE-2026-2708 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-channel/sl-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 601 Released: Tue Jun 30 11:54:13 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1240751,1252555,1258120,1258170,1258508,1263656,1263658,CVE-2025-12105,CVE-2025-32049,CVE-2026-2369,CVE-2026-2443,CVE-2026-2708,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.38-slfo.1.1_9.1 updated - container:suse-toolbox-image-1.0.0-5.102 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:54:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:54:08 +0200 (CEST) Subject: SUSE-CU-2026:9754-1: Security update of rancher/elemental-channel/sl-micro Message-ID: <20260908185408.A7E26FCC7@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-channel/sl-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9754-1 Container Tags : rancher/elemental-channel/sl-micro:6.1-base , rancher/elemental-channel/sl-micro:6.1-base-15.1 Container Release : 15.1 Severity : moderate Type : security References : 1240751 1252555 1258120 1258170 1258508 1263656 1263658 CVE-2025-12105 CVE-2025-32049 CVE-2026-2369 CVE-2026-2443 CVE-2026-2708 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-channel/sl-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 601 Released: Tue Jun 30 11:54:13 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1240751,1252555,1258120,1258170,1258508,1263656,1263658,CVE-2025-12105,CVE-2025-32049,CVE-2026-2369,CVE-2026-2443,CVE-2026-2708,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.38-slfo.1.1_9.1 updated - container:suse-toolbox-image-1.0.0-5.102 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:54:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:54:19 +0200 (CEST) Subject: SUSE-CU-2026:9755-1: Security update of rancher/elemental-channel/sl-micro Message-ID: <20260908185419.2DB78FCC7@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-channel/sl-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9755-1 Container Tags : rancher/elemental-channel/sl-micro:6.1-kvm , rancher/elemental-channel/sl-micro:6.1-kvm-15.1 Container Release : 15.1 Severity : moderate Type : security References : 1240751 1252555 1258120 1258170 1258508 1263656 1263658 CVE-2025-12105 CVE-2025-32049 CVE-2026-2369 CVE-2026-2443 CVE-2026-2708 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-channel/sl-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 601 Released: Tue Jun 30 11:54:13 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1240751,1252555,1258120,1258170,1258508,1263656,1263658,CVE-2025-12105,CVE-2025-32049,CVE-2026-2369,CVE-2026-2443,CVE-2026-2708,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.38-slfo.1.1_9.1 updated - container:suse-toolbox-image-1.0.0-5.102 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:54:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:54:29 +0200 (CEST) Subject: SUSE-CU-2026:9756-1: Security update of rancher/elemental-channel/sl-micro Message-ID: <20260908185429.1E792FCC7@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-channel/sl-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9756-1 Container Tags : rancher/elemental-channel/sl-micro:6.1-rt , rancher/elemental-channel/sl-micro:6.1-rt-15.1 Container Release : 15.1 Severity : moderate Type : security References : 1240751 1252555 1258120 1258170 1258508 1263656 1263658 CVE-2025-12105 CVE-2025-32049 CVE-2026-2369 CVE-2026-2443 CVE-2026-2708 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-channel/sl-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 601 Released: Tue Jun 30 11:54:13 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1240751,1252555,1258120,1258170,1258508,1263656,1263658,CVE-2025-12105,CVE-2025-32049,CVE-2026-2369,CVE-2026-2443,CVE-2026-2708,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.38-slfo.1.1_9.1 updated - container:suse-toolbox-image-1.0.0-5.102 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:54:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:54:41 +0200 (CEST) Subject: SUSE-CU-2026:9757-1: Security update of rancher/elemental-channel/sl-micro Message-ID: <20260908185441.9C045FCC7@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-channel/sl-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9757-1 Container Tags : rancher/elemental-channel/sl-micro:6.2-baremetal , rancher/elemental-channel/sl-micro:6.2-baremetal-10.1 Container Release : 10.1 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-channel/sl-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1157 Released: Fri Jul 3 15:19:16 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.40-160000.6.1 updated - container:bci-bci-base-16.0-ad95af6d4b236fa9854b30fc156984456c83dc7dd51684e200844e721861f542-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:54:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:54:50 +0200 (CEST) Subject: SUSE-CU-2026:9758-1: Security update of rancher/elemental-channel/sl-micro Message-ID: <20260908185450.0300EFCE4@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-channel/sl-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9758-1 Container Tags : rancher/elemental-channel/sl-micro:6.2-base , rancher/elemental-channel/sl-micro:6.2-base-10.1 Container Release : 10.1 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-channel/sl-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1157 Released: Fri Jul 3 15:19:16 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.40-160000.6.1 updated - container:bci-bci-base-16.0-ad95af6d4b236fa9854b30fc156984456c83dc7dd51684e200844e721861f542-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:54:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:54:58 +0200 (CEST) Subject: SUSE-CU-2026:9759-1: Security update of rancher/elemental-channel/sl-micro Message-ID: <20260908185458.00B84FCC7@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-channel/sl-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9759-1 Container Tags : rancher/elemental-channel/sl-micro:6.2-kvm , rancher/elemental-channel/sl-micro:6.2-kvm-10.1 Container Release : 10.1 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-channel/sl-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1157 Released: Fri Jul 3 15:19:16 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.40-160000.6.1 updated - container:bci-bci-base-16.0-ad95af6d4b236fa9854b30fc156984456c83dc7dd51684e200844e721861f542-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:55:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:55:04 +0200 (CEST) Subject: SUSE-CU-2026:9760-1: Security update of rancher/elemental-channel/sl-micro Message-ID: <20260908185504.F3169FCE4@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-channel/sl-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9760-1 Container Tags : rancher/elemental-channel/sl-micro:6.2-rt , rancher/elemental-channel/sl-micro:6.2-rt-10.1 Container Release : 10.1 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-channel/sl-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1157 Released: Fri Jul 3 15:19:16 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.40-160000.6.1 updated - container:bci-bci-base-16.0-ad95af6d4b236fa9854b30fc156984456c83dc7dd51684e200844e721861f542-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:55:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:55:10 +0200 (CEST) Subject: SUSE-CU-2026:9761-1: Security update of rancher/elemental-operator Message-ID: <20260908185510.68D00FCC7@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-operator ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9761-1 Container Tags : rancher/elemental-operator:1.9.2 , rancher/elemental-operator:1.9.2-5.9 , rancher/elemental-operator:latest Container Release : 5.9 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-operator was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1157 Released: Fri Jul 3 15:19:16 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - elemental-operator1.9-1.9.2-160000.2.9 updated - glibc-2.40-160000.6.1 updated - container:bci-bci-base-16.0-ad95af6d4b236fa9854b30fc156984456c83dc7dd51684e200844e721861f542-0 updated From sle-container-updates at lists.suse.com Tue Sep 8 18:55:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:55:45 +0200 (CEST) Subject: SUSE-CU-2026:9762-1: Security update of rancher/elemental-operator Message-ID: <20260908185545.269C8FCC7@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-operator ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9762-1 Container Tags : rancher/elemental-operator:1.6.11 , rancher/elemental-operator:1.6.11-11.16 Container Release : 11.16 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-operator was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 784 Released: Mon Jul 6 15:38:37 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - compat-usrmerge-tools-84.87-3.1 updated - elemental-operator-1.6.11-1.1 updated - system-user-root-20190513-2.208 updated - filesystem-84.87-5.2 updated - glibc-2.38-14.1 updated - libtasn1-6-4.19.0-5.1 updated - libpcre2-8-0-10.42-2.179 updated - libgmp10-6.3.0-1.119 updated - libgcc_s1-13.3.0+git8781-2.1 added - libffi8-3.4.4-3.1 updated - libcap2-2.69-3.1 updated - libattr1-2.5.1-3.1 updated - libacl1-2.3.1-3.1 updated - libselinux1-3.5-3.1 updated - libstdc++6-13.3.0+git8781-2.1 added - libp11-kit0-0.25.3-1.6 updated - libncurses6-6.4.20240224-11.1 updated - terminfo-base-6.4.20240224-11.1 updated - p11-kit-0.25.3-1.6 updated - p11-kit-tools-0.25.3-1.6 updated - libreadline8-8.2-2.180 updated - bash-5.2.15-3.1 updated - bash-sh-5.2.15-3.1 updated - coreutils-9.4-5.1 updated - ca-certificates-2+git20230406.2dae8b7-3.1 updated - ca-certificates-mozilla-2.84-1.1 updated - container:suse-toolbox-image-1.0.0-9.163 added - container:bci-bci-base-16.0-805467666d108312e881b9628f4665193ecf336170d383c8c4781efce42503dc-0 removed From sle-container-updates at lists.suse.com Tue Sep 8 18:55:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:55:54 +0200 (CEST) Subject: SUSE-CU-2026:9764-1: Security update of rancher/elemental-operator Message-ID: <20260908185554.1BDC6FCE4@maintenance.suse.de> SUSE Container Update Advisory: rancher/elemental-operator ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9764-1 Container Tags : rancher/elemental-operator:1.8.2 , rancher/elemental-operator:1.8.2-6.9 Container Release : 6.9 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/elemental-operator was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1157 Released: Fri Jul 3 15:19:16 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - compat-usrmerge-tools-84.87-160000.2.2 updated - elemental-operator-1.8.2-160000.2.9 updated - system-user-root-20190513-160000.2.2 updated - filesystem-84.87-160000.2.2 updated - glibc-2.40-160000.6.1 updated - terminfo-base-6.5.20250531-160000.3.1 updated - libncurses6-6.5.20250531-160000.3.1 updated - libtasn1-6-4.21.0-160000.1.1 updated - libpcre2-8-0-10.45-160000.3.1 updated - libgmp10-6.3.0-160000.2.2 updated - libffi8-3.4.6-160000.2.2 updated - libcap2-2.73-160000.3.1 updated - libattr1-2.5.2-160000.2.2 updated - libacl1-2.3.2-160000.2.2 updated - libreadline8-8.2.13-160000.2.2 updated - libselinux1-3.8.1-160000.4.1 updated - libp11-kit0-0.25.5-160000.2.2 updated - bash-5.2.37-160000.2.2 updated - bash-sh-5.2.37-160000.2.2 updated - p11-kit-0.25.5-160000.2.2 updated - p11-kit-tools-0.25.5-160000.2.2 updated - coreutils-9.6-160000.2.2 updated - ca-certificates-2+git20240805.fd24d50-160000.2.2 updated - ca-certificates-mozilla-2.84-160000.1.1 updated - container:bci-bci-base-16.0-ad95af6d4b236fa9854b30fc156984456c83dc7dd51684e200844e721861f542-0 added - container:suse-toolbox-image-1.0.0-5.102 removed - libgcc_s1-14.3.0+git11799-slfo.1.1_1.1 removed - libstdc++6-14.3.0+git11799-slfo.1.1_1.1 removed From sle-container-updates at lists.suse.com Tue Sep 8 18:56:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 8 Sep 2026 20:56:41 +0200 (CEST) Subject: SUSE-CU-2026:9766-1: Security update of rancher/seedimage-builder Message-ID: <20260908185641.5B7BBFCC7@maintenance.suse.de> SUSE Container Update Advisory: rancher/seedimage-builder ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9766-1 Container Tags : rancher/seedimage-builder:1.6.11 , rancher/seedimage-builder:1.6.11-11.22 Container Release : 11.22 Severity : important Type : security References : 1259798 1260563 1260908 1261630 1261845 1263656 1263658 1264096 1265224 1265384 1271045 1271980 CVE-2025-28162 CVE-2025-54518 CVE-2025-64505 CVE-2025-64506 CVE-2025-64720 CVE-2025-65018 CVE-2025-66293 CVE-2026-22695 CVE-2026-22801 CVE-2026-23243 CVE-2026-23274 CVE-2026-23317 CVE-2026-23437 CVE-2026-25646 CVE-2026-31406 CVE-2026-33416 CVE-2026-33636 CVE-2026-34757 CVE-2026-46300 CVE-2026-46333 CVE-2026-50811 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/seedimage-builder was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 810 Released: Wed May 27 18:45:13 2026 Summary: Optional update for xfig Type: optional Severity: moderate References: 1271045,CVE-2026-50811 This update for xfig fixes the following issue: - Remove dependency on update-desktop-files (jsc#PED-15248): ----------------------------------------------------------------- Advisory ID: 841 Released: Mon Jun 1 11:46:34 2026 Summary: Security update for the Linux Kernel RT (Live Patch 0 for SUSE Linux Enterprise 16) Type: security Severity: important References: 1259798,1260563,1260908,1264096,1265224,1265384,CVE-2025-28162,CVE-2025-54518,CVE-2025-64505,CVE-2025-64506,CVE-2025-64720,CVE-2025-65018,CVE-2025-66293,CVE-2026-22695,CVE-2026-22801,CVE-2026-23243,CVE-2026-23274,CVE-2026-23317,CVE-2026-25646,CVE-2026-33416,CVE-2026-33636,CVE-2026-34757,CVE-2026-46300,CVE-2026-46333 This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.5.1 fixes various security issues The following security issues were fixed: - CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). - CVE-2026-23243: RDMA/umad: Reject negative data_len in ib_umad_write (bsc#1259798). - CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (bsc#1260908). - CVE-2026-23317: drm/vmwgfx: Return the correct value in vmw_translate_ptr functions (bsc#1260563). - CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). - CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). ----------------------------------------------------------------- Advisory ID: 843 Released: Mon Jun 1 13:24:31 2026 Summary: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise 16) Type: security Severity: important References: 1261630,1261845,1271980,CVE-2026-23437,CVE-2026-31406 This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.32.1 fixes various security issues The following security issues were fixed: - CVE-2026-23437: net: shaper: protect late read accesses to the hierarchy (bsc#1261845). - CVE-2026-31406: xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini() (bsc#1261630). ----------------------------------------------------------------- Advisory ID: 784 Released: Mon Jul 6 15:38:37 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - boost-license1_84_0-1.84.0-1.4 added - btrfsprogs-udev-rules-6.1.3-6.19 updated - compat-usrmerge-tools-84.87-3.1 updated - crypto-policies-20230920.570ea89-2.1 updated - elemental-httpfy-1.6.11-1.1 updated - elemental-seedimage-hooks-1.6.11-1.1 updated - file-magic-5.44-4.151 updated - kbd-legacy-2.6.4-1.3 added - libsemanage-conf-3.5-3.1 updated - pkgconf-m4-1.8.0-2.205 updated - system-user-root-20190513-2.208 updated - filesystem-84.87-5.2 updated - glibc-2.38-14.1 updated - libzstd1-1.5.5-8.142 updated - libz1-1.2.13-7.1 updated - libxxhash0-0.8.1-2.194 updated - libuuid1-2.39.3-8.1 updated - liburcu8-0.14.0-2.8 updated - libunistring5-1.1-3.1 updated - libtextstyle0-0.21.1-6.1 updated - libtasn1-6-4.19.0-5.1 updated - libsmartcols1-2.39.3-8.1 updated - libsepol2-3.5-3.1 updated - libseccomp2-2.5.4-3.1 updated - libpopt0-1.19-2.184 updated - libpkgconf3-1.8.0-2.205 added - libpcre2-8-0-10.42-2.179 updated - libparted-fs-resize0-3.5-2.11 updated - libnss_usrfiles2-2.27-3.1 updated - libnghttp2-14-1.52.0-7.1 updated - liblzo2-2-2.10-3.1 updated - liblzma5-5.4.3-6.1 updated - liblz4-1-1.9.4-4.1 updated - liblua5_4-5-5.4.6-1.68 updated - libjson-c5-0.16-3.1 updated - libjitterentropy3-3.4.1-3.1 updated - libip4tc2-1.8.9-4.1 added - libgpg-error0-1.47-4.136 updated - libgmp10-6.3.0-1.119 updated - libgcc_s1-13.3.0+git8781-2.1 updated - libfuse2-2.9.9-3.1 added - libffi8-3.4.4-3.1 updated - libexpat1-2.7.1-5.1 updated - libeconf0-0.6.1-1.13 updated - libcrypt1-4.4.36-1.134 updated - libcom_err2-1.47.0-3.1 updated - libcap2-2.69-3.1 updated - libcap-ng0-0.8.3-4.1 updated - libbz2-1-1.0.8-4.1 updated - libburn4-1.5.4-1.9 updated - libbtrfsutil1-6.1.3-6.19 updated - libbtrfs0-6.1.3-6.19 updated - libbrotlicommon1-1.1.0-1.6 updated - libblkid1-2.39.3-8.1 updated - libaudit1-3.0.9-4.1 updated - libattr1-2.5.1-3.1 updated - libargon2-1-20190702-3.1 added - libalternatives1-1.2+30.a5431e9-3.1 updated - libaio1-0.3.113-3.1 updated - libacl1-2.3.1-3.1 updated - fillup-1.42-3.1 updated - dosfstools-4.2-2.9 updated - diffutils-3.10-2.101 updated - libpng16-16-1.6.58-1.1 updated - libidn2-0-2.3.4-3.1 updated - pkgconf-1.8.0-2.205 updated - libselinux1-3.5-3.1 updated - netcfg-11.6-4.42 updated - libxml2-2-2.11.6-13.1 updated - squashfs-4.6.1-3.7 updated - libgcrypt20-1.10.3-4.1 updated - libstdc++6-13.3.0+git8781-2.1 updated - libp11-kit0-0.25.3-1.6 updated - perl-base-5.38.2-5.1 updated - libext2fs2-1.47.0-3.1 updated - libudev1-254.27-4.1 updated - chkstat-1600_20240206-1.8 added - libzio1-1.08-3.1 updated - libmagic1-5.44-4.151 updated - libjte2-1.22-1.8 updated - libbrotlidec1-1.1.0-1.6 updated - libfdisk1-2.39.3-8.1 updated - alts-1.2+30.a5431e9-3.1 updated - libpsl5-0.21.2-3.1 updated - sed-4.9-3.1 updated - libsubid4-4.15.1-1.1 added - libsemanage2-3.5-3.1 updated - libmount1-2.39.3-8.1 updated - findutils-4.9.0-4.1 updated - libsystemd0-254.27-4.1 updated - libncurses6-6.4.20240224-11.1 updated - terminfo-base-6.4.20240224-11.1 updated - libinih0-56-3.1 updated - libboost_thread1_84_0-1.84.0-1.4 added - p11-kit-0.25.3-1.6 updated - p11-kit-tools-0.25.3-1.6 updated - libisofs6-1.5.4-1.9 updated - libfreetype6-2.14.3-1.1 updated - ncurses-utils-6.4.20240224-11.1 updated - libreadline8-8.2-2.180 updated - libedit0-20210910.3.1-9.169 updated - gptfdisk-1.0.9-4.1 updated - libisoburn1-1.5.4-1.9 updated - bash-5.2.15-3.1 updated - bash-sh-5.2.15-3.1 updated - xz-5.4.3-6.1 updated - systemd-default-settings-branding-openSUSE-0.7-2.4 added - systemd-default-settings-0.7-2.4 added - pkgconf-pkg-config-1.8.0-2.205 updated - login_defs-4.15.1-1.1 updated - libdevmapper1_03-2.03.22_1.02.196-1.8 updated - gzip-1.13-3.1 updated - grep-3.11-4.8 updated - gettext-runtime-0.21.1-6.1 updated - coreutils-9.4-5.1 updated - ALP-dummy-release-0.1-8.67 updated - libparted2-3.5-2.11 updated - libdevmapper-event1_03-2.03.22_1.02.196-1.8 updated - info-7.0.3-4.1 updated - xfsprogs-6.5.0-1.9 updated - thin-provisioning-tools-0.9.0-2.10 updated - systemd-rpm-macros-24-1.205 updated - systemd-presets-common-SUSE-15-5.1 updated - rpm-config-SUSE-20240214-1.1 updated - rpm-4.18.0-8.1 updated - permissions-config-1600_20240206-1.8 updated - glibc-locale-base-2.38-14.1 updated - e2fsprogs-1.47.0-3.1 updated - ca-certificates-2+git20230406.2dae8b7-3.1 updated - ca-certificates-mozilla-2.84-1.1 updated - btrfsprogs-6.1.3-6.19 updated - parted-3.5-2.11 updated - liblvm2cmd2_03-2.03.22-1.8 updated - xorriso-1.5.4-1.9 updated - device-mapper-2.03.22_1.02.196-1.8 updated - systemd-presets-branding-ALP-transactional-20230214-3.1 added - permissions-1600_20240206-1.8 updated - mtools-4.0.43-4.9 updated - libopenssl3-3.1.4-17.1 updated - pam-1.6.0-6.1 updated - grub2-2.12~rc1-9.1 updated - grub2-i386-pc-2.12~rc1-9.1 updated - suse-module-tools-16.0.43-1.1 updated - kmod-30-12.1 updated - rsync-3.2.7-8.1 updated - libkmod2-30-12.1 updated - libcurl-mini4-8.14.1-8.1 added - libcryptsetup12-2.6.1-5.1 updated - util-linux-2.39.3-8.1 updated - shadow-4.15.1-1.1 updated - pam-config-2.11-2.1 updated - kbd-2.6.4-1.3 updated - curl-8.14.1-8.1 updated - libsnapper7-0.10.5-2.10 updated - aaa_base-84.87+git20240906.742565b-1.1 updated - dbus-1-daemon-1.14.10-1.11 added - dbus-1-tools-1.14.10-1.11 updated - systemd-254.27-4.1 updated - sysuser-shadow-3.1-2.197 updated - dbus-1-common-1.14.10-1.11 updated - libdbus-1-3-1.14.10-1.11 updated - dbus-1-1.14.10-1.11 updated - system-group-kvm-20170617-2.197 updated - system-group-hardware-20170617-2.197 updated - udev-254.27-4.1 updated - snapper-0.10.5-2.10 updated - lvm2-2.03.22-1.8 updated - elemental-toolkit-2.1.6-1.1 updated - container:suse-toolbox-image-1.0.0-9.163 added - boost-license1_86_0-1.86.0-160000.2.2 removed - container:bci-bci-base-16.0-805467666d108312e881b9628f4665193ecf336170d383c8c4781efce42503dc-0 removed - cpio-2.15-160000.2.2 removed - dbus-broker-36-160000.3.1 removed - dbus-broker-block-restart-36-160000.3.1 removed - dracut-059+suse.722.gdd9d67ff5-160000.1.1 removed - elfutils-0.192-160000.3.1 removed - envsubst-0.22.5-160000.2.2 removed - file-5.46-160000.2.2 removed - gawk-5.3.2-160000.2.2 removed - glibc-gconv-modules-extra-2.40-160000.5.1 removed - grub2-common-2.12-160000.6.1 removed - krb5-1.21.3-160000.3.1 removed - libasm1-0.192-160000.3.1 removed - libboost_thread1_86_0-1.86.0-160000.2.2 removed - libcurl4-8.14.1-160000.7.1 removed - libdw1-0.192-160000.3.1 removed - libelf1-0.192-160000.3.1 removed - libfuse3-3-3.16.2-160000.2.2 removed - libkbdfile1-2.7.1-160000.2.2 removed - libkeymap1-2.7.1-160000.2.2 removed - libkeyutils1-1.6.3-160000.3.2 removed - libkfont0-2.7.1-160000.2.2 removed - liblastlog2-2-2.41.1-160000.4.1 removed - libldap-2-2.6.10+10-160000.3.1 removed - libldap-data-2.6.10+10-160000.3.1 removed - liblz1-1.15-160000.2.2 removed - libmpdec4-4.0.1-160000.2.2 removed - libmpfr6-4.2.1-160000.2.2 removed - libpkgconf5-2.2.0-160000.2.2 removed - libpython3_13-1_0-3.13.13-160000.1.1 removed - libsasl2-3-2.1.28-160000.3.1 removed - libsqlite3-0-3.53.2-160000.1.1 removed - libssh-config-0.11.4-160000.1.1 removed - libssh4-0.11.4-160000.1.1 removed - libsubid5-4.17.2-160000.2.2 removed - libverto1-0.3.2-160000.2.2 removed - pam-extra-1.7.1-160000.4.1 removed - permctl-1699_20250120-160000.2.2 removed - pigz-2.8-160000.2.2 removed - python313-base-3.13.13-160000.1.1 removed - system-user-lp-20170617-160000.2.2 removed - systemd-default-settings-branding-upstream-0.10-160000.2.2 removed - systemd-presets-branding-SLE-15.1-160000.4.1 removed - util-linux-systemd-2.41.1-160000.4.1 removed - zstd-1.5.7-160000.2.2 removed From sle-container-updates at lists.suse.com Wed Sep 9 07:07:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:07:43 +0200 (CEST) Subject: SUSE-CU-2026:9766-1: Security update of rancher/seedimage-builder Message-ID: <20260909070743.941C5FF19@maintenance.suse.de> SUSE Container Update Advisory: rancher/seedimage-builder ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9766-1 Container Tags : rancher/seedimage-builder:1.6.11 , rancher/seedimage-builder:1.6.11-11.22 Container Release : 11.22 Severity : important Type : security References : 1259798 1260563 1260908 1261630 1261845 1263656 1263658 1264096 1265224 1265384 1271045 1271980 CVE-2025-28162 CVE-2025-54518 CVE-2025-64505 CVE-2025-64506 CVE-2025-64720 CVE-2025-65018 CVE-2025-66293 CVE-2026-22695 CVE-2026-22801 CVE-2026-23243 CVE-2026-23274 CVE-2026-23317 CVE-2026-23437 CVE-2026-25646 CVE-2026-31406 CVE-2026-33416 CVE-2026-33636 CVE-2026-34757 CVE-2026-46300 CVE-2026-46333 CVE-2026-50811 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container rancher/seedimage-builder was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 810 Released: Wed May 27 18:45:13 2026 Summary: Optional update for xfig Type: optional Severity: moderate References: 1271045,CVE-2026-50811 This update for xfig fixes the following issue: - Remove dependency on update-desktop-files (jsc#PED-15248): ----------------------------------------------------------------- Advisory ID: 841 Released: Mon Jun 1 11:46:34 2026 Summary: Security update for the Linux Kernel RT (Live Patch 0 for SUSE Linux Enterprise 16) Type: security Severity: important References: 1259798,1260563,1260908,1264096,1265224,1265384,CVE-2025-28162,CVE-2025-54518,CVE-2025-64505,CVE-2025-64506,CVE-2025-64720,CVE-2025-65018,CVE-2025-66293,CVE-2026-22695,CVE-2026-22801,CVE-2026-23243,CVE-2026-23274,CVE-2026-23317,CVE-2026-25646,CVE-2026-33416,CVE-2026-33636,CVE-2026-34757,CVE-2026-46300,CVE-2026-46333 This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.5.1 fixes various security issues The following security issues were fixed: - CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). - CVE-2026-23243: RDMA/umad: Reject negative data_len in ib_umad_write (bsc#1259798). - CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (bsc#1260908). - CVE-2026-23317: drm/vmwgfx: Return the correct value in vmw_translate_ptr functions (bsc#1260563). - CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). - CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). ----------------------------------------------------------------- Advisory ID: 843 Released: Mon Jun 1 13:24:31 2026 Summary: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise 16) Type: security Severity: important References: 1261630,1261845,1271980,CVE-2026-23437,CVE-2026-31406 This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.32.1 fixes various security issues The following security issues were fixed: - CVE-2026-23437: net: shaper: protect late read accesses to the hierarchy (bsc#1261845). - CVE-2026-31406: xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini() (bsc#1261630). ----------------------------------------------------------------- Advisory ID: 784 Released: Mon Jul 6 15:38:37 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - boost-license1_84_0-1.84.0-1.4 added - btrfsprogs-udev-rules-6.1.3-6.19 updated - compat-usrmerge-tools-84.87-3.1 updated - crypto-policies-20230920.570ea89-2.1 updated - elemental-httpfy-1.6.11-1.1 updated - elemental-seedimage-hooks-1.6.11-1.1 updated - file-magic-5.44-4.151 updated - kbd-legacy-2.6.4-1.3 added - libsemanage-conf-3.5-3.1 updated - pkgconf-m4-1.8.0-2.205 updated - system-user-root-20190513-2.208 updated - filesystem-84.87-5.2 updated - glibc-2.38-14.1 updated - libzstd1-1.5.5-8.142 updated - libz1-1.2.13-7.1 updated - libxxhash0-0.8.1-2.194 updated - libuuid1-2.39.3-8.1 updated - liburcu8-0.14.0-2.8 updated - libunistring5-1.1-3.1 updated - libtextstyle0-0.21.1-6.1 updated - libtasn1-6-4.19.0-5.1 updated - libsmartcols1-2.39.3-8.1 updated - libsepol2-3.5-3.1 updated - libseccomp2-2.5.4-3.1 updated - libpopt0-1.19-2.184 updated - libpkgconf3-1.8.0-2.205 added - libpcre2-8-0-10.42-2.179 updated - libparted-fs-resize0-3.5-2.11 updated - libnss_usrfiles2-2.27-3.1 updated - libnghttp2-14-1.52.0-7.1 updated - liblzo2-2-2.10-3.1 updated - liblzma5-5.4.3-6.1 updated - liblz4-1-1.9.4-4.1 updated - liblua5_4-5-5.4.6-1.68 updated - libjson-c5-0.16-3.1 updated - libjitterentropy3-3.4.1-3.1 updated - libip4tc2-1.8.9-4.1 added - libgpg-error0-1.47-4.136 updated - libgmp10-6.3.0-1.119 updated - libgcc_s1-13.3.0+git8781-2.1 updated - libfuse2-2.9.9-3.1 added - libffi8-3.4.4-3.1 updated - libexpat1-2.7.1-5.1 updated - libeconf0-0.6.1-1.13 updated - libcrypt1-4.4.36-1.134 updated - libcom_err2-1.47.0-3.1 updated - libcap2-2.69-3.1 updated - libcap-ng0-0.8.3-4.1 updated - libbz2-1-1.0.8-4.1 updated - libburn4-1.5.4-1.9 updated - libbtrfsutil1-6.1.3-6.19 updated - libbtrfs0-6.1.3-6.19 updated - libbrotlicommon1-1.1.0-1.6 updated - libblkid1-2.39.3-8.1 updated - libaudit1-3.0.9-4.1 updated - libattr1-2.5.1-3.1 updated - libargon2-1-20190702-3.1 added - libalternatives1-1.2+30.a5431e9-3.1 updated - libaio1-0.3.113-3.1 updated - libacl1-2.3.1-3.1 updated - fillup-1.42-3.1 updated - dosfstools-4.2-2.9 updated - diffutils-3.10-2.101 updated - libpng16-16-1.6.58-1.1 updated - libidn2-0-2.3.4-3.1 updated - pkgconf-1.8.0-2.205 updated - libselinux1-3.5-3.1 updated - netcfg-11.6-4.42 updated - libxml2-2-2.11.6-13.1 updated - squashfs-4.6.1-3.7 updated - libgcrypt20-1.10.3-4.1 updated - libstdc++6-13.3.0+git8781-2.1 updated - libp11-kit0-0.25.3-1.6 updated - perl-base-5.38.2-5.1 updated - libext2fs2-1.47.0-3.1 updated - libudev1-254.27-4.1 updated - chkstat-1600_20240206-1.8 added - libzio1-1.08-3.1 updated - libmagic1-5.44-4.151 updated - libjte2-1.22-1.8 updated - libbrotlidec1-1.1.0-1.6 updated - libfdisk1-2.39.3-8.1 updated - alts-1.2+30.a5431e9-3.1 updated - libpsl5-0.21.2-3.1 updated - sed-4.9-3.1 updated - libsubid4-4.15.1-1.1 added - libsemanage2-3.5-3.1 updated - libmount1-2.39.3-8.1 updated - findutils-4.9.0-4.1 updated - libsystemd0-254.27-4.1 updated - libncurses6-6.4.20240224-11.1 updated - terminfo-base-6.4.20240224-11.1 updated - libinih0-56-3.1 updated - libboost_thread1_84_0-1.84.0-1.4 added - p11-kit-0.25.3-1.6 updated - p11-kit-tools-0.25.3-1.6 updated - libisofs6-1.5.4-1.9 updated - libfreetype6-2.14.3-1.1 updated - ncurses-utils-6.4.20240224-11.1 updated - libreadline8-8.2-2.180 updated - libedit0-20210910.3.1-9.169 updated - gptfdisk-1.0.9-4.1 updated - libisoburn1-1.5.4-1.9 updated - bash-5.2.15-3.1 updated - bash-sh-5.2.15-3.1 updated - xz-5.4.3-6.1 updated - systemd-default-settings-branding-openSUSE-0.7-2.4 added - systemd-default-settings-0.7-2.4 added - pkgconf-pkg-config-1.8.0-2.205 updated - login_defs-4.15.1-1.1 updated - libdevmapper1_03-2.03.22_1.02.196-1.8 updated - gzip-1.13-3.1 updated - grep-3.11-4.8 updated - gettext-runtime-0.21.1-6.1 updated - coreutils-9.4-5.1 updated - ALP-dummy-release-0.1-8.67 updated - libparted2-3.5-2.11 updated - libdevmapper-event1_03-2.03.22_1.02.196-1.8 updated - info-7.0.3-4.1 updated - xfsprogs-6.5.0-1.9 updated - thin-provisioning-tools-0.9.0-2.10 updated - systemd-rpm-macros-24-1.205 updated - systemd-presets-common-SUSE-15-5.1 updated - rpm-config-SUSE-20240214-1.1 updated - rpm-4.18.0-8.1 updated - permissions-config-1600_20240206-1.8 updated - glibc-locale-base-2.38-14.1 updated - e2fsprogs-1.47.0-3.1 updated - ca-certificates-2+git20230406.2dae8b7-3.1 updated - ca-certificates-mozilla-2.84-1.1 updated - btrfsprogs-6.1.3-6.19 updated - parted-3.5-2.11 updated - liblvm2cmd2_03-2.03.22-1.8 updated - xorriso-1.5.4-1.9 updated - device-mapper-2.03.22_1.02.196-1.8 updated - systemd-presets-branding-ALP-transactional-20230214-3.1 added - permissions-1600_20240206-1.8 updated - mtools-4.0.43-4.9 updated - libopenssl3-3.1.4-17.1 updated - pam-1.6.0-6.1 updated - grub2-2.12~rc1-9.1 updated - grub2-i386-pc-2.12~rc1-9.1 updated - suse-module-tools-16.0.43-1.1 updated - kmod-30-12.1 updated - rsync-3.2.7-8.1 updated - libkmod2-30-12.1 updated - libcurl-mini4-8.14.1-8.1 added - libcryptsetup12-2.6.1-5.1 updated - util-linux-2.39.3-8.1 updated - shadow-4.15.1-1.1 updated - pam-config-2.11-2.1 updated - kbd-2.6.4-1.3 updated - curl-8.14.1-8.1 updated - libsnapper7-0.10.5-2.10 updated - aaa_base-84.87+git20240906.742565b-1.1 updated - dbus-1-daemon-1.14.10-1.11 added - dbus-1-tools-1.14.10-1.11 updated - systemd-254.27-4.1 updated - sysuser-shadow-3.1-2.197 updated - dbus-1-common-1.14.10-1.11 updated - libdbus-1-3-1.14.10-1.11 updated - dbus-1-1.14.10-1.11 updated - system-group-kvm-20170617-2.197 updated - system-group-hardware-20170617-2.197 updated - udev-254.27-4.1 updated - snapper-0.10.5-2.10 updated - lvm2-2.03.22-1.8 updated - elemental-toolkit-2.1.6-1.1 updated - container:suse-toolbox-image-1.0.0-9.163 added - boost-license1_86_0-1.86.0-160000.2.2 removed - container:bci-bci-base-16.0-805467666d108312e881b9628f4665193ecf336170d383c8c4781efce42503dc-0 removed - cpio-2.15-160000.2.2 removed - dbus-broker-36-160000.3.1 removed - dbus-broker-block-restart-36-160000.3.1 removed - dracut-059+suse.722.gdd9d67ff5-160000.1.1 removed - elfutils-0.192-160000.3.1 removed - envsubst-0.22.5-160000.2.2 removed - file-5.46-160000.2.2 removed - gawk-5.3.2-160000.2.2 removed - glibc-gconv-modules-extra-2.40-160000.5.1 removed - grub2-common-2.12-160000.6.1 removed - krb5-1.21.3-160000.3.1 removed - libasm1-0.192-160000.3.1 removed - libboost_thread1_86_0-1.86.0-160000.2.2 removed - libcurl4-8.14.1-160000.7.1 removed - libdw1-0.192-160000.3.1 removed - libelf1-0.192-160000.3.1 removed - libfuse3-3-3.16.2-160000.2.2 removed - libkbdfile1-2.7.1-160000.2.2 removed - libkeymap1-2.7.1-160000.2.2 removed - libkeyutils1-1.6.3-160000.3.2 removed - libkfont0-2.7.1-160000.2.2 removed - liblastlog2-2-2.41.1-160000.4.1 removed - libldap-2-2.6.10+10-160000.3.1 removed - libldap-data-2.6.10+10-160000.3.1 removed - liblz1-1.15-160000.2.2 removed - libmpdec4-4.0.1-160000.2.2 removed - libmpfr6-4.2.1-160000.2.2 removed - libpkgconf5-2.2.0-160000.2.2 removed - libpython3_13-1_0-3.13.13-160000.1.1 removed - libsasl2-3-2.1.28-160000.3.1 removed - libsqlite3-0-3.53.2-160000.1.1 removed - libssh-config-0.11.4-160000.1.1 removed - libssh4-0.11.4-160000.1.1 removed - libsubid5-4.17.2-160000.2.2 removed - libverto1-0.3.2-160000.2.2 removed - pam-extra-1.7.1-160000.4.1 removed - permctl-1699_20250120-160000.2.2 removed - pigz-2.8-160000.2.2 removed - python313-base-3.13.13-160000.1.1 removed - system-user-lp-20170617-160000.2.2 removed - systemd-default-settings-branding-upstream-0.10-160000.2.2 removed - systemd-presets-branding-SLE-15.1-160000.4.1 removed - util-linux-systemd-2.41.1-160000.4.1 removed - zstd-1.5.7-160000.2.2 removed From sle-container-updates at lists.suse.com Wed Sep 9 07:07:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:07:48 +0200 (CEST) Subject: SUSE-CU-2026:9767-1: Security update of rancher/seedimage-builder Message-ID: <20260909070748.5887FFF1F@maintenance.suse.de> SUSE Container Update Advisory: rancher/seedimage-builder ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9767-1 Container Tags : rancher/seedimage-builder:1.7.5 , rancher/seedimage-builder:1.7.5-6.20 Container Release : 6.20 Severity : important Type : security References : 1252752 1262225 1262226 1262227 1262228 1262232 1271045 CVE-2025-14813 CVE-2025-62725 CVE-2026-0636 CVE-2026-3505 CVE-2026-50811 CVE-2026-5588 CVE-2026-5598 ----------------------------------------------------------------- The container rancher/seedimage-builder was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 643 Released: Fri Apr 24 17:29:58 2026 Summary: Security update for bouncycastle Type: security Severity: important References: 1252752,1262225,1262226,1262227,1262228,1262232,1271045,CVE-2025-14813,CVE-2025-62725,CVE-2026-0636,CVE-2026-3505,CVE-2026-50811,CVE-2026-5588,CVE-2026-5598 This update for bouncycastle fixes the following issues: - Update to version 1.84: - CVE-2025-14813: GOSTCTR implementation unable to process more than 255 blocks correctly (bsc#1262225). - CVE-2026-0636: LDAP Injection Vulnerability in LDAPStoreHelper.java (bsc#1262226). - CVE-2026-3505: Unbounded PGP AEAD chunk size leads to pre-auth resource exhaustion (bsc#1262232). - CVE-2026-5588: PKIX draft CompositeVerifier accepts empty signature sequence as valid (bsc#1262228). - CVE-2026-5598: Non-constant time comparisons risk private key leakage in FrodoKEM (bsc#1262227). The following package changes have been done: - boost-license1_84_0-1.84.0-slfo.1.1_1.4 updated - btrfsprogs-udev-rules-6.8.1-slfo.1.1_1.2 updated - compat-usrmerge-tools-84.87-slfo.1.1_1.5 updated - crypto-policies-20230920.570ea89-slfo.1.1_2.1 updated - elemental-httpfy-1.7.5-slfo.1.1_1.1 updated - elemental-seedimage-hooks-1.7.5-slfo.1.1_1.1 updated - libsemanage-conf-3.5-slfo.1.1_1.3 updated - libssh-config-0.10.6-slfo.1.1_6.1 added - pkgconf-m4-1.8.0-slfo.1.1_1.5 updated - system-user-root-20190513-slfo.1.1_1.2 updated - filesystem-84.87-slfo.1.1_1.2 updated - glibc-2.38-slfo.1.1_9.1 updated - libzstd1-1.5.5-slfo.1.1_1.4 updated - libz1-1.2.13-slfo.1.1_2.1 updated - libxxhash0-0.8.1-slfo.1.1_2.1 updated - libverto1-0.3.2-slfo.1.1_1.2 added - libuuid1-2.40.4-slfo.1.1_7.1 updated - liburcu8-0.14.0-slfo.1.1_1.3 updated - libunistring5-1.1-slfo.1.1_1.2 updated - libtextstyle0-0.21.1-slfo.1.1_2.1 updated - libtasn1-6-4.19.0-slfo.1.1_3.1 updated - libsmartcols1-2.40.4-slfo.1.1_7.1 updated - libsepol2-3.5-slfo.1.1_1.3 updated - libseccomp2-2.5.4-slfo.1.1_1.4 updated - libsasl2-3-2.1.28-slfo.1.1_1.2 added - libpopt0-1.19-slfo.1.1_1.3 updated - libpkgconf3-1.8.0-slfo.1.1_1.5 updated - libpcre2-8-0-10.42-slfo.1.1_1.4 updated - libparted-fs-resize0-3.5-slfo.1.1_1.2 updated - libnss_usrfiles2-2.27-slfo.1.1_1.3 updated - libnghttp2-14-1.52.0-slfo.1.1_3.1 updated - liblzo2-2-2.10-slfo.1.1_1.3 updated - liblzma5-5.4.3-slfo.1.1_3.1 updated - liblz4-1-1.9.4-slfo.1.1_1.2 updated - liblua5_4-5-5.4.6-slfo.1.1_1.3 updated - libkeyutils1-1.6.3-slfo.1.1_1.3 added - libjson-c5-0.16-slfo.1.1_1.2 updated - libjitterentropy3-3.4.1-slfo.1.1_1.3 updated - libip4tc2-1.8.9-slfo.1.1_2.1 updated - libgpg-error0-1.47-slfo.1.1_1.3 updated - libgmp10-6.3.0-slfo.1.1_1.5 updated - libgcc_s1-14.3.0+git11799-slfo.1.1_1.1 updated - libfuse2-2.9.9-slfo.1.1_1.2 updated - libffi8-3.4.6-slfo.1.1_1.4 updated - libexpat1-2.7.1-slfo.1.1_5.1 updated - libeconf0-0.7.2-slfo.1.1_1.3 updated - libcrypt1-4.4.36-slfo.1.1_1.4 updated - libcom_err2-1.47.0-slfo.1.1_1.2 updated - libcap2-2.69-slfo.1.1_2.1 updated - libcap-ng0-0.8.3-slfo.1.1_1.4 updated - libbz2-1-1.0.8-slfo.1.1_2.1 updated - libburn4-1.5.4-slfo.1.1_1.2 updated - libbtrfsutil1-6.8.1-slfo.1.1_1.2 updated - libbtrfs0-6.8.1-slfo.1.1_1.2 updated - libbrotlicommon1-1.1.0-slfo.1.1_1.3 updated - libaudit1-3.1.1-slfo.1.1_2.1 updated - libattr1-2.5.1-slfo.1.1_1.3 updated - libargon2-1-20190702-slfo.1.1_1.2 updated - libalternatives1-1.2+30.a5431e9-slfo.1.1_1.3 updated - libaio1-0.3.113-slfo.1.1_1.2 updated - libacl1-2.3.1-slfo.1.1_1.3 updated - fillup-1.42-slfo.1.1_2.2 updated - dosfstools-4.2-slfo.1.1_1.2 updated - diffutils-3.10-slfo.1.1_1.3 updated - libpng16-16-1.6.58-slfo.1.1_1.1 updated - libidn2-0-2.3.4-slfo.1.1_1.2 updated - pkgconf-1.8.0-slfo.1.1_1.5 updated - libselinux1-3.5-slfo.1.1_1.3 updated - netcfg-11.6-slfo.1.1_1.2 updated - libxml2-2-2.11.6-slfo.1.1_9.1 updated - squashfs-4.6.1-slfo.1.1_1.2 updated - libgcrypt20-1.10.3-slfo.1.1_4.1 updated - libstdc++6-14.3.0+git11799-slfo.1.1_1.1 updated - libp11-kit0-0.25.3-slfo.1.1_1.2 updated - libblkid1-2.40.4-slfo.1.1_7.1 updated - perl-base-5.38.2-slfo.1.1_3.1 updated - libext2fs2-1.47.0-slfo.1.1_1.2 updated - libudev1-254.27-slfo.1.1_5.1 updated - chkstat-1600_20240206-slfo.1.1_1.5 updated - libzio1-1.08-slfo.1.1_1.3 updated - libjte2-1.22-slfo.1.1_1.2 updated - libbrotlidec1-1.1.0-slfo.1.1_1.3 updated - alts-1.2+30.a5431e9-slfo.1.1_1.3 updated - libpsl5-0.21.2-slfo.1.1_1.2 updated - sed-4.9-slfo.1.1_2.1 updated - libsubid4-4.15.1-slfo.1.1_1.3 updated - libsemanage2-3.5-slfo.1.1_1.3 updated - findutils-4.9.0-slfo.1.1_2.1 updated - libsystemd0-254.27-slfo.1.1_5.1 updated - libncurses6-6.4.20240224-slfo.1.1_2.1 updated - terminfo-base-6.4.20240224-slfo.1.1_2.1 updated - libinih0-56-slfo.1.1_1.3 updated - libboost_thread1_84_0-1.84.0-slfo.1.1_1.4 updated - p11-kit-0.25.3-slfo.1.1_1.2 updated - p11-kit-tools-0.25.3-slfo.1.1_1.2 updated - libmount1-2.40.4-slfo.1.1_7.1 updated - libfdisk1-2.40.4-slfo.1.1_7.1 updated - libisofs6-1.5.4-slfo.1.1_1.2 updated - libfreetype6-2.14.3-slfo.1.1_1.1 updated - ncurses-utils-6.4.20240224-slfo.1.1_2.1 updated - libreadline8-8.2-slfo.1.1_1.4 updated - libedit0-20210910.3.1-slfo.1.1_1.3 updated - gptfdisk-1.0.9-slfo.1.1_2.1 updated - libisoburn1-1.5.4-slfo.1.1_1.2 updated - bash-5.2.15-slfo.1.1_1.6 updated - bash-sh-5.2.15-slfo.1.1_1.6 updated - xz-5.4.3-slfo.1.1_3.1 updated - systemd-default-settings-branding-openSUSE-0.7-slfo.1.1_1.2 updated - systemd-default-settings-0.7-slfo.1.1_1.2 updated - pkgconf-pkg-config-1.8.0-slfo.1.1_1.5 updated - login_defs-4.15.1-slfo.1.1_1.3 updated - libdevmapper1_03-2.03.22_1.02.196-slfo.1.1_1.3 updated - gzip-1.13-slfo.1.1_4.1 updated - grep-3.11-slfo.1.1_1.2 updated - gettext-runtime-0.21.1-slfo.1.1_2.1 updated - coreutils-9.4-slfo.1.1_2.1 updated - ALP-dummy-release-0.1-slfo.1.1_1.5 updated - libparted2-3.5-slfo.1.1_1.2 updated - libdevmapper-event1_03-2.03.22_1.02.196-slfo.1.1_1.3 updated - info-7.0.3-slfo.1.1_1.3 updated - xfsprogs-6.5.0-slfo.1.1_1.2 updated - thin-provisioning-tools-0.9.0-slfo.1.1_1.4 updated - systemd-rpm-macros-24-slfo.1.1_1.2 updated - systemd-presets-common-SUSE-15-slfo.1.1_1.2 updated - rpm-config-SUSE-20240214-slfo.1.1_1.2 updated - rpm-4.18.0-slfo.1.1_3.1 updated - permissions-config-1600_20240206-slfo.1.1_1.5 updated - glibc-locale-base-2.38-slfo.1.1_9.1 updated - e2fsprogs-1.47.0-slfo.1.1_1.2 updated - ca-certificates-2+git20240805.fd24d50-slfo.1.1_1.2 updated - ca-certificates-mozilla-2.84-slfo.1.1_1.1 updated - btrfsprogs-6.8.1-slfo.1.1_1.2 updated - parted-3.5-slfo.1.1_1.2 updated - liblvm2cmd2_03-2.03.22-slfo.1.1_1.3 updated - xorriso-1.5.4-slfo.1.1_1.2 updated - device-mapper-2.03.22_1.02.196-slfo.1.1_1.3 updated - systemd-presets-branding-ALP-transactional-20230214-slfo.1.1_1.2 updated - permissions-1600_20240206-slfo.1.1_1.5 updated - mtools-4.0.43-slfo.1.1_1.2 updated - libopenssl3-3.1.4-slfo.1.1_13.1 updated - pam-1.6.1-slfo.1.1_5.1 updated - grub2-2.12-slfo.1.1_7.1 updated - grub2-i386-pc-2.12-slfo.1.1_7.1 updated - suse-module-tools-16.0.43-slfo.1.1_1.2 updated - kmod-32-slfo.1.1_2.1 updated - rsync-3.3.0-slfo.1.1_7.1 updated - libldap2-2.6.4-slfo.1.1_1.2 added - libkmod2-32-slfo.1.1_2.1 updated - libcryptsetup12-2.6.1-slfo.1.1_2.1 updated - krb5-1.21.3-slfo.1.1_5.1 added - util-linux-2.40.4-slfo.1.1_7.1 updated - shadow-4.15.1-slfo.1.1_1.3 updated - pam-config-2.11+git.20240906-slfo.1.1_2.1 updated - kbd-2.6.4-slfo.1.1_1.3 updated - libssh4-0.10.6-slfo.1.1_6.1 added - libsnapper7-0.11.2-slfo.1.1_1.2 updated - aaa_base-84.87+git20250903.33e5ba4-slfo.1.1_1.1 updated - libcurl4-8.14.1-slfo.1.1_10.1 added - dbus-1-daemon-1.14.10-slfo.1.1_1.2 updated - curl-8.14.1-slfo.1.1_10.1 updated - dbus-1-tools-1.14.10-slfo.1.1_1.2 updated - systemd-254.27-slfo.1.1_5.1 updated - sysuser-shadow-3.1-slfo.1.1_1.2 updated - dbus-1-common-1.14.10-slfo.1.1_1.2 updated - libdbus-1-3-1.14.10-slfo.1.1_1.2 updated - dbus-1-1.14.10-slfo.1.1_1.2 updated - system-group-kvm-20170617-slfo.1.1_1.2 updated - system-group-hardware-20170617-slfo.1.1_1.2 updated - udev-254.27-slfo.1.1_5.1 updated - snapper-0.11.2-slfo.1.1_1.2 updated - lvm2-2.03.22-slfo.1.1_1.3 updated - elemental-toolkit-2.2.9-slfo.1.1_1.1 updated - container:suse-toolbox-image-1.0.0-5.102 updated - file-magic-5.44-4.151 removed - kbd-legacy-2.6.4-1.3 removed - libcurl-mini4-8.14.1-8.1 removed - libmagic1-5.44-4.151 removed From sle-container-updates at lists.suse.com Wed Sep 9 07:21:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:21:44 +0200 (CEST) Subject: SUSE-CU-2026:9746-1: Security update of private-registry/harbor-jobservice Message-ID: <20260909072144.C1DEAFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9746-1 Container Tags : private-registry/harbor-jobservice:2.13 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5-1.56 , private-registry/harbor-jobservice:2.13.5-1.56 , private-registry/harbor-jobservice:latest Container Release : 1.56 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.13.5-150700.1.30 updated - harbor213-jobservice-2.13.5-150700.1.30 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:21:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:21:58 +0200 (CEST) Subject: SUSE-CU-2026:9787-1: Security update of private-registry/harbor-portal Message-ID: <20260909072158.22157FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9787-1 Container Tags : private-registry/harbor-portal:2.13 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5-1.61 , private-registry/harbor-portal:2.13.5-1.61 , private-registry/harbor-portal:latest Container Release : 1.61 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.13.5-150700.1.30 updated - harbor213-portal-2.13.5-150700.1.30 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:22:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:22:11 +0200 (CEST) Subject: SUSE-CU-2026:9789-1: Security update of private-registry/harbor-registry Message-ID: <20260909072211.349F0FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9789-1 Container Tags : private-registry/harbor-registry:2.8.3 , private-registry/harbor-registry:2.8.3-1.57 , private-registry/harbor-registry:latest Container Release : 1.57 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.13.5-150700.1.30 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:22:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:22:22 +0200 (CEST) Subject: SUSE-CU-2026:9791-1: Security update of private-registry/harbor-registryctl Message-ID: <20260909072222.7D0E0FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9791-1 Container Tags : private-registry/harbor-registryctl:2.13 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5-1.56 , private-registry/harbor-registryctl:2.13.5-1.56 , private-registry/harbor-registryctl:latest Container Release : 1.56 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - system-user-harbor-2.13.5-150700.1.30 updated - harbor213-registryctl-2.13.5-150700.1.30 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:22:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:22:38 +0200 (CEST) Subject: SUSE-CU-2026:9793-1: Security update of private-registry/harbor-trivy-adapter Message-ID: <20260909072238.1627EFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9793-1 Container Tags : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.60 , private-registry/harbor-trivy-adapter:latest Container Release : 1.60 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - system-user-harbor-2.13.5-150700.1.30 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:30:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:30:36 +0200 (CEST) Subject: SUSE-CU-2026:9798-1: Security update of suse/sle-micro/5.3/toolbox Message-ID: <20260909073036.7892BFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9798-1 Container Tags : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.277 , suse/sle-micro/5.3/toolbox:latest Container Release : 6.11.277 Severity : important Type : security References : 1262633 1263440 1264971 1268412 1274740 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3958-1 Released: Thu Sep 3 15:31:59 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3987-1 Released: Sun Sep 6 12:47:18 2026 Summary: Recommended update for container-suseconnect Type: recommended Severity: moderate References: This update for container-suseconnect fixes the following issues: Update to version 2.6.0: - simplify use_fips_mode conditional in specfile - Fix package for %suse_version bump (jsc#PED-15783) The following package changes have been done: - container-suseconnect-2.6.0-150000.4.95.2 updated - curl-8.14.1-150400.5.91.1 updated - libcurl4-8.14.1-150400.5.91.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:30:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:30:37 +0200 (CEST) Subject: SUSE-CU-2026:9799-1: Security update of suse/sle-micro/5.3/toolbox Message-ID: <20260909073037.E7C4AFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9799-1 Container Tags : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.278 , suse/sle-micro/5.3/toolbox:latest Container Release : 6.11.278 Severity : important Type : security References : 1266664 1266786 1274774 1274788 1274795 1274856 1274857 1274858 1277247 CVE-2026-23679 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4033-1 Released: Mon Sep 7 09:48:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,1277247,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - cpio-2.13-150400.3.10.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.104.1 updated - libopenssl1_1-1.1.1l-150400.7.104.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated - openssl-1_1-1.1.1l-150400.7.104.1 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:34:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:34:44 +0200 (CEST) Subject: SUSE-CU-2026:9800-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260909073444.56831FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9800-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.180 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.180 Severity : important Type : security References : 1266664 1266786 1274774 1274788 1274795 1274856 1274857 1274858 1277199 1277203 1277205 1277208 1277209 1277210 1277212 1277247 CVE-2026-23679 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4033-1 Released: Mon Sep 7 09:48:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,1277247,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4051-1 Released: Mon Sep 7 17:46:53 2026 Summary: Security update for multipath-tools Type: security Severity: moderate References: 1277199,1277203,1277205,1277208,1277209,1277210,1277212 This update for multipath-tools fixes the following issues: - Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). - Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). - SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). - Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). - Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). - DoS on multipathd socket by exhausting connections (bsc#1277203). - Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: - Update to version 0.9.0+187+suse.5bd6993. - Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - cpio-2.13-150400.3.10.1 updated - kpartx-0.9.0+187+suse.5bd6993-150400.4.25.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libmpath0-0.9.0+187+suse.5bd6993-150400.4.25.1 updated - libopenssl1_1-1.1.1l-150400.7.104.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated - multipath-tools-0.9.0+187+suse.5bd6993-150400.4.25.1 updated - openssl-1_1-1.1.1l-150400.7.104.1 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:34:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:34:45 +0200 (CEST) Subject: SUSE-CU-2026:9801-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260909073445.6315BFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9801-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.182 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.182 Severity : important Type : security References : 1267696 1268322 1273580 1276764 CVE-2026-10805 CVE-2026-16445 CVE-2026-19685 CVE-2026-6893 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4066-1 Released: Tue Sep 8 09:03:11 2026 Summary: Security update for NetworkManager Type: security Severity: important References: 1267696,1276764,CVE-2026-10805,CVE-2026-19685 This update for NetworkManager fixes the following issues: - CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). - CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4078-1 Released: Tue Sep 8 09:12:54 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: - CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). - CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: - Update to version 055+suse.371.g92f67c2: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset The following package changes have been done: - NetworkManager-1.38.2-150400.3.9.1 updated - dracut-mkinitrd-deprecated-055+suse.371.g92f67c2-150400.3.55.1 updated - dracut-055+suse.371.g92f67c2-150400.3.55.1 updated - libnm0-1.38.2-150400.3.9.1 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:37:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:37:28 +0200 (CEST) Subject: SUSE-CU-2026:9802-1: Security update of suse/sle-micro/5.4/toolbox Message-ID: <20260909073728.083BEFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9802-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.279 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.279 Severity : important Type : security References : 1266664 1266786 1274774 1274788 1274795 1274856 1274857 1274858 1277247 CVE-2026-23679 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4033-1 Released: Mon Sep 7 09:48:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,1277247,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - cpio-2.13-150400.3.10.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.104.1 updated - libopenssl1_1-1.1.1l-150400.7.104.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated - openssl-1_1-1.1.1l-150400.7.104.1 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:39:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:39:30 +0200 (CEST) Subject: SUSE-CU-2026:9803-1: Security update of suse/sle-micro/5.5/toolbox Message-ID: <20260909073930.C58D8FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9803-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.190 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.190 Severity : moderate Type : security References : 1266664 1266786 1274856 1274857 1274858 CVE-2026-23679 CVE-2026-42250 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - cpio-2.13-150400.3.10.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:41:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:41:59 +0200 (CEST) Subject: SUSE-IU-2026:6853-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260909074159.164A5FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6853-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.243 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.243 Severity : important Type : security References : 1261013 1263859 1263863 1263974 1274740 CVE-2026-28532 CVE-2026-37457 CVE-2026-37458 CVE-2026-5107 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 884 Released: Wed Jun 3 11:46:09 2026 Summary: Security update for frr Type: security Severity: important References: 1261013,1263859,1263863,1263974,1274740,CVE-2026-28532,CVE-2026-37457,CVE-2026-37458,CVE-2026-5107 This update for frr fixes the following issues: - CVE-2026-5107: Fixed an improper access controls in EVPN Type-2 Route Handler (bsc#1261013). - CVE-2026-28532: Harden TE/SR TLV iteration against malformed lengths (bsc#1263859). - CVE-2026-37457: Fix off-by-one error in FlowSpec operator array bounds check (bsc#1263863). - CVE-2026-37458: Validate MP_REACH_NLRI attribute against incorrect next-hop (bsc#1263974). The following package changes have been done: - libtirpc-netconfig-1.3.4-2.1 updated - libtirpc3-1.3.4-2.1 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:42:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:42:00 +0200 (CEST) Subject: SUSE-IU-2026:6854-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260909074200.11AC6FF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6854-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.244 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.244 Severity : moderate Type : security References : 1262472 1267696 1276764 1277199 1277203 1277205 1277208 1277209 1277210 1277212 CVE-2026-10805 CVE-2026-19685 CVE-2026-41051 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 885 Released: Wed Jun 3 11:47:33 2026 Summary: Recommended update for aaa_base Type: recommended Severity: moderate References: 1267696,1276764,CVE-2026-10805,CVE-2026-19685 This update for aaa_base fixes the following issues: - Fix a typo and follow symlinks in alljava ----------------------------------------------------------------- Advisory ID: 886 Released: Wed Jun 3 12:13:35 2026 Summary: Security update for csync2 Type: security Severity: moderate References: 1262472,1277199,1277203,1277205,1277208,1277209,1277210,1277212,CVE-2026-41051 This update for csync2 fixes the following issues Security issue: - CVE-2026-41051: uses insecure temporary directories when compiled with C99 or later (bsc#1262472). Non security issue: - Fix packages for Immutable Mode (jsc#PED-14855). The following package changes have been done: - libnm0-1.42.6-9.1 updated - NetworkManager-1.42.6-9.1 updated - kpartx-0.9.8+312+suse.c6cbd08-1.1 updated - libmpath0-0.9.8+312+suse.c6cbd08-1.1 updated - multipath-tools-0.9.8+312+suse.c6cbd08-1.1 updated - NetworkManager-wwan-1.42.6-9.1 updated - container:SL-Micro-base-container-2.1.3-7.208 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:58:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:58:55 +0200 (CEST) Subject: SUSE-IU-2026:6859-1: Recommended update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260909075855.864E5FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6859-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.166 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.166 Severity : moderate Type : recommended References : 1212841 1262574 1274740 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 712 Released: Wed May 6 19:49:50 2026 Summary: Recommended update for nvidia-open-driver-G07-signed Type: recommended Severity: moderate References: 1212841,1262574,1274740 This update for nvidia-open-driver-G07-signed fixes the following issues: Changes in nvidia-open-driver-G07-signed: - update CUDA variant to 595.71.05 - update non-CUDA variant to 595.71.05 (boo#1262574) * get rid of confusing objtool warnings (boo#1212841) The following package changes have been done: - libtirpc-netconfig-1.3.4-slfo.1.1_2.1 updated - libtirpc3-1.3.4-slfo.1.1_2.1 updated From sle-container-updates at lists.suse.com Wed Sep 9 07:58:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 09:58:56 +0200 (CEST) Subject: SUSE-IU-2026:6860-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260909075856.6D110FF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6860-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.168 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.168 Severity : critical Type : security References : 1204562 1212841 1218548 1219642 1221342 1221900 1221901 1222171 1231775 1231776 1232553 1234383 1243005 1244528 1248660 1254324 1257010 1259719 1259740 1260439 1262749 1267696 1276764 1277199 1277203 1277205 1277208 1277209 1277210 1277212 CVE-2024-58251 CVE-2025-49133 CVE-2026-10805 CVE-2026-19685 CVE-2026-21444 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 713 Released: Wed May 6 19:54:17 2026 Summary: Recommended update for nvidia-open-driver-G06-signed Type: recommended Severity: critical References: 1212841,1218548,1219642,1221342,1221900,1221901,1222171,1231775,1231776,1232553,1257010,1259719,1259740,1262749,1267696,1276764,CVE-2026-10805,CVE-2026-19685 This update for nvidia-open-driver-G06-signed fixes the following issues: Changes in nvidia-open-driver-G06-signed: - update CUDA variant to 580.159.03 - update non-CUDA variant to 580.159.03 (boo#1262749) - get rid of confusing objtool warnings (boo#1212841) - improved RPM description for -cuda and non-cuda variant - add 'Provides: open-driver-non-cuda-variant = %version' for non-CUDA variant to be able to distinguish between both variants; to be used by nvidia-open-driver-G06-signed-kmp-meta for TW ... (boo#1259740) ----------------------------------------------------------------- Advisory ID: 714 Released: Wed May 6 20:19:25 2026 Summary: Security update for libtpms Type: security Severity: moderate References: 1204562,1234383,1243005,1244528,1248660,1254324,1260439,1277199,1277203,1277205,1277208,1277209,1277210,1277212,CVE-2024-58251,CVE-2025-49133,CVE-2026-21444 This update for libtpms fixes the following issues: - CVE-2025-49133: Fixed potential out of bounds (OOB) read vulnerability (bsc#1244528). - CVE-2026-21444: Fixed remote data confidentiality compromise via incorrect Initialization Vector (IV) handling (bsc#1260439). The following package changes have been done: - libnm0-1.42.6-slfo.1.1_5.1 updated - NetworkManager-1.42.6-slfo.1.1_5.1 updated - kpartx-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 updated - libmpath0-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 updated - multipath-tools-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 updated - NetworkManager-wwan-1.42.6-slfo.1.1_5.1 updated - container:SL-Micro-base-container-2.2.1-5.184 updated From sle-container-updates at lists.suse.com Wed Sep 9 08:18:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 10:18:38 +0200 (CEST) Subject: SUSE-IU-2026:6860-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260909081838.8F6D9FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6860-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.168 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.168 Severity : important Type : security References : 1204562 1218548 1219642 1221342 1221900 1221901 1222171 1231775 1231776 1232553 1234383 1243005 1248660 1254324 1257010 1267696 1276764 1277199 1277203 1277205 1277208 1277209 1277210 1277212 CVE-2024-58251 CVE-2026-10805 CVE-2026-19685 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 714 Released: Tue Sep 8 11:21:17 2026 Summary: Security update for multipath-tools Type: security Severity: moderate References: 1204562,1234383,1243005,1248660,1254324,1277199,1277203,1277205,1277208,1277209,1277210,1277212,CVE-2024-58251 This update for multipath-tools fixes the following issues: - Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). - Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). - SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). - Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). - Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). - DoS on multipathd socket by exhausting connections (bsc#1277203). - Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: - Update to version 0.10.8+212+suse.3dc4ecc. - Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). ----------------------------------------------------------------- Advisory ID: 713 Released: Tue Sep 8 11:21:17 2026 Summary: Security update for NetworkManager Type: security Severity: important References: 1218548,1219642,1221342,1221900,1221901,1222171,1231775,1231776,1232553,1257010,1267696,1276764,CVE-2026-10805,CVE-2026-19685 This update for NetworkManager fixes the following issues: - CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). - CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). The following package changes have been done: - libnm0-1.42.6-slfo.1.1_5.1 updated - NetworkManager-1.42.6-slfo.1.1_5.1 updated - kpartx-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 updated - libmpath0-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 updated - multipath-tools-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 updated - NetworkManager-wwan-1.42.6-slfo.1.1_5.1 updated - container:SL-Micro-base-container-2.2.1-5.184 updated From sle-container-updates at lists.suse.com Wed Sep 9 08:40:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 10:40:16 +0200 (CEST) Subject: SUSE-IU-2026:6866-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260909084016.DF610FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6866-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.129 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.129 Severity : moderate Type : security References : 1266664 1266667 1277199 1277203 1277205 1277208 1277209 1277210 1277212 CVE-2026-23679 CVE-2026-47104 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1631 Released: Mon Sep 7 12:17:39 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,1266667,CVE-2026-23679,CVE-2026-47104 This update for libusb-1_0 fixes the following issues: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). - CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667). ----------------------------------------------------------------- Advisory ID: 1633 Released: Mon Sep 7 17:03:57 2026 Summary: Security update for multipath-tools Type: security Severity: moderate References: 1277199,1277203,1277205,1277208,1277209,1277210,1277212 This update for multipath-tools fixes the following issues: - Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). - Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). - SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). - Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). - Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). - DoS on multipathd socket by exhausting connections (bsc#1277203). - Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: - Update to version 0.12.4+278+suse.9cf9c5c. - Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). The following package changes have been done: - libusb-1_0-0-1.0.28-160000.3.1 updated - kpartx-0.12.4+278+suse.9cf9c5c-160000.1.1 updated - libmpath0-0.12.4+278+suse.9cf9c5c-160000.1.1 updated - multipath-tools-0.12.4+278+suse.9cf9c5c-160000.1.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-d65530abf75418cd43c2da7dfcc5842e3fec2b7be34cbdfdf42ab4a8b927e9e1-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 08:40:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 10:40:19 +0200 (CEST) Subject: SUSE-IU-2026:6867-1: Recommended update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260909084019.85A0DFF1F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6867-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.130 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.130 Severity : moderate Type : recommended References : 1277106 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1644 Released: Tue Sep 8 18:29:21 2026 Summary: Recommended update for sg3_utils Type: recommended Severity: moderate References: 1277106 This update for sg3_utils fixes the following issues: Changes in sg3_utils: - Update to version 1.48~20221101+8.02dda5f: * sg_inq: avoid including 0-bytes in SCSI name strings (bsc#1277106) The following package changes have been done: - libsgutils2-1_48-2-1.48~20221101+8.02dda5f-160000.1.1 updated - sg3_utils-1.48~20221101+8.02dda5f-160000.1.1 updated From sle-container-updates at lists.suse.com Wed Sep 9 08:50:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 10:50:07 +0200 (CEST) Subject: SUSE-IU-2026:6877-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260909085007.62619FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6877-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.67 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.67 Severity : moderate Type : security References : 1266664 1266667 CVE-2026-23679 CVE-2026-47104 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1631 Released: Mon Sep 7 12:17:39 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,1266667,CVE-2026-23679,CVE-2026-47104 This update for libusb-1_0 fixes the following issues: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). - CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667). The following package changes have been done: - libusb-1_0-0-1.0.28-160000.3.1 updated From sle-container-updates at lists.suse.com Wed Sep 9 08:50:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 10:50:10 +0200 (CEST) Subject: SUSE-IU-2026:6878-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260909085010.4BEF3FF1F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6878-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.68 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.68 Severity : critical Type : security References : 1257249 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1639 Released: Tue Sep 8 17:42:08 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). Changes for libzypp: Update to version 17.38.1: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Log all solver problem rules (bsc#1277790) The log contains the most relevant problem rule, but sometimes it helps to know all rules associated with this problem. zypper shows them on demand as 'detail'. The log now remembers them as well. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - repoGpgCheck: Strictly follow the repo_gpgcheck setting (bsc#1274625) There's been a legacy exception for unsigned repositories which were explicitly accepted in the past. After switching the repo_gpgcheck from off to on, they were allowed to stay unsigned until a first signed version was retrieved. From there on the handling was strict. Now the handling is strict as soon as the repo_gpgcheck turned on. The next set of metadata retrieved must be signed. - Iniparser: each new file starts in the unnamed section (bsc#1272534) - Fix hasCredentials() to require both username AND password to be non-empty (bsc#1273242) This avoids an unnecessary 2nd 401 response sending just the username in case the username but no password is known. Now it immediately fetches the credentials from disk if no password is known. - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730) The short Id (32bit/8byte) is not considered to be a safe identifier for a gpg key. A long id (64bit/16byte) or even better the full fingerprint is needed to identify the key. - zypp: Improve Testcase Loading for MCP Tools. Changes for zypper: Update to version 1.14.99: - Show solver problem details per default in not-interactive mode (bsc#1277790) This way they see all details when capturing zypper's output because the (d)etail button can't be pressed in not-interactive mode. - Add --servicesd-dir global option to relocate /etc/zypp/services.d (bsc#1257249) - info: check for missing positional args before systemSetup (bsc#1274091) - Remove deprecated installRecommends option from zypper.conf. The system wide default for all libzypp based applications is defined in zypp.conf(5). It is not recommended to define this in zypper exclusively. The following package changes have been done: - libzypp-17.38.15-160000.1.1 updated - zypper-1.14.101-160000.1.1 updated From sle-container-updates at lists.suse.com Wed Sep 9 09:16:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 11:16:40 +0200 (CEST) Subject: SUSE-CU-2026:9816-1: Security update of suse/ltss/sle15.4/sle15 Message-ID: <20260909091640.93985FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.4/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9816-1 Container Tags : suse/ltss/sle15.4/bci-base:15.4 , suse/ltss/sle15.4/bci-base:15.4-6.46 , suse/ltss/sle15.4/sle15:15.4 , suse/ltss/sle15.4/sle15:15.4-6.46 , suse/ltss/sle15.4/sle15:latest Container Release : 6.46 Severity : important Type : security References : 1274774 1274788 1274795 1277247 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container suse/ltss/sle15.4/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4033-1 Released: Mon Sep 7 09:48:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,1277247,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). The following package changes have been done: - libopenssl1_1-hmac-1.1.1l-150400.7.104.1 updated - libopenssl1_1-1.1.1l-150400.7.104.1 updated - openssl-1_1-1.1.1l-150400.7.104.1 updated From sle-container-updates at lists.suse.com Wed Sep 9 09:23:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 11:23:10 +0200 (CEST) Subject: SUSE-CU-2026:9818-1: Security update of suse/ltss/sle15.6/sle15 Message-ID: <20260909092310.0B2D0FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9818-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.89 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.89 , suse/ltss/sle15.6/sle15:latest Container Release : 5.89 Severity : moderate Type : security References : 1262633 1263440 1264971 1268412 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-5773 CVE-2026-7168 CVE-2026-80229 CVE-2026-80230 CVE-2026-8926 ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4047-1 Released: Mon Sep 7 15:53:38 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) The following package changes have been done: - curl-8.14.1-150600.4.51.1 updated - libcurl4-8.14.1-150600.4.51.1 updated From sle-container-updates at lists.suse.com Wed Sep 9 09:24:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 11:24:14 +0200 (CEST) Subject: SUSE-CU-2026:9819-1: Security update of bci/dotnet-aspnet Message-ID: <20260909092414.3E41EFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9819-1 Container Tags : bci/dotnet-aspnet:10.0 , bci/dotnet-aspnet:10.0-sles15 , bci/dotnet-aspnet:10.0.11 , bci/dotnet-aspnet:10.0.11-28.7 , bci/dotnet-aspnet:latest Container Release : 28.7 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 09:25:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 11:25:39 +0200 (CEST) Subject: SUSE-CU-2026:9821-1: Security update of bci/dotnet-aspnet Message-ID: <20260909092539.A1C5CFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9821-1 Container Tags : bci/dotnet-aspnet:8.0 , bci/dotnet-aspnet:8.0-sles15 , bci/dotnet-aspnet:8.0.30 , bci/dotnet-aspnet:8.0.30-98.7 Container Release : 98.7 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 09:26:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 11:26:59 +0200 (CEST) Subject: SUSE-CU-2026:9823-1: Security update of bci/dotnet-aspnet Message-ID: <20260909092659.C4708FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9823-1 Container Tags : bci/dotnet-aspnet:9.0 , bci/dotnet-aspnet:9.0-sles15 , bci/dotnet-aspnet:9.0.19 , bci/dotnet-aspnet:9.0.19-57.7 Container Release : 57.7 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 09:28:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 11:28:15 +0200 (CEST) Subject: SUSE-CU-2026:9825-1: Security update of bci/bci-base-fips Message-ID: <20260909092815.08058FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9825-1 Container Tags : bci/bci-base-fips:15.7 , bci/bci-base-fips:15.7-22.28 , bci/bci-base-fips:latest Container Release : 22.28 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container bci/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 09:29:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 11:29:20 +0200 (CEST) Subject: SUSE-CU-2026:9827-1: Security update of bci/dotnet-sdk Message-ID: <20260909092920.C97D8FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9827-1 Container Tags : bci/dotnet-sdk:10.0 , bci/dotnet-sdk:10.0-sles15 , bci/dotnet-sdk:10.0.11 , bci/dotnet-sdk:10.0.11-28.7 , bci/dotnet-sdk:latest Container Release : 28.7 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 09:30:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 11:30:44 +0200 (CEST) Subject: SUSE-CU-2026:9829-1: Security update of bci/dotnet-sdk Message-ID: <20260909093044.D4B91FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9829-1 Container Tags : bci/dotnet-sdk:8.0 , bci/dotnet-sdk:8.0-sles15 , bci/dotnet-sdk:8.0.30 , bci/dotnet-sdk:8.0.30-98.7 Container Release : 98.7 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 09:32:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 11:32:22 +0200 (CEST) Subject: SUSE-CU-2026:9831-1: Security update of bci/dotnet-sdk Message-ID: <20260909093222.EF3EEFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9831-1 Container Tags : bci/dotnet-sdk:9.0 , bci/dotnet-sdk:9.0-sles15 , bci/dotnet-sdk:9.0.19 , bci/dotnet-sdk:9.0.19-58.7 Container Release : 58.7 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 09:33:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 11:33:22 +0200 (CEST) Subject: SUSE-CU-2026:9833-1: Security update of bci/dotnet-runtime Message-ID: <20260909093322.0C12CFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9833-1 Container Tags : bci/dotnet-runtime:10.0 , bci/dotnet-runtime:10.0-sles15 , bci/dotnet-runtime:10.0.11 , bci/dotnet-runtime:10.0.11-28.7 , bci/dotnet-runtime:latest Container Release : 28.7 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 09:34:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 11:34:42 +0200 (CEST) Subject: SUSE-CU-2026:9835-1: Security update of bci/dotnet-runtime Message-ID: <20260909093442.CC542FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9835-1 Container Tags : bci/dotnet-runtime:8.0 , bci/dotnet-runtime:8.0-sles15 , bci/dotnet-runtime:8.0.30 , bci/dotnet-runtime:8.0.30-98.7 Container Release : 98.7 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 09:35:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 11:35:59 +0200 (CEST) Subject: SUSE-CU-2026:9837-1: Security update of bci/dotnet-runtime Message-ID: <20260909093559.01707FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9837-1 Container Tags : bci/dotnet-runtime:9.0 , bci/dotnet-runtime:9.0-sles15 , bci/dotnet-runtime:9.0.19 , bci/dotnet-runtime:9.0.19-57.7 Container Release : 57.7 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Wed Sep 9 09:36:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 9 Sep 2026 11:36:02 +0200 (CEST) Subject: SUSE-CU-2026:9839-1: Security update of bci/golang Message-ID: <20260909093602.E6F6FFF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9839-1 Container Tags : bci/golang:1.25 , bci/golang:1.25-sles15 , bci/golang:1.25.14 , bci/golang:1.25.14-3.72.4 , bci/golang:oldoldstable Container Release : 72.4 Severity : important Type : security References : 1266343 1266786 1269489 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:06:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:06:52 +0200 (CEST) Subject: SUSE-CU-2026:9841-1: Recommended update of private-registry/1.2/harbor-core Message-ID: <20260910070652.2E2CDFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9841-1 Container Tags : private-registry/1.2/harbor-core:1.2.1 , private-registry/1.2/harbor-core:1.2.1-1.96 , private-registry/1.2/harbor-core:latest Container Release : 1.96 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/1.2/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.15.2-150700.1.13 updated - harbor-core-2.15.2-150700.1.13 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:07:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:07:18 +0200 (CEST) Subject: SUSE-CU-2026:9843-1: Recommended update of private-registry/1.2/harbor-exporter Message-ID: <20260910070718.5B27AFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9843-1 Container Tags : private-registry/1.2/harbor-exporter:1.2.1 , private-registry/1.2/harbor-exporter:1.2.1-1.96 , private-registry/1.2/harbor-exporter:latest Container Release : 1.96 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/1.2/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - harbor-exporter-2.15.2-150700.1.13 updated - system-user-harbor-2.15.2-150700.1.13 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:07:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:07:45 +0200 (CEST) Subject: SUSE-CU-2026:9845-1: Recommended update of private-registry/1.2/harbor-jobservice Message-ID: <20260910070745.90073FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9845-1 Container Tags : private-registry/1.2/harbor-jobservice:1.2.1 , private-registry/1.2/harbor-jobservice:1.2.1-1.94 , private-registry/1.2/harbor-jobservice:latest Container Release : 1.94 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/1.2/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.15.2-150700.1.13 updated - harbor-jobservice-2.15.2-150700.1.13 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:08:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:08:14 +0200 (CEST) Subject: SUSE-CU-2026:9847-1: Recommended update of private-registry/1.2/harbor-portal Message-ID: <20260910070814.40AA1FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9847-1 Container Tags : private-registry/1.2/harbor-portal:1.2.1 , private-registry/1.2/harbor-portal:1.2.1-1.105 , private-registry/1.2/harbor-portal:latest Container Release : 1.105 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.15.2-150700.1.13 updated - harbor-portal-2.15.2-150700.1.13 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:08:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:08:48 +0200 (CEST) Subject: SUSE-CU-2026:9849-1: Recommended update of private-registry/1.2/harbor-registry Message-ID: <20260910070848.16636FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9849-1 Container Tags : private-registry/1.2/harbor-registry:1.2.1 , private-registry/1.2/harbor-registry:1.2.1-1.96 , private-registry/1.2/harbor-registry:latest Container Release : 1.96 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.15.2-150700.1.13 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:09:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:09:18 +0200 (CEST) Subject: SUSE-CU-2026:9851-1: Recommended update of private-registry/1.2/harbor-registryctl Message-ID: <20260910070918.6EF05FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9851-1 Container Tags : private-registry/1.2/harbor-registryctl:1.2.1 , private-registry/1.2/harbor-registryctl:1.2.1-1.96 , private-registry/1.2/harbor-registryctl:latest Container Release : 1.96 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.15.2-150700.1.13 updated - harbor-registryctl-2.15.2-150700.1.13 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:09:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:09:51 +0200 (CEST) Subject: SUSE-CU-2026:9853-1: Recommended update of private-registry/1.2/harbor-trivy-adapter Message-ID: <20260910070951.1AE46FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9853-1 Container Tags : private-registry/1.2/harbor-trivy-adapter:1.2.1 , private-registry/1.2/harbor-trivy-adapter:1.2.1-1.105 , private-registry/1.2/harbor-trivy-adapter:latest Container Release : 1.105 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/1.2/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.15.2-150700.1.13 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:11:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:11:25 +0200 (CEST) Subject: SUSE-CU-2026:9855-1: Recommended update of private-registry/harbor-core Message-ID: <20260910071125.D621AFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9855-1 Container Tags : private-registry/harbor-core:1.1.3 , private-registry/harbor-core:1.1.3-2.110 , private-registry/harbor-core:latest Container Release : 2.110 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.14.4-150700.1.44 updated - harbor-core-2.14.4-150700.1.44 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:13:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:13:10 +0200 (CEST) Subject: SUSE-CU-2026:9857-1: Recommended update of private-registry/harbor-exporter Message-ID: <20260910071310.095CDFF1E@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9857-1 Container Tags : private-registry/harbor-exporter:1.1.3 , private-registry/harbor-exporter:1.1.3-2.111 , private-registry/harbor-exporter:latest Container Release : 2.111 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - harbor-exporter-2.14.4-150700.1.44 updated - system-user-harbor-2.14.4-150700.1.44 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:14:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:14:53 +0200 (CEST) Subject: SUSE-CU-2026:9859-1: Recommended update of private-registry/harbor-jobservice Message-ID: <20260910071453.2DBABFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9859-1 Container Tags : private-registry/harbor-jobservice:1.1.3 , private-registry/harbor-jobservice:1.1.3-2.110 , private-registry/harbor-jobservice:latest Container Release : 2.110 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.14.4-150700.1.44 updated - harbor-jobservice-2.14.4-150700.1.44 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:16:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:16:39 +0200 (CEST) Subject: SUSE-CU-2026:9861-1: Recommended update of private-registry/harbor-portal Message-ID: <20260910071639.53849FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9861-1 Container Tags : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.123 , private-registry/harbor-portal:latest Container Release : 2.123 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.14.4-150700.1.44 updated - harbor-portal-2.14.4-150700.1.44 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:17:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:17:37 +0200 (CEST) Subject: SUSE-CU-2026:9863-1: Recommended update of private-registry/harbor-registry Message-ID: <20260910071737.7C39FFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9863-1 Container Tags : private-registry/harbor-registry:1.1.3 , private-registry/harbor-registry:1.1.3-2.111 , private-registry/harbor-registry:latest Container Release : 2.111 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.14.4-150700.1.44 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:19:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:19:04 +0200 (CEST) Subject: SUSE-CU-2026:9865-1: Recommended update of private-registry/harbor-registryctl Message-ID: <20260910071904.5BD11FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9865-1 Container Tags : private-registry/harbor-registryctl:1.1.3 , private-registry/harbor-registryctl:1.1.3-2.112 , private-registry/harbor-registryctl:latest Container Release : 2.112 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.14.4-150700.1.44 updated - harbor-registryctl-2.14.4-150700.1.44 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:20:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:20:34 +0200 (CEST) Subject: SUSE-CU-2026:9867-1: Recommended update of private-registry/harbor-trivy-adapter Message-ID: <20260910072034.0F044FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9867-1 Container Tags : private-registry/harbor-trivy-adapter:1.1.3 , private-registry/harbor-trivy-adapter:1.1.3-2.124 , private-registry/harbor-trivy-adapter:latest Container Release : 2.124 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.14.4-150700.1.44 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:20:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:20:52 +0200 (CEST) Subject: SUSE-CU-2026:9868-1: Recommended update of private-registry/harbor-core Message-ID: <20260910072052.529F7FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9868-1 Container Tags : private-registry/harbor-core:2.13 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5-1.62 , private-registry/harbor-core:2.13.5-1.62 , private-registry/harbor-core:latest Container Release : 1.62 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.13.5-150700.1.32 updated - harbor213-core-2.13.5-150700.1.32 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:21:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:21:13 +0200 (CEST) Subject: SUSE-CU-2026:9871-1: Recommended update of private-registry/harbor-exporter Message-ID: <20260910072113.62896FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9871-1 Container Tags : private-registry/harbor-exporter:2.13 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5-1.62 , private-registry/harbor-exporter:2.13.5-1.62 , private-registry/harbor-exporter:latest Container Release : 1.62 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - harbor213-exporter-2.13.5-150700.1.32 updated - system-user-harbor-2.13.5-150700.1.32 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:21:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:21:34 +0200 (CEST) Subject: SUSE-CU-2026:9874-1: Recommended update of private-registry/harbor-jobservice Message-ID: <20260910072134.5F4CFFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9874-1 Container Tags : private-registry/harbor-jobservice:2.13 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5-1.62 , private-registry/harbor-jobservice:2.13.5-1.62 , private-registry/harbor-jobservice:latest Container Release : 1.62 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.13.5-150700.1.32 updated - harbor213-jobservice-2.13.5-150700.1.32 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:21:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:21:58 +0200 (CEST) Subject: SUSE-CU-2026:9877-1: Recommended update of private-registry/harbor-portal Message-ID: <20260910072158.4CBAFFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9877-1 Container Tags : private-registry/harbor-portal:2.13 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5-1.67 , private-registry/harbor-portal:2.13.5-1.67 , private-registry/harbor-portal:latest Container Release : 1.67 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.13.5-150700.1.32 updated - harbor213-portal-2.13.5-150700.1.32 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:22:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:22:19 +0200 (CEST) Subject: SUSE-CU-2026:9880-1: Recommended update of private-registry/harbor-registry Message-ID: <20260910072219.66654FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9880-1 Container Tags : private-registry/harbor-registry:2.8.3 , private-registry/harbor-registry:2.8.3-1.63 , private-registry/harbor-registry:latest Container Release : 1.63 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.13.5-150700.1.32 updated - harbor-distribution-registry-2.8.3-150700.1.7 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:22:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:22:38 +0200 (CEST) Subject: SUSE-CU-2026:9883-1: Recommended update of private-registry/harbor-registryctl Message-ID: <20260910072238.B7D23FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9883-1 Container Tags : private-registry/harbor-registryctl:2.13 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5-1.62 , private-registry/harbor-registryctl:2.13.5-1.62 , private-registry/harbor-registryctl:latest Container Release : 1.62 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - system-user-harbor-2.13.5-150700.1.32 updated - harbor-distribution-registry-2.8.3-150700.1.7 updated - harbor213-registryctl-2.13.5-150700.1.32 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 07:23:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 09:23:01 +0200 (CEST) Subject: SUSE-CU-2026:9886-1: Recommended update of private-registry/harbor-trivy-adapter Message-ID: <20260910072301.31E30FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9886-1 Container Tags : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.66 , private-registry/harbor-trivy-adapter:latest Container Release : 1.66 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - harbor-scanner-trivy-0.35.1-150700.1.7 updated - system-user-harbor-2.13.5-150700.1.32 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 08:45:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 10:45:42 +0200 (CEST) Subject: SUSE-CU-2026:9886-1: Recommended update of private-registry/harbor-trivy-adapter Message-ID: <20260910084542.B1E91FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9886-1 Container Tags : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.66 , private-registry/harbor-trivy-adapter:latest Container Release : 1.66 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - harbor-scanner-trivy-0.35.1-150700.1.7 updated - system-user-harbor-2.13.5-150700.1.32 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 08:56:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 10:56:37 +0200 (CEST) Subject: SUSE-CU-2026:9890-1: Security update of suse/sle-micro/5.3/toolbox Message-ID: <20260910085637.207F8FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9890-1 Container Tags : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.280 , suse/sle-micro/5.3/toolbox:latest Container Release : 6.11.280 Severity : critical Type : security References : 1257249 1261038 1268321 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4096-1 Released: Wed Sep 9 10:34:28 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. The following package changes have been done: - libzypp-17.38.15-150400.3.161.1 updated - zypper-1.14.101-150400.3.107.1 updated From sle-container-updates at lists.suse.com Thu Sep 10 09:03:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 11:03:51 +0200 (CEST) Subject: SUSE-CU-2026:9891-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260910090351.57810FF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9891-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.183 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.183 Severity : critical Type : security References : 1257249 1261038 1268321 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4096-1 Released: Wed Sep 9 10:34:28 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. The following package changes have been done: - libzypp-17.38.15-150400.3.161.1 updated - zypper-1.14.101-150400.3.107.1 updated From sle-container-updates at lists.suse.com Thu Sep 10 09:08:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 11:08:18 +0200 (CEST) Subject: SUSE-CU-2026:9892-1: Security update of suse/sle-micro/5.4/toolbox Message-ID: <20260910090818.50921FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9892-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.281 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.281 Severity : critical Type : security References : 1257249 1261038 1268321 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4096-1 Released: Wed Sep 9 10:34:28 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. The following package changes have been done: - libzypp-17.38.15-150400.3.161.1 updated - zypper-1.14.101-150400.3.107.1 updated From sle-container-updates at lists.suse.com Thu Sep 10 09:15:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 11:15:04 +0200 (CEST) Subject: SUSE-IU-2026:6899-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260910091504.0E24BFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6899-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.209 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.209 Severity : critical Type : security References : 1257249 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 890 Released: Wed Sep 9 16:10:30 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) Changes for zypper: - Update to version 1.14.101. The following package changes have been done: - libzypp-17.38.15-1.1 updated - zypper-1.14.101-1.1 updated - container:suse-toolbox-image-1.0.0-9.164 updated From sle-container-updates at lists.suse.com Thu Sep 10 09:34:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 11:34:45 +0200 (CEST) Subject: SUSE-CU-2026:9897-1: Security update of suse/sl-micro/6.0/toolbox Message-ID: <20260910093445.958EBFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9897-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.164 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.164 Severity : critical Type : security References : 1257249 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 890 Released: Wed Sep 9 16:10:30 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) Changes for zypper: - Update to version 1.14.101. The following package changes have been done: - libzypp-17.38.15-1.1 updated - zypper-1.14.101-1.1 updated From sle-container-updates at lists.suse.com Thu Sep 10 09:40:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 11:40:44 +0200 (CEST) Subject: SUSE-IU-2026:6903-1: Security update of suse/sl-micro/6.1/base-os-container Message-ID: <20260910094044.894C0FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6903-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.185 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.185 Severity : critical Type : security References : 1239696 1257249 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 718 Released: Wed Sep 9 15:10:41 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1239696,1257249,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). Changes for libzypp: Update to version 17.38.1: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Log all solver problem rules (bsc#1277790) The log contains the most relevant problem rule, but sometimes it helps to know all rules associated with this problem. zypper shows them on demand as 'detail'. The log now remembers them as well. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - repoGpgCheck: Strictly follow the repo_gpgcheck setting (bsc#1274625) There's been a legacy exception for unsigned repositories which were explicitly accepted in the past. After switching the repo_gpgcheck from off to on, they were allowed to stay unsigned until a first signed version was retrieved. From there on the handling was strict. Now the handling is strict as soon as the repo_gpgcheck turned on. The next set of metadata retrieved must be signed. - Iniparser: each new file starts in the unnamed section (bsc#1272534) - Fix hasCredentials() to require both username AND password to be non-empty (bsc#1273242) This avoids an unnecessary 2nd 401 response sending just the username in case the username but no password is known. Now it immediately fetches the credentials from disk if no password is known. - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730) The short Id (32bit/8byte) is not considered to be a safe identifier for a gpg key. A long id (64bit/16byte) or even better the full fingerprint is needed to identify the key. - zypp: Improve Testcase Loading for MCP Tools. Changes for zypper: Update to version 1.14.99: - Show solver problem details per default in not-interactive mode (bsc#1277790) This way they see all details when capturing zypper's output because the (d)etail button can't be pressed in not-interactive mode. - Add --servicesd-dir global option to relocate /etc/zypp/services.d (bsc#1257249) - info: check for missing positional args before systemSetup (bsc#1274091) - Remove deprecated installRecommends option from zypper.conf. The system wide default for all libzypp based applications is defined in zypp.conf(5). It is not recommended to define this in zypper exclusively. The following package changes have been done: - libzypp-17.38.15-slfo.1.1_1.1 updated - zypper-1.14.101-slfo.1.1_1.1 updated - container:suse-toolbox-image-1.0.0-5.103 updated From sle-container-updates at lists.suse.com Thu Sep 10 10:01:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 12:01:27 +0200 (CEST) Subject: SUSE-IU-2026:6907-1: Recommended update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260910100127.BFBAEFF24@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6907-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.134 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.134 Severity : moderate Type : recommended References : 1272547 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1647 Released: Wed Sep 9 15:16:45 2026 Summary: Recommended update for libssh Type: recommended Severity: moderate References: 1272547 This update for libssh fixes the following issues: Changes in libssh: - Fix: libssh ignores system wide crypto policies (bsc#1272547) The following package changes have been done: - libssh-config-0.11.5-160000.2.1 updated - libssh4-0.11.5-160000.2.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-14bcc1115c957bb5b24dfc2362fd40578eba5c6e10efece0317a455abd309fc6-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 10:01:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 12:01:26 +0200 (CEST) Subject: SUSE-IU-2026:6906-1: Recommended update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260910100126.70D03FF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6906-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.133 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.133 Severity : moderate Type : recommended References : 1275219 1275492 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1650 Released: Wed Sep 9 16:07:45 2026 Summary: Recommended update for selinux-policy Type: recommended Severity: moderate References: 1275219,1275492 This update for selinux-policy fixes the following issues: Changes in selinux-policy: - Fix: SELinux denials during bees service startup / stop (bsc#1275219): * named filetrans for netconfig * Fix regression that was introduced with fix_unconfined patch - Fix: [SELinux] kanidm_ssh_authorizedkeys unable to access user's ssh key, denying ssh access (bsc#1275492): * sshd_session_t needs to access kanidm sshkeys * Fix broken kanidm_sshkeys_t security context The following package changes have been done: - selinux-policy-20250627+git398.8dcc9d038-160000.1.1 updated - selinux-policy-targeted-20250627+git398.8dcc9d038-160000.1.1 updated From sle-container-updates at lists.suse.com Thu Sep 10 10:12:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 12:12:14 +0200 (CEST) Subject: SUSE-IU-2026:6911-1: Recommended update of suse/sl-micro/6.2/base-os-container Message-ID: <20260910101214.AD53BFF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6911-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.69 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.69 Severity : moderate Type : recommended References : 1272547 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1647 Released: Wed Sep 9 15:16:45 2026 Summary: Recommended update for libssh Type: recommended Severity: moderate References: 1272547 This update for libssh fixes the following issues: Changes in libssh: - Fix: libssh ignores system wide crypto policies (bsc#1272547) The following package changes have been done: - libssh-config-0.11.5-160000.2.1 updated - libssh4-0.11.5-160000.2.1 updated From sle-container-updates at lists.suse.com Thu Sep 10 10:22:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 12:22:52 +0200 (CEST) Subject: SUSE-IU-2026:6914-1: Recommended update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260910102252.64FB4FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6914-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.115 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.115 Severity : important Type : recommended References : 1274579 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1645 Released: Wed Sep 9 10:09:38 2026 Summary: Recommended update for qemu Type: recommended Severity: important References: 1274579 This update for qemu fixes the following issues: Changes in qemu: - Fix: Live migration does not work in 16.0/virt-operator:1.8.3-2.2 (bsc#1274579): * target/i386: Add compatibility property for pdcm feature - Update to version 10.0.13: * target/riscv/tcg: sret in virtual user mode raises virtual instruction exception * target/riscv: + Enforce even register constraints for Zdinx fcvt pairs + Reject FMV.X.W/FMV.W.X under Zfinx + Honor zicbo* envcfg gating in linux-user mode + Allow menvcfg/henvcfg LPE and SSE bits on RV32 + Use SXL instead of MXL for read_sstatus + Fix PC sync in trans_sspopchk for CFI exception handling * disas/riscv: + Fix typo in th.lbib format + Fix isa decoding of rev8 + Fix rv32 encoding of zext.h * hw/riscv/riscv-iommu: + Preserve requested perm in spa_fetch() + Fix U-bit check to apply only to leaf S/VS-stage PTEs * disas/riscv: + Decode unsigned vector immediates as unsigned + Use signed type for vector immediates + Fix 6-bit immediate extraction + Fix th.srri decoding * hw/watchdog: Add lower bound check for watchdogNumber * tcg: + Export tcg_gen_ussub_i{32,64,tl} + Defer tb_flush when initial thread region alloc fails + Return success from tcg_region_alloc + Return success from tcg_region_alloc__locked * target/loongarch: Check FPE before reading fcc in bceqz/bcnez * meson: Make linker warnings non-fatal on Linux * serial: Clear transmit retry callback on unrealize * target/i386: + Decode opcode extensions group 3 /1 as TEST + Allow transition to virtual-8086 mode only if CPL == 0 and CPU is not in long mode + Fix long mode segment override prefix decoding + Fix incorrect decoding of EXTRQ_i + Clear OF, SF, and AF for fcomi/fucomi + Use correct type for get_float_exception_flags() values * tcg/optimize: + Fix s_mask computation for shifts + INDEX_op_mul is commutative * hw/elf_ops: Defend against weird elf headers * hw/nvme: Add SPDM_SOCKET Kconfig dependency * hw/block/pflash_cfi01: Restore ROMD mode after migration * hw/net/rtl8139: + Send whole of vlan-tagged packet when doing loopback + Fix handling of VLAN tags on incoming short packets * tests/qtest/ahci: Regression test for ATAPI read vs. drain * hw/ide/atapi: Read the whole elementary transfer asynchronously * tests/qtest/ahci: Cover raw (2352-byte) ATAPI CD reads * tests/qtest/libqos/ahci: Support raw (2352-byte) READ CD * tests/qtest/ide-test: + Cover raw (2352-byte) ATAPI CD reads + Add a multi-sector ATAPI DMA read test + Parametrize the ATAPI CD-ROM read test The following package changes have been done: - qemu-guest-agent-10.0.13-160000.1.1 updated From sle-container-updates at lists.suse.com Thu Sep 10 10:22:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 12:22:55 +0200 (CEST) Subject: SUSE-IU-2026:6916-1: Recommended update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260910102255.8E441FF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6916-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.117 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.117 Severity : moderate Type : recommended References : 1272547 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1647 Released: Wed Sep 9 15:16:45 2026 Summary: Recommended update for libssh Type: recommended Severity: moderate References: 1272547 This update for libssh fixes the following issues: Changes in libssh: - Fix: libssh ignores system wide crypto policies (bsc#1272547) The following package changes have been done: - libssh-config-0.11.5-160000.2.1 updated - libssh4-0.11.5-160000.2.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-14bcc1115c957bb5b24dfc2362fd40578eba5c6e10efece0317a455abd309fc6-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 10:34:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 12:34:00 +0200 (CEST) Subject: SUSE-IU-2026:6925-1: Recommended update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260910103400.07484FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6925-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.153 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.153 Severity : moderate Type : recommended References : 1272547 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1647 Released: Wed Sep 9 15:16:45 2026 Summary: Recommended update for libssh Type: recommended Severity: moderate References: 1272547 This update for libssh fixes the following issues: Changes in libssh: - Fix: libssh ignores system wide crypto policies (bsc#1272547) The following package changes have been done: - libssh-config-0.11.5-160000.2.1 updated - libssh4-0.11.5-160000.2.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-7bf7ffd84642f675911d90eeff787da1c66f755728660445d9f2c51c78840812-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 10:46:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 12:46:25 +0200 (CEST) Subject: SUSE-CU-2026:9903-1: Security update of suse/ltss/sle15.4/sle15 Message-ID: <20260910104625.D920BFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.4/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9903-1 Container Tags : suse/ltss/sle15.4/bci-base:15.4 , suse/ltss/sle15.4/bci-base:15.4-6.47 , suse/ltss/sle15.4/sle15:15.4 , suse/ltss/sle15.4/sle15:15.4-6.47 , suse/ltss/sle15.4/sle15:latest Container Release : 6.47 Severity : critical Type : security References : 1257249 1261038 1268321 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/ltss/sle15.4/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4096-1 Released: Wed Sep 9 10:34:28 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. The following package changes have been done: - libzypp-17.38.15-150400.3.161.1 updated - zypper-1.14.101-150400.3.107.1 updated From sle-container-updates at lists.suse.com Thu Sep 10 10:51:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 12:51:53 +0200 (CEST) Subject: SUSE-CU-2026:9904-1: Recommended update of suse/ltss/sle15.6/bci-base-fips Message-ID: <20260910105153.0D251FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9904-1 Container Tags : suse/ltss/sle15.6/bci-base-fips:15.6 , suse/ltss/sle15.6/bci-base-fips:15.6-35.100 , suse/ltss/sle15.6/bci-base-fips:latest Container Release : 35.100 Severity : important Type : recommended References : 1242233 1243830 1277267 ----------------------------------------------------------------- The container suse/ltss/sle15.6/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4116-1 Released: Wed Sep 9 21:41:52 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Revert the previous change since the syntax is not understood in this crypto-policies version. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.22.1 updated - container:sles15-ltss-image-15.6.0-5.91 updated From sle-container-updates at lists.suse.com Thu Sep 10 10:54:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 12:54:56 +0200 (CEST) Subject: SUSE-CU-2026:9905-1: Security update of suse/ltss/sle15.6/sle15 Message-ID: <20260910105456.89CDDFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9905-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.91 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.91 , suse/ltss/sle15.6/sle15:latest Container Release : 5.91 Severity : critical Type : security References : 1242233 1243830 1257249 1261038 1268321 1271730 1272534 1273242 1274091 1274625 1277267 1277790 ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4112-1 Released: Wed Sep 9 18:17:10 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4116-1 Released: Wed Sep 9 21:41:52 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Revert the previous change since the syntax is not understood in this crypto-policies version. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.22.1 updated - libzypp-17.38.15-150600.3.95.1 updated - zypper-1.14.101-150600.10.58.1 updated From sle-container-updates at lists.suse.com Thu Sep 10 11:01:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 13:01:01 +0200 (CEST) Subject: SUSE-CU-2026:9909-1: Recommended update of bci/bci-base-fips Message-ID: <20260910110101.43C0FFF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9909-1 Container Tags : bci/bci-base-fips:15.7 , bci/bci-base-fips:15.7-23.3 , bci/bci-base-fips:latest Container Release : 23.3 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 11:10:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 13:10:12 +0200 (CEST) Subject: SUSE-CU-2026:9839-1: Security update of bci/golang Message-ID: <20260910111012.2D4A1FBAA@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9839-1 Container Tags : bci/golang:1.25 , bci/golang:1.25-sles15 , bci/golang:1.25.14 , bci/golang:1.25.14-3.72.4 , bci/golang:oldoldstable Container Release : 72.4 Severity : important Type : security References : 1266343 1266786 1269489 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 11:11:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 13:11:45 +0200 (CEST) Subject: SUSE-CU-2026:9917-1: Security update of bci/golang Message-ID: <20260910111145.23C11FBAA@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9917-1 Container Tags : bci/golang:1.26 , bci/golang:1.26-sles15 , bci/golang:1.26.7 , bci/golang:1.26.7-2.73.4 , bci/golang:oldstable Container Release : 73.4 Severity : important Type : security References : 1266343 1266786 1269489 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 11:11:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 13:11:47 +0200 (CEST) Subject: SUSE-CU-2026:9918-1: Recommended update of bci/golang Message-ID: <20260910111147.1EC19FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9918-1 Container Tags : bci/golang:1.26 , bci/golang:1.26-sles15 , bci/golang:1.26.8 , bci/golang:1.26.8-2.73.6 , bci/golang:oldstable Container Release : 73.6 Severity : important Type : recommended References : 1255111 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4091-1 Released: Tue Sep 8 17:58:45 2026 Summary: Recommended update for go1.26 Type: recommended Severity: important References: 1255111 This update for go1.26 fixes the following issues: - go1.26.8 (released 2026-09-01) includes fixes to cgo, the compiler, the runtime, and the debug/elf and os packages. (bsc#1255111) * cmd/compile/internal/test: TestMergeLocalsIntegration failures * debug/elf: applyRelocationsPPC was broken by CL 705075 * os: TestRootMultiMkdirAllShallow failures on openbsd * cmd/go: pseudo #cgo directive FFLAGS value mixed up with CXXFLAGS in Go 1.26 * runtime: async preemption corrupts AVX (YMM) state on netbsd/amd64 The following package changes have been done: - go1.26-doc-1.26.8-150000.1.30.1 updated - go1.26-1.26.8-150000.1.30.1 updated - go1.26-race-1.26.8-150000.1.30.1 updated - container:registry.suse.com-bci-bci-base-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated From sle-container-updates at lists.suse.com Thu Sep 10 11:13:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 10 Sep 2026 13:13:34 +0200 (CEST) Subject: SUSE-CU-2026:9919-1: Security update of bci/golang Message-ID: <20260910111334.7720DFBAA@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9919-1 Container Tags : bci/golang:1.25-openssl , bci/golang:1.25-sles15-openssl , bci/golang:1.25.14-openssl , bci/golang:1.25.14-openssl-90.8 , bci/golang:oldstable-openssl Container Release : 90.8 Severity : important Type : security References : 1266343 1266786 1269489 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - libopenssl-3-devel-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:09:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:09:16 +0200 (CEST) Subject: SUSE-IU-2026:6932-1: Recommended update of suse/sle-micro/base-5.5 Message-ID: <20260911070916.4DA1DFF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6932-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.316 , suse/sle-micro/base-5.5:latest Image Release : 5.8.316 Severity : moderate Type : recommended References : 1261914 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4121-1 Released: Thu Sep 10 11:56:57 2026 Summary: Recommended update for apparmor Type: recommended Severity: moderate References: 1261914 This update for apparmor fixes the following issues: - dovecot profile: allow PROC/PID/stat access (bsc#1261914) The following package changes have been done: - libapparmor1-3.0.4-150500.11.21.1 updated - apparmor-parser-3.0.4-150500.11.21.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:12:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:12:59 +0200 (CEST) Subject: SUSE-IU-2026:6933-1: Recommended update of suse/sle-micro/kvm-5.5 Message-ID: <20260911071300.00F7EFF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/kvm-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6933-1 Image Tags : suse/sle-micro/kvm-5.5:2.0.4 , suse/sle-micro/kvm-5.5:2.0.4-3.5.609 , suse/sle-micro/kvm-5.5:latest Image Release : 3.5.609 Severity : moderate Type : recommended References : 1261914 ----------------------------------------------------------------- The container suse/sle-micro/kvm-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4121-1 Released: Thu Sep 10 11:56:57 2026 Summary: Recommended update for apparmor Type: recommended Severity: moderate References: 1261914 This update for apparmor fixes the following issues: - dovecot profile: allow PROC/PID/stat access (bsc#1261914) The following package changes have been done: - libapparmor1-3.0.4-150500.11.21.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.316 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:18:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:18:16 +0200 (CEST) Subject: SUSE-IU-2026:6934-1: Recommended update of suse/sle-micro/rt-5.5 Message-ID: <20260911071816.904F5FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6934-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.720 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.720 Severity : moderate Type : recommended References : 1261914 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4121-1 Released: Thu Sep 10 11:56:57 2026 Summary: Recommended update for apparmor Type: recommended Severity: moderate References: 1261914 This update for apparmor fixes the following issues: - dovecot profile: allow PROC/PID/stat access (bsc#1261914) The following package changes have been done: - libapparmor1-3.0.4-150500.11.21.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.111 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:21:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:21:40 +0200 (CEST) Subject: SUSE-IU-2026:6935-1: Recommended update of suse/sle-micro/5.5 Message-ID: <20260911072140.ABE1CFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6935-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.111 , suse/sle-micro/5.5:latest Image Release : 5.8.111 Severity : moderate Type : recommended References : 1261914 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4121-1 Released: Thu Sep 10 11:56:57 2026 Summary: Recommended update for apparmor Type: recommended Severity: moderate References: 1261914 This update for apparmor fixes the following issues: - dovecot profile: allow PROC/PID/stat access (bsc#1261914) The following package changes have been done: - libapparmor1-3.0.4-150500.11.21.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.316 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:29:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:29:09 +0200 (CEST) Subject: SUSE-CU-2026:9921-1: Recommended update of private-registry/1.2/harbor-core Message-ID: <20260911072909.109C3FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9921-1 Container Tags : private-registry/1.2/harbor-core:1.2.1 , private-registry/1.2/harbor-core:1.2.1-1.101 , private-registry/1.2/harbor-core:latest Container Release : 1.101 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/1.2/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:29:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:29:39 +0200 (CEST) Subject: SUSE-CU-2026:9923-1: Recommended update of private-registry/1.2/harbor-exporter Message-ID: <20260911072939.89033FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9923-1 Container Tags : private-registry/1.2/harbor-exporter:1.2.1 , private-registry/1.2/harbor-exporter:1.2.1-1.101 , private-registry/1.2/harbor-exporter:latest Container Release : 1.101 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/1.2/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:30:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:30:11 +0200 (CEST) Subject: SUSE-CU-2026:9925-1: Recommended update of private-registry/1.2/harbor-jobservice Message-ID: <20260911073011.96E9DFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9925-1 Container Tags : private-registry/1.2/harbor-jobservice:1.2.1 , private-registry/1.2/harbor-jobservice:1.2.1-1.99 , private-registry/1.2/harbor-jobservice:latest Container Release : 1.99 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/1.2/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:30:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:30:45 +0200 (CEST) Subject: SUSE-CU-2026:9927-1: Recommended update of private-registry/1.2/harbor-portal Message-ID: <20260911073045.AFFE0FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9927-1 Container Tags : private-registry/1.2/harbor-portal:1.2.1 , private-registry/1.2/harbor-portal:1.2.1-1.110 , private-registry/1.2/harbor-portal:latest Container Release : 1.110 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:31:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:31:13 +0200 (CEST) Subject: SUSE-CU-2026:9929-1: Recommended update of private-registry/1.2/harbor-registry Message-ID: <20260911073113.D76F0FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9929-1 Container Tags : private-registry/1.2/harbor-registry:1.2.1 , private-registry/1.2/harbor-registry:1.2.1-1.101 , private-registry/1.2/harbor-registry:latest Container Release : 1.101 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:31:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:31:45 +0200 (CEST) Subject: SUSE-CU-2026:9931-1: Recommended update of private-registry/1.2/harbor-registryctl Message-ID: <20260911073145.1E1E2FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9931-1 Container Tags : private-registry/1.2/harbor-registryctl:1.2.1 , private-registry/1.2/harbor-registryctl:1.2.1-1.101 , private-registry/1.2/harbor-registryctl:latest Container Release : 1.101 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:32:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:32:19 +0200 (CEST) Subject: SUSE-CU-2026:9933-1: Recommended update of private-registry/1.2/harbor-trivy-adapter Message-ID: <20260911073219.43529FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9933-1 Container Tags : private-registry/1.2/harbor-trivy-adapter:1.2.1 , private-registry/1.2/harbor-trivy-adapter:1.2.1-1.110 , private-registry/1.2/harbor-trivy-adapter:latest Container Release : 1.110 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/1.2/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:34:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:34:06 +0200 (CEST) Subject: SUSE-CU-2026:9935-1: Recommended update of private-registry/harbor-core Message-ID: <20260911073406.81C7CFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9935-1 Container Tags : private-registry/harbor-core:1.1.3 , private-registry/harbor-core:1.1.3-2.115 , private-registry/harbor-core:latest Container Release : 2.115 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:35:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:35:38 +0200 (CEST) Subject: SUSE-CU-2026:9937-1: Recommended update of private-registry/harbor-exporter Message-ID: <20260911073538.81529FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9937-1 Container Tags : private-registry/harbor-exporter:1.1.3 , private-registry/harbor-exporter:1.1.3-2.116 , private-registry/harbor-exporter:latest Container Release : 2.116 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:37:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:37:46 +0200 (CEST) Subject: SUSE-CU-2026:9939-1: Recommended update of private-registry/harbor-jobservice Message-ID: <20260911073746.BE803FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9939-1 Container Tags : private-registry/harbor-jobservice:1.1.3 , private-registry/harbor-jobservice:1.1.3-2.115 , private-registry/harbor-jobservice:latest Container Release : 2.115 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:39:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:39:59 +0200 (CEST) Subject: SUSE-CU-2026:9941-1: Recommended update of private-registry/harbor-portal Message-ID: <20260911073959.63100FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9941-1 Container Tags : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.128 , private-registry/harbor-portal:latest Container Release : 2.128 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:41:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:41:02 +0200 (CEST) Subject: SUSE-CU-2026:9943-1: Recommended update of private-registry/harbor-registry Message-ID: <20260911074102.6DA0FFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9943-1 Container Tags : private-registry/harbor-registry:1.1.3 , private-registry/harbor-registry:1.1.3-2.116 , private-registry/harbor-registry:latest Container Release : 2.116 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:43:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:43:02 +0200 (CEST) Subject: SUSE-CU-2026:9945-1: Recommended update of private-registry/harbor-registryctl Message-ID: <20260911074302.4BAA7FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9945-1 Container Tags : private-registry/harbor-registryctl:1.1.3 , private-registry/harbor-registryctl:1.1.3-2.117 , private-registry/harbor-registryctl:latest Container Release : 2.117 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:44:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:44:52 +0200 (CEST) Subject: SUSE-CU-2026:9947-1: Recommended update of private-registry/harbor-trivy-adapter Message-ID: <20260911074452.AC39AFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9947-1 Container Tags : private-registry/harbor-trivy-adapter:1.1.3 , private-registry/harbor-trivy-adapter:1.1.3-2.129 , private-registry/harbor-trivy-adapter:latest Container Release : 2.129 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:45:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:45:18 +0200 (CEST) Subject: SUSE-CU-2026:9949-1: Recommended update of private-registry/harbor-core Message-ID: <20260911074518.7F79EFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9949-1 Container Tags : private-registry/harbor-core:2.13 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5-1.69 , private-registry/harbor-core:2.13.5-1.69 , private-registry/harbor-core:latest Container Release : 1.69 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:45:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:45:43 +0200 (CEST) Subject: SUSE-CU-2026:9951-1: Recommended update of private-registry/harbor-exporter Message-ID: <20260911074543.27128FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9951-1 Container Tags : private-registry/harbor-exporter:2.13 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5-1.69 , private-registry/harbor-exporter:2.13.5-1.69 , private-registry/harbor-exporter:latest Container Release : 1.69 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 07:46:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 09:46:04 +0200 (CEST) Subject: SUSE-CU-2026:9953-1: Recommended update of private-registry/harbor-jobservice Message-ID: <20260911074604.D78F9FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9953-1 Container Tags : private-registry/harbor-jobservice:2.13 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5-1.69 , private-registry/harbor-jobservice:2.13.5-1.69 , private-registry/harbor-jobservice:latest Container Release : 1.69 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 11:50:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 13:50:12 +0200 (CEST) Subject: SUSE-IU-2026:6936-1: Security update of suse/sle-micro/base-5.5 Message-ID: <20260911115012.16EC0FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6936-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.317 , suse/sle-micro/base-5.5:latest Image Release : 5.8.317 Severity : critical Type : security References : 1257249 1261038 1268321 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4129-1 Released: Fri Sep 11 08:52:28 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. The following package changes have been done: - libzypp-17.38.15-150500.6.77.1 updated - zypper-1.14.101-150500.6.48.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:04:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:04:08 +0200 (CEST) Subject: SUSE-CU-2026:9954-1: Recommended update of private-registry/1.2/harbor-core Message-ID: <20260911120408.77824FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9954-1 Container Tags : private-registry/1.2/harbor-core:1.2.1 , private-registry/1.2/harbor-core:1.2.1-1.102 , private-registry/1.2/harbor-core:latest Container Release : 1.102 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/1.2/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:04:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:04:30 +0200 (CEST) Subject: SUSE-CU-2026:9955-1: Recommended update of private-registry/1.2/harbor-exporter Message-ID: <20260911120430.5CF54FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9955-1 Container Tags : private-registry/1.2/harbor-exporter:1.2.1 , private-registry/1.2/harbor-exporter:1.2.1-1.102 , private-registry/1.2/harbor-exporter:latest Container Release : 1.102 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/1.2/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:04:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:04:59 +0200 (CEST) Subject: SUSE-CU-2026:9956-1: Recommended update of private-registry/1.2/harbor-jobservice Message-ID: <20260911120459.AA6C5FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9956-1 Container Tags : private-registry/1.2/harbor-jobservice:1.2.1 , private-registry/1.2/harbor-jobservice:1.2.1-1.100 , private-registry/1.2/harbor-jobservice:latest Container Release : 1.100 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/1.2/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:05:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:05:26 +0200 (CEST) Subject: SUSE-CU-2026:9957-1: Recommended update of private-registry/1.2/harbor-portal Message-ID: <20260911120526.57119FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9957-1 Container Tags : private-registry/1.2/harbor-portal:1.2.1 , private-registry/1.2/harbor-portal:1.2.1-1.111 , private-registry/1.2/harbor-portal:latest Container Release : 1.111 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:05:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:05:51 +0200 (CEST) Subject: SUSE-CU-2026:9958-1: Recommended update of private-registry/1.2/harbor-registry Message-ID: <20260911120551.C8E06FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9958-1 Container Tags : private-registry/1.2/harbor-registry:1.2.1 , private-registry/1.2/harbor-registry:1.2.1-1.102 , private-registry/1.2/harbor-registry:latest Container Release : 1.102 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:06:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:06:14 +0200 (CEST) Subject: SUSE-CU-2026:9959-1: Recommended update of private-registry/1.2/harbor-registryctl Message-ID: <20260911120614.CB133FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9959-1 Container Tags : private-registry/1.2/harbor-registryctl:1.2.1 , private-registry/1.2/harbor-registryctl:1.2.1-1.102 , private-registry/1.2/harbor-registryctl:latest Container Release : 1.102 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:06:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:06:41 +0200 (CEST) Subject: SUSE-CU-2026:9960-1: Recommended update of private-registry/1.2/harbor-trivy-adapter Message-ID: <20260911120641.27FC8FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9960-1 Container Tags : private-registry/1.2/harbor-trivy-adapter:1.2.1 , private-registry/1.2/harbor-trivy-adapter:1.2.1-1.111 , private-registry/1.2/harbor-trivy-adapter:latest Container Release : 1.111 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/1.2/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:07:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:07:57 +0200 (CEST) Subject: SUSE-CU-2026:9961-1: Recommended update of private-registry/harbor-core Message-ID: <20260911120757.538C5FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9961-1 Container Tags : private-registry/harbor-core:1.1.3 , private-registry/harbor-core:1.1.3-2.116 , private-registry/harbor-core:latest Container Release : 2.116 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:09:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:09:13 +0200 (CEST) Subject: SUSE-CU-2026:9962-1: Recommended update of private-registry/harbor-exporter Message-ID: <20260911120913.278F8FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9962-1 Container Tags : private-registry/harbor-exporter:1.1.3 , private-registry/harbor-exporter:1.1.3-2.117 , private-registry/harbor-exporter:latest Container Release : 2.117 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:10:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:10:23 +0200 (CEST) Subject: SUSE-CU-2026:9963-1: Recommended update of private-registry/harbor-jobservice Message-ID: <20260911121023.28509FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9963-1 Container Tags : private-registry/harbor-jobservice:1.1.3 , private-registry/harbor-jobservice:1.1.3-2.116 , private-registry/harbor-jobservice:latest Container Release : 2.116 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:11:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:11:33 +0200 (CEST) Subject: SUSE-CU-2026:9964-1: Recommended update of private-registry/harbor-portal Message-ID: <20260911121133.75BF9FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9964-1 Container Tags : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.129 , private-registry/harbor-portal:latest Container Release : 2.129 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:12:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:12:07 +0200 (CEST) Subject: SUSE-CU-2026:9965-1: Recommended update of private-registry/harbor-registry Message-ID: <20260911121207.8F456FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9965-1 Container Tags : private-registry/harbor-registry:1.1.3 , private-registry/harbor-registry:1.1.3-2.117 , private-registry/harbor-registry:latest Container Release : 2.117 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:13:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:13:12 +0200 (CEST) Subject: SUSE-CU-2026:9966-1: Recommended update of private-registry/harbor-registryctl Message-ID: <20260911121312.C6AE3FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9966-1 Container Tags : private-registry/harbor-registryctl:1.1.3 , private-registry/harbor-registryctl:1.1.3-2.118 , private-registry/harbor-registryctl:latest Container Release : 2.118 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:14:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:14:24 +0200 (CEST) Subject: SUSE-CU-2026:9967-1: Recommended update of private-registry/harbor-trivy-adapter Message-ID: <20260911121424.4A57FFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9967-1 Container Tags : private-registry/harbor-trivy-adapter:1.1.3 , private-registry/harbor-trivy-adapter:1.1.3-2.130 , private-registry/harbor-trivy-adapter:latest Container Release : 2.130 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:14:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:14:43 +0200 (CEST) Subject: SUSE-CU-2026:9968-1: Recommended update of private-registry/harbor-core Message-ID: <20260911121443.65904FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9968-1 Container Tags : private-registry/harbor-core:2.13 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5-1.70 , private-registry/harbor-core:2.13.5-1.70 , private-registry/harbor-core:latest Container Release : 1.70 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:15:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:15:00 +0200 (CEST) Subject: SUSE-CU-2026:9969-1: Recommended update of private-registry/harbor-exporter Message-ID: <20260911121500.6635FFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9969-1 Container Tags : private-registry/harbor-exporter:2.13 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5-1.70 , private-registry/harbor-exporter:2.13.5-1.70 , private-registry/harbor-exporter:latest Container Release : 1.70 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:15:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:15:16 +0200 (CEST) Subject: SUSE-CU-2026:9970-1: Recommended update of private-registry/harbor-jobservice Message-ID: <20260911121516.4D20DFF1E@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9970-1 Container Tags : private-registry/harbor-jobservice:2.13 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5-1.70 , private-registry/harbor-jobservice:2.13.5-1.70 , private-registry/harbor-jobservice:latest Container Release : 1.70 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:15:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:15:15 +0200 (CEST) Subject: SUSE-CU-2026:9953-1: Recommended update of private-registry/harbor-jobservice Message-ID: <20260911121515.71E60FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9953-1 Container Tags : private-registry/harbor-jobservice:2.13 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5-1.69 , private-registry/harbor-jobservice:2.13.5-1.69 , private-registry/harbor-jobservice:latest Container Release : 1.69 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:15:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:15:35 +0200 (CEST) Subject: SUSE-CU-2026:9972-1: Recommended update of private-registry/harbor-portal Message-ID: <20260911121535.939ABFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9972-1 Container Tags : private-registry/harbor-portal:2.13 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5-1.74 , private-registry/harbor-portal:2.13.5-1.74 , private-registry/harbor-portal:latest Container Release : 1.74 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:15:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:15:36 +0200 (CEST) Subject: SUSE-CU-2026:9973-1: Recommended update of private-registry/harbor-portal Message-ID: <20260911121536.87402FF1E@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9973-1 Container Tags : private-registry/harbor-portal:2.13 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5-1.75 , private-registry/harbor-portal:2.13.5-1.75 , private-registry/harbor-portal:latest Container Release : 1.75 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:42:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:42:10 +0200 (CEST) Subject: SUSE-CU-2026:9973-1: Recommended update of private-registry/harbor-portal Message-ID: <20260911124210.0B333FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9973-1 Container Tags : private-registry/harbor-portal:2.13 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5-1.75 , private-registry/harbor-portal:2.13.5-1.75 , private-registry/harbor-portal:latest Container Release : 1.75 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:42:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:42:28 +0200 (CEST) Subject: SUSE-CU-2026:9975-1: Recommended update of private-registry/harbor-registry Message-ID: <20260911124228.CF4FFFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9975-1 Container Tags : private-registry/harbor-registry:2.8.3 , private-registry/harbor-registry:2.8.3-1.70 , private-registry/harbor-registry:latest Container Release : 1.70 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:42:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:42:29 +0200 (CEST) Subject: SUSE-CU-2026:9976-1: Recommended update of private-registry/harbor-registry Message-ID: <20260911124229.C69CFFF1E@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9976-1 Container Tags : private-registry/harbor-registry:2.8.3 , private-registry/harbor-registry:2.8.3-1.71 , private-registry/harbor-registry:latest Container Release : 1.71 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:42:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:42:47 +0200 (CEST) Subject: SUSE-CU-2026:9979-1: Recommended update of private-registry/harbor-registryctl Message-ID: <20260911124247.E7E48FF1E@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9979-1 Container Tags : private-registry/harbor-registryctl:2.13 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5-1.70 , private-registry/harbor-registryctl:2.13.5-1.70 , private-registry/harbor-registryctl:latest Container Release : 1.70 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:42:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:42:47 +0200 (CEST) Subject: SUSE-CU-2026:9978-1: Recommended update of private-registry/harbor-registryctl Message-ID: <20260911124247.38CBFFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9978-1 Container Tags : private-registry/harbor-registryctl:2.13 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5-1.69 , private-registry/harbor-registryctl:2.13.5-1.69 , private-registry/harbor-registryctl:latest Container Release : 1.69 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:43:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:43:05 +0200 (CEST) Subject: SUSE-CU-2026:9981-1: Recommended update of private-registry/harbor-trivy-adapter Message-ID: <20260911124305.737F9FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9981-1 Container Tags : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.73 , private-registry/harbor-trivy-adapter:latest Container Release : 1.73 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:43:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:43:06 +0200 (CEST) Subject: SUSE-CU-2026:9982-1: Recommended update of private-registry/harbor-trivy-adapter Message-ID: <20260911124306.4642CFF1E@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9982-1 Container Tags : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.74 , private-registry/harbor-trivy-adapter:latest Container Release : 1.74 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:45:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:45:28 +0200 (CEST) Subject: SUSE-CU-2026:9983-1: Security update of suse/sle-micro/5.5/toolbox Message-ID: <20260911124528.D5F6CFBAA@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9983-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.194 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.194 Severity : critical Type : security References : 1257249 1261038 1268321 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4129-1 Released: Fri Sep 11 08:52:28 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. The following package changes have been done: - libzypp-17.38.15-150500.6.77.1 updated - zypper-1.14.101-150500.6.48.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 12:47:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 14:47:56 +0200 (CEST) Subject: SUSE-IU-2026:6940-1: Recommended update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260911124756.A303FFBAA@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6940-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.247 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.247 Severity : moderate Type : recommended References : 1275219 1277106 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 893 Released: Thu Sep 10 12:31:25 2026 Summary: Recommended update for sg3_utils Type: recommended Severity: moderate References: 1277106 This update for sg3_utils fixes the following issues: - Update to version 1.48~20221101+3.9463741: * sg_inq: avoid including 0-bytes in SCSI name strings (bsc#1277106) ----------------------------------------------------------------- Advisory ID: 894 Released: Thu Sep 10 14:38:28 2026 Summary: Recommended update for selinux-policy Type: recommended Severity: moderate References: 1275219 This update for selinux-policy fixes the following issues: - Fix: SELinux denials during bees service startup / stop (bsc#1275219): * named filetrans for netconfig * Fix regression that was introduced with fix_unconfined patch The following package changes have been done: - libsgutils2-1_48-2-1.48~20221101+3.9463741-1.1 updated - sg3_utils-1.48~20221101+3.9463741-1.1 updated - selinux-policy-20230523+git37.6a385191c-1.1 updated - selinux-policy-targeted-20230523+git37.6a385191c-1.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 13:01:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 15:01:47 +0200 (CEST) Subject: SUSE-IU-2026:6942-1: Recommended update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260911130147.D4B88FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6942-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.170 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.170 Severity : moderate Type : recommended References : 1265267 1277106 CVE-2026-44431 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 722 Released: Thu Sep 10 12:43:52 2026 Summary: Recommended update for sg3_utils Type: recommended Severity: moderate References: 1265267,1277106,CVE-2026-44431 This update for sg3_utils fixes the following issues: - Update to version 1.48~20221101+3.9463741: * sg_inq: avoid including 0-bytes in SCSI name strings (bsc#1277106) The following package changes have been done: - libsgutils2-1_48-2-1.48~20221101+3.9463741-slfo.1.1_1.1 updated - sg3_utils-1.48~20221101+3.9463741-slfo.1.1_1.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 13:01:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 15:01:48 +0200 (CEST) Subject: SUSE-IU-2026:6943-1: Recommended update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260911130148.BF436FF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6943-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.171 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.171 Severity : moderate Type : recommended References : 1249964 1259438 1261280 1275219 CVE-2026-34743 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 723 Released: Thu Sep 10 16:21:35 2026 Summary: Recommended update for selinux-policy Type: recommended Severity: moderate References: 1249964,1259438,1261280,1275219,CVE-2026-34743 This update for selinux-policy fixes the following issues: - Fix: SELinux denials during bees service startup / stop (bsc#1275219): * named filetrans for netconfig * Fix regression that was introduced with fix_unconfined patch - Allow cloud init to domtrans into ssh keygen (bsc#1249964) - Make stalld stalld_var_run_t labeling rules more generic (bsc#1259438) The following package changes have been done: - selinux-policy-20241031+git24.fd2ea411a-slfo.1.1_1.1 updated - selinux-policy-targeted-20241031+git24.fd2ea411a-slfo.1.1_1.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 13:16:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 15:16:16 +0200 (CEST) Subject: SUSE-IU-2026:6947-1: Recommended update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260911131616.92EEDFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6947-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.136 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.136 Severity : important Type : recommended References : 1239787 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1658 Released: Thu Sep 10 15:05:39 2026 Summary: Recommended update for openldap2_6 Type: recommended Severity: important References: 1239787 This update for openldap2_6 fixes the following issues: Changes in openldap2_6: - Update to version 2.6.13+157: * Add export symbols related to LDAP_CONNECTIONLESS * Clear after free: + Cleaning up memory and immediately erasing the pointer's memory address * prevent double free: + Ensuring the application never releases the exact same block of memory twice * liblber calloc: + OpenLDAP's specialized memory allocator that automatically wipes memory clean * Fix: openldap2_5: segfault when try to add bad escaped regex (bsc#1239787): + prevent double free in info rewrite * Set default ldapi path to be consistent for SUSE * guide.html file cherry-picked from https://src.opensuse.org/jengelh/openldap2/src/branch/master/openldap-2.6.8.tgz * Use OpenSSL API to verify host * Change malloc to use calloc to prevent memory reuse corruption * Return to release engineering The following package changes have been done: - libldap-data-2.6.13+157-160000.1.1 updated - libldap-2-2.6.13+157-160000.1.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-1573ccc244b323da9be0715737b7ecdc235b0b54fed957128669646f9acb59d2-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 13:24:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 15:24:37 +0200 (CEST) Subject: SUSE-IU-2026:6952-1: Recommended update of suse/sl-micro/6.2/base-os-container Message-ID: <20260911132437.8B04AFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6952-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.71 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.71 Severity : important Type : recommended References : 1239787 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1658 Released: Thu Sep 10 15:05:39 2026 Summary: Recommended update for openldap2_6 Type: recommended Severity: important References: 1239787 This update for openldap2_6 fixes the following issues: Changes in openldap2_6: - Update to version 2.6.13+157: * Add export symbols related to LDAP_CONNECTIONLESS * Clear after free: + Cleaning up memory and immediately erasing the pointer's memory address * prevent double free: + Ensuring the application never releases the exact same block of memory twice * liblber calloc: + OpenLDAP's specialized memory allocator that automatically wipes memory clean * Fix: openldap2_5: segfault when try to add bad escaped regex (bsc#1239787): + prevent double free in info rewrite * Set default ldapi path to be consistent for SUSE * guide.html file cherry-picked from https://src.opensuse.org/jengelh/openldap2/src/branch/master/openldap-2.6.8.tgz * Use OpenSSL API to verify host * Change malloc to use calloc to prevent memory reuse corruption * Return to release engineering The following package changes have been done: - libldap-data-2.6.13+157-160000.1.1 updated - libldap-2-2.6.13+157-160000.1.1 updated - container:bci-bci-base-16.0-ba19ab26c38c827cb76e92649f115190dc2824ebd0091bab164a09a136131311-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 13:32:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 15:32:00 +0200 (CEST) Subject: SUSE-IU-2026:6956-1: Recommended update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260911133200.3E467FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6956-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.119 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.119 Severity : important Type : recommended References : 1239787 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1658 Released: Thu Sep 10 15:05:39 2026 Summary: Recommended update for openldap2_6 Type: recommended Severity: important References: 1239787 This update for openldap2_6 fixes the following issues: Changes in openldap2_6: - Update to version 2.6.13+157: * Add export symbols related to LDAP_CONNECTIONLESS * Clear after free: + Cleaning up memory and immediately erasing the pointer's memory address * prevent double free: + Ensuring the application never releases the exact same block of memory twice * liblber calloc: + OpenLDAP's specialized memory allocator that automatically wipes memory clean * Fix: openldap2_5: segfault when try to add bad escaped regex (bsc#1239787): + prevent double free in info rewrite * Set default ldapi path to be consistent for SUSE * guide.html file cherry-picked from https://src.opensuse.org/jengelh/openldap2/src/branch/master/openldap-2.6.8.tgz * Use OpenSSL API to verify host * Change malloc to use calloc to prevent memory reuse corruption * Return to release engineering The following package changes have been done: - libldap-data-2.6.13+157-160000.1.1 updated - libldap-2-2.6.13+157-160000.1.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-1573ccc244b323da9be0715737b7ecdc235b0b54fed957128669646f9acb59d2-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 13:41:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 15:41:01 +0200 (CEST) Subject: SUSE-IU-2026:6963-1: Recommended update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260911134101.45235FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6963-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.156 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.156 Severity : important Type : recommended References : 1239787 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1658 Released: Thu Sep 10 15:05:39 2026 Summary: Recommended update for openldap2_6 Type: recommended Severity: important References: 1239787 This update for openldap2_6 fixes the following issues: Changes in openldap2_6: - Update to version 2.6.13+157: * Add export symbols related to LDAP_CONNECTIONLESS * Clear after free: + Cleaning up memory and immediately erasing the pointer's memory address * prevent double free: + Ensuring the application never releases the exact same block of memory twice * liblber calloc: + OpenLDAP's specialized memory allocator that automatically wipes memory clean * Fix: openldap2_5: segfault when try to add bad escaped regex (bsc#1239787): + prevent double free in info rewrite * Set default ldapi path to be consistent for SUSE * guide.html file cherry-picked from https://src.opensuse.org/jengelh/openldap2/src/branch/master/openldap-2.6.8.tgz * Use OpenSSL API to verify host * Change malloc to use calloc to prevent memory reuse corruption * Return to release engineering The following package changes have been done: - libldap-data-2.6.13+157-160000.1.1 updated - libldap-2-2.6.13+157-160000.1.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-23b124eeef46fea717e68a56119b1bd2d07eeb67083c293b1d5eff11efe14336-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 13:51:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 15:51:42 +0200 (CEST) Subject: SUSE-CU-2026:9995-1: Recommended update of suse/ltss/sle15.6/bci-base-fips Message-ID: <20260911135142.59CDAFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9995-1 Container Tags : suse/ltss/sle15.6/bci-base-fips:15.6 , suse/ltss/sle15.6/bci-base-fips:15.6-35.101 , suse/ltss/sle15.6/bci-base-fips:latest Container Release : 35.101 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container suse/ltss/sle15.6/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:sles15-ltss-image-15.6.0-5.92 updated From sle-container-updates at lists.suse.com Fri Sep 11 13:54:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 15:54:01 +0200 (CEST) Subject: SUSE-CU-2026:9996-1: Recommended update of suse/ltss/sle15.6/sle15 Message-ID: <20260911135401.D9472FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9996-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.92 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.92 , suse/ltss/sle15.6/sle15:latest Container Release : 5.92 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 13:55:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 15:55:04 +0200 (CEST) Subject: SUSE-CU-2026:9997-1: Recommended update of bci/dotnet-aspnet Message-ID: <20260911135504.27A26FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9997-1 Container Tags : bci/dotnet-aspnet:10.0 , bci/dotnet-aspnet:10.0-sles15 , bci/dotnet-aspnet:10.0.12 , bci/dotnet-aspnet:10.0.12-29.3 , bci/dotnet-aspnet:latest Container Release : 29.3 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 13:55:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 15:55:05 +0200 (CEST) Subject: SUSE-CU-2026:9998-1: Recommended update of bci/dotnet-aspnet Message-ID: <20260911135505.4615BFF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9998-1 Container Tags : bci/dotnet-aspnet:10.0 , bci/dotnet-aspnet:10.0-sles15 , bci/dotnet-aspnet:10.0.12 , bci/dotnet-aspnet:10.0.12-29.5 , bci/dotnet-aspnet:latest Container Release : 29.5 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 13:56:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 15:56:18 +0200 (CEST) Subject: SUSE-CU-2026:9999-1: Recommended update of bci/dotnet-aspnet Message-ID: <20260911135618.724B4FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9999-1 Container Tags : bci/dotnet-aspnet:8.0 , bci/dotnet-aspnet:8.0-sles15 , bci/dotnet-aspnet:8.0.31 , bci/dotnet-aspnet:8.0.31-99.3 Container Release : 99.3 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 13:56:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 15:56:19 +0200 (CEST) Subject: SUSE-CU-2026:10000-1: Recommended update of bci/dotnet-aspnet Message-ID: <20260911135619.8ADF4FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10000-1 Container Tags : bci/dotnet-aspnet:8.0 , bci/dotnet-aspnet:8.0-sles15 , bci/dotnet-aspnet:8.0.31 , bci/dotnet-aspnet:8.0.31-99.5 Container Release : 99.5 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:30:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:30:35 +0200 (CEST) Subject: SUSE-CU-2026:10000-1: Recommended update of bci/dotnet-aspnet Message-ID: <20260911143035.A85E2FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10000-1 Container Tags : bci/dotnet-aspnet:8.0 , bci/dotnet-aspnet:8.0-sles15 , bci/dotnet-aspnet:8.0.31 , bci/dotnet-aspnet:8.0.31-99.5 Container Release : 99.5 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:31:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:31:40 +0200 (CEST) Subject: SUSE-CU-2026:10001-1: Recommended update of bci/dotnet-aspnet Message-ID: <20260911143140.92CAAFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10001-1 Container Tags : bci/dotnet-aspnet:9.0 , bci/dotnet-aspnet:9.0-sles15 , bci/dotnet-aspnet:9.0.20 , bci/dotnet-aspnet:9.0.20-58.3 Container Release : 58.3 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:31:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:31:41 +0200 (CEST) Subject: SUSE-CU-2026:10002-1: Recommended update of bci/dotnet-aspnet Message-ID: <20260911143141.A6305FF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10002-1 Container Tags : bci/dotnet-aspnet:9.0 , bci/dotnet-aspnet:9.0-sles15 , bci/dotnet-aspnet:9.0.20 , bci/dotnet-aspnet:9.0.20-58.5 Container Release : 58.5 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:32:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:32:47 +0200 (CEST) Subject: SUSE-CU-2026:10003-1: Recommended update of bci/bci-base-fips Message-ID: <20260911143247.00CAAFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10003-1 Container Tags : bci/bci-base-fips:15.7 , bci/bci-base-fips:15.7-23.6 , bci/bci-base-fips:latest Container Release : 23.6 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:33:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:33:06 +0200 (CEST) Subject: SUSE-CU-2026:10004-1: Recommended update of bci/bci-busybox Message-ID: <20260911143306.E2C6DFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-busybox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10004-1 Container Tags : bci/bci-busybox:15.7 , bci/bci-busybox:15.7-25.25 , bci/bci-busybox:latest Container Release : 25.25 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/bci-busybox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:33:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:33:56 +0200 (CEST) Subject: SUSE-CU-2026:10005-1: Recommended update of bci/dotnet-sdk Message-ID: <20260911143356.3C595FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10005-1 Container Tags : bci/dotnet-sdk:10.0 , bci/dotnet-sdk:10.0-sles15 , bci/dotnet-sdk:10.0.12 , bci/dotnet-sdk:10.0.12-29.3 , bci/dotnet-sdk:latest Container Release : 29.3 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:33:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:33:57 +0200 (CEST) Subject: SUSE-CU-2026:10006-1: Recommended update of bci/dotnet-sdk Message-ID: <20260911143357.4F095FF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10006-1 Container Tags : bci/dotnet-sdk:10.0 , bci/dotnet-sdk:10.0-sles15 , bci/dotnet-sdk:10.0.12 , bci/dotnet-sdk:10.0.12-29.5 , bci/dotnet-sdk:latest Container Release : 29.5 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:35:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:35:13 +0200 (CEST) Subject: SUSE-CU-2026:10007-1: Recommended update of bci/dotnet-sdk Message-ID: <20260911143513.D039BFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10007-1 Container Tags : bci/dotnet-sdk:8.0 , bci/dotnet-sdk:8.0-sles15 , bci/dotnet-sdk:8.0.31 , bci/dotnet-sdk:8.0.31-99.3 Container Release : 99.3 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:35:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:35:14 +0200 (CEST) Subject: SUSE-CU-2026:10008-1: Recommended update of bci/dotnet-sdk Message-ID: <20260911143514.E052CFF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10008-1 Container Tags : bci/dotnet-sdk:8.0 , bci/dotnet-sdk:8.0-sles15 , bci/dotnet-sdk:8.0.31 , bci/dotnet-sdk:8.0.31-99.5 Container Release : 99.5 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:36:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:36:43 +0200 (CEST) Subject: SUSE-CU-2026:10009-1: Recommended update of bci/dotnet-sdk Message-ID: <20260911143643.EB1A1FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10009-1 Container Tags : bci/dotnet-sdk:9.0 , bci/dotnet-sdk:9.0-sles15 , bci/dotnet-sdk:9.0.20 , bci/dotnet-sdk:9.0.20-59.3 Container Release : 59.3 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:36:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:36:45 +0200 (CEST) Subject: SUSE-CU-2026:10010-1: Recommended update of bci/dotnet-sdk Message-ID: <20260911143645.207F0FF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10010-1 Container Tags : bci/dotnet-sdk:9.0 , bci/dotnet-sdk:9.0-sles15 , bci/dotnet-sdk:9.0.20 , bci/dotnet-sdk:9.0.20-59.5 Container Release : 59.5 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:37:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:37:44 +0200 (CEST) Subject: SUSE-CU-2026:10011-1: Recommended update of bci/dotnet-runtime Message-ID: <20260911143744.CCAFCFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10011-1 Container Tags : bci/dotnet-runtime:10.0 , bci/dotnet-runtime:10.0-sles15 , bci/dotnet-runtime:10.0.12 , bci/dotnet-runtime:10.0.12-29.3 , bci/dotnet-runtime:latest Container Release : 29.3 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:37:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:37:45 +0200 (CEST) Subject: SUSE-CU-2026:10012-1: Recommended update of bci/dotnet-runtime Message-ID: <20260911143745.B856AFF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10012-1 Container Tags : bci/dotnet-runtime:10.0 , bci/dotnet-runtime:10.0-sles15 , bci/dotnet-runtime:10.0.12 , bci/dotnet-runtime:10.0.12-29.5 , bci/dotnet-runtime:latest Container Release : 29.5 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:39:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:39:05 +0200 (CEST) Subject: SUSE-CU-2026:10013-1: Recommended update of bci/dotnet-runtime Message-ID: <20260911143905.A0CE7FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10013-1 Container Tags : bci/dotnet-runtime:8.0 , bci/dotnet-runtime:8.0-sles15 , bci/dotnet-runtime:8.0.31 , bci/dotnet-runtime:8.0.31-99.3 Container Release : 99.3 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:39:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:39:06 +0200 (CEST) Subject: SUSE-CU-2026:10014-1: Recommended update of bci/dotnet-runtime Message-ID: <20260911143906.A8EB4FF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10014-1 Container Tags : bci/dotnet-runtime:8.0 , bci/dotnet-runtime:8.0-sles15 , bci/dotnet-runtime:8.0.31 , bci/dotnet-runtime:8.0.31-99.5 Container Release : 99.5 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:40:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:40:15 +0200 (CEST) Subject: SUSE-CU-2026:10015-1: Recommended update of bci/dotnet-runtime Message-ID: <20260911144015.936D4FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10015-1 Container Tags : bci/dotnet-runtime:9.0 , bci/dotnet-runtime:9.0-sles15 , bci/dotnet-runtime:9.0.20 , bci/dotnet-runtime:9.0.20-58.3 Container Release : 58.3 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:40:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:40:16 +0200 (CEST) Subject: SUSE-CU-2026:10016-1: Recommended update of bci/dotnet-runtime Message-ID: <20260911144016.9732DFF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10016-1 Container Tags : bci/dotnet-runtime:9.0 , bci/dotnet-runtime:9.0-sles15 , bci/dotnet-runtime:9.0.20 , bci/dotnet-runtime:9.0.20-58.5 Container Release : 58.5 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:40:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:40:20 +0200 (CEST) Subject: SUSE-CU-2026:10017-1: Recommended update of bci/golang Message-ID: <20260911144020.B9E46FF46@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10017-1 Container Tags : bci/golang:1.25 , bci/golang:1.25-sles15 , bci/golang:1.25.14 , bci/golang:1.25.14-3.72.9 , bci/golang:oldoldstable Container Release : 72.9 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 1277247 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - glibc-2.38-150600.14.55.1 updated - glibc-devel-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:41:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:41:22 +0200 (CEST) Subject: SUSE-CU-2026:10018-1: Recommended update of bci/golang Message-ID: <20260911144122.58209FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10018-1 Container Tags : bci/golang:1.26 , bci/golang:1.26-sles15 , bci/golang:1.26.8 , bci/golang:1.26.8-2.73.10 , bci/golang:oldstable Container Release : 73.10 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 1277247 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - glibc-2.38-150600.14.55.1 updated - glibc-devel-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:42:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:42:36 +0200 (CEST) Subject: SUSE-CU-2026:9919-1: Security update of bci/golang Message-ID: <20260911144236.37EDBFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9919-1 Container Tags : bci/golang:1.25-openssl , bci/golang:1.25-sles15-openssl , bci/golang:1.25.14-openssl , bci/golang:1.25.14-openssl-90.8 , bci/golang:oldstable-openssl Container Release : 90.8 Severity : important Type : security References : 1266343 1266786 1269489 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - libopenssl-3-devel-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 14:42:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 16:42:38 +0200 (CEST) Subject: SUSE-CU-2026:10020-1: Recommended update of bci/golang Message-ID: <20260911144238.1BAEDFF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10020-1 Container Tags : bci/golang:1.25-openssl , bci/golang:1.25-sles15-openssl , bci/golang:1.25.14-openssl , bci/golang:1.25.14-openssl-90.12 , bci/golang:oldstable-openssl Container Release : 90.12 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 1277247 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - glibc-devel-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:15:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:15:52 +0200 (CEST) Subject: SUSE-CU-2026:10026-1: Security update of suse/ltss/sle15.5/sle15 Message-ID: <20260911161552.17E3DFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.5/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10026-1 Container Tags : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.70 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.70 , suse/ltss/sle15.5/sle15:latest Container Release : 8.70 Severity : critical Type : security References : 1257249 1261038 1268321 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4129-1 Released: Fri Sep 11 08:52:28 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. The following package changes have been done: - libzypp-17.38.15-150500.6.77.1 updated - zypper-1.14.101-150500.6.48.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:20:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:20:19 +0200 (CEST) Subject: SUSE-CU-2026:10020-1: Recommended update of bci/golang Message-ID: <20260911162019.3438EFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10020-1 Container Tags : bci/golang:1.25-openssl , bci/golang:1.25-sles15-openssl , bci/golang:1.25.14-openssl , bci/golang:1.25.14-openssl-90.12 , bci/golang:oldstable-openssl Container Release : 90.12 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 1277247 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - glibc-devel-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:21:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:21:49 +0200 (CEST) Subject: SUSE-CU-2026:10028-1: Security update of bci/golang Message-ID: <20260911162149.A885CFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10028-1 Container Tags : bci/golang:1.27 , bci/golang:1.27-sles15 , bci/golang:1.27.1 , bci/golang:1.27.1-1.73.5 , bci/golang:latest , bci/golang:stable Container Release : 73.5 Severity : important Type : security References : 1266343 1266786 1269489 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - go1.27-doc-1.27.1-150000.1.9.1 updated - go1.27-1.27.1-150000.1.9.1 updated - go1.27-race-1.27.1-150000.1.9.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:21:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:21:51 +0200 (CEST) Subject: SUSE-CU-2026:10030-1: Recommended update of bci/golang Message-ID: <20260911162151.B2860FF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10030-1 Container Tags : bci/golang:1.27 , bci/golang:1.27-sles15 , bci/golang:1.27.1 , bci/golang:1.27.1-1.73.10 , bci/golang:latest , bci/golang:stable Container Release : 73.10 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 1277247 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - glibc-2.38-150600.14.55.1 updated - glibc-devel-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:23:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:23:56 +0200 (CEST) Subject: SUSE-CU-2026:10031-1: Security update of bci/golang Message-ID: <20260911162356.F28E4FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10031-1 Container Tags : bci/golang:1.26-openssl , bci/golang:1.26-sles15-openssl , bci/golang:1.26.7-openssl , bci/golang:1.26.7-openssl-90.8 , bci/golang:latest , bci/golang:stable-openssl Container Release : 90.8 Severity : important Type : security References : 1266343 1266786 1269489 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - libopenssl-3-devel-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:23:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:23:59 +0200 (CEST) Subject: SUSE-CU-2026:10033-1: Recommended update of bci/golang Message-ID: <20260911162359.C517DFF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10033-1 Container Tags : bci/golang:1.26-openssl , bci/golang:1.26-sles15-openssl , bci/golang:1.26.7-openssl , bci/golang:1.26.7-openssl-90.11 , bci/golang:latest , bci/golang:stable-openssl Container Release : 90.11 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:24:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:24:01 +0200 (CEST) Subject: SUSE-CU-2026:10034-1: Recommended update of bci/golang Message-ID: <20260911162401.9DD99FF46@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10034-1 Container Tags : bci/golang:1.26-openssl , bci/golang:1.26-sles15-openssl , bci/golang:1.26.7-openssl , bci/golang:1.26.7-openssl-90.13 , bci/golang:latest , bci/golang:stable-openssl Container Release : 90.13 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - glibc-devel-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:24:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:24:06 +0200 (CEST) Subject: SUSE-CU-2026:10035-1: Recommended update of suse/hpc/warewulf4-x86_64/sle-hpc-node Message-ID: <20260911162406.1B67FFF48@maintenance.suse.de> SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10035-1 Container Tags : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7.20.8.152 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest Container Release : 20.8.152 Severity : important Type : recommended References : 1274740 ----------------------------------------------------------------- The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr The following package changes have been done: - container-suseconnect-2.6.0-150700.4.97.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:24:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:24:08 +0200 (CEST) Subject: SUSE-CU-2026:10036-1: Security update of suse/hpc/warewulf4-x86_64/sle-hpc-node Message-ID: <20260911162408.2DA04FF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10036-1 Container Tags : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7.20.8.153 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest Container Release : 20.8.153 Severity : important Type : security References : 1266343 1269489 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1274856 1274857 1274858 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-75803 ----------------------------------------------------------------- The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - cpio-2.13-150400.3.10.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - openssl-3-3.5.0-150700.5.50.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:24:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:24:10 +0200 (CEST) Subject: SUSE-CU-2026:10037-1: Security update of suse/hpc/warewulf4-x86_64/sle-hpc-node Message-ID: <20260911162410.78D27FF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10037-1 Container Tags : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7.20.8.154 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest Container Release : 20.8.154 Severity : moderate Type : security References : 1266664 1266786 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-23679 CVE-2026-42250 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - curl-8.14.1-150700.7.26.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:24:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:24:12 +0200 (CEST) Subject: SUSE-CU-2026:10038-1: Security update of suse/hpc/warewulf4-x86_64/sle-hpc-node Message-ID: <20260911162412.6CA1AFF46@maintenance.suse.de> SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10038-1 Container Tags : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7.20.8.158 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest Container Release : 20.8.158 Severity : critical Type : security References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1257249 1258311 1259825 1261038 1262315 1268321 1271730 1272534 1273242 1274091 1274625 1275660 1277790 ----------------------------------------------------------------- The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4092-1 Released: Tue Sep 8 18:31:37 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - container-suseconnect-2.6.0-150700.4.97.2 updated - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - libzypp-17.38.15-150700.6.16.1 updated - zypper-1.14.101-150700.13.9.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:24:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:24:14 +0200 (CEST) Subject: SUSE-CU-2026:10039-1: Recommended update of suse/hpc/warewulf4-x86_64/sle-hpc-node Message-ID: <20260911162414.5F581FF4B@maintenance.suse.de> SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10039-1 Container Tags : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7.20.8.161 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest Container Release : 20.8.161 Severity : moderate Type : recommended References : 1273300 1277247 1278351 ----------------------------------------------------------------- The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - glibc-locale-base-2.38-150600.14.55.1 updated - glibc-2.38-150600.14.55.1 updated - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:25:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:25:59 +0200 (CEST) Subject: SUSE-CU-2026:10040-1: Security update of bci/bci-init Message-ID: <20260911162559.8E077FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10040-1 Container Tags : bci/bci-init:15.7 , bci/bci-init:15.7-53.43 , bci/bci-init:latest Container Release : 53.43 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1274856 1274857 1274858 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-75803 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - cpio-2.13-150400.3.10.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:26:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:26:02 +0200 (CEST) Subject: SUSE-CU-2026:10042-1: Recommended update of bci/bci-init Message-ID: <20260911162602.A5D31FF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10042-1 Container Tags : bci/bci-init:15.7 , bci/bci-init:15.7-53.46 , bci/bci-init:latest Container Release : 53.46 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:26:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:26:04 +0200 (CEST) Subject: SUSE-CU-2026:10043-1: Recommended update of bci/bci-init Message-ID: <20260911162604.75868FF46@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10043-1 Container Tags : bci/bci-init:15.7 , bci/bci-init:15.7-53.48 , bci/bci-init:latest Container Release : 53.48 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:27:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:27:58 +0200 (CEST) Subject: SUSE-CU-2026:10047-1: Recommended update of suse/kea Message-ID: <20260911162758.06FECFF46@maintenance.suse.de> SUSE Container Update Advisory: suse/kea ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10047-1 Container Tags : suse/kea:2.6 , suse/kea:2.6-79.30 Container Release : 79.30 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/kea was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:27:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:27:53 +0200 (CEST) Subject: SUSE-CU-2026:10044-1: Security update of suse/kea Message-ID: <20260911162753.AC528FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/kea ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10044-1 Container Tags : suse/kea:2.6 , suse/kea:2.6-79.22 Container Release : 79.22 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275001 1275002 1275042 1275043 1275044 1275046 1275047 1275048 1275049 1275050 1275051 1275052 1275053 1275054 1275055 1275056 1275057 1275058 1275059 1275060 1275061 1275062 1275063 1275064 1275065 1275066 1275067 1275068 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14676 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681 CVE-2026-15741 CVE-2026-15742 CVE-2026-16238 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-18798 CVE-2026-19385 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container suse/kea was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4014-1 Released: Mon Sep 7 09:36:08 2026 Summary: Security update for postgresql18 Type: security Severity: important References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275052,1275053,1275054,1275055,1275056,1275057,1275058,1275059,1275060,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14676,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-14681,CVE-2026-15741,CVE-2026-15742,CVE-2026-16238,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471 This update for postgresql18 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql18: - Update to version 18.6: * https://www.postgresql.org/docs/18/release-18-6.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - libpq5-18.6-150600.13.16.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - coreutils-8.32-150400.9.12.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - sles-release-15.7-150700.67.6.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Fri Sep 11 16:27:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:27:55 +0200 (CEST) Subject: SUSE-CU-2026:10045-1: Recommended update of suse/kea Message-ID: <20260911162755.34ACEFF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/kea ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10045-1 Container Tags : suse/kea:2.6 , suse/kea:2.6-79.26 Container Release : 79.26 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/kea was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:30:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:30:28 +0200 (CEST) Subject: SUSE-CU-2026:10048-1: Security update of suse/kiosk/firefox-esr Message-ID: <20260911163028.E8DEBFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10048-1 Container Tags : suse/kiosk/firefox-esr:140.14 , suse/kiosk/firefox-esr:140.14-75.25 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.25 Severity : important Type : security References : 1266343 1266664 1266786 1269489 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1274856 1274857 1274858 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-23679 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - cpio-2.13-150400.3.10.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - coreutils-8.32-150400.9.12.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - sles-release-15.7-150700.67.6.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Fri Sep 11 16:30:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:30:30 +0200 (CEST) Subject: SUSE-CU-2026:10049-1: Recommended update of suse/kiosk/firefox-esr Message-ID: <20260911163030.A226AFF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10049-1 Container Tags : suse/kiosk/firefox-esr:140.14 , suse/kiosk/firefox-esr:140.14-75.29 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.29 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Fri Sep 11 16:30:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 11 Sep 2026 18:30:33 +0200 (CEST) Subject: SUSE-CU-2026:10051-1: Recommended update of suse/kiosk/firefox-esr Message-ID: <20260911163033.8E650FF46@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10051-1 Container Tags : suse/kiosk/firefox-esr:140.14 , suse/kiosk/firefox-esr:140.14-75.33 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.33 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 12 07:16:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 09:16:18 +0200 (CEST) Subject: SUSE-IU-2026:6971-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260912071618.9DD2EFF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6971-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.138 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.138 Severity : moderate Type : security References : 1265071 1269221 CVE-2026-43895 CVE-2026-47770 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1662 Released: Fri Sep 11 17:00:17 2026 Summary: Security update for jq Type: security Severity: moderate References: 1265071,1269221,CVE-2026-43895,CVE-2026-47770 This update for jq fixes the following issues: - CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). - CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). The following package changes have been done: - libjq1-1.7.1-160000.5.1 updated - jq-1.7.1-160000.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 12 07:16:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 09:16:21 +0200 (CEST) Subject: SUSE-IU-2026:6972-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260912071621.C1B1EFF1F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6972-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.139 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.139 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1661 Released: Fri Sep 11 13:45:57 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent The following package changes have been done: - libattr1-2.6.0-160000.1.1 updated - libacl1-2.4.0-160000.1.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-5b945e219d7dc4b1546b5377a6ad8bc9ce044f4cb6aefc6d07772e0e4c40849a-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 07:27:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 09:27:00 +0200 (CEST) Subject: SUSE-IU-2026:6976-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260912072700.751D0FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6976-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.72 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.72 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1661 Released: Fri Sep 11 13:45:57 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent The following package changes have been done: - libattr1-2.6.0-160000.1.1 updated - libacl1-2.4.0-160000.1.1 updated From sle-container-updates at lists.suse.com Sat Sep 12 07:35:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 09:35:25 +0200 (CEST) Subject: SUSE-IU-2026:6980-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260912073525.4DAD7FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6980-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.121 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.121 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1661 Released: Fri Sep 11 13:45:57 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent The following package changes have been done: - libattr1-2.6.0-160000.1.1 updated - libacl1-2.4.0-160000.1.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-5b945e219d7dc4b1546b5377a6ad8bc9ce044f4cb6aefc6d07772e0e4c40849a-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:02:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:02:41 +0200 (CEST) Subject: SUSE-CU-2026:10059-1: Recommended update of bci/bci-base-fips Message-ID: <20260912080241.660EDFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10059-1 Container Tags : bci/bci-base-fips:15.7 , bci/bci-base-fips:15.7-23.8 , bci/bci-base-fips:latest Container Release : 23.8 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container bci/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated - container:registry.suse.com-bci-bci-base-15.7-31dce1f05f6f1bd8f55a19aad195829fd37ccd11819e1dd937f55f40650512bf-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:14:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:14:48 +0200 (CEST) Subject: SUSE-CU-2026:10051-1: Recommended update of suse/kiosk/firefox-esr Message-ID: <20260912081448.6D4BEFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10051-1 Container Tags : suse/kiosk/firefox-esr:140.14 , suse/kiosk/firefox-esr:140.14-75.33 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.33 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:15:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:15:28 +0200 (CEST) Subject: SUSE-CU-2026:10067-1: Security update of suse/kubectl Message-ID: <20260912081528.CCF0DFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/kubectl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10067-1 Container Tags : suse/kubectl:1.33 , suse/kubectl:1.33.11 , suse/kubectl:1.33.11-2.70.15 , suse/kubectl:oldstable Container Release : 70.15 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container suse/kubectl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libncurses6-6.1-150000.5.33.1 removed - libreadline7-7.0-150400.27.6.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sat Sep 12 08:15:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:15:30 +0200 (CEST) Subject: SUSE-CU-2026:10068-1: Security update of suse/kubectl Message-ID: <20260912081530.22C3FFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/kubectl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10068-1 Container Tags : suse/kubectl:1.35 , suse/kubectl:1.35.4 , suse/kubectl:1.35.4-2.61.2 , suse/kubectl:oldstable Container Release : 61.2 Severity : important Type : security References : 1251168 1262270 1265748 CVE-2026-33814 CVE-2026-35469 ----------------------------------------------------------------- The container suse/kubectl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4510-1 Released: Tue Dec 23 12:24:56 2025 Summary: Recommended update for kubernetes Type: recommended Severity: moderate References: This update for kubernetes fixes the following issues: - Update to version 1.35.0: initial package for Kubernetes v1.35.0 * Full changelog - https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1350 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:74-1 Released: Thu Jan 8 17:01:10 2026 Summary: Recommended update for kubernetes Type: recommended Severity: moderate References: 1251168 This update for kubernetes fixes the following issues: - bump `diffutils` as `Requires` in the Kubernetes*-client package (bsc#1251168) * Adding as `Recommends` didn't work - recommends do not actually get respected in container builds, as container builds are configured to install with packages marked as required. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:325-1 Released: Wed Jan 28 15:54:07 2026 Summary: Security update for kubernetes Type: security Severity: important References: This update for kubernetes rebuilds it against the current GO security release. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:572-1 Released: Tue Feb 17 19:47:05 2026 Summary: Security update for kubernetes Type: security Severity: important References: This update for kubernetes rebuilds it against the current GO security release. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:917-1 Released: Wed Mar 18 08:47:07 2026 Summary: Security update for kubernetes Type: security Severity: important References: This update for kubernetes rebuilds it against the current go 1.25 security release. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1490-1 Released: Mon Apr 20 17:54:45 2026 Summary: Security update for kubernetes Type: security Severity: important References: This update for kubernetes rebuilds it against the current go 1.25 security release. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2342-1 Released: Wed Jun 10 15:15:00 2026 Summary: Security update for kubernetes Type: security Severity: important References: 1262270,1265748,CVE-2026-33814,CVE-2026-35469 This update for kubernetes fixes the following issues - CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265748). - CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262270). Changes for kubernetes: - Update to version 1.35.4: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2942-1 Released: Tue Jul 14 08:10:15 2026 Summary: Security update for kubernetes Type: security Severity: important References: This update for kubernetes rebuilds it against the current go security release. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3660-1 Released: Thu Aug 20 20:17:13 2026 Summary: Security update for kubernetes Type: security Severity: important References: This update for kubernetes rebuilds it against the current go security release. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3824-1 Released: Wed Aug 26 13:07:49 2026 Summary: Security update for kubernetes Type: security Severity: important References: This update for kubernetes rebuilds it against the current go security release. The following package changes have been done: - kubernetes1.35-client-1.35.4-150600.13.40.1 added - kubernetes1.35-client-common-1.35.4-150600.13.40.1 added - container:suse-sle15-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated - kubernetes1.33-client-1.33.11-150600.13.38.1 removed - kubernetes1.33-client-common-1.33.11-150600.13.38.1 removed From sle-container-updates at lists.suse.com Sat Sep 12 08:16:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:16:12 +0200 (CEST) Subject: SUSE-CU-2026:10070-1: Security update of suse/kubectl Message-ID: <20260912081612.A7346FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/kubectl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10070-1 Container Tags : suse/kubectl:1.35 , suse/kubectl:1.35.4 , suse/kubectl:1.35.4-1.70.15 , suse/kubectl:latest , suse/kubectl:stable Container Release : 70.15 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container suse/kubectl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libncurses6-6.1-150000.5.33.1 removed - libreadline7-7.0-150400.27.6.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sat Sep 12 08:16:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:16:13 +0200 (CEST) Subject: SUSE-CU-2026:10071-1: Recommended update of suse/kubectl Message-ID: <20260912081613.EA2B2FF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/kubectl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10071-1 Container Tags : suse/kubectl:1.37 , suse/kubectl:1.37.0 , suse/kubectl:1.37.0-1.61.2 , suse/kubectl:latest , suse/kubectl:stable Container Release : 61.2 Severity : important Type : recommended References : 1084766 ----------------------------------------------------------------- The container suse/kubectl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3986-1 Released: Sun Sep 6 12:46:38 2026 Summary: Recommended update for kubernetes Type: recommended Severity: important References: 1084766 This update for kubernetes fixes the following issues: Update to version 1.37.0: * Full changelog - https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.37.md#v1370 The following package changes have been done: - kubernetes1.37-client-1.37.0-150600.13.43.1 added - kubernetes1.37-client-common-1.37.0-150600.13.43.1 added - container:suse-sle15-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated - kubernetes1.35-client-1.35.4-150600.13.40.1 removed - kubernetes1.35-client-common-1.35.4-150600.13.40.1 removed From sle-container-updates at lists.suse.com Sat Sep 12 08:16:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:16:55 +0200 (CEST) Subject: SUSE-CU-2026:10074-1: Recommended update of bci/bci-micro-fips Message-ID: <20260912081655.63380FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10074-1 Container Tags : bci/bci-micro-fips:15.7 , bci/bci-micro-fips:15.7-27.12 , bci/bci-micro-fips:latest Container Release : 27.12 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/bci-micro-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:bci-bci-base-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:16:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:16:54 +0200 (CEST) Subject: SUSE-CU-2026:10073-1: Security update of bci/bci-micro-fips Message-ID: <20260912081654.84F03FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10073-1 Container Tags : bci/bci-micro-fips:15.7 , bci/bci-micro-fips:15.7-27.9 , bci/bci-micro-fips:latest Container Release : 27.9 Severity : important Type : security References : 1266343 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container bci/bci-micro-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - container:bci-bci-base-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:16:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:16:56 +0200 (CEST) Subject: SUSE-CU-2026:10075-1: Recommended update of bci/bci-micro-fips Message-ID: <20260912081656.4C7E4FF24@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10075-1 Container Tags : bci/bci-micro-fips:15.7 , bci/bci-micro-fips:15.7-27.15 , bci/bci-micro-fips:latest Container Release : 27.15 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/bci-micro-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:17:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:17:26 +0200 (CEST) Subject: SUSE-CU-2026:10077-1: Recommended update of bci/bci-micro Message-ID: <20260912081726.9BC0CFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10077-1 Container Tags : bci/bci-micro:15.7 , bci/bci-micro:15.7-61.5 , bci/bci-micro:latest Container Release : 61.5 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/bci-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:18:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:18:11 +0200 (CEST) Subject: SUSE-CU-2026:10078-1: Security update of bci/bci-minimal Message-ID: <20260912081811.605F4FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-minimal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10078-1 Container Tags : bci/bci-minimal:15.7 , bci/bci-minimal:15.7-26.49 , bci/bci-minimal:latest Container Release : 26.49 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container bci/bci-minimal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:18:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:18:12 +0200 (CEST) Subject: SUSE-CU-2026:10079-1: Recommended update of bci/bci-minimal Message-ID: <20260912081812.994FBFF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-minimal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10079-1 Container Tags : bci/bci-minimal:15.7 , bci/bci-minimal:15.7-26.54 , bci/bci-minimal:latest Container Release : 26.54 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/bci-minimal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:19:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:19:34 +0200 (CEST) Subject: SUSE-CU-2026:10081-1: Security update of bci/nodejs Message-ID: <20260912081934.E386FFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10081-1 Container Tags : bci/node:22 , bci/node:22-sles15 , bci/node:22.23.2 , bci/node:22.23.2-24.43 , bci/nodejs:22 , bci/nodejs:22-sles15 , bci/nodejs:22.23.2 , bci/nodejs:22.23.2-24.43 Container Release : 24.43 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:21:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:21:05 +0200 (CEST) Subject: SUSE-CU-2026:10083-1: Security update of bci/openjdk-devel Message-ID: <20260912082105.6080CFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10083-1 Container Tags : bci/openjdk-devel:17 , bci/openjdk-devel:17-sles15 , bci/openjdk-devel:17.0.20.1 , bci/openjdk-devel:17.0.20.1-21.50 Container Release : 21.50 Severity : important Type : security References : 1266343 1266786 1273163 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1274856 1274857 1274858 1275035 1275764 1275777 1275778 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-60589 CVE-2026-61308 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-64607 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-70907 CVE-2026-75803 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4002-1 Released: Mon Sep 7 09:27:14 2026 Summary: Security update for java-17-openjdk Type: security Severity: moderate References: 1275035,1275764,1275777,1275778,CVE-2026-60589,CVE-2026-61308,CVE-2026-70907 This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.20.1+1 (August 2026 CSPU). - CVE-2026-60589: unauthenticated attacker with network access via multiple protocols can gain unauthorized read access to a subset of accessible data (bsc#1275777). - CVE-2026-61308: unauthenticated attacker with network access via HTTP can gain unauthorized access to critical data (bsc#1275778). - CVE-2026-70907: unauthenticated attacker with network access via TLS can cause a partial denial of service (bsc#1275764). Changes for java-17-openjdk: - Upgrade to upstream tag jdk-17.0.20.1+1 (August 2026 CSPU): + JDK-8389947: [17u] Remove designator `DEFAULT_PROMOTED_VERSION_PRE=ea` for release 17.0.20.1. + JDK-8333743: Change `.jcheck/conf` branches property to match valid branches + JDK-8388790: Bump update version for OpenJDK: jdk-17.0.20.1 - Backport upcoming upgrade of timezone data (bsc#1275035) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4028-1 Released: Mon Sep 7 09:45:04 2026 Summary: Security update for httpcomponents-client Type: security Severity: moderate References: 1273163,CVE-2026-64607 This update for httpcomponents-client fixes the following issue: - CVE-2026-64607: improper release of underlying connection back to connection manager when an invalid or unsupported `Content-Encoding` header value in a response message (bsc#1273163). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - cpio-2.13-150400.3.10.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - java-17-openjdk-headless-17.0.20.1-150400.3.72.1 updated - java-17-openjdk-17.0.20.1-150400.3.72.1 updated - java-17-openjdk-devel-17.0.20.1-150400.3.72.1 updated - httpcomponents-client-4.5.14-150200.3.12.1 updated - container:bci-openjdk-17-15.7.17-20.42 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:21:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:21:07 +0200 (CEST) Subject: SUSE-CU-2026:10085-1: Recommended update of bci/openjdk-devel Message-ID: <20260912082107.8FF93FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10085-1 Container Tags : bci/openjdk-devel:17 , bci/openjdk-devel:17-sles15 , bci/openjdk-devel:17.0.20.1 , bci/openjdk-devel:17.0.20.1-21.54 Container Release : 21.54 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:bci-openjdk-17-15.7.17-20.46 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:22:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:22:24 +0200 (CEST) Subject: SUSE-CU-2026:10086-1: Security update of bci/openjdk Message-ID: <20260912082224.990A1FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10086-1 Container Tags : bci/openjdk:17 , bci/openjdk:17-sles15 , bci/openjdk:17.0.20.1 , bci/openjdk:17.0.20.1-20.42 Container Release : 20.42 Severity : important Type : security References : 1266343 1266786 1269489 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275035 1275764 1275777 1275778 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-60589 CVE-2026-61308 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-70907 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4002-1 Released: Mon Sep 7 09:27:14 2026 Summary: Security update for java-17-openjdk Type: security Severity: moderate References: 1275035,1275764,1275777,1275778,CVE-2026-60589,CVE-2026-61308,CVE-2026-70907 This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.20.1+1 (August 2026 CSPU). - CVE-2026-60589: unauthenticated attacker with network access via multiple protocols can gain unauthorized read access to a subset of accessible data (bsc#1275777). - CVE-2026-61308: unauthenticated attacker with network access via HTTP can gain unauthorized access to critical data (bsc#1275778). - CVE-2026-70907: unauthenticated attacker with network access via TLS can cause a partial denial of service (bsc#1275764). Changes for java-17-openjdk: - Upgrade to upstream tag jdk-17.0.20.1+1 (August 2026 CSPU): + JDK-8389947: [17u] Remove designator `DEFAULT_PROMOTED_VERSION_PRE=ea` for release 17.0.20.1. + JDK-8333743: Change `.jcheck/conf` branches property to match valid branches + JDK-8388790: Bump update version for OpenJDK: jdk-17.0.20.1 - Backport upcoming upgrade of timezone data (bsc#1275035) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - java-17-openjdk-headless-17.0.20.1-150400.3.72.1 updated - java-17-openjdk-17.0.20.1-150400.3.72.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:22:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:22:26 +0200 (CEST) Subject: SUSE-CU-2026:10088-1: Recommended update of bci/openjdk Message-ID: <20260912082226.91FE5FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10088-1 Container Tags : bci/openjdk:17 , bci/openjdk:17-sles15 , bci/openjdk:17.0.20.1 , bci/openjdk:17.0.20.1-20.46 Container Release : 20.46 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:22:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:22:27 +0200 (CEST) Subject: SUSE-CU-2026:10089-1: Recommended update of bci/openjdk Message-ID: <20260912082227.B70DCFF24@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10089-1 Container Tags : bci/openjdk:17 , bci/openjdk:17-sles15 , bci/openjdk:17.0.20.1 , bci/openjdk:17.0.20.1-20.47 Container Release : 20.47 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:23:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:23:55 +0200 (CEST) Subject: SUSE-CU-2026:10090-1: Security update of bci/openjdk-devel Message-ID: <20260912082355.B0693FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10090-1 Container Tags : bci/openjdk-devel:21 , bci/openjdk-devel:21-sles15 , bci/openjdk-devel:21.0.12.1 , bci/openjdk-devel:21.0.12.1-25.50 Container Release : 25.50 Severity : important Type : security References : 1221224 1266343 1266786 1273163 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1274856 1274857 1274858 1275035 1275764 1275777 1275778 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-60589 CVE-2026-61308 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-64607 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-70907 CVE-2026-75803 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4006-1 Released: Mon Sep 7 09:32:11 2026 Summary: Security update for java-21-openjdk Type: security Severity: moderate References: 1221224,1275035,1275764,1275777,1275778,CVE-2026-60589,CVE-2026-61308,CVE-2026-70907 This update for java-21-openjdk fixes the following issues: Security issues fixed: - CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). - CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). - CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). Non security issue fixed: - java-21-openjdk classlist depends on the CPU count of the build machine (bsc#1221224). Changes for java-21-openjdk: - Update to jdk-21.0.12.1+1 (August 2026 CSPU) + backport upcoming upgrade of timezone data (bsc#1275035) + Explicitly use G1 if the JVM supports it. GC ergonomics pick SerialGC on single-CPU machines. SerialGC does not support dumping of the shared heap, thus the classlist is different on a single-CPU builder. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4028-1 Released: Mon Sep 7 09:45:04 2026 Summary: Security update for httpcomponents-client Type: security Severity: moderate References: 1273163,CVE-2026-64607 This update for httpcomponents-client fixes the following issue: - CVE-2026-64607: improper release of underlying connection back to connection manager when an invalid or unsupported `Content-Encoding` header value in a response message (bsc#1273163). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - cpio-2.13-150400.3.10.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - java-21-openjdk-headless-21.0.12.1-150600.3.32.1 updated - java-21-openjdk-21.0.12.1-150600.3.32.1 updated - java-21-openjdk-devel-21.0.12.1-150600.3.32.1 updated - httpcomponents-client-4.5.14-150200.3.12.1 updated - container:bci-openjdk-21-15.7.21-24.41 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:23:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:23:57 +0200 (CEST) Subject: SUSE-CU-2026:10092-1: Recommended update of bci/openjdk-devel Message-ID: <20260912082357.B2264FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10092-1 Container Tags : bci/openjdk-devel:21 , bci/openjdk-devel:21-sles15 , bci/openjdk-devel:21.0.12.1 , bci/openjdk-devel:21.0.12.1-25.53 Container Release : 25.53 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:bci-openjdk-21-15.7.21-24.44 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:25:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:25:18 +0200 (CEST) Subject: SUSE-CU-2026:10093-1: Security update of bci/openjdk Message-ID: <20260912082518.5AB25FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10093-1 Container Tags : bci/openjdk:21 , bci/openjdk:21-sles15 , bci/openjdk:21.0.12.1 , bci/openjdk:21.0.12.1-24.41 Container Release : 24.41 Severity : important Type : security References : 1221224 1266343 1266786 1269489 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275035 1275764 1275777 1275778 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-60589 CVE-2026-61308 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-70907 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4006-1 Released: Mon Sep 7 09:32:11 2026 Summary: Security update for java-21-openjdk Type: security Severity: moderate References: 1221224,1275035,1275764,1275777,1275778,CVE-2026-60589,CVE-2026-61308,CVE-2026-70907 This update for java-21-openjdk fixes the following issues: Security issues fixed: - CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). - CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). - CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). Non security issue fixed: - java-21-openjdk classlist depends on the CPU count of the build machine (bsc#1221224). Changes for java-21-openjdk: - Update to jdk-21.0.12.1+1 (August 2026 CSPU) + backport upcoming upgrade of timezone data (bsc#1275035) + Explicitly use G1 if the JVM supports it. GC ergonomics pick SerialGC on single-CPU machines. SerialGC does not support dumping of the shared heap, thus the classlist is different on a single-CPU builder. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - java-21-openjdk-headless-21.0.12.1-150600.3.32.1 updated - java-21-openjdk-21.0.12.1-150600.3.32.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:25:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:25:20 +0200 (CEST) Subject: SUSE-CU-2026:10095-1: Recommended update of bci/openjdk Message-ID: <20260912082520.47D07FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10095-1 Container Tags : bci/openjdk:21 , bci/openjdk:21-sles15 , bci/openjdk:21.0.12.1 , bci/openjdk:21.0.12.1-24.44 Container Release : 24.44 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:25:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:25:21 +0200 (CEST) Subject: SUSE-CU-2026:10096-1: Recommended update of bci/openjdk Message-ID: <20260912082521.5EAC0FF24@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10096-1 Container Tags : bci/openjdk:21 , bci/openjdk:21-sles15 , bci/openjdk:21.0.12.1 , bci/openjdk:21.0.12.1-24.46 Container Release : 24.46 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:26:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:26:15 +0200 (CEST) Subject: SUSE-CU-2026:10097-1: Security update of bci/openjdk-devel Message-ID: <20260912082615.9E1C4FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10097-1 Container Tags : bci/openjdk-devel:25 , bci/openjdk-devel:25-sles15 , bci/openjdk-devel:25.0.4.1 , bci/openjdk-devel:25.0.4.1-9.51 , bci/openjdk-devel:latest Container Release : 9.51 Severity : important Type : security References : 1266343 1266786 1273163 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1274856 1274857 1274858 1275035 1275763 1275764 1275777 1275778 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-60589 CVE-2026-61308 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-64607 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-70906 CVE-2026-70907 CVE-2026-75803 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3999-1 Released: Mon Sep 7 09:24:37 2026 Summary: Security update for java-25-openjdk Type: security Severity: important References: 1275035,1275763,1275764,1275777,1275778,CVE-2026-60589,CVE-2026-61308,CVE-2026-70906,CVE-2026-70907 This update for java-25-openjdk fixes the following issues: - CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). - CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). - CVE-2026-70906: OpenJDK: Improve font loading (bsc#1275763). - CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). Changes for java-25-openjdk: - Update to jdk-25.0.4.1+1 (August 2026 CSPU) + backport upcoming upgrade of timezone data (bsc#1275035) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4028-1 Released: Mon Sep 7 09:45:04 2026 Summary: Security update for httpcomponents-client Type: security Severity: moderate References: 1273163,CVE-2026-64607 This update for httpcomponents-client fixes the following issue: - CVE-2026-64607: improper release of underlying connection back to connection manager when an invalid or unsupported `Content-Encoding` header value in a response message (bsc#1273163). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - cpio-2.13-150400.3.10.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - java-25-openjdk-headless-25.0.4.1-150700.15.16.1 updated - java-25-openjdk-25.0.4.1-150700.15.16.1 updated - java-25-openjdk-devel-25.0.4.1-150700.15.16.1 updated - httpcomponents-client-4.5.14-150200.3.12.1 updated - container:bci-openjdk-25-15.7.25-9.41 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:27:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:27:11 +0200 (CEST) Subject: SUSE-CU-2026:10099-1: Security update of bci/openjdk Message-ID: <20260912082711.77703FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10099-1 Container Tags : bci/openjdk:25 , bci/openjdk:25-sles15 , bci/openjdk:25.0.4.1 , bci/openjdk:25.0.4.1-9.41 , bci/openjdk:latest Container Release : 9.41 Severity : important Type : security References : 1266343 1266786 1269489 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275035 1275763 1275764 1275777 1275778 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-60589 CVE-2026-61308 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-70906 CVE-2026-70907 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3999-1 Released: Mon Sep 7 09:24:37 2026 Summary: Security update for java-25-openjdk Type: security Severity: important References: 1275035,1275763,1275764,1275777,1275778,CVE-2026-60589,CVE-2026-61308,CVE-2026-70906,CVE-2026-70907 This update for java-25-openjdk fixes the following issues: - CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). - CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). - CVE-2026-70906: OpenJDK: Improve font loading (bsc#1275763). - CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). Changes for java-25-openjdk: - Update to jdk-25.0.4.1+1 (August 2026 CSPU) + backport upcoming upgrade of timezone data (bsc#1275035) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - java-25-openjdk-headless-25.0.4.1-150700.15.16.1 updated - java-25-openjdk-25.0.4.1-150700.15.16.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:27:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:27:13 +0200 (CEST) Subject: SUSE-CU-2026:10101-1: Recommended update of bci/openjdk Message-ID: <20260912082713.71E97FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10101-1 Container Tags : bci/openjdk:25 , bci/openjdk:25-sles15 , bci/openjdk:25.0.4.1 , bci/openjdk:25.0.4.1-9.45 , bci/openjdk:latest Container Release : 9.45 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:27:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:27:14 +0200 (CEST) Subject: SUSE-CU-2026:10102-1: Recommended update of bci/openjdk Message-ID: <20260912082714.A1565FF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10102-1 Container Tags : bci/openjdk:25 , bci/openjdk:25-sles15 , bci/openjdk:25.0.4.1 , bci/openjdk:25.0.4.1-9.46 , bci/openjdk:latest Container Release : 9.46 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:28:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:28:32 +0200 (CEST) Subject: SUSE-CU-2026:10103-1: Security update of bci/php-apache Message-ID: <20260912082832.DFD50FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/php-apache ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10103-1 Container Tags : bci/php-apache:8 , bci/php-apache:8-sles15 , bci/php-apache:8.3.33 , bci/php-apache:8.3.33-26.6 , bci/php-apache:latest Container Release : 26.6 Severity : important Type : security References : 1278257 CVE-2026-84361 ----------------------------------------------------------------- The container bci/php-apache was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4059-1 Released: Tue Sep 8 08:59:57 2026 Summary: Security update for php-composer2 Type: security Severity: important References: 1278257,CVE-2026-84361 This update for php-composer2 fixes the following issue: - CVE-2026-84361: Arbitrary code execution via malicious Perforce source URL (bsc#1278257). The following package changes have been done: - php-composer2-2.6.4-150600.3.18.1 updated - container:bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:29:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:29:50 +0200 (CEST) Subject: SUSE-CU-2026:10107-1: Security update of bci/php-fpm Message-ID: <20260912082950.86E60FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/php-fpm ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10107-1 Container Tags : bci/php-fpm:8 , bci/php-fpm:8-sles15 , bci/php-fpm:8.3.33 , bci/php-fpm:8.3.33-26.4 , bci/php-fpm:latest Container Release : 26.4 Severity : important Type : security References : 1278257 CVE-2026-84361 ----------------------------------------------------------------- The container bci/php-fpm was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4059-1 Released: Tue Sep 8 08:59:57 2026 Summary: Security update for php-composer2 Type: security Severity: important References: 1278257,CVE-2026-84361 This update for php-composer2 fixes the following issue: - CVE-2026-84361: Arbitrary code execution via malicious Perforce source URL (bsc#1278257). The following package changes have been done: - php-composer2-2.6.4-150600.3.18.1 updated - container:bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:30:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:30:58 +0200 (CEST) Subject: SUSE-CU-2026:10111-1: Security update of bci/php Message-ID: <20260912083058.74C5EFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/php ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10111-1 Container Tags : bci/php:8 , bci/php:8-sles15 , bci/php:8.3.33 , bci/php:8.3.33-26.4 , bci/php:latest Container Release : 26.4 Severity : important Type : security References : 1278257 CVE-2026-84361 ----------------------------------------------------------------- The container bci/php was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4059-1 Released: Tue Sep 8 08:59:57 2026 Summary: Security update for php-composer2 Type: security Severity: important References: 1278257,CVE-2026-84361 This update for php-composer2 fixes the following issue: - CVE-2026-84361: Arbitrary code execution via malicious Perforce source URL (bsc#1278257). The following package changes have been done: - php-composer2-2.6.4-150600.3.18.1 updated - container:bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:32:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:32:01 +0200 (CEST) Subject: SUSE-CU-2026:10115-1: Security update of suse/postgres Message-ID: <20260912083201.763F6FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10115-1 Container Tags : suse/postgres:16-contrib , suse/postgres:16.15 , suse/postgres:16.15-contrib , suse/postgres:16.15-contrib-93.25 Container Release : 93.25 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275001 1275002 1275042 1275043 1275044 1275046 1275047 1275048 1275049 1275050 1275051 1275052 1275053 1275054 1275055 1275056 1275057 1275058 1275059 1275060 1275061 1275062 1275063 1275064 1275065 1275066 1275067 1275068 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14676 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681 CVE-2026-15741 CVE-2026-15742 CVE-2026-16238 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-18798 CVE-2026-19385 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4014-1 Released: Mon Sep 7 09:36:08 2026 Summary: Security update for postgresql18 Type: security Severity: important References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275052,1275053,1275054,1275055,1275056,1275057,1275058,1275059,1275060,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14676,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-14681,CVE-2026-15741,CVE-2026-15742,CVE-2026-16238,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471 This update for postgresql18 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql18: - Update to version 18.6: * https://www.postgresql.org/docs/18/release-18-6.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - libpq5-18.6-150600.13.16.1 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sat Sep 12 08:32:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:32:03 +0200 (CEST) Subject: SUSE-CU-2026:10116-1: Recommended update of suse/postgres Message-ID: <20260912083203.3237BFF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10116-1 Container Tags : suse/postgres:16-contrib , suse/postgres:16.15 , suse/postgres:16.15-contrib , suse/postgres:16.15-contrib-93.29 Container Release : 93.29 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:32:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:32:04 +0200 (CEST) Subject: SUSE-CU-2026:10117-1: Recommended update of suse/postgres Message-ID: <20260912083204.C67BDFF46@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10117-1 Container Tags : suse/postgres:16-contrib , suse/postgres:16.15 , suse/postgres:16.15-contrib , suse/postgres:16.15-contrib-93.32 Container Release : 93.32 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-locale-base-2.38-150600.14.55.1 updated - glibc-locale-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:32:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:32:07 +0200 (CEST) Subject: SUSE-CU-2026:10119-1: Recommended update of suse/postgres Message-ID: <20260912083207.E24E4FF48@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10119-1 Container Tags : suse/postgres:16-contrib , suse/postgres:16.15 , suse/postgres:16.15-contrib , suse/postgres:16.15-contrib-93.34 Container Release : 93.34 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:32:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:32:33 +0200 (CEST) Subject: SUSE-CU-2026:10120-1: Security update of suse/postgres Message-ID: <20260912083233.A4DF6FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10120-1 Container Tags : suse/postgres:16 , suse/postgres:16.15 , suse/postgres:16.15 , suse/postgres:16.15-93.25 Container Release : 93.25 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275001 1275002 1275042 1275043 1275044 1275046 1275047 1275048 1275049 1275050 1275051 1275052 1275053 1275054 1275055 1275056 1275057 1275058 1275059 1275060 1275061 1275062 1275063 1275064 1275065 1275066 1275067 1275068 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14676 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681 CVE-2026-15741 CVE-2026-15742 CVE-2026-16238 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-18798 CVE-2026-19385 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4014-1 Released: Mon Sep 7 09:36:08 2026 Summary: Security update for postgresql18 Type: security Severity: important References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275052,1275053,1275054,1275055,1275056,1275057,1275058,1275059,1275060,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14676,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-14681,CVE-2026-15741,CVE-2026-15742,CVE-2026-16238,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471 This update for postgresql18 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql18: - Update to version 18.6: * https://www.postgresql.org/docs/18/release-18-6.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - libpq5-18.6-150600.13.16.1 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sat Sep 12 08:32:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:32:35 +0200 (CEST) Subject: SUSE-CU-2026:10121-1: Recommended update of suse/postgres Message-ID: <20260912083235.45F58FF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10121-1 Container Tags : suse/postgres:16 , suse/postgres:16.15 , suse/postgres:16.15 , suse/postgres:16.15-93.29 Container Release : 93.29 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:32:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:32:36 +0200 (CEST) Subject: SUSE-CU-2026:10122-1: Recommended update of suse/postgres Message-ID: <20260912083236.C748AFF46@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10122-1 Container Tags : suse/postgres:16 , suse/postgres:16.15 , suse/postgres:16.15 , suse/postgres:16.15-93.31 Container Release : 93.31 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-locale-base-2.38-150600.14.55.1 updated - glibc-locale-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:32:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:32:39 +0200 (CEST) Subject: SUSE-CU-2026:10124-1: Recommended update of suse/postgres Message-ID: <20260912083239.9FD71FF48@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10124-1 Container Tags : suse/postgres:16 , suse/postgres:16.15 , suse/postgres:16.15 , suse/postgres:16.15-93.34 Container Release : 93.34 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:33:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:33:42 +0200 (CEST) Subject: SUSE-CU-2026:10125-1: Security update of suse/postgres Message-ID: <20260912083342.3F860FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10125-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.11 , suse/postgres:17.11-contrib , suse/postgres:17.11-contrib-83.24 Container Release : 83.24 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275001 1275001 1275002 1275002 1275042 1275042 1275043 1275043 1275044 1275044 1275046 1275046 1275047 1275047 1275048 1275048 1275049 1275049 1275050 1275050 1275051 1275051 1275052 1275053 1275053 1275054 1275054 1275055 1275055 1275056 1275056 1275057 1275057 1275058 1275058 1275059 1275059 1275060 1275061 1275062 1275062 1275063 1275063 1275064 1275064 1275065 1275065 1275066 1275066 1275067 1275067 1275068 1275068 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-14662 CVE-2026-14662 CVE-2026-14663 CVE-2026-14663 CVE-2026-14664 CVE-2026-14664 CVE-2026-14666 CVE-2026-14666 CVE-2026-14668 CVE-2026-14668 CVE-2026-14669 CVE-2026-14669 CVE-2026-14670 CVE-2026-14670 CVE-2026-14671 CVE-2026-14671 CVE-2026-14672 CVE-2026-14672 CVE-2026-14673 CVE-2026-14676 CVE-2026-14677 CVE-2026-14677 CVE-2026-14678 CVE-2026-14678 CVE-2026-14679 CVE-2026-14679 CVE-2026-14680 CVE-2026-14680 CVE-2026-14681 CVE-2026-14681 CVE-2026-15741 CVE-2026-15741 CVE-2026-15742 CVE-2026-15742 CVE-2026-16238 CVE-2026-16239 CVE-2026-16239 CVE-2026-16241 CVE-2026-16241 CVE-2026-18024 CVE-2026-18024 CVE-2026-18408 CVE-2026-18408 CVE-2026-18798 CVE-2026-19385 CVE-2026-19385 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-6464 CVE-2026-6464 CVE-2026-6469 CVE-2026-6469 CVE-2026-6470 CVE-2026-6470 CVE-2026-6471 CVE-2026-6471 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4014-1 Released: Mon Sep 7 09:36:08 2026 Summary: Security update for postgresql18 Type: security Severity: important References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275052,1275053,1275054,1275055,1275056,1275057,1275058,1275059,1275060,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14676,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-14681,CVE-2026-15741,CVE-2026-15742,CVE-2026-16238,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471 This update for postgresql18 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql18: - Update to version 18.6: * https://www.postgresql.org/docs/18/release-18-6.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4016-1 Released: Mon Sep 7 09:37:47 2026 Summary: Security update for postgresql17 Type: security Severity: important References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275053,1275054,1275055,1275056,1275057,1275058,1275059,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-14681,CVE-2026-15741,CVE-2026-15742,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471 This update for postgresql17 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql17: - Update to version 17.11: * https://www.postgresql.org/docs/17/release-17-11.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - libpq5-18.6-150600.13.16.1 updated - postgresql17-17.11-150600.13.32.1 updated - postgresql17-server-17.11-150600.13.32.1 updated - postgresql17-contrib-17.11-150600.13.32.1 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sat Sep 12 08:33:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:33:43 +0200 (CEST) Subject: SUSE-CU-2026:10126-1: Recommended update of suse/postgres Message-ID: <20260912083343.67C45FF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10126-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.11 , suse/postgres:17.11-contrib , suse/postgres:17.11-contrib-83.28 Container Release : 83.28 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:33:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:33:45 +0200 (CEST) Subject: SUSE-CU-2026:10127-1: Recommended update of suse/postgres Message-ID: <20260912083345.C2DF3FF46@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10127-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.11 , suse/postgres:17.11-contrib , suse/postgres:17.11-contrib-83.31 Container Release : 83.31 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-locale-base-2.38-150600.14.55.1 updated - glibc-locale-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:33:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:33:48 +0200 (CEST) Subject: SUSE-CU-2026:10129-1: Recommended update of suse/postgres Message-ID: <20260912083348.3E414FF48@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10129-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.11 , suse/postgres:17.11-contrib , suse/postgres:17.11-contrib-83.33 Container Release : 83.33 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:34:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:34:15 +0200 (CEST) Subject: SUSE-CU-2026:10130-1: Security update of suse/postgres Message-ID: <20260912083415.39247FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10130-1 Container Tags : suse/postgres:17 , suse/postgres:17.11 , suse/postgres:17.11 , suse/postgres:17.11-83.24 Container Release : 83.24 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275001 1275001 1275002 1275002 1275042 1275042 1275043 1275043 1275044 1275044 1275046 1275046 1275047 1275047 1275048 1275048 1275049 1275049 1275050 1275050 1275051 1275051 1275052 1275053 1275053 1275054 1275054 1275055 1275055 1275056 1275056 1275057 1275057 1275058 1275058 1275059 1275059 1275060 1275061 1275062 1275062 1275063 1275063 1275064 1275064 1275065 1275065 1275066 1275066 1275067 1275067 1275068 1275068 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-14662 CVE-2026-14662 CVE-2026-14663 CVE-2026-14663 CVE-2026-14664 CVE-2026-14664 CVE-2026-14666 CVE-2026-14666 CVE-2026-14668 CVE-2026-14668 CVE-2026-14669 CVE-2026-14669 CVE-2026-14670 CVE-2026-14670 CVE-2026-14671 CVE-2026-14671 CVE-2026-14672 CVE-2026-14672 CVE-2026-14673 CVE-2026-14676 CVE-2026-14677 CVE-2026-14677 CVE-2026-14678 CVE-2026-14678 CVE-2026-14679 CVE-2026-14679 CVE-2026-14680 CVE-2026-14680 CVE-2026-14681 CVE-2026-14681 CVE-2026-15741 CVE-2026-15741 CVE-2026-15742 CVE-2026-15742 CVE-2026-16238 CVE-2026-16239 CVE-2026-16239 CVE-2026-16241 CVE-2026-16241 CVE-2026-18024 CVE-2026-18024 CVE-2026-18408 CVE-2026-18408 CVE-2026-18798 CVE-2026-19385 CVE-2026-19385 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-6464 CVE-2026-6464 CVE-2026-6469 CVE-2026-6469 CVE-2026-6470 CVE-2026-6470 CVE-2026-6471 CVE-2026-6471 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4014-1 Released: Mon Sep 7 09:36:08 2026 Summary: Security update for postgresql18 Type: security Severity: important References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275052,1275053,1275054,1275055,1275056,1275057,1275058,1275059,1275060,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14676,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-14681,CVE-2026-15741,CVE-2026-15742,CVE-2026-16238,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471 This update for postgresql18 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql18: - Update to version 18.6: * https://www.postgresql.org/docs/18/release-18-6.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4016-1 Released: Mon Sep 7 09:37:47 2026 Summary: Security update for postgresql17 Type: security Severity: important References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275053,1275054,1275055,1275056,1275057,1275058,1275059,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-14681,CVE-2026-15741,CVE-2026-15742,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471 This update for postgresql17 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql17: - Update to version 17.11: * https://www.postgresql.org/docs/17/release-17-11.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - libpq5-18.6-150600.13.16.1 updated - postgresql17-17.11-150600.13.32.1 updated - postgresql17-server-17.11-150600.13.32.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sat Sep 12 08:34:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:34:17 +0200 (CEST) Subject: SUSE-CU-2026:10131-1: Recommended update of suse/postgres Message-ID: <20260912083417.933B6FF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10131-1 Container Tags : suse/postgres:17 , suse/postgres:17.11 , suse/postgres:17.11 , suse/postgres:17.11-83.28 Container Release : 83.28 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:34:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:34:18 +0200 (CEST) Subject: SUSE-CU-2026:10132-1: Recommended update of suse/postgres Message-ID: <20260912083418.A92EBFF46@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10132-1 Container Tags : suse/postgres:17 , suse/postgres:17.11 , suse/postgres:17.11 , suse/postgres:17.11-83.31 Container Release : 83.31 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-locale-base-2.38-150600.14.55.1 updated - glibc-locale-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:34:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:34:21 +0200 (CEST) Subject: SUSE-CU-2026:10133-1: Recommended update of suse/postgres Message-ID: <20260912083421.1F74FFF48@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10133-1 Container Tags : suse/postgres:17 , suse/postgres:17.11 , suse/postgres:17.11 , suse/postgres:17.11-83.33 Container Release : 83.33 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Sat Sep 12 08:35:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 12 Sep 2026 10:35:06 +0200 (CEST) Subject: SUSE-CU-2026:10134-1: Security update of suse/postgres Message-ID: <20260912083506.A1042FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10134-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.6 , suse/postgres:18.6-contrib , suse/postgres:18.6-contrib-73.24 , suse/postgres:latest Container Release : 73.24 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275001 1275002 1275042 1275043 1275044 1275046 1275047 1275048 1275049 1275050 1275051 1275052 1275053 1275054 1275055 1275056 1275057 1275058 1275059 1275060 1275061 1275062 1275063 1275064 1275065 1275066 1275067 1275068 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14676 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681 CVE-2026-15741 CVE-2026-15742 CVE-2026-16238 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-18798 CVE-2026-19385 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4014-1 Released: Mon Sep 7 09:36:08 2026 Summary: Security update for postgresql18 Type: security Severity: important References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275052,1275053,1275054,1275055,1275056,1275057,1275058,1275059,1275060,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14676,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-14681,CVE-2026-15741,CVE-2026-15742,CVE-2026-16238,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471 This update for postgresql18 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql18: - Update to version 18.6: * https://www.postgresql.org/docs/18/release-18-6.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - libpq5-18.6-150600.13.16.1 updated - postgresql18-18.6-150600.13.16.1 updated - postgresql18-server-18.6-150600.13.16.1 updated - postgresql18-contrib-18.6-150600.13.16.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sun Sep 13 07:35:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 09:35:19 +0200 (CEST) Subject: SUSE-IU-2026:6991-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260913073519.0D169FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6991-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.159 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.159 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1661 Released: Fri Sep 11 13:45:57 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent The following package changes have been done: - libattr1-2.6.0-160000.1.1 updated - libacl1-2.4.0-160000.1.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-0938c275fb73407ad74eab1caefad981de22ca9259d117177db494ab16996f4a-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 07:55:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 09:55:16 +0200 (CEST) Subject: SUSE-CU-2026:10139-1: Recommended update of bci/nodejs Message-ID: <20260913075516.B9DC6FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10139-1 Container Tags : bci/node:22 , bci/node:22-sles15 , bci/node:22.23.2 , bci/node:22.23.2-24.50 , bci/nodejs:22 , bci/nodejs:22-sles15 , bci/nodejs:22.23.2 , bci/nodejs:22.23.2-24.50 Container Release : 24.50 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1273300 1275660 1277247 1278351 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - glibc-2.38-150600.14.55.1 updated - permissions-20250826-150700.16.5.1 updated - container:registry.suse.com-bci-bci-base-15.7-31dce1f05f6f1bd8f55a19aad195829fd37ccd11819e1dd937f55f40650512bf-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 07:57:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 09:57:05 +0200 (CEST) Subject: SUSE-CU-2026:10140-1: Recommended update of bci/openjdk-devel Message-ID: <20260913075705.1AD51FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10140-1 Container Tags : bci/openjdk-devel:17 , bci/openjdk-devel:17-sles15 , bci/openjdk-devel:17.0.20.1 , bci/openjdk-devel:17.0.20.1-21.57 Container Release : 21.57 Severity : moderate Type : recommended References : 1273300 1277247 1278351 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - permissions-20250826-150700.16.5.1 updated - container:bci-openjdk-17-15.7.17-20.48 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:00:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:00:29 +0200 (CEST) Subject: SUSE-CU-2026:10142-1: Recommended update of bci/openjdk-devel Message-ID: <20260913080029.852EBFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10142-1 Container Tags : bci/openjdk-devel:21 , bci/openjdk-devel:21-sles15 , bci/openjdk-devel:21.0.12.1 , bci/openjdk-devel:21.0.12.1-25.57 Container Release : 25.57 Severity : moderate Type : recommended References : 1273300 1277247 1278351 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - permissions-20250826-150700.16.5.1 updated - container:bci-openjdk-21-15.7.21-24.47 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:02:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:02:42 +0200 (CEST) Subject: SUSE-CU-2026:10144-1: Recommended update of bci/openjdk-devel Message-ID: <20260913080242.B92FEFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10144-1 Container Tags : bci/openjdk-devel:25 , bci/openjdk-devel:25-sles15 , bci/openjdk-devel:25.0.4.1 , bci/openjdk-devel:25.0.4.1-9.58 , bci/openjdk-devel:latest Container Release : 9.58 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1273300 1275660 1277247 1278351 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - glibc-2.38-150600.14.55.1 updated - permissions-20250826-150700.16.5.1 updated - container:bci-openjdk-25-15.7.25-9.47 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:10:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:10:15 +0200 (CEST) Subject: SUSE-CU-2026:10134-1: Security update of suse/postgres Message-ID: <20260913081015.33292FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10134-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.6 , suse/postgres:18.6-contrib , suse/postgres:18.6-contrib-73.24 , suse/postgres:latest Container Release : 73.24 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275001 1275002 1275042 1275043 1275044 1275046 1275047 1275048 1275049 1275050 1275051 1275052 1275053 1275054 1275055 1275056 1275057 1275058 1275059 1275060 1275061 1275062 1275063 1275064 1275065 1275066 1275067 1275068 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14676 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681 CVE-2026-15741 CVE-2026-15742 CVE-2026-16238 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-18798 CVE-2026-19385 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4014-1 Released: Mon Sep 7 09:36:08 2026 Summary: Security update for postgresql18 Type: security Severity: important References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275052,1275053,1275054,1275055,1275056,1275057,1275058,1275059,1275060,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14676,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-14681,CVE-2026-15741,CVE-2026-15742,CVE-2026-16238,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471 This update for postgresql18 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql18: - Update to version 18.6: * https://www.postgresql.org/docs/18/release-18-6.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - libpq5-18.6-150600.13.16.1 updated - postgresql18-18.6-150600.13.16.1 updated - postgresql18-server-18.6-150600.13.16.1 updated - postgresql18-contrib-18.6-150600.13.16.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sun Sep 13 08:10:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:10:18 +0200 (CEST) Subject: SUSE-CU-2026:10149-1: Recommended update of suse/postgres Message-ID: <20260913081018.254CBFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10149-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.6 , suse/postgres:18.6-contrib , suse/postgres:18.6-contrib-73.28 , suse/postgres:latest Container Release : 73.28 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:10:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:10:20 +0200 (CEST) Subject: SUSE-CU-2026:10150-1: Recommended update of suse/postgres Message-ID: <20260913081020.0F295FF24@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10150-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.6 , suse/postgres:18.6-contrib , suse/postgres:18.6-contrib-73.31 , suse/postgres:latest Container Release : 73.31 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-locale-base-2.38-150600.14.55.1 updated - glibc-locale-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:10:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:10:23 +0200 (CEST) Subject: SUSE-CU-2026:10152-1: Recommended update of suse/postgres Message-ID: <20260913081023.57D3BFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10152-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.6 , suse/postgres:18.6-contrib , suse/postgres:18.6-contrib-73.33 , suse/postgres:latest Container Release : 73.33 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:10:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:10:50 +0200 (CEST) Subject: SUSE-CU-2026:10153-1: Security update of suse/postgres Message-ID: <20260913081050.7A2AFFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10153-1 Container Tags : suse/postgres:18 , suse/postgres:18.6 , suse/postgres:18.6 , suse/postgres:18.6-73.24 , suse/postgres:latest Container Release : 73.24 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275001 1275002 1275042 1275043 1275044 1275046 1275047 1275048 1275049 1275050 1275051 1275052 1275053 1275054 1275055 1275056 1275057 1275058 1275059 1275060 1275061 1275062 1275063 1275064 1275065 1275066 1275067 1275068 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14676 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681 CVE-2026-15741 CVE-2026-15742 CVE-2026-16238 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-18798 CVE-2026-19385 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4014-1 Released: Mon Sep 7 09:36:08 2026 Summary: Security update for postgresql18 Type: security Severity: important References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275052,1275053,1275054,1275055,1275056,1275057,1275058,1275059,1275060,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14676,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-14681,CVE-2026-15741,CVE-2026-15742,CVE-2026-16238,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471 This update for postgresql18 fixes the following issues: - CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). - CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). - CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). - CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). - CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). - CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). - CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). - CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). - CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). - CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). - CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). - CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). - CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). - CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). - CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060). - CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). - CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). - CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). - CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056). - CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). - CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). - CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). - CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052). - CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). - CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). - CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). - CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). - CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql18: - Update to version 18.6: * https://www.postgresql.org/docs/18/release-18-6.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - libpq5-18.6-150600.13.16.1 updated - postgresql18-18.6-150600.13.16.1 updated - postgresql18-server-18.6-150600.13.16.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sun Sep 13 08:10:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:10:52 +0200 (CEST) Subject: SUSE-CU-2026:10154-1: Recommended update of suse/postgres Message-ID: <20260913081052.539D4FF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10154-1 Container Tags : suse/postgres:18 , suse/postgres:18.6 , suse/postgres:18.6 , suse/postgres:18.6-73.28 , suse/postgres:latest Container Release : 73.28 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:10:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:10:54 +0200 (CEST) Subject: SUSE-CU-2026:10155-1: Recommended update of suse/postgres Message-ID: <20260913081054.357E5FF24@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10155-1 Container Tags : suse/postgres:18 , suse/postgres:18.6 , suse/postgres:18.6 , suse/postgres:18.6-73.31 , suse/postgres:latest Container Release : 73.31 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-locale-base-2.38-150600.14.55.1 updated - glibc-locale-2.38-150600.14.55.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:10:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:10:57 +0200 (CEST) Subject: SUSE-CU-2026:10157-1: Recommended update of suse/postgres Message-ID: <20260913081057.853F2FF47@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10157-1 Container Tags : suse/postgres:18 , suse/postgres:18.6 , suse/postgres:18.6 , suse/postgres:18.6-73.33 , suse/postgres:latest Container Release : 73.33 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:12:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:12:11 +0200 (CEST) Subject: SUSE-CU-2026:10158-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260913081211.66C2DFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10158-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-73.24 , suse/kiosk/pulseaudio:latest Container Release : 73.24 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1274856 1274857 1274858 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-75803 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - cpio-2.13-150400.3.10.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - coreutils-8.32-150400.9.12.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - sles-release-15.7-150700.67.6.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sun Sep 13 08:12:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:12:12 +0200 (CEST) Subject: SUSE-CU-2026:10159-1: Recommended update of suse/kiosk/pulseaudio Message-ID: <20260913081212.9E9A2FF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10159-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-73.28 , suse/kiosk/pulseaudio:latest Container Release : 73.28 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:12:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:12:13 +0200 (CEST) Subject: SUSE-CU-2026:10160-1: Recommended update of suse/kiosk/pulseaudio Message-ID: <20260913081213.D1A40FF24@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10160-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-73.32 , suse/kiosk/pulseaudio:latest Container Release : 73.32 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:13:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:13:35 +0200 (CEST) Subject: SUSE-CU-2026:10161-1: Security update of bci/python Message-ID: <20260913081335.F0878FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10161-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.46 Container Release : 85.46 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:13:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:13:37 +0200 (CEST) Subject: SUSE-CU-2026:10163-1: Recommended update of bci/python Message-ID: <20260913081337.EFB38FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10163-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.50 Container Release : 85.50 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:13:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:13:39 +0200 (CEST) Subject: SUSE-CU-2026:10164-1: Recommended update of bci/python Message-ID: <20260913081339.24AE7FF24@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10164-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.51 Container Release : 85.51 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:14:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:14:58 +0200 (CEST) Subject: SUSE-CU-2026:10166-1: Security update of bci/python Message-ID: <20260913081458.F0B80FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10166-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.14 , bci/python:3.13.14-88.41 , bci/python:latest Container Release : 88.41 Severity : important Type : security References : 1266343 1266786 1269489 1273090 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13346 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4030-1 Released: Mon Sep 7 09:45:47 2026 Summary: Security update for python313-pip Type: security Severity: moderate References: 1273090,CVE-2026-13346 This update for python313-pip fixes the following issue: - CVE-2026-13346: incorrect handling of doubly-encoded package URLs from malicious indexes allows files to be installed to arbitrary locations on disk (bsc#1273090). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - python313-pip-24.2-150700.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:15:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:15:01 +0200 (CEST) Subject: SUSE-CU-2026:10168-1: Recommended update of bci/python Message-ID: <20260913081501.0125FFF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10168-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.14 , bci/python:3.13.14-88.46 , bci/python:latest Container Release : 88.46 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 1277247 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:16:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:16:26 +0200 (CEST) Subject: SUSE-CU-2026:10170-1: Security update of bci/python Message-ID: <20260913081626.F37A5FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10170-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.40 Container Release : 84.40 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:16:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:16:28 +0200 (CEST) Subject: SUSE-CU-2026:10172-1: Recommended update of bci/python Message-ID: <20260913081628.A9632FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10172-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.44 Container Release : 84.44 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:16:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:16:29 +0200 (CEST) Subject: SUSE-CU-2026:10173-1: Recommended update of bci/python Message-ID: <20260913081629.C005CFF24@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10173-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.45 Container Release : 84.45 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:17:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:17:03 +0200 (CEST) Subject: SUSE-CU-2026:10175-1: Security update of suse/mariadb-client Message-ID: <20260913081703.8F2EBFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10175-1 Container Tags : suse/mariadb-client:11.8 , suse/mariadb-client:11.8.8 , suse/mariadb-client:11.8.8-72.17 , suse/mariadb-client:latest Container Release : 72.17 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/mariadb-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - coreutils-8.32-150400.9.12.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sun Sep 13 08:17:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:17:04 +0200 (CEST) Subject: SUSE-CU-2026:10176-1: Recommended update of suse/mariadb-client Message-ID: <20260913081704.CC38FFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10176-1 Container Tags : suse/mariadb-client:11.8 , suse/mariadb-client:11.8.8 , suse/mariadb-client:11.8.8-72.21 , suse/mariadb-client:latest Container Release : 72.21 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/mariadb-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:17:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:17:06 +0200 (CEST) Subject: SUSE-CU-2026:10178-1: Recommended update of suse/mariadb-client Message-ID: <20260913081706.E7AC5FF24@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10178-1 Container Tags : suse/mariadb-client:11.8 , suse/mariadb-client:11.8.8 , suse/mariadb-client:11.8.8-72.25 , suse/mariadb-client:latest Container Release : 72.25 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/mariadb-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:18:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:18:00 +0200 (CEST) Subject: SUSE-CU-2026:10179-1: Security update of suse/mariadb Message-ID: <20260913081800.0FFEEFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10179-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-79.24 , suse/mariadb:latest Container Release : 79.24 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - sles-release-15.7-150700.67.6.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sun Sep 13 08:18:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:18:01 +0200 (CEST) Subject: SUSE-CU-2026:10180-1: Recommended update of suse/mariadb Message-ID: <20260913081801.4E3DDFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10180-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-79.28 , suse/mariadb:latest Container Release : 79.28 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:18:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:18:03 +0200 (CEST) Subject: SUSE-CU-2026:10182-1: Recommended update of suse/mariadb Message-ID: <20260913081803.6B358FF24@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10182-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-79.32 , suse/mariadb:latest Container Release : 79.32 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:19:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:19:21 +0200 (CEST) Subject: SUSE-CU-2026:10183-1: Security update of suse/rmt-server Message-ID: <20260913081921.2E890FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10183-1 Container Tags : suse/rmt-server:3 , suse/rmt-server:3.1 , suse/rmt-server:3.1-71.8 , suse/rmt-server:latest Container Release : 71.8 Severity : important Type : security References : 1266343 1266664 1266786 1269489 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-23679 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - container:suse-sle15-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:19:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:19:22 +0200 (CEST) Subject: SUSE-CU-2026:10184-1: Recommended update of suse/rmt-server Message-ID: <20260913081922.39D68FF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10184-1 Container Tags : suse/rmt-server:3 , suse/rmt-server:3.1 , suse/rmt-server:3.1-71.11 , suse/rmt-server:latest Container Release : 71.11 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:19:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:19:23 +0200 (CEST) Subject: SUSE-CU-2026:10185-1: Recommended update of suse/rmt-server Message-ID: <20260913081923.32C67FF24@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10185-1 Container Tags : suse/rmt-server:3 , suse/rmt-server:3.1 , suse/rmt-server:3.1-71.15 , suse/rmt-server:latest Container Release : 71.15 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated - container:suse-sle15-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c91d4d0987d8c9c2c7925d61288033edf9d910ffdf759c056c741c04afad959c-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:20:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:20:45 +0200 (CEST) Subject: SUSE-CU-2026:10186-1: Security update of bci/ruby Message-ID: <20260913082045.34FC3FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10186-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-27.8 , bci/ruby:2.5-sles15 Container Release : 27.8 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:20:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:20:47 +0200 (CEST) Subject: SUSE-CU-2026:10188-1: Recommended update of bci/ruby Message-ID: <20260913082047.4D699FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10188-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-27.15 , bci/ruby:2.5-sles15 Container Release : 27.15 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1273300 1275660 1277247 1278351 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - glibc-2.38-150600.14.55.1 updated - permissions-20250826-150700.16.5.1 updated - glibc-devel-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-31dce1f05f6f1bd8f55a19aad195829fd37ccd11819e1dd937f55f40650512bf-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:22:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:22:14 +0200 (CEST) Subject: SUSE-CU-2026:10189-1: Security update of bci/ruby Message-ID: <20260913082214.CFD89FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10189-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-26.8 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 26.8 Severity : important Type : security References : 1266343 1266786 1269489 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:22:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:22:17 +0200 (CEST) Subject: SUSE-CU-2026:10191-1: Recommended update of bci/ruby Message-ID: <20260913082217.059F5FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10191-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-26.15 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 26.15 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1273300 1275660 1277247 1278351 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - glibc-2.38-150600.14.55.1 updated - permissions-20250826-150700.16.5.1 updated - glibc-devel-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-31dce1f05f6f1bd8f55a19aad195829fd37ccd11819e1dd937f55f40650512bf-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:23:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:23:18 +0200 (CEST) Subject: SUSE-CU-2026:10192-1: Security update of bci/rust Message-ID: <20260913082318.89A48FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10192-1 Container Tags : bci/rust:1.97 , bci/rust:1.97-sles15 , bci/rust:1.97.1 , bci/rust:1.97.1-2.2.1 , bci/rust:oldstable Container Release : 2.1 Severity : important Type : security References : 1266343 1266786 1269489 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3170-1 Released: Tue Jul 21 23:15:49 2026 Summary: Recommended update for rust Type: recommended Severity: moderate References: This update for rust fixes the following issues: Update to rust1.97.1: - Release notes can be found externally: https://github.com/rust-lang/rust/releases/tag/1.97.1 Changes in rust: - Update to version 1.97.0 - for details see the rust1.97 package ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - rust1.97-1.97.1-150300.7.5.1 added - cargo1.97-1.97.1-150300.7.5.1 added - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated - cargo1.96-1.96.1-150300.7.6.1 removed - rust1.96-1.96.1-150300.7.6.1 removed From sle-container-updates at lists.suse.com Sun Sep 13 08:23:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:23:19 +0200 (CEST) Subject: SUSE-CU-2026:10193-1: Recommended update of bci/rust Message-ID: <20260913082319.C3BC3FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10193-1 Container Tags : bci/rust:1.97 , bci/rust:1.97-sles15 , bci/rust:1.97.1 , bci/rust:1.97.1-2.2.6 , bci/rust:oldstable Container Release : 2.6 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 1277247 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - glibc-2.38-150600.14.55.1 updated - glibc-devel-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:24:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:24:42 +0200 (CEST) Subject: SUSE-CU-2026:10195-1: Security update of bci/rust Message-ID: <20260913082442.08C7AFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10195-1 Container Tags : bci/rust:1.98 , bci/rust:1.98-sles15 , bci/rust:1.98.0 , bci/rust:1.98.0-1.2.1 , bci/rust:latest , bci/rust:stable Container Release : 2.1 Severity : important Type : security References : 1266343 1266786 1269489 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3988-1 Released: Mon Sep 7 06:10:47 2026 Summary: Recommended update for rust, rust1.98 Type: recommended Severity: moderate References: This update for rust, rust1.98 fixes the following issues: Changes in rust1.98: - Update to rust1.98.0 - Release notes can be found externally: https://github.com/rust-lang/rust/releases/tag/1.98.0 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - rust1.98-1.98.0-150300.7.3.1 added - cargo1.98-1.98.0-150300.7.3.1 added - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated - cargo1.97-1.97.1-150300.7.5.1 removed - rust1.97-1.97.1-150300.7.5.1 removed From sle-container-updates at lists.suse.com Sun Sep 13 08:24:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:24:43 +0200 (CEST) Subject: SUSE-CU-2026:10196-1: Recommended update of bci/rust Message-ID: <20260913082443.3F970FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10196-1 Container Tags : bci/rust:1.98 , bci/rust:1.98-sles15 , bci/rust:1.98.0 , bci/rust:1.98.0-1.2.6 , bci/rust:latest , bci/rust:stable Container Release : 2.6 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 1277247 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - glibc-2.38-150600.14.55.1 updated - glibc-devel-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:25:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:25:38 +0200 (CEST) Subject: SUSE-CU-2026:10198-1: Security update of suse/samba-client Message-ID: <20260913082538.4747DFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10198-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-75.20 , suse/samba-client:latest Container Release : 75.20 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - coreutils-8.32-150400.9.12.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sun Sep 13 08:25:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:25:39 +0200 (CEST) Subject: SUSE-CU-2026:10199-1: Recommended update of suse/samba-client Message-ID: <20260913082539.85D8EFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10199-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-75.24 , suse/samba-client:latest Container Release : 75.24 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:25:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:25:41 +0200 (CEST) Subject: SUSE-CU-2026:10201-1: Recommended update of suse/samba-client Message-ID: <20260913082541.B452CFF24@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10201-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-75.28 , suse/samba-client:latest Container Release : 75.28 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:26:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:26:40 +0200 (CEST) Subject: SUSE-CU-2026:10202-1: Security update of suse/samba-server Message-ID: <20260913082640.83968FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10202-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-76.21 , suse/samba-server:latest Container Release : 76.21 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - coreutils-8.32-150400.9.12.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sun Sep 13 08:26:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:26:41 +0200 (CEST) Subject: SUSE-CU-2026:10203-1: Recommended update of suse/samba-server Message-ID: <20260913082641.B90DEFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10203-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-76.25 , suse/samba-server:latest Container Release : 76.25 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:26:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:26:43 +0200 (CEST) Subject: SUSE-CU-2026:10205-1: Recommended update of suse/samba-server Message-ID: <20260913082643.CDEC9FF24@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10205-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-76.29 , suse/samba-server:latest Container Release : 76.29 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:27:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:27:37 +0200 (CEST) Subject: SUSE-CU-2026:10206-1: Security update of suse/samba-toolbox Message-ID: <20260913082737.6B875FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10206-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-76.20 , suse/samba-toolbox:latest Container Release : 76.20 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - coreutils-8.32-150400.9.12.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sun Sep 13 08:27:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:27:38 +0200 (CEST) Subject: SUSE-CU-2026:10207-1: Recommended update of suse/samba-toolbox Message-ID: <20260913082738.9D6BCFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10207-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-76.24 , suse/samba-toolbox:latest Container Release : 76.24 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:27:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:27:40 +0200 (CEST) Subject: SUSE-CU-2026:10209-1: Recommended update of suse/samba-toolbox Message-ID: <20260913082740.C099EFF24@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10209-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-76.28 , suse/samba-toolbox:latest Container Release : 76.28 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 08:29:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 10:29:00 +0200 (CEST) Subject: SUSE-CU-2026:10210-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260913082900.7382AFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10210-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-61.4 , bci/bci-sle15-kernel-module-devel:latest Container Release : 61.4 Severity : important Type : security References : 1266786 1274774 1274788 1274795 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3979-1 Released: Sun Sep 6 09:43:09 2026 Summary: Recommended update for python-rpm-macros Type: recommended Severity: moderate References: This update for python-rpm-macros fixes the following issues: - Sync with slfo-main - Update to version 20260821.08c5ec8: * Use the primary interpreter for generic python3 macros * Add python315 macros, remove python39 - Update to version 20260629.bcd36db: * don't use realpath to the interpreter binary * doc: add a shot documentation text for %python_site{lib,arch}_module. * Add initial pyproject declarative buildsystem * fix: handle the situation when either `name` or `meta_name` is not found * Consolidate site directory name normalization into %__python_sitedir_name * Normalize the name of the directory * Definitions of %python_site{lib,arch}_module macros. - Update to version 20260601.4a231f4: * fix: allow function of `%pythonXX_provides` w/o /usr/bin/python3 * Update python version handling in default-prjconf * Rewrite README.md to have headlines for each macro. - Allow function of `%pythonXX_provides` even without the access to /usr/bin/python3. - Update to version 20260317.5e02b19: * fix: don't double escape %{**} code. * Copy libalternatives binaries from buildroot to flavorbin - Update to version 20250923.c3cfac8: * Remove py_setup_args macro completely. * Move libalternative conf creation to FLAVOR_alternative_conf * Update default-prjconf for primary python: python313 * Drop python38, add python314 * Make RPM macro expansions POSIX sh-compatible ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - bzip2-1.0.8-150400.3.4.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - python-rpm-macros-20260821.08c5ec8-150400.3.21.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:13:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:13:05 +0200 (CEST) Subject: SUSE-CU-2026:10210-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260913101305.33593FF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10210-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-61.4 , bci/bci-sle15-kernel-module-devel:latest Container Release : 61.4 Severity : important Type : security References : 1266786 1274774 1274788 1274795 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3979-1 Released: Sun Sep 6 09:43:09 2026 Summary: Recommended update for python-rpm-macros Type: recommended Severity: moderate References: This update for python-rpm-macros fixes the following issues: - Sync with slfo-main - Update to version 20260821.08c5ec8: * Use the primary interpreter for generic python3 macros * Add python315 macros, remove python39 - Update to version 20260629.bcd36db: * don't use realpath to the interpreter binary * doc: add a shot documentation text for %python_site{lib,arch}_module. * Add initial pyproject declarative buildsystem * fix: handle the situation when either `name` or `meta_name` is not found * Consolidate site directory name normalization into %__python_sitedir_name * Normalize the name of the directory * Definitions of %python_site{lib,arch}_module macros. - Update to version 20260601.4a231f4: * fix: allow function of `%pythonXX_provides` w/o /usr/bin/python3 * Update python version handling in default-prjconf * Rewrite README.md to have headlines for each macro. - Allow function of `%pythonXX_provides` even without the access to /usr/bin/python3. - Update to version 20260317.5e02b19: * fix: don't double escape %{**} code. * Copy libalternatives binaries from buildroot to flavorbin - Update to version 20250923.c3cfac8: * Remove py_setup_args macro completely. * Move libalternative conf creation to FLAVOR_alternative_conf * Update default-prjconf for primary python: python313 * Drop python38, add python314 * Make RPM macro expansions POSIX sh-compatible ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - bzip2-1.0.8-150400.3.4.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - python-rpm-macros-20260821.08c5ec8-150400.3.21.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:13:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:13:06 +0200 (CEST) Subject: SUSE-CU-2026:10211-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260913101306.969D1FF46@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10211-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-61.5 , bci/bci-sle15-kernel-module-devel:latest Container Release : 61.5 Severity : important Type : security References : 1266343 1269489 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1274856 1274857 1274858 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - cpio-2.13-150400.3.10.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:13:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:13:09 +0200 (CEST) Subject: SUSE-CU-2026:10213-1: Recommended update of bci/bci-sle15-kernel-module-devel Message-ID: <20260913101309.142D4FF48@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10213-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-61.11 , bci/bci-sle15-kernel-module-devel:latest Container Release : 61.11 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 1277247 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4118-1 Released: Thu Sep 10 03:04:49 2026 Summary: Recommended update for python-rpm-macros Type: recommended Severity: moderate References: This update for python-rpm-macros fixes the following issues: - Provide a primary_python fallback for legacy projects ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - glibc-2.38-150600.14.55.1 updated - glibc-locale-base-2.38-150600.14.55.1 updated - python-rpm-macros-20260908.1ec0542-150400.3.24.1 updated - glibc-locale-2.38-150600.14.55.1 updated - glibc-devel-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:13:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:13:10 +0200 (CEST) Subject: SUSE-CU-2026:10214-1: Recommended update of bci/bci-sle15-kernel-module-devel Message-ID: <20260913101310.858A8FF4A@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10214-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-61.13 , bci/bci-sle15-kernel-module-devel:latest Container Release : 61.13 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated - container:registry.suse.com-bci-bci-base-15.7-31dce1f05f6f1bd8f55a19aad195829fd37ccd11819e1dd937f55f40650512bf-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:14:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:14:09 +0200 (CEST) Subject: SUSE-CU-2026:10215-1: Security update of suse/sle15 Message-ID: <20260913101409.D55AAFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10215-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.23.27 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.23.27 , suse/sle15:latest Container Release : 5.23.27 Severity : important Type : security References : 1266343 1266664 1266786 1269489 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1274856 1274857 1274858 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-23679 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - container-suseconnect-2.6.0-150700.4.97.1 updated - cpio-2.13-150400.3.10.1 updated - curl-8.14.1-150700.7.26.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated - openssl-3-3.5.0-150700.5.50.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:14:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:14:11 +0200 (CEST) Subject: SUSE-CU-2026:10216-1: Security update of suse/sle15 Message-ID: <20260913101411.1211FFF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10216-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.23.29 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.23.29 , suse/sle15:latest Container Release : 5.23.29 Severity : critical Type : security References : 1257249 1261038 1268321 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4092-1 Released: Tue Sep 8 18:31:37 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. The following package changes have been done: - container-suseconnect-2.6.0-150700.4.97.2 updated - libzypp-17.38.15-150700.6.16.1 updated - zypper-1.14.101-150700.13.9.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:14:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:14:12 +0200 (CEST) Subject: SUSE-CU-2026:10217-1: Recommended update of suse/sle15 Message-ID: <20260913101412.5E17BFF46@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10217-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.23.32 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.23.32 , suse/sle15:latest Container Release : 5.23.32 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:14:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:14:13 +0200 (CEST) Subject: SUSE-CU-2026:10218-1: Recommended update of suse/sle15 Message-ID: <20260913101413.B468EFF48@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10218-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.23.33 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.23.33 , suse/sle15:latest Container Release : 5.23.33 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:14:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:14:14 +0200 (CEST) Subject: SUSE-CU-2026:10219-1: Recommended update of suse/sle15 Message-ID: <20260913101414.F04CBFF4A@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10219-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.23.34 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.23.34 , suse/sle15:latest Container Release : 5.23.34 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:15:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:15:56 +0200 (CEST) Subject: SUSE-CU-2026:10220-1: Security update of bci/spack Message-ID: <20260913101556.C0E59FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10220-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.49 , bci/spack:latest Container Release : 25.49 Severity : important Type : security References : 1266343 1266786 1269489 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1275837 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 CVE-2026-80229 CVE-2026-80230 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4029-1 Released: Mon Sep 7 09:45:31 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue: - CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4048-1 Released: Mon Sep 7 15:54:05 2026 Summary: Security update for curl Type: security Severity: low References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230 This update for curl fixes the following issues: - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - bzip2-1.0.8-150400.3.4.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - libnghttp2-devel-1.64.0-150700.3.6.1 updated - libbz2-devel-1.0.8-150400.3.4.1 updated - libopenssl-3-devel-3.5.0-150700.5.50.1 updated - libcurl-devel-8.14.1-150700.7.26.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:15:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:15:58 +0200 (CEST) Subject: SUSE-CU-2026:10221-1: Security update of bci/spack Message-ID: <20260913101558.03F6AFF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10221-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.50 , bci/spack:latest Container Release : 25.50 Severity : important Type : security References : 1266664 1274740 CVE-2026-23679 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). The following package changes have been done: - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libnghttp2-14-1.64.0-150700.3.6.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl-3-fips-provider-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libcurl4-8.14.1-150700.7.26.1 updated - curl-8.14.1-150700.7.26.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:16:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:16:00 +0200 (CEST) Subject: SUSE-CU-2026:10223-1: Recommended update of bci/spack Message-ID: <20260913101600.5C87AFF46@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10223-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.53 , bci/spack:latest Container Release : 25.53 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:16:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:16:01 +0200 (CEST) Subject: SUSE-CU-2026:10224-1: Recommended update of bci/spack Message-ID: <20260913101601.A6DB6FF48@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10224-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.55 , bci/spack:latest Container Release : 25.55 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - glibc-devel-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:16:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:16:02 +0200 (CEST) Subject: SUSE-CU-2026:10225-1: Recommended update of bci/spack Message-ID: <20260913101602.E1C63FF4A@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10225-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.57 , bci/spack:latest Container Release : 25.57 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated - container:registry.suse.com-bci-bci-base-15.7-31dce1f05f6f1bd8f55a19aad195829fd37ccd11819e1dd937f55f40650512bf-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:16:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:16:11 +0200 (CEST) Subject: SUSE-CU-2026:10226-1: Security update of suse/kiosk/tigervnc-x11vnc Message-ID: <20260913101611.ABE85FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/tigervnc-x11vnc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10226-1 Container Tags : suse/kiosk/tigervnc-x11vnc:1 , suse/kiosk/tigervnc-x11vnc:1.14 , suse/kiosk/tigervnc-x11vnc:1.14-63.26 , suse/kiosk/tigervnc-x11vnc:latest Container Release : 63.26 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274774 1274777 1274788 1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797 1274798 1274856 1274857 1274858 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-63072 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-75803 ----------------------------------------------------------------- The container suse/kiosk/tigervnc-x11vnc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - cpio-2.13-150400.3.10.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libopenssl1_1-1.1.1w-150700.11.30.1 updated - openssl-3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - coreutils-8.32-150400.9.12.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - sles-release-15.7-150700.67.6.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sun Sep 13 10:16:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:16:12 +0200 (CEST) Subject: SUSE-CU-2026:10227-1: Recommended update of suse/kiosk/tigervnc-x11vnc Message-ID: <20260913101612.AF70AFF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/tigervnc-x11vnc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10227-1 Container Tags : suse/kiosk/tigervnc-x11vnc:1 , suse/kiosk/tigervnc-x11vnc:1.14 , suse/kiosk/tigervnc-x11vnc:1.14-63.30 , suse/kiosk/tigervnc-x11vnc:latest Container Release : 63.30 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/kiosk/tigervnc-x11vnc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:16:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:16:14 +0200 (CEST) Subject: SUSE-CU-2026:10229-1: Recommended update of suse/kiosk/tigervnc-x11vnc Message-ID: <20260913101614.6B07DFF46@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/tigervnc-x11vnc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10229-1 Container Tags : suse/kiosk/tigervnc-x11vnc:1 , suse/kiosk/tigervnc-x11vnc:1.14 , suse/kiosk/tigervnc-x11vnc:1.14-63.34 , suse/kiosk/tigervnc-x11vnc:latest Container Release : 63.34 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/kiosk/tigervnc-x11vnc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:17:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:17:03 +0200 (CEST) Subject: SUSE-CU-2026:10230-1: Security update of suse/kiosk/xorg-client Message-ID: <20260913101703.A62B0FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10230-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-80.3 , suse/kiosk/xorg-client:latest Container Release : 80.3 Severity : important Type : security References : 1266343 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1274856 1274857 1274858 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-75803 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). The following package changes have been done: - cpio-2.13-150400.3.10.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:17:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:17:04 +0200 (CEST) Subject: SUSE-CU-2026:10231-1: Security update of suse/kiosk/xorg-client Message-ID: <20260913101704.B5DDCFF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10231-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-80.4 , suse/kiosk/xorg-client:latest Container Release : 80.4 Severity : low Type : security References : 1266786 CVE-2026-42250 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - libbz2-1-1.0.8-150400.3.4.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:17:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:17:05 +0200 (CEST) Subject: SUSE-CU-2026:10232-1: Recommended update of suse/kiosk/xorg-client Message-ID: <20260913101705.D2F17FF46@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10232-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-80.8 , suse/kiosk/xorg-client:latest Container Release : 80.8 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:17:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:17:07 +0200 (CEST) Subject: SUSE-CU-2026:10234-1: Recommended update of suse/kiosk/xorg-client Message-ID: <20260913101707.AF273FF48@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10234-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-80.12 , suse/kiosk/xorg-client:latest Container Release : 80.12 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:18:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:18:10 +0200 (CEST) Subject: SUSE-CU-2026:10235-1: Security update of suse/kiosk/xorg Message-ID: <20260913101810.CB90AFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10235-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-83.24 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 83.24 Severity : important Type : security References : 1266343 1266786 1274740 1274774 1274777 1274788 1274790 1274791 1274792 1274795 1274796 1274797 1274798 1274856 1274857 1274858 1275837 CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-34181 CVE-2026-42250 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-75803 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4039-1 Released: Mon Sep 7 10:29:11 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release. - CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). - CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). - CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). - CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). - CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). - CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). - CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). - CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). The following package changes have been done: - cpio-2.13-150400.3.10.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libopenssl3-3.5.0-150700.5.50.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated - bash-4.4-150400.27.6.1 removed - bash-sh-4.4-150400.27.6.1 removed - coreutils-8.32-150400.9.12.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - sles-release-15.7-150700.67.6.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Sun Sep 13 10:18:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:18:11 +0200 (CEST) Subject: SUSE-CU-2026:10236-1: Recommended update of suse/kiosk/xorg Message-ID: <20260913101811.EFB1FFF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10236-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-83.28 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 83.28 Severity : important Type : recommended References : 1212476 1227370 1236165 1239009 1242233 1243830 1252696 1253025 1258311 1259825 1262315 1275660 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:suse-sle15-15.7-f176fde88947383bf0cc78e75a858239708509c8b64ac87ec8ed886d5dc0df93-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4776c5a8380b126f45421aa2c1a3c0ef04b32ba1fb73c7fa21a3be61ebfeff1d-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:18:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:18:13 +0200 (CEST) Subject: SUSE-CU-2026:10238-1: Recommended update of suse/kiosk/xorg Message-ID: <20260913101813.E0006FF46@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10238-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-83.32 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 83.32 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:41:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:41:20 +0200 (CEST) Subject: SUSE-CU-2026:10310-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260913104120.D3096FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10310-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.118 , suse/sles/16.0/toolbox:latest Container Release : 1.118 Severity : moderate Type : security References : 1266664 1266667 CVE-2026-23679 CVE-2026-47104 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1631 Released: Mon Sep 7 12:17:39 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,1266667,CVE-2026-23679,CVE-2026-47104 This update for libusb-1_0 fixes the following issues: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). - CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667). The following package changes have been done: - libusb-1_0-0-1.0.28-160000.3.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:41:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:41:21 +0200 (CEST) Subject: SUSE-CU-2026:10311-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260913104122.00493FF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10311-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.119 , suse/sles/16.0/toolbox:latest Container Release : 1.119 Severity : critical Type : security References : 1257249 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1639 Released: Tue Sep 8 17:42:08 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). Changes for libzypp: Update to version 17.38.1: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Log all solver problem rules (bsc#1277790) The log contains the most relevant problem rule, but sometimes it helps to know all rules associated with this problem. zypper shows them on demand as 'detail'. The log now remembers them as well. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - repoGpgCheck: Strictly follow the repo_gpgcheck setting (bsc#1274625) There's been a legacy exception for unsigned repositories which were explicitly accepted in the past. After switching the repo_gpgcheck from off to on, they were allowed to stay unsigned until a first signed version was retrieved. From there on the handling was strict. Now the handling is strict as soon as the repo_gpgcheck turned on. The next set of metadata retrieved must be signed. - Iniparser: each new file starts in the unnamed section (bsc#1272534) - Fix hasCredentials() to require both username AND password to be non-empty (bsc#1273242) This avoids an unnecessary 2nd 401 response sending just the username in case the username but no password is known. Now it immediately fetches the credentials from disk if no password is known. - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730) The short Id (32bit/8byte) is not considered to be a safe identifier for a gpg key. A long id (64bit/16byte) or even better the full fingerprint is needed to identify the key. - zypp: Improve Testcase Loading for MCP Tools. Changes for zypper: Update to version 1.14.99: - Show solver problem details per default in not-interactive mode (bsc#1277790) This way they see all details when capturing zypper's output because the (d)etail button can't be pressed in not-interactive mode. - Add --servicesd-dir global option to relocate /etc/zypp/services.d (bsc#1257249) - info: check for missing positional args before systemSetup (bsc#1274091) - Remove deprecated installRecommends option from zypper.conf. The system wide default for all libzypp based applications is defined in zypp.conf(5). It is not recommended to define this in zypper exclusively. The following package changes have been done: - libzypp-17.38.15-160000.1.1 updated - zypper-1.14.101-160000.1.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:41:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:41:23 +0200 (CEST) Subject: SUSE-CU-2026:10312-1: Recommended update of suse/sles/16.0/toolbox Message-ID: <20260913104123.33B5FFF46@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10312-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.120 , suse/sles/16.0/toolbox:latest Container Release : 1.120 Severity : important Type : recommended References : 1239787 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1658 Released: Thu Sep 10 15:05:39 2026 Summary: Recommended update for openldap2_6 Type: recommended Severity: important References: 1239787 This update for openldap2_6 fixes the following issues: Changes in openldap2_6: - Update to version 2.6.13+157: * Add export symbols related to LDAP_CONNECTIONLESS * Clear after free: + Cleaning up memory and immediately erasing the pointer's memory address * prevent double free: + Ensuring the application never releases the exact same block of memory twice * liblber calloc: + OpenLDAP's specialized memory allocator that automatically wipes memory clean * Fix: openldap2_5: segfault when try to add bad escaped regex (bsc#1239787): + prevent double free in info rewrite * Set default ldapi path to be consistent for SUSE * guide.html file cherry-picked from https://src.opensuse.org/jengelh/openldap2/src/branch/master/openldap-2.6.8.tgz * Use OpenSSL API to verify host * Change malloc to use calloc to prevent memory reuse corruption * Return to release engineering The following package changes have been done: - libldap-2-2.6.13+157-160000.1.1 updated - libldap-data-2.6.13+157-160000.1.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:41:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:41:24 +0200 (CEST) Subject: SUSE-CU-2026:10313-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260913104124.6AB1DFF48@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10313-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.121 , suse/sles/16.0/toolbox:latest Container Release : 1.121 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1661 Released: Fri Sep 11 13:45:57 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent The following package changes have been done: - libacl1-2.4.0-160000.1.1 updated - libattr1-2.6.0-160000.1.1 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:50:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:50:46 +0200 (CEST) Subject: SUSE-CU-2026:10375-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260913105046.1C5DFFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10375-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.33 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.33 Severity : important Type : security References : 1274774 1274788 1274795 1277247 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4033-1 Released: Mon Sep 7 09:48:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,1277247,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). The following package changes have been done: - libopenssl1_1-1.1.1l-150400.7.104.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.104.1 updated - container:sles15-ltss-image-15.4.0-6.46 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:50:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:50:47 +0200 (CEST) Subject: SUSE-CU-2026:10376-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260913105047.4E90DFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10376-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.35 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.35 Severity : critical Type : security References : 1257249 1261038 1268321 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4096-1 Released: Wed Sep 9 10:34:28 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. The following package changes have been done: - libzypp-17.38.15-150400.3.161.1 updated - zypper-1.14.101-150400.3.107.1 updated - container:sles15-ltss-image-15.4.0-6.47 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:53:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:53:07 +0200 (CEST) Subject: SUSE-CU-2026:10378-1: Security update of suse/manager/4.3/proxy-salt-broker Message-ID: <20260913105307.4D30EFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-salt-broker ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10378-1 Container Tags : suse/manager/4.3/proxy-salt-broker:4.3.19 , suse/manager/4.3/proxy-salt-broker:4.3.19.9.72.37 , suse/manager/4.3/proxy-salt-broker:latest Container Release : 9.72.37 Severity : important Type : security References : 1274774 1274788 1274795 1277247 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4033-1 Released: Mon Sep 7 09:48:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,1277247,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). The following package changes have been done: - libopenssl1_1-1.1.1l-150400.7.104.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.104.1 updated - openssl-1_1-1.1.1l-150400.7.104.1 updated - container:sles15-ltss-image-15.4.0-6.46 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:53:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:53:08 +0200 (CEST) Subject: SUSE-CU-2026:10379-1: Security update of suse/manager/4.3/proxy-salt-broker Message-ID: <20260913105308.921A2FF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-salt-broker ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10379-1 Container Tags : suse/manager/4.3/proxy-salt-broker:4.3.19 , suse/manager/4.3/proxy-salt-broker:4.3.19.9.72.39 , suse/manager/4.3/proxy-salt-broker:latest Container Release : 9.72.39 Severity : critical Type : security References : 1257249 1261038 1268321 1271730 1272534 1273242 1274091 1274625 1277790 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4096-1 Released: Wed Sep 9 10:34:28 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. The following package changes have been done: - libzypp-17.38.15-150400.3.161.1 updated - zypper-1.14.101-150400.3.107.1 updated - container:sles15-ltss-image-15.4.0-6.47 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:55:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:55:41 +0200 (CEST) Subject: SUSE-CU-2026:10381-1: Security update of suse/manager/4.3/proxy-squid Message-ID: <20260913105541.11034FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-squid ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10381-1 Container Tags : suse/manager/4.3/proxy-squid:4.3.19 , suse/manager/4.3/proxy-squid:4.3.19.9.81.24 , suse/manager/4.3/proxy-squid:latest Container Release : 9.81.24 Severity : important Type : security References : 1274774 1274788 1274795 1277247 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4033-1 Released: Mon Sep 7 09:48:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,1277247,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). The following package changes have been done: - libopenssl1_1-1.1.1l-150400.7.104.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.104.1 updated - container:sles15-ltss-image-15.4.0-6.46 updated From sle-container-updates at lists.suse.com Sun Sep 13 10:58:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 12:58:26 +0200 (CEST) Subject: SUSE-CU-2026:10383-1: Security update of suse/manager/4.3/proxy-ssh Message-ID: <20260913105826.3EE3BFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-ssh ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10383-1 Container Tags : suse/manager/4.3/proxy-ssh:4.3.19 , suse/manager/4.3/proxy-ssh:4.3.19.9.72.24 , suse/manager/4.3/proxy-ssh:latest Container Release : 9.72.24 Severity : important Type : security References : 1274774 1274788 1274795 1277247 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-ssh was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4033-1 Released: Mon Sep 7 09:48:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,1277247,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). The following package changes have been done: - libopenssl1_1-1.1.1l-150400.7.104.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.104.1 updated - container:sles15-ltss-image-15.4.0-6.46 updated From sle-container-updates at lists.suse.com Sun Sep 13 11:00:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 13:00:49 +0200 (CEST) Subject: SUSE-CU-2026:10385-1: Security update of suse/manager/4.3/proxy-tftpd Message-ID: <20260913110049.123D5FF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-tftpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10385-1 Container Tags : suse/manager/4.3/proxy-tftpd:4.3.19 , suse/manager/4.3/proxy-tftpd:4.3.19.9.72.24 , suse/manager/4.3/proxy-tftpd:latest Container Release : 9.72.24 Severity : important Type : security References : 1274774 1274788 1274795 1277247 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4033-1 Released: Mon Sep 7 09:48:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,1277247,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). The following package changes have been done: - libopenssl1_1-1.1.1l-150400.7.104.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.104.1 updated - openssl-1_1-1.1.1l-150400.7.104.1 updated - container:sles15-ltss-image-15.4.0-6.46 updated From sle-container-updates at lists.suse.com Sun Sep 13 11:02:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 13:02:20 +0200 (CEST) Subject: SUSE-CU-2026:10394-1: Security update of trento/mcp-server-trento Message-ID: <20260913110220.11B3CFF1E@maintenance.suse.de> SUSE Container Update Advisory: trento/mcp-server-trento ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10394-1 Container Tags : trento/mcp-server-trento:1.1.1 , trento/mcp-server-trento:1.1.1-build1.10.20 , trento/mcp-server-trento:latest Container Release : 1.10.20 Severity : moderate Type : security References : 1252306 1253043 1257463 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container trento/mcp-server-trento was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 11:02:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 13:02:22 +0200 (CEST) Subject: SUSE-CU-2026:10397-1: Recommended update of trento/mcp-server-trento Message-ID: <20260913110222.C6859FF24@maintenance.suse.de> SUSE Container Update Advisory: trento/mcp-server-trento ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10397-1 Container Tags : trento/mcp-server-trento:1.1.1 , trento/mcp-server-trento:1.1.1-build1.10.24 , trento/mcp-server-trento:latest Container Release : 1.10.24 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container trento/mcp-server-trento was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 11:02:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 13:02:28 +0200 (CEST) Subject: SUSE-CU-2026:10399-1: Security update of trento/trento-checks Message-ID: <20260913110228.37F09FF47@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-checks ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10399-1 Container Tags : trento/trento-checks:1.3.1 , trento/trento-checks:1.3.1-build1.20.20 , trento/trento-checks:latest Container Release : 1.20.20 Severity : moderate Type : security References : 1252306 1253043 1257463 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container trento/trento-checks was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 11:02:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 13:02:31 +0200 (CEST) Subject: SUSE-CU-2026:10402-1: Recommended update of trento/trento-checks Message-ID: <20260913110231.1A919FF1E@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-checks ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10402-1 Container Tags : trento/trento-checks:1.3.1 , trento/trento-checks:1.3.1-build1.20.24 , trento/trento-checks:latest Container Release : 1.20.24 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container trento/trento-checks was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 11:02:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 13:02:39 +0200 (CEST) Subject: SUSE-CU-2026:10404-1: Security update of trento/trento-wanda Message-ID: <20260913110239.1FF41FF24@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-wanda ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10404-1 Container Tags : trento/trento-wanda:2.1.0 , trento/trento-wanda:2.1.0-build1.35.33 , trento/trento-wanda:latest Container Release : 1.35.33 Severity : important Type : security References : 1242233 1243830 1252306 1253043 1257463 1260446 1261400 1261982 1261983 1262305 1263656 1263658 1267644 1267647 1271712 1274774 1274788 1274795 1277267 CVE-2026-40226 CVE-2026-5435 CVE-2026-54874 CVE-2026-6238 CVE-2026-63072 ----------------------------------------------------------------- The container trento/trento-wanda was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3515-1 Released: Thu Aug 6 13:08:56 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3878-1 Released: Mon Aug 31 11:12:55 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). Changes for openssl-1_1: - August 2026 release (bsc#1274774) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - glibc-2.38-150600.14.52.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - libgcrypt20-1.11.0-150700.5.10.1 updated - libopenssl1_1-1.1.1w-150600.5.38.1 updated - libsystemd0-254.27-150600.4.71.2 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 11:02:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 13:02:40 +0200 (CEST) Subject: SUSE-CU-2026:10406-1: Recommended update of trento/trento-wanda Message-ID: <20260913110240.AEF55FF1E@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-wanda ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10406-1 Container Tags : trento/trento-wanda:2.1.0 , trento/trento-wanda:2.1.0-build1.35.36 , trento/trento-wanda:latest Container Release : 1.35.36 Severity : important Type : recommended References : 1242233 1243830 1277267 ----------------------------------------------------------------- The container trento/trento-wanda was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4116-1 Released: Wed Sep 9 21:41:52 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Revert the previous change since the syntax is not understood in this crypto-policies version. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 11:02:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 13:02:41 +0200 (CEST) Subject: SUSE-CU-2026:10407-1: Recommended update of trento/trento-wanda Message-ID: <20260913110241.8C84DFF47@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-wanda ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10407-1 Container Tags : trento/trento-wanda:2.1.0 , trento/trento-wanda:2.1.0-build1.35.38 , trento/trento-wanda:latest Container Release : 1.35.38 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container trento/trento-wanda was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 11:02:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 13:02:58 +0200 (CEST) Subject: SUSE-CU-2026:10409-1: Security update of trento/trento-web Message-ID: <20260913110258.34CCBFF19@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-web ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10409-1 Container Tags : trento/trento-web:3.1.5 , trento/trento-web:3.1.5-build4.62.10 , trento/trento-web:latest Container Release : 4.62.10 Severity : important Type : security References : 1242233 1243830 1260446 1274774 1274788 1274795 1277267 CVE-2026-54874 CVE-2026-63072 ----------------------------------------------------------------- The container trento/trento-web was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3878-1 Released: Mon Aug 31 11:12:55 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). Changes for openssl-1_1: - August 2026 release (bsc#1274774) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20230920.570ea89-150600.3.19.1 updated - libopenssl1_1-1.1.1w-150600.5.38.1 updated - container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 11:03:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 13:03:00 +0200 (CEST) Subject: SUSE-CU-2026:10411-1: Recommended update of trento/trento-web Message-ID: <20260913110300.3E101FF1F@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-web ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10411-1 Container Tags : trento/trento-web:3.1.5 , trento/trento-web:3.1.5-build4.62.13 , trento/trento-web:latest Container Release : 4.62.13 Severity : important Type : recommended References : 1242233 1243830 1277267 ----------------------------------------------------------------- The container trento/trento-web was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4116-1 Released: Wed Sep 9 21:41:52 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Revert the previous change since the syntax is not understood in this crypto-policies version. (bsc#1243830, bsc#1242233, bsc#1277267) The following package changes have been done: - crypto-policies-20250714.cd6043a-150700.6.4.2 updated - container:registry.suse.com-bci-bci-base-15.7-d3f6b1886d7a1693a63a8c643652e3df6c2ca76ac0f7421eccc261e8ba5243f5-0 updated From sle-container-updates at lists.suse.com Sun Sep 13 11:03:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 13 Sep 2026 13:03:01 +0200 (CEST) Subject: SUSE-CU-2026:10412-1: Recommended update of trento/trento-web Message-ID: <20260913110301.51F80FF46@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-web ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10412-1 Container Tags : trento/trento-web:3.1.5 , trento/trento-web:3.1.5-build4.62.15 , trento/trento-web:latest Container Release : 4.62.15 Severity : moderate Type : recommended References : 1277247 ----------------------------------------------------------------- The container trento/trento-web was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.38-150600.14.55.1 updated - container:registry.suse.com-bci-bci-base-15.7-8110321e05cb09a1be9f0f5033479877ea799b971358f117c3e864759a93d805-0 updated From sle-container-updates at lists.suse.com Mon Sep 14 15:54:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 17:54:06 +0200 (CEST) Subject: SUSE-IU-2026:7001-1: Security update of suse/sle-micro/base-5.5 Message-ID: <20260914155406.44D3AFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7001-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.318 , suse/sle-micro/base-5.5:latest Image Release : 5.8.318 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1268867 1271649 1272772 1272773 1272774 1273243 1274867 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - libfreebl3-3.125-150400.3.74.1 updated - mozilla-nspr-4.39-150400.12.3.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated From sle-container-updates at lists.suse.com Mon Sep 14 15:56:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 17:56:57 +0200 (CEST) Subject: SUSE-IU-2026:7002-1: Security update of suse/sle-micro/kvm-5.5 Message-ID: <20260914155657.4C923FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/kvm-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7002-1 Image Tags : suse/sle-micro/kvm-5.5:2.0.4 , suse/sle-micro/kvm-5.5:2.0.4-3.5.612 , suse/sle-micro/kvm-5.5:latest Image Release : 3.5.612 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1268867 1271649 1272772 1272773 1272774 1273243 1274867 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container suse/sle-micro/kvm-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - libfreebl3-3.125-150400.3.74.1 updated - mozilla-nspr-4.39-150400.12.3.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.318 updated From sle-container-updates at lists.suse.com Mon Sep 14 16:00:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 18:00:58 +0200 (CEST) Subject: SUSE-IU-2026:7004-1: Security update of suse/sle-micro/rt-5.5 Message-ID: <20260914160058.EBBA3FF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7004-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.725 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.725 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1268867 1271649 1272772 1272773 1272774 1273243 1274867 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - libfreebl3-3.125-150400.3.74.1 updated - mozilla-nspr-4.39-150400.12.3.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.115 updated From sle-container-updates at lists.suse.com Mon Sep 14 16:03:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 18:03:40 +0200 (CEST) Subject: SUSE-IU-2026:7006-1: Security update of suse/sle-micro/5.5 Message-ID: <20260914160340.19399FF24@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7006-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.115 , suse/sle-micro/5.5:latest Image Release : 5.8.115 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1268867 1271649 1272772 1272773 1272774 1273243 1274867 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - libfreebl3-3.125-150400.3.74.1 updated - mozilla-nspr-4.39-150400.12.3.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.318 updated From sle-container-updates at lists.suse.com Mon Sep 14 16:03:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 18:03:36 +0200 (CEST) Subject: SUSE-IU-2026:7005-1: Recommended update of suse/sle-micro/5.5 Message-ID: <20260914160336.8036FFF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7005-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.113 , suse/sle-micro/5.5:latest Image Release : 5.8.113 Severity : moderate Type : recommended References : 1277106 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4135-1 Released: Mon Sep 14 08:00:30 2026 Summary: Recommended update for sg3_utils Type: recommended Severity: moderate References: 1277106 This update for sg3_utils fixes the following issues: - sg_inq: avoid including 0-bytes in SCSI name strings (bsc#1277106) The following package changes have been done: - libsgutils2-1_47-2-1.47+17.417547d-150400.3.19.1 updated - sg3_utils-1.47+17.417547d-150400.3.19.1 updated From sle-container-updates at lists.suse.com Mon Sep 14 16:33:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 18:33:41 +0200 (CEST) Subject: SUSE-CU-2026:10440-1: Security update of suse/sle-micro/5.3/toolbox Message-ID: <20260914163341.769D7FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10440-1 Container Tags : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.283 , suse/sle-micro/5.3/toolbox:latest Container Release : 6.11.283 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libacl1-2.4.0-150000.4.6.1 updated - libattr1-2.6.0-150000.4.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 14 16:50:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 18:50:33 +0200 (CEST) Subject: SUSE-CU-2026:10441-1: Recommended update of suse/sle-micro-rancher/5.4 Message-ID: <20260914165033.0C395FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10441-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.186 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.186 Severity : moderate Type : recommended References : 1261914 1277106 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4135-1 Released: Mon Sep 14 08:00:30 2026 Summary: Recommended update for sg3_utils Type: recommended Severity: moderate References: 1277106 This update for sg3_utils fixes the following issues: - sg_inq: avoid including 0-bytes in SCSI name strings (bsc#1277106) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4138-1 Released: Mon Sep 14 08:03:21 2026 Summary: Recommended update for apparmor Type: recommended Severity: moderate References: 1261914 This update for apparmor fixes the following issues: - dovecot profile: allow PROC/PID/stat access (bsc#1261914) The following package changes have been done: - apparmor-parser-3.0.4-150400.5.21.1 updated - libapparmor1-3.0.4-150400.5.21.1 updated - libsgutils2-1_47-2-1.47+17.417547d-150400.3.19.1 updated - sg3_utils-1.47+17.417547d-150400.3.19.1 updated From sle-container-updates at lists.suse.com Mon Sep 14 16:50:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 18:50:34 +0200 (CEST) Subject: SUSE-CU-2026:10442-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260914165034.8E531FF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10442-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.187 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.187 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1268867 1271649 1272772 1272773 1272774 1273243 1274867 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libacl1-2.4.0-150000.4.6.1 updated - libattr1-2.6.0-150000.4.3.1 updated - libfreebl3-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - mozilla-nspr-4.39-150400.12.3.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated From sle-container-updates at lists.suse.com Mon Sep 14 16:54:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 18:54:19 +0200 (CEST) Subject: SUSE-CU-2026:10443-1: Security update of suse/sle-micro/5.4/toolbox Message-ID: <20260914165419.7E68DFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10443-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.284 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.284 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libacl1-2.4.0-150000.4.6.1 updated - libattr1-2.6.0-150000.4.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 14 16:57:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 18:57:18 +0200 (CEST) Subject: SUSE-CU-2026:10444-1: Security update of suse/sle-micro/5.5/toolbox Message-ID: <20260914165718.D1CFFFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10444-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.195 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.195 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libacl1-2.4.0-150000.4.6.1 updated - libattr1-2.6.0-150000.4.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 14 17:00:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 19:00:21 +0200 (CEST) Subject: SUSE-IU-2026:7007-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260914170021.901A2FF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7007-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.248 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.248 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 897 Released: Mon Sep 14 12:17:14 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-15.1 updated - SL-Micro-release-6.0-25.132 updated - glibc-locale-base-2.38-15.1 updated - container:SL-Micro-base-container-2.1.3-7.210 updated From sle-container-updates at lists.suse.com Mon Sep 14 17:02:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 19:02:47 +0200 (CEST) Subject: SUSE-IU-2026:7008-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260914170247.83D23FF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7008-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.210 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.210 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 897 Released: Mon Sep 14 12:17:14 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-15.1 updated - SL-Micro-release-6.0-25.132 updated - glibc-locale-base-2.38-15.1 updated - container:suse-toolbox-image-1.0.0-9.165 updated From sle-container-updates at lists.suse.com Mon Sep 14 17:05:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 19:05:13 +0200 (CEST) Subject: SUSE-IU-2026:7009-1: Security update of suse/sl-micro/6.0/kvm-os-container Message-ID: <20260914170513.F0953FF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7009-1 Image Tags : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.220 , suse/sl-micro/6.0/kvm-os-container:latest Image Release : 6.220 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 897 Released: Mon Sep 14 12:17:14 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-15.1 updated - SL-Micro-release-6.0-25.132 updated - glibc-locale-base-2.38-15.1 updated - container:SL-Micro-base-container-2.1.3-7.210 updated From sle-container-updates at lists.suse.com Mon Sep 14 17:08:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 19:08:37 +0200 (CEST) Subject: SUSE-IU-2026:7010-1: Security update of suse/sl-micro/6.0/rt-os-container Message-ID: <20260914170837.5E542FF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7010-1 Image Tags : suse/sl-micro/6.0/rt-os-container:2.1.3 , suse/sl-micro/6.0/rt-os-container:2.1.3-7.241 , suse/sl-micro/6.0/rt-os-container:latest Image Release : 7.241 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 897 Released: Mon Sep 14 12:17:14 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-15.1 updated - SL-Micro-release-6.0-25.132 updated - glibc-locale-base-2.38-15.1 updated - container:SL-Micro-container-2.1.3-6.248 updated From sle-container-updates at lists.suse.com Mon Sep 14 17:10:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 19:10:16 +0200 (CEST) Subject: SUSE-CU-2026:10445-1: Security update of suse/sl-micro/6.0/baremetal-iso-image Message-ID: <20260914171016.0338BFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/baremetal-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10445-1 Container Tags : suse/sl-micro/6.0/baremetal-iso-image:2.1.4 , suse/sl-micro/6.0/baremetal-iso-image:2.1.4-6.239 , suse/sl-micro/6.0/baremetal-iso-image:latest Container Release : 6.239 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 897 Released: Mon Sep 14 12:17:14 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-15.1 updated - container:SL-Micro-container-2.1.3-6.248 updated From sle-container-updates at lists.suse.com Mon Sep 14 17:12:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 19:12:55 +0200 (CEST) Subject: SUSE-CU-2026:10446-1: Security update of suse/sl-micro/6.0/base-iso-image Message-ID: <20260914171255.7ED1FFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/base-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10446-1 Container Tags : suse/sl-micro/6.0/base-iso-image:2.1.4 , suse/sl-micro/6.0/base-iso-image:2.1.4-5.239 , suse/sl-micro/6.0/base-iso-image:latest Container Release : 5.239 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 897 Released: Mon Sep 14 12:17:14 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-15.1 updated - container:SL-Micro-base-container-2.1.3-7.210 updated - container:SL-Micro-container-2.1.3-6.248 updated From sle-container-updates at lists.suse.com Mon Sep 14 17:15:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 19:15:37 +0200 (CEST) Subject: SUSE-CU-2026:10447-1: Security update of suse/sl-micro/6.0/kvm-iso-image Message-ID: <20260914171537.E12FFFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/kvm-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10447-1 Container Tags : suse/sl-micro/6.0/kvm-iso-image:2.1.4 , suse/sl-micro/6.0/kvm-iso-image:2.1.4-6.252 , suse/sl-micro/6.0/kvm-iso-image:latest Container Release : 6.252 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 897 Released: Mon Sep 14 12:17:14 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-15.1 updated - container:SL-Micro-kvm-container-2.1.3-6.220 updated - container:SL-Micro-container-2.1.3-6.248 updated From sle-container-updates at lists.suse.com Mon Sep 14 17:17:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 19:17:28 +0200 (CEST) Subject: SUSE-CU-2026:10448-1: Security update of suse/sl-micro/6.0/rt-iso-image Message-ID: <20260914171728.BF636FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/rt-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10448-1 Container Tags : suse/sl-micro/6.0/rt-iso-image:2.1.4 , suse/sl-micro/6.0/rt-iso-image:2.1.4-6.235 , suse/sl-micro/6.0/rt-iso-image:latest Container Release : 6.235 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 897 Released: Mon Sep 14 12:17:14 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-15.1 updated - container:SL-Micro-rt-container-2.1.3-7.241 updated - container:SL-Micro-container-2.1.3-6.248 updated From sle-container-updates at lists.suse.com Mon Sep 14 17:19:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 19:19:00 +0200 (CEST) Subject: SUSE-CU-2026:10449-1: Security update of suse/sl-micro/6.0/toolbox Message-ID: <20260914171900.168EBFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10449-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.165 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.165 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 897 Released: Mon Sep 14 12:17:14 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - SL-Micro-release-6.0-25.132 updated - glibc-locale-base-2.38-15.1 updated - glibc-locale-2.38-15.1 updated - glibc-2.38-15.1 updated - skelcd-EULA-SL-Micro-2024.01.19-8.131 updated From sle-container-updates at lists.suse.com Mon Sep 14 17:21:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 19:21:23 +0200 (CEST) Subject: SUSE-IU-2026:7011-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260914172123.CDF5EFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7011-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.172 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.172 Severity : moderate Type : security References : 1263704 1263705 1263707 1263708 1263709 1263710 1263711 1263712 1263713 1263714 1263715 1263716 1265071 1269221 CVE-2026-33845 CVE-2026-33846 CVE-2026-3833 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015 CVE-2026-43895 CVE-2026-47770 CVE-2026-5260 CVE-2026-5419 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 725 Released: Mon Sep 14 11:42:12 2026 Summary: Security update for jq Type: security Severity: moderate References: 1263704,1263705,1263707,1263708,1263709,1263710,1263711,1263712,1263713,1263714,1263715,1263716,1265071,1269221,CVE-2026-33845,CVE-2026-33846,CVE-2026-3833,CVE-2026-42009,CVE-2026-42010,CVE-2026-42011,CVE-2026-42012,CVE-2026-42013,CVE-2026-42014,CVE-2026-42015,CVE-2026-43895,CVE-2026-47770,CVE-2026-5260,CVE-2026-5419 This update for jq fixes the following issues: - CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). - CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). The following package changes have been done: - libjq1-1.7.1-slfo.1.1_5.1 updated - jq-1.7.1-slfo.1.1_5.1 updated From sle-container-updates at lists.suse.com Mon Sep 14 17:54:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 19:54:21 +0200 (CEST) Subject: SUSE-CU-2026:10454-1: Security update of suse/ltss/sle15.4/bci-base-fips Message-ID: <20260914175421.EA058FBAA@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.4/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10454-1 Container Tags : suse/ltss/sle15.4/bci-base-fips:15.4 , suse/ltss/sle15.4/bci-base-fips:15.4.2.104 , suse/ltss/sle15.4/bci-base-fips:latest Container Release : 2.104 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/ltss/sle15.4/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:sles15-ltss-image-15.4.0-6.48 updated From sle-container-updates at lists.suse.com Mon Sep 14 17:57:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 19:57:02 +0200 (CEST) Subject: SUSE-CU-2026:10455-1: Security update of suse/ltss/sle15.4/sle15 Message-ID: <20260914175702.7E8F2FBAA@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.4/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10455-1 Container Tags : suse/ltss/sle15.4/bci-base:15.4 , suse/ltss/sle15.4/bci-base:15.4-6.48 , suse/ltss/sle15.4/sle15:15.4 , suse/ltss/sle15.4/sle15:15.4-6.48 , suse/ltss/sle15.4/sle15:latest Container Release : 6.48 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/ltss/sle15.4/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libacl1-2.4.0-150000.4.6.1 updated - libattr1-2.6.0-150000.4.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 14 18:02:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 20:02:30 +0200 (CEST) Subject: SUSE-CU-2026:10456-1: Security update of suse/ltss/sle15.5/sle15 Message-ID: <20260914180231.01591FF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.5/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10456-1 Container Tags : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.71 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.71 , suse/ltss/sle15.5/sle15:latest Container Release : 8.71 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libacl1-2.4.0-150000.4.6.1 updated - libattr1-2.6.0-150000.4.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 14 18:03:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 20:03:31 +0200 (CEST) Subject: SUSE-CU-2026:10457-1: Security update of suse/ltss/sle15.6/bci-base-fips Message-ID: <20260914180331.6C4BFFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10457-1 Container Tags : suse/ltss/sle15.6/bci-base-fips:15.6 , suse/ltss/sle15.6/bci-base-fips:15.6-35.103 , suse/ltss/sle15.6/bci-base-fips:latest Container Release : 35.103 Severity : important Type : security References : 1268867 1278351 953659 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/ltss/sle15.6/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2019:44-1 Released: Tue Jan 8 13:07:32 2019 Summary: Recommended update for acl Type: recommended Severity: low References: 953659 This update for acl fixes the following issues: - test: Add helper library to fake passwd/group files. - quote: Escape literal backslashes. (bsc#953659) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4142-1 Released: Mon Sep 14 09:59:10 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1278351 This update for permissions fixes the following issue: - Update to version 20240826: * profiles: backport nvidia-modprobe (bsc#1278351) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - permissions-20240826-150600.10.21.1 updated - container:sles15-ltss-image-15.6.0-5.94 updated From sle-container-updates at lists.suse.com Mon Sep 14 18:06:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 20:06:06 +0200 (CEST) Subject: SUSE-CU-2026:10458-1: Recommended update of suse/ltss/sle15.6/sle15 Message-ID: <20260914180606.7E9A6FF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10458-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.93 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.93 , suse/ltss/sle15.6/sle15:latest Container Release : 5.93 Severity : moderate Type : recommended References : 1278351 ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4142-1 Released: Mon Sep 14 09:59:10 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1278351 This update for permissions fixes the following issue: - Update to version 20240826: * profiles: backport nvidia-modprobe (bsc#1278351) The following package changes have been done: - permissions-20240826-150600.10.21.1 updated From sle-container-updates at lists.suse.com Mon Sep 14 18:06:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 20:06:07 +0200 (CEST) Subject: SUSE-CU-2026:10459-1: Security update of suse/ltss/sle15.6/sle15 Message-ID: <20260914180607.C013FFF24@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10459-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.94 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.94 , suse/ltss/sle15.6/sle15:latest Container Release : 5.94 Severity : important Type : security References : 1268867 953659 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2019:44-1 Released: Tue Jan 8 13:07:32 2019 Summary: Recommended update for acl Type: recommended Severity: low References: 953659 This update for acl fixes the following issues: - test: Add helper library to fake passwd/group files. - quote: Escape literal backslashes. (bsc#953659) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libacl1-2.4.0-150000.4.6.1 updated - libattr1-2.6.0-150000.4.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 14 18:06:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 20:06:20 +0200 (CEST) Subject: SUSE-CU-2026:10460-1: Security update of suse/hpc/warewulf4-x86_64/sle-hpc-node Message-ID: <20260914180620.C75CEFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10460-1 Container Tags : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7.20.8.164 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest Container Release : 20.8.164 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1267696 1268867 1271649 1272772 1272773 1272774 1273243 1274867 1276764 1277106 1278001 1279863 CVE-2026-10805 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-19685 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4136-1 Released: Mon Sep 14 08:01:27 2026 Summary: Recommended update for sg3_utils Type: recommended Severity: moderate References: 1277106 This update for sg3_utils fixes the following issues: - sg_inq: avoid including 0-bytes in SCSI name strings (bsc#1277106) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4148-1 Released: Mon Sep 14 10:01:38 2026 Summary: Security update for NetworkManager Type: security Severity: important References: 1267696,1276764,CVE-2026-10805,CVE-2026-19685 This update for NetworkManager fixes the following issues: - CVE-2026-10805: Local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). - CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - NetworkManager-1.44.2-150600.3.10.1 updated - libacl1-2.4.0-150000.4.6.1 updated - libattr1-2.6.0-150000.4.3.1 updated - libfreebl3-3.125-150400.3.74.1 updated - libnm0-1.44.2-150600.3.10.1 updated - libsgutils2-1_48-2-1.48+13.88f0f67-150600.3.9.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - mozilla-nspr-4.39-150400.12.3.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - sg3_utils-1.48+13.88f0f67-150600.3.9.1 updated From sle-container-updates at lists.suse.com Mon Sep 14 18:25:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 14 Sep 2026 20:25:44 +0200 (CEST) Subject: SUSE-CU-2026:10461-1: Recommended update of suse/manager/4.3/proxy-httpd Message-ID: <20260914182544.7E3DFFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10461-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.36 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.36 Severity : moderate Type : recommended References : 1261914 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4138-1 Released: Mon Sep 14 08:03:21 2026 Summary: Recommended update for apparmor Type: recommended Severity: moderate References: 1261914 This update for apparmor fixes the following issues: - dovecot profile: allow PROC/PID/stat access (bsc#1261914) The following package changes have been done: - libapparmor1-3.0.4-150400.5.21.1 updated From sle-container-updates at lists.suse.com Tue Sep 15 07:09:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 09:09:00 +0200 (CEST) Subject: SUSE-IU-2026:7013-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260915070900.0B1EFFF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7013-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.173 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.173 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 728 Released: Mon Sep 14 17:52:13 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-slfo.1.1_10.1 updated - SL-Micro-release-6.1-slfo.1.12.75 updated - glibc-locale-base-2.38-slfo.1.1_10.1 updated - container:SL-Micro-base-container-2.2.1-5.186 updated From sle-container-updates at lists.suse.com Tue Sep 15 07:11:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 09:11:19 +0200 (CEST) Subject: SUSE-IU-2026:7014-1: Security update of suse/sl-micro/6.1/base-os-container Message-ID: <20260915071119.0585CFF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7014-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.186 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.186 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 728 Released: Mon Sep 14 17:52:13 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-slfo.1.1_10.1 updated - SL-Micro-release-6.1-slfo.1.12.75 updated - glibc-locale-base-2.38-slfo.1.1_10.1 updated - container:suse-toolbox-image-1.0.0-5.104 updated From sle-container-updates at lists.suse.com Tue Sep 15 07:13:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 09:13:55 +0200 (CEST) Subject: SUSE-IU-2026:7015-1: Security update of suse/sl-micro/6.1/kvm-os-container Message-ID: <20260915071355.58369FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7015-1 Image Tags : suse/sl-micro/6.1/kvm-os-container:2.2.1 , suse/sl-micro/6.1/kvm-os-container:2.2.1-5.188 , suse/sl-micro/6.1/kvm-os-container:latest Image Release : 5.188 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 728 Released: Mon Sep 14 17:52:13 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-slfo.1.1_10.1 updated - SL-Micro-release-6.1-slfo.1.12.75 updated - glibc-locale-base-2.38-slfo.1.1_10.1 updated - container:SL-Micro-base-container-2.2.1-5.186 updated From sle-container-updates at lists.suse.com Tue Sep 15 07:16:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 09:16:48 +0200 (CEST) Subject: SUSE-IU-2026:7016-1: Security update of suse/sl-micro/6.1/rt-os-container Message-ID: <20260915071648.AA5A0FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7016-1 Image Tags : suse/sl-micro/6.1/rt-os-container:2.2.1 , suse/sl-micro/6.1/rt-os-container:2.2.1-5.185 , suse/sl-micro/6.1/rt-os-container:latest Image Release : 5.185 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.1/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 728 Released: Mon Sep 14 17:52:13 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-slfo.1.1_10.1 updated - SL-Micro-release-6.1-slfo.1.12.75 updated - glibc-locale-base-2.38-slfo.1.1_10.1 updated - container:SL-Micro-container-2.2.1-7.173 updated From sle-container-updates at lists.suse.com Tue Sep 15 07:18:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 09:18:53 +0200 (CEST) Subject: SUSE-CU-2026:10468-1: Security update of suse/sl-micro/6.1/baremetal-iso-image Message-ID: <20260915071853.038DBFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.1/baremetal-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10468-1 Container Tags : suse/sl-micro/6.1/baremetal-iso-image:2.2.1 , suse/sl-micro/6.1/baremetal-iso-image:2.2.1-5.180 , suse/sl-micro/6.1/baremetal-iso-image:latest Container Release : 5.180 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 728 Released: Mon Sep 14 17:52:13 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-slfo.1.1_10.1 updated - container:SL-Micro-container-2.2.1-7.173 updated From sle-container-updates at lists.suse.com Tue Sep 15 07:20:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 09:20:56 +0200 (CEST) Subject: SUSE-CU-2026:10469-1: Security update of suse/sl-micro/6.1/base-iso-image Message-ID: <20260915072056.D5A57FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.1/base-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10469-1 Container Tags : suse/sl-micro/6.1/base-iso-image:2.2.1 , suse/sl-micro/6.1/base-iso-image:2.2.1-5.197 , suse/sl-micro/6.1/base-iso-image:latest Container Release : 5.197 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 728 Released: Mon Sep 14 17:52:13 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-slfo.1.1_10.1 updated - container:SL-Micro-base-container-2.2.1-5.186 updated - container:SL-Micro-container-2.2.1-7.173 updated From sle-container-updates at lists.suse.com Tue Sep 15 07:23:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 09:23:12 +0200 (CEST) Subject: SUSE-CU-2026:10470-1: Security update of suse/sl-micro/6.1/kvm-iso-image Message-ID: <20260915072312.5D07FFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.1/kvm-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10470-1 Container Tags : suse/sl-micro/6.1/kvm-iso-image:2.2.1 , suse/sl-micro/6.1/kvm-iso-image:2.2.1-5.217 , suse/sl-micro/6.1/kvm-iso-image:latest Container Release : 5.217 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 728 Released: Mon Sep 14 17:52:13 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-slfo.1.1_10.1 updated - container:SL-Micro-kvm-container-2.2.1-5.188 updated - container:SL-Micro-container-2.2.1-7.173 updated From sle-container-updates at lists.suse.com Tue Sep 15 07:25:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 09:25:28 +0200 (CEST) Subject: SUSE-CU-2026:10471-1: Security update of suse/sl-micro/6.1/rt-iso-image Message-ID: <20260915072528.E7850FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.1/rt-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10471-1 Container Tags : suse/sl-micro/6.1/rt-iso-image:2.2.1 , suse/sl-micro/6.1/rt-iso-image:2.2.1-5.181 , suse/sl-micro/6.1/rt-iso-image:latest Container Release : 5.181 Severity : moderate Type : security References : 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sl-micro/6.1/rt-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 728 Released: Mon Sep 14 17:52:13 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-slfo.1.1_10.1 updated - container:SL-Micro-rt-container-2.2.1-5.185 updated - container:SL-Micro-container-2.2.1-7.173 updated From sle-container-updates at lists.suse.com Tue Sep 15 08:03:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 10:03:37 +0200 (CEST) Subject: SUSE-CU-2026:10490-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260915080337.D5393FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10490-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.37 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.37 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:sles15-ltss-image-15.4.0-6.48 updated From sle-container-updates at lists.suse.com Tue Sep 15 08:05:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 10:05:40 +0200 (CEST) Subject: SUSE-CU-2026:10491-1: Security update of suse/manager/4.3/proxy-salt-broker Message-ID: <20260915080540.65DB1FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-salt-broker ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10491-1 Container Tags : suse/manager/4.3/proxy-salt-broker:4.3.19 , suse/manager/4.3/proxy-salt-broker:4.3.19.9.72.41 , suse/manager/4.3/proxy-salt-broker:latest Container Release : 9.72.41 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:sles15-ltss-image-15.4.0-6.48 updated From sle-container-updates at lists.suse.com Tue Sep 15 08:07:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 10:07:52 +0200 (CEST) Subject: SUSE-CU-2026:10492-1: Security update of suse/manager/4.3/proxy-squid Message-ID: <20260915080752.C2104FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-squid ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10492-1 Container Tags : suse/manager/4.3/proxy-squid:4.3.19 , suse/manager/4.3/proxy-squid:4.3.19.9.81.27 , suse/manager/4.3/proxy-squid:latest Container Release : 9.81.27 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:sles15-ltss-image-15.4.0-6.48 updated From sle-container-updates at lists.suse.com Tue Sep 15 08:10:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 10:10:26 +0200 (CEST) Subject: SUSE-CU-2026:10493-1: Security update of suse/manager/4.3/proxy-ssh Message-ID: <20260915081026.2BA49FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-ssh ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10493-1 Container Tags : suse/manager/4.3/proxy-ssh:4.3.19 , suse/manager/4.3/proxy-ssh:4.3.19.9.72.27 , suse/manager/4.3/proxy-ssh:latest Container Release : 9.72.27 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-ssh was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:sles15-ltss-image-15.4.0-6.48 updated From sle-container-updates at lists.suse.com Tue Sep 15 08:12:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 10:12:46 +0200 (CEST) Subject: SUSE-CU-2026:10494-1: Security update of suse/manager/4.3/proxy-tftpd Message-ID: <20260915081246.2A1A5FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-tftpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10494-1 Container Tags : suse/manager/4.3/proxy-tftpd:4.3.19 , suse/manager/4.3/proxy-tftpd:4.3.19.9.72.27 , suse/manager/4.3/proxy-tftpd:latest Container Release : 9.72.27 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:sles15-ltss-image-15.4.0-6.48 updated From sle-container-updates at lists.suse.com Tue Sep 15 16:36:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 18:36:22 +0200 (CEST) Subject: SUSE-IU-2026:7039-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260915163622.E9FECFF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7039-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.249 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.249 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 901 Released: Tue Sep 15 09:05:00 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-3.1 updated - container:SL-Micro-base-container-2.1.3-7.212 updated From sle-container-updates at lists.suse.com Tue Sep 15 16:39:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 18:39:07 +0200 (CEST) Subject: SUSE-IU-2026:7040-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260915163907.E7271FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7040-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.212 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.212 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 901 Released: Tue Sep 15 09:05:00 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-3.1 updated - container:suse-toolbox-image-1.0.0-9.166 updated From sle-container-updates at lists.suse.com Tue Sep 15 16:41:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 18:41:44 +0200 (CEST) Subject: SUSE-IU-2026:7041-1: Security update of suse/sl-micro/6.0/kvm-os-container Message-ID: <20260915164144.517AEFF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7041-1 Image Tags : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.221 , suse/sl-micro/6.0/kvm-os-container:latest Image Release : 6.221 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 901 Released: Tue Sep 15 09:05:00 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-3.1 updated - container:SL-Micro-base-container-2.1.3-7.212 updated From sle-container-updates at lists.suse.com Tue Sep 15 16:44:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 18:44:38 +0200 (CEST) Subject: SUSE-IU-2026:7042-1: Security update of suse/sl-micro/6.0/rt-os-container Message-ID: <20260915164438.584E6FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7042-1 Image Tags : suse/sl-micro/6.0/rt-os-container:2.1.3 , suse/sl-micro/6.0/rt-os-container:2.1.3-7.242 , suse/sl-micro/6.0/rt-os-container:latest Image Release : 7.242 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 901 Released: Tue Sep 15 09:05:00 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-3.1 updated - container:SL-Micro-container-2.1.3-6.249 updated From sle-container-updates at lists.suse.com Tue Sep 15 16:46:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 18:46:23 +0200 (CEST) Subject: SUSE-CU-2026:10495-1: Security update of suse/sl-micro/6.0/baremetal-iso-image Message-ID: <20260915164623.83448FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/baremetal-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10495-1 Container Tags : suse/sl-micro/6.0/baremetal-iso-image:2.1.4 , suse/sl-micro/6.0/baremetal-iso-image:2.1.4-6.240 , suse/sl-micro/6.0/baremetal-iso-image:latest Container Release : 6.240 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 901 Released: Tue Sep 15 09:05:00 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-3.1 updated - container:SL-Micro-container-2.1.3-6.249 updated From sle-container-updates at lists.suse.com Tue Sep 15 16:48:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 18:48:54 +0200 (CEST) Subject: SUSE-CU-2026:10496-1: Security update of suse/sl-micro/6.0/base-iso-image Message-ID: <20260915164854.D583EFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/base-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10496-1 Container Tags : suse/sl-micro/6.0/base-iso-image:2.1.4 , suse/sl-micro/6.0/base-iso-image:2.1.4-5.240 , suse/sl-micro/6.0/base-iso-image:latest Container Release : 5.240 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 901 Released: Tue Sep 15 09:05:00 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-3.1 updated - container:SL-Micro-base-container-2.1.3-7.212 updated - container:SL-Micro-container-2.1.3-6.249 updated From sle-container-updates at lists.suse.com Tue Sep 15 16:51:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 18:51:27 +0200 (CEST) Subject: SUSE-CU-2026:10497-1: Security update of suse/sl-micro/6.0/kvm-iso-image Message-ID: <20260915165127.4DBA5FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/kvm-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10497-1 Container Tags : suse/sl-micro/6.0/kvm-iso-image:2.1.4 , suse/sl-micro/6.0/kvm-iso-image:2.1.4-6.253 , suse/sl-micro/6.0/kvm-iso-image:latest Container Release : 6.253 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 901 Released: Tue Sep 15 09:05:00 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-3.1 updated - container:SL-Micro-kvm-container-2.1.3-6.221 updated - container:SL-Micro-container-2.1.3-6.249 updated From sle-container-updates at lists.suse.com Tue Sep 15 16:53:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 18:53:18 +0200 (CEST) Subject: SUSE-CU-2026:10498-1: Security update of suse/sl-micro/6.0/rt-iso-image Message-ID: <20260915165318.99B9CFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/rt-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10498-1 Container Tags : suse/sl-micro/6.0/rt-iso-image:2.1.4 , suse/sl-micro/6.0/rt-iso-image:2.1.4-6.236 , suse/sl-micro/6.0/rt-iso-image:latest Container Release : 6.236 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 901 Released: Tue Sep 15 09:05:00 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-3.1 updated - container:SL-Micro-rt-container-2.1.3-7.242 updated - container:SL-Micro-container-2.1.3-6.249 updated From sle-container-updates at lists.suse.com Tue Sep 15 16:54:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 18:54:43 +0200 (CEST) Subject: SUSE-CU-2026:10499-1: Security update of suse/sl-micro/6.0/toolbox Message-ID: <20260915165443.D5309FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10499-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.166 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.166 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 901 Released: Tue Sep 15 09:05:00 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-3.1 updated From sle-container-updates at lists.suse.com Tue Sep 15 16:59:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 18:59:21 +0200 (CEST) Subject: SUSE-IU-2026:7044-1: Security update of suse/sl-micro/6.1/base-os-container Message-ID: <20260915165921.76B82FF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7044-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.188 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.188 Severity : important Type : security References : 1257312 1265304 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 730 Released: Tue Sep 15 09:31:40 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1257312,1265304,1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-slfo.1.1_2.1 updated - container:suse-toolbox-image-1.0.0-5.105 updated From sle-container-updates at lists.suse.com Tue Sep 15 17:01:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 19:01:44 +0200 (CEST) Subject: SUSE-IU-2026:7045-1: Security update of suse/sl-micro/6.1/kvm-os-container Message-ID: <20260915170144.B9B22FF1F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7045-1 Image Tags : suse/sl-micro/6.1/kvm-os-container:2.2.1 , suse/sl-micro/6.1/kvm-os-container:2.2.1-5.190 , suse/sl-micro/6.1/kvm-os-container:latest Image Release : 5.190 Severity : important Type : security References : 1257312 1265304 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 730 Released: Tue Sep 15 09:31:40 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1257312,1265304,1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-slfo.1.1_2.1 updated - container:SL-Micro-base-container-2.2.1-5.188 updated From sle-container-updates at lists.suse.com Tue Sep 15 17:04:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 19:04:37 +0200 (CEST) Subject: SUSE-IU-2026:7046-1: Security update of suse/sl-micro/6.1/rt-os-container Message-ID: <20260915170437.3434AFF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7046-1 Image Tags : suse/sl-micro/6.1/rt-os-container:2.2.1 , suse/sl-micro/6.1/rt-os-container:2.2.1-5.187 , suse/sl-micro/6.1/rt-os-container:latest Image Release : 5.187 Severity : important Type : security References : 1257312 1265304 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.1/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 730 Released: Tue Sep 15 09:31:40 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1257312,1265304,1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-slfo.1.1_2.1 updated - container:SL-Micro-container-2.2.1-7.175 updated From sle-container-updates at lists.suse.com Tue Sep 15 17:06:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 19:06:39 +0200 (CEST) Subject: SUSE-CU-2026:10500-1: Security update of suse/sl-micro/6.1/baremetal-iso-image Message-ID: <20260915170639.49AC0FF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.1/baremetal-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10500-1 Container Tags : suse/sl-micro/6.1/baremetal-iso-image:2.2.1 , suse/sl-micro/6.1/baremetal-iso-image:2.2.1-5.182 , suse/sl-micro/6.1/baremetal-iso-image:latest Container Release : 5.182 Severity : important Type : security References : 1257312 1265304 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 730 Released: Tue Sep 15 09:31:40 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1257312,1265304,1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-slfo.1.1_2.1 updated - container:SL-Micro-container-2.2.1-7.175 updated From sle-container-updates at lists.suse.com Tue Sep 15 17:08:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 19:08:53 +0200 (CEST) Subject: SUSE-CU-2026:10501-1: Security update of suse/sl-micro/6.1/base-iso-image Message-ID: <20260915170853.75C6CFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.1/base-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10501-1 Container Tags : suse/sl-micro/6.1/base-iso-image:2.2.1 , suse/sl-micro/6.1/base-iso-image:2.2.1-5.199 , suse/sl-micro/6.1/base-iso-image:latest Container Release : 5.199 Severity : important Type : security References : 1257312 1265304 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 730 Released: Tue Sep 15 09:31:40 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1257312,1265304,1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-slfo.1.1_2.1 updated - container:SL-Micro-base-container-2.2.1-5.188 updated - container:SL-Micro-container-2.2.1-7.175 updated From sle-container-updates at lists.suse.com Tue Sep 15 17:11:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 19:11:03 +0200 (CEST) Subject: SUSE-CU-2026:10502-1: Security update of suse/sl-micro/6.1/kvm-iso-image Message-ID: <20260915171103.EFE17FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.1/kvm-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10502-1 Container Tags : suse/sl-micro/6.1/kvm-iso-image:2.2.1 , suse/sl-micro/6.1/kvm-iso-image:2.2.1-5.218 , suse/sl-micro/6.1/kvm-iso-image:latest Container Release : 5.218 Severity : important Type : security References : 1257312 1265304 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 730 Released: Tue Sep 15 09:31:40 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1257312,1265304,1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-slfo.1.1_2.1 updated - container:SL-Micro-kvm-container-2.2.1-5.190 updated - container:SL-Micro-container-2.2.1-7.175 updated From sle-container-updates at lists.suse.com Tue Sep 15 17:13:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 19:13:27 +0200 (CEST) Subject: SUSE-CU-2026:10503-1: Security update of suse/sl-micro/6.1/rt-iso-image Message-ID: <20260915171327.268E0FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.1/rt-iso-image ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10503-1 Container Tags : suse/sl-micro/6.1/rt-iso-image:2.2.1 , suse/sl-micro/6.1/rt-iso-image:2.2.1-5.182 , suse/sl-micro/6.1/rt-iso-image:latest Container Release : 5.182 Severity : important Type : security References : 1257312 1265304 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sl-micro/6.1/rt-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 730 Released: Tue Sep 15 09:31:40 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1257312,1265304,1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-slfo.1.1_2.1 updated - container:SL-Micro-rt-container-2.2.1-5.187 updated - container:SL-Micro-container-2.2.1-7.175 updated From sle-container-updates at lists.suse.com Tue Sep 15 17:36:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 19:36:42 +0200 (CEST) Subject: SUSE-IU-2026:7047-1: Recommended update of suse/sl-micro/6.2/base-os-container Message-ID: <20260915173642.DD44AFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7047-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.74 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.74 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1683 Released: Tue Sep 15 12:14:12 2026 Summary: Recommended update for dmidecode Type: recommended Severity: moderate References: This update for dmidecode fixes the following issues: Changes in dmidecode: - Display slot information for EDSFF (jsc#PED-16127) The following package changes have been done: - dmidecode-3.7-160000.2.1 updated - container:bci-bci-base-16.0-65d0d2c152d9a543a733017ef883565998f7adbcdcbfdf6702d6cdd95c206aea-0 updated From sle-container-updates at lists.suse.com Tue Sep 15 17:57:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 19:57:18 +0200 (CEST) Subject: SUSE-CU-2026:10505-1: Recommended update of bci/bci-init Message-ID: <20260915175718.6212FFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10505-1 Container Tags : bci/bci-init:15.7 , bci/bci-init:15.7-53.51 , bci/bci-init:latest Container Release : 53.51 Severity : moderate Type : recommended References : 1273300 1278351 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4127-1 Released: Fri Sep 11 08:49:46 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1273300,1278351 This update for permissions fixes the following issue: - Update to version 20250826: * profiles: backport nvidia-modprobe (bsc#1278351) * profiles: add cacti-spine cap_net_raw (bsc#1273300) The following package changes have been done: - permissions-20250826-150700.16.5.1 updated - container:registry.suse.com-bci-bci-base-15.7-31dce1f05f6f1bd8f55a19aad195829fd37ccd11819e1dd937f55f40650512bf-0 updated From sle-container-updates at lists.suse.com Tue Sep 15 17:58:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 19:58:10 +0200 (CEST) Subject: SUSE-CU-2026:10506-1: Security update of bci/bci-micro-fips Message-ID: <20260915175810.EAB19FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10506-1 Container Tags : bci/bci-micro-fips:15.7 , bci/bci-micro-fips:15.7-27.18 , bci/bci-micro-fips:latest Container Release : 27.18 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/bci-micro-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:bci-bci-base-15.7-31dce1f05f6f1bd8f55a19aad195829fd37ccd11819e1dd937f55f40650512bf-0 updated From sle-container-updates at lists.suse.com Tue Sep 15 17:58:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 19:58:43 +0200 (CEST) Subject: SUSE-CU-2026:10507-1: Security update of bci/bci-micro Message-ID: <20260915175843.0F11BFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10507-1 Container Tags : bci/bci-micro:15.7 , bci/bci-micro:15.7-61.7 , bci/bci-micro:latest Container Release : 61.7 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/bci-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:bci-bci-base-15.7-31dce1f05f6f1bd8f55a19aad195829fd37ccd11819e1dd937f55f40650512bf-0 updated From sle-container-updates at lists.suse.com Tue Sep 15 17:59:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 19:59:22 +0200 (CEST) Subject: SUSE-CU-2026:10508-1: Security update of bci/bci-minimal Message-ID: <20260915175922.B31B2FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-minimal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10508-1 Container Tags : bci/bci-minimal:15.7 , bci/bci-minimal:15.7-26.58 , bci/bci-minimal:latest Container Release : 26.58 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/bci-minimal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libacl1-2.4.0-150000.4.6.1 updated - libattr1-2.6.0-150000.4.3.1 updated From sle-container-updates at lists.suse.com Tue Sep 15 18:00:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 20:00:59 +0200 (CEST) Subject: SUSE-CU-2026:10509-1: Security update of bci/openjdk-devel Message-ID: <20260915180059.4FD12FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10509-1 Container Tags : bci/openjdk-devel:17 , bci/openjdk-devel:17-sles15 , bci/openjdk-devel:17.0.20.1 , bci/openjdk-devel:17.0.20.1-21.59 Container Release : 21.59 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1271649 1272772 1272773 1272774 1273243 1274867 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. The following package changes have been done: - libfreebl3-3.125-150400.3.74.1 updated - mozilla-nspr-4.39-150400.12.3.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - container:bci-openjdk-17-15.7.17-20.50 updated From sle-container-updates at lists.suse.com Tue Sep 15 18:02:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 20:02:21 +0200 (CEST) Subject: SUSE-CU-2026:10510-1: Security update of bci/openjdk Message-ID: <20260915180221.1C406FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10510-1 Container Tags : bci/openjdk:17 , bci/openjdk:17-sles15 , bci/openjdk:17.0.20.1 , bci/openjdk:17.0.20.1-20.50 Container Release : 20.50 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1271649 1272772 1272773 1272774 1273243 1274867 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. The following package changes have been done: - libfreebl3-3.125-150400.3.74.1 updated - mozilla-nspr-4.39-150400.12.3.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - mozilla-nss-sysinit-3.125-150400.3.74.1 updated From sle-container-updates at lists.suse.com Tue Sep 15 18:03:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 20:03:49 +0200 (CEST) Subject: SUSE-CU-2026:10511-1: Security update of bci/openjdk-devel Message-ID: <20260915180349.366E6FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10511-1 Container Tags : bci/openjdk-devel:21 , bci/openjdk-devel:21-sles15 , bci/openjdk-devel:21.0.12.1 , bci/openjdk-devel:21.0.12.1-25.59 Container Release : 25.59 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1271649 1272772 1272773 1272774 1273243 1274867 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. The following package changes have been done: - libfreebl3-3.125-150400.3.74.1 updated - mozilla-nspr-4.39-150400.12.3.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - container:bci-openjdk-21-15.7.21-24.49 updated From sle-container-updates at lists.suse.com Tue Sep 15 18:05:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 20:05:24 +0200 (CEST) Subject: SUSE-CU-2026:10512-1: Security update of bci/openjdk Message-ID: <20260915180524.4B8A4FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10512-1 Container Tags : bci/openjdk:21 , bci/openjdk:21-sles15 , bci/openjdk:21.0.12.1 , bci/openjdk:21.0.12.1-24.49 Container Release : 24.49 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1271649 1272772 1272773 1272774 1273243 1274867 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. The following package changes have been done: - libfreebl3-3.125-150400.3.74.1 updated - mozilla-nspr-4.39-150400.12.3.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - mozilla-nss-sysinit-3.125-150400.3.74.1 updated From sle-container-updates at lists.suse.com Tue Sep 15 18:06:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 20:06:19 +0200 (CEST) Subject: SUSE-CU-2026:10513-1: Security update of bci/openjdk-devel Message-ID: <20260915180619.ED5B4FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10513-1 Container Tags : bci/openjdk-devel:25 , bci/openjdk-devel:25-sles15 , bci/openjdk-devel:25.0.4.1 , bci/openjdk-devel:25.0.4.1-9.60 , bci/openjdk-devel:latest Container Release : 9.60 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1271649 1272772 1272773 1272774 1273243 1274867 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. The following package changes have been done: - libfreebl3-3.125-150400.3.74.1 updated - mozilla-nspr-4.39-150400.12.3.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - container:bci-openjdk-25-15.7.25-9.49 updated From sle-container-updates at lists.suse.com Tue Sep 15 18:07:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 20:07:22 +0200 (CEST) Subject: SUSE-CU-2026:10514-1: Security update of bci/openjdk Message-ID: <20260915180722.F0357FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10514-1 Container Tags : bci/openjdk:25 , bci/openjdk:25-sles15 , bci/openjdk:25.0.4.1 , bci/openjdk:25.0.4.1-9.49 , bci/openjdk:latest Container Release : 9.49 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1271649 1272772 1272773 1272774 1273243 1274867 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. The following package changes have been done: - libfreebl3-3.125-150400.3.74.1 updated - mozilla-nspr-4.39-150400.12.3.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - mozilla-nss-sysinit-3.125-150400.3.74.1 updated From sle-container-updates at lists.suse.com Tue Sep 15 18:12:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 20:12:06 +0200 (CEST) Subject: SUSE-CU-2026:10515-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260915181206.06069FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10515-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-61.15 , bci/bci-sle15-kernel-module-devel:latest Container Release : 61.15 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1271649 1272772 1272773 1272774 1273243 1274867 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. The following package changes have been done: - libfreebl3-3.125-150400.3.74.1 updated - mozilla-nspr-4.39-150400.12.3.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - mozilla-nss-tools-3.125-150400.3.74.1 updated From sle-container-updates at lists.suse.com Tue Sep 15 18:13:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 15 Sep 2026 20:13:07 +0200 (CEST) Subject: SUSE-CU-2026:10516-1: Security update of suse/sle15 Message-ID: <20260915181307.E9E87FF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10516-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.23.37 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.23.37 , suse/sle15:latest Container Release : 5.23.37 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libacl1-2.4.0-150000.4.6.1 updated - libattr1-2.6.0-150000.4.3.1 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:07:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:07:17 +0200 (CEST) Subject: SUSE-CU-2026:10549-1: Security update of private-registry/1.2/harbor-core Message-ID: <20260916070717.C8F4AFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10549-1 Container Tags : private-registry/1.2/harbor-core:1.2.1 , private-registry/1.2/harbor-core:1.2.1-1.105 , private-registry/1.2/harbor-core:latest Container Release : 1.105 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/1.2/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:07:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:07:52 +0200 (CEST) Subject: SUSE-CU-2026:10550-1: Security update of private-registry/1.2/harbor-exporter Message-ID: <20260916070752.48D93FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10550-1 Container Tags : private-registry/1.2/harbor-exporter:1.2.1 , private-registry/1.2/harbor-exporter:1.2.1-1.105 , private-registry/1.2/harbor-exporter:latest Container Release : 1.105 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/1.2/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:08:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:08:28 +0200 (CEST) Subject: SUSE-CU-2026:10551-1: Security update of private-registry/1.2/harbor-jobservice Message-ID: <20260916070828.A3FA9FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10551-1 Container Tags : private-registry/1.2/harbor-jobservice:1.2.1 , private-registry/1.2/harbor-jobservice:1.2.1-1.103 , private-registry/1.2/harbor-jobservice:latest Container Release : 1.103 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/1.2/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:09:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:09:10 +0200 (CEST) Subject: SUSE-CU-2026:10552-1: Security update of private-registry/1.2/harbor-portal Message-ID: <20260916070910.06315FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10552-1 Container Tags : private-registry/1.2/harbor-portal:1.2.1 , private-registry/1.2/harbor-portal:1.2.1-1.114 , private-registry/1.2/harbor-portal:latest Container Release : 1.114 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:09:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:09:52 +0200 (CEST) Subject: SUSE-CU-2026:10553-1: Security update of private-registry/1.2/harbor-registry Message-ID: <20260916070952.206A7FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10553-1 Container Tags : private-registry/1.2/harbor-registry:1.2.1 , private-registry/1.2/harbor-registry:1.2.1-1.105 , private-registry/1.2/harbor-registry:latest Container Release : 1.105 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:10:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:10:36 +0200 (CEST) Subject: SUSE-CU-2026:10554-1: Security update of private-registry/1.2/harbor-registryctl Message-ID: <20260916071036.439CBFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10554-1 Container Tags : private-registry/1.2/harbor-registryctl:1.2.1 , private-registry/1.2/harbor-registryctl:1.2.1-1.105 , private-registry/1.2/harbor-registryctl:latest Container Release : 1.105 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:11:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:11:31 +0200 (CEST) Subject: SUSE-CU-2026:10555-1: Security update of private-registry/1.2/harbor-trivy-adapter Message-ID: <20260916071131.61217FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10555-1 Container Tags : private-registry/1.2/harbor-trivy-adapter:1.2.1 , private-registry/1.2/harbor-trivy-adapter:1.2.1-1.114 , private-registry/1.2/harbor-trivy-adapter:latest Container Release : 1.114 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/1.2/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:13:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:13:26 +0200 (CEST) Subject: SUSE-CU-2026:10556-1: Security update of private-registry/harbor-core Message-ID: <20260916071326.8B91BFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10556-1 Container Tags : private-registry/harbor-core:1.1.3 , private-registry/harbor-core:1.1.3-2.120 , private-registry/harbor-core:latest Container Release : 2.120 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:15:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:15:27 +0200 (CEST) Subject: SUSE-CU-2026:10557-1: Security update of private-registry/harbor-exporter Message-ID: <20260916071527.19CDFFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10557-1 Container Tags : private-registry/harbor-exporter:1.1.3 , private-registry/harbor-exporter:1.1.3-2.121 , private-registry/harbor-exporter:latest Container Release : 2.121 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:17:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:17:34 +0200 (CEST) Subject: SUSE-CU-2026:10558-1: Security update of private-registry/harbor-jobservice Message-ID: <20260916071734.97B08FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10558-1 Container Tags : private-registry/harbor-jobservice:1.1.3 , private-registry/harbor-jobservice:1.1.3-2.120 , private-registry/harbor-jobservice:latest Container Release : 2.120 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:19:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:19:35 +0200 (CEST) Subject: SUSE-CU-2026:10559-1: Security update of private-registry/harbor-portal Message-ID: <20260916071935.6C078FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10559-1 Container Tags : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.133 , private-registry/harbor-portal:latest Container Release : 2.133 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:20:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:20:27 +0200 (CEST) Subject: SUSE-CU-2026:10560-1: Security update of private-registry/harbor-registry Message-ID: <20260916072027.6220BFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10560-1 Container Tags : private-registry/harbor-registry:1.1.3 , private-registry/harbor-registry:1.1.3-2.121 , private-registry/harbor-registry:latest Container Release : 2.121 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:22:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:22:27 +0200 (CEST) Subject: SUSE-CU-2026:10561-1: Security update of private-registry/harbor-registryctl Message-ID: <20260916072227.B1E97FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10561-1 Container Tags : private-registry/harbor-registryctl:1.1.3 , private-registry/harbor-registryctl:1.1.3-2.122 , private-registry/harbor-registryctl:latest Container Release : 2.122 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:24:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:24:16 +0200 (CEST) Subject: SUSE-CU-2026:10562-1: Security update of private-registry/harbor-trivy-adapter Message-ID: <20260916072416.60261FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10562-1 Container Tags : private-registry/harbor-trivy-adapter:1.1.3 , private-registry/harbor-trivy-adapter:1.1.3-2.134 , private-registry/harbor-trivy-adapter:latest Container Release : 2.134 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:24:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:24:43 +0200 (CEST) Subject: SUSE-CU-2026:10563-1: Security update of private-registry/harbor-jobservice Message-ID: <20260916072443.22B65FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10563-1 Container Tags : private-registry/harbor-jobservice:2.13 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5-1.74 , private-registry/harbor-jobservice:2.13.5-1.74 , private-registry/harbor-jobservice:latest Container Release : 1.74 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:25:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:25:09 +0200 (CEST) Subject: SUSE-CU-2026:10564-1: Security update of private-registry/harbor-portal Message-ID: <20260916072509.1C90CFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10564-1 Container Tags : private-registry/harbor-portal:2.13 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5-1.79 , private-registry/harbor-portal:2.13.5-1.79 , private-registry/harbor-portal:latest Container Release : 1.79 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:25:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:25:31 +0200 (CEST) Subject: SUSE-CU-2026:10565-1: Security update of private-registry/harbor-registry Message-ID: <20260916072531.B5DF2FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10565-1 Container Tags : private-registry/harbor-registry:2.8.3 , private-registry/harbor-registry:2.8.3-1.75 , private-registry/harbor-registry:latest Container Release : 1.75 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:25:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:25:56 +0200 (CEST) Subject: SUSE-CU-2026:10566-1: Security update of private-registry/harbor-registryctl Message-ID: <20260916072556.46EA4FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10566-1 Container Tags : private-registry/harbor-registryctl:2.13 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5-1.74 , private-registry/harbor-registryctl:2.13.5-1.74 , private-registry/harbor-registryctl:latest Container Release : 1.74 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - system-user-harbor-2.13.5-150700.2.2 updated - harbor213-registryctl-2.13.5-150700.2.2 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:26:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:26:24 +0200 (CEST) Subject: SUSE-CU-2026:10567-1: Security update of private-registry/harbor-trivy-adapter Message-ID: <20260916072624.8430FFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10567-1 Container Tags : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.78 , private-registry/harbor-trivy-adapter:latest Container Release : 1.78 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:29:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:29:54 +0200 (CEST) Subject: SUSE-CU-2026:10568-1: Security update of suse/sle-micro/5.3/toolbox Message-ID: <20260916072954.3812BFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10568-1 Container Tags : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.284 , suse/sle-micro/5.3/toolbox:latest Container Release : 6.11.284 Severity : important Type : security References : 1279584 1279588 1279593 1279595 1279782 1279783 1279784 CVE-2026-0799 CVE-2026-18238 CVE-2026-18313 CVE-2026-31911 CVE-2026-31912 CVE-2026-6244 CVE-2026-6554 ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4195-1 Released: Tue Sep 15 16:28:18 2026 Summary: Security update for libpcap Type: security Severity: important References: 1279584,1279588,1279593,1279595,1279782,1279783,1279784,CVE-2026-0799,CVE-2026-18238,CVE-2026-18313,CVE-2026-31911,CVE-2026-31912,CVE-2026-6244,CVE-2026-6554 This update for libpcap fixes the following issues: - CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). - CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). - CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). - CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). - CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ` message received from the client and never frees the memory (bsc#1279784). - CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). - CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). The following package changes have been done: - libpcap1-1.10.1-150400.3.12.1 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:32:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:32:59 +0200 (CEST) Subject: SUSE-CU-2026:10569-1: Security update of suse/sle-micro/5.4/toolbox Message-ID: <20260916073259.13A9FFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10569-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.285 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.285 Severity : important Type : security References : 1279584 1279588 1279593 1279595 1279782 1279783 1279784 CVE-2026-0799 CVE-2026-18238 CVE-2026-18313 CVE-2026-31911 CVE-2026-31912 CVE-2026-6244 CVE-2026-6554 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4195-1 Released: Tue Sep 15 16:28:18 2026 Summary: Security update for libpcap Type: security Severity: important References: 1279584,1279588,1279593,1279595,1279782,1279783,1279784,CVE-2026-0799,CVE-2026-18238,CVE-2026-18313,CVE-2026-31911,CVE-2026-31912,CVE-2026-6244,CVE-2026-6554 This update for libpcap fixes the following issues: - CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). - CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). - CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). - CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). - CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ` message received from the client and never frees the memory (bsc#1279784). - CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). - CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). The following package changes have been done: - libpcap1-1.10.1-150400.3.12.1 updated From sle-container-updates at lists.suse.com Wed Sep 16 07:35:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 09:35:37 +0200 (CEST) Subject: SUSE-CU-2026:10570-1: Security update of suse/sle-micro/5.5/toolbox Message-ID: <20260916073537.B61A8FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10570-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.196 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.196 Severity : important Type : security References : 1279584 1279588 1279593 1279595 1279782 1279783 1279784 CVE-2026-0799 CVE-2026-18238 CVE-2026-18313 CVE-2026-31911 CVE-2026-31912 CVE-2026-6244 CVE-2026-6554 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4195-1 Released: Tue Sep 15 16:28:18 2026 Summary: Security update for libpcap Type: security Severity: important References: 1279584,1279588,1279593,1279595,1279782,1279783,1279784,CVE-2026-0799,CVE-2026-18238,CVE-2026-18313,CVE-2026-31911,CVE-2026-31912,CVE-2026-6244,CVE-2026-6554 This update for libpcap fixes the following issues: - CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). - CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). - CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). - CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). - CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ` message received from the client and never frees the memory (bsc#1279784). - CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). - CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). The following package changes have been done: - libpcap1-1.10.1-150400.3.12.1 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:22:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:22:15 +0200 (CEST) Subject: SUSE-CU-2026:10571-1: Security update of bci/dotnet-aspnet Message-ID: <20260916082215.4421CFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10571-1 Container Tags : bci/dotnet-aspnet:10.0 , bci/dotnet-aspnet:10.0-sles15 , bci/dotnet-aspnet:10.0.12 , bci/dotnet-aspnet:10.0.12-29.8 , bci/dotnet-aspnet:latest Container Release : 29.8 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:23:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:23:56 +0200 (CEST) Subject: SUSE-CU-2026:10572-1: Security update of bci/dotnet-aspnet Message-ID: <20260916082356.22987FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10572-1 Container Tags : bci/dotnet-aspnet:8.0 , bci/dotnet-aspnet:8.0-sles15 , bci/dotnet-aspnet:8.0.31 , bci/dotnet-aspnet:8.0.31-99.8 Container Release : 99.8 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:25:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:25:20 +0200 (CEST) Subject: SUSE-CU-2026:10573-1: Security update of bci/dotnet-aspnet Message-ID: <20260916082521.00282FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10573-1 Container Tags : bci/dotnet-aspnet:9.0 , bci/dotnet-aspnet:9.0-sles15 , bci/dotnet-aspnet:9.0.20 , bci/dotnet-aspnet:9.0.20-58.8 Container Release : 58.8 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:26:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:26:34 +0200 (CEST) Subject: SUSE-CU-2026:10574-1: Security update of bci/bci-base-fips Message-ID: <20260916082634.27E7FFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10574-1 Container Tags : bci/bci-base-fips:15.7 , bci/bci-base-fips:15.7-23.10 , bci/bci-base-fips:latest Container Release : 23.10 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:27:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:27:37 +0200 (CEST) Subject: SUSE-CU-2026:10575-1: Security update of bci/dotnet-sdk Message-ID: <20260916082737.AA6FEFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10575-1 Container Tags : bci/dotnet-sdk:10.0 , bci/dotnet-sdk:10.0-sles15 , bci/dotnet-sdk:10.0.12 , bci/dotnet-sdk:10.0.12-29.8 , bci/dotnet-sdk:latest Container Release : 29.8 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:29:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:29:06 +0200 (CEST) Subject: SUSE-CU-2026:10576-1: Security update of bci/dotnet-sdk Message-ID: <20260916082906.D2369FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10576-1 Container Tags : bci/dotnet-sdk:8.0 , bci/dotnet-sdk:8.0-sles15 , bci/dotnet-sdk:8.0.31 , bci/dotnet-sdk:8.0.31-99.8 Container Release : 99.8 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:30:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:30:44 +0200 (CEST) Subject: SUSE-CU-2026:10577-1: Security update of bci/dotnet-sdk Message-ID: <20260916083044.779D4FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10577-1 Container Tags : bci/dotnet-sdk:9.0 , bci/dotnet-sdk:9.0-sles15 , bci/dotnet-sdk:9.0.20 , bci/dotnet-sdk:9.0.20-59.8 Container Release : 59.8 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:31:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:31:55 +0200 (CEST) Subject: SUSE-CU-2026:10578-1: Security update of bci/dotnet-runtime Message-ID: <20260916083155.BC756FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10578-1 Container Tags : bci/dotnet-runtime:10.0 , bci/dotnet-runtime:10.0-sles15 , bci/dotnet-runtime:10.0.12 , bci/dotnet-runtime:10.0.12-29.8 , bci/dotnet-runtime:latest Container Release : 29.8 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:33:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:33:37 +0200 (CEST) Subject: SUSE-CU-2026:10579-1: Security update of bci/dotnet-runtime Message-ID: <20260916083337.EF5A9FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10579-1 Container Tags : bci/dotnet-runtime:8.0 , bci/dotnet-runtime:8.0-sles15 , bci/dotnet-runtime:8.0.31 , bci/dotnet-runtime:8.0.31-99.8 Container Release : 99.8 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:35:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:35:20 +0200 (CEST) Subject: SUSE-CU-2026:10580-1: Security update of bci/dotnet-runtime Message-ID: <20260916083520.DA7E9FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10580-1 Container Tags : bci/dotnet-runtime:9.0 , bci/dotnet-runtime:9.0-sles15 , bci/dotnet-runtime:9.0.20 , bci/dotnet-runtime:9.0.20-58.8 Container Release : 58.8 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:36:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:36:59 +0200 (CEST) Subject: SUSE-CU-2026:10581-1: Security update of bci/bci-init Message-ID: <20260916083659.C17CBFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10581-1 Container Tags : bci/bci-init:15.7 , bci/bci-init:15.7-53.52 , bci/bci-init:latest Container Release : 53.52 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:40:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:40:59 +0200 (CEST) Subject: SUSE-CU-2026:10583-1: Security update of suse/kiosk/firefox-esr Message-ID: <20260916084059.4FEE9FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10583-1 Container Tags : suse/kiosk/firefox-esr:153.2 , suse/kiosk/firefox-esr:153.2-75.36 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.36 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1269550 1271649 1272755 1272757 1272759 1272760 1272761 1272762 1272763 1272772 1272773 1272774 1273243 1274268 1274270 1274282 1274287 1274289 1274867 1276408 1276409 1276410 1276412 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-58049 CVE-2026-64833 CVE-2026-64834 CVE-2026-65703 CVE-2026-65704 CVE-2026-65705 CVE-2026-65706 CVE-2026-66036 CVE-2026-70628 CVE-2026-70629 CVE-2026-70630 CVE-2026-70631 CVE-2026-70632 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75142 CVE-2026-75143 CVE-2026-75144 CVE-2026-75146 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4149-1 Released: Mon Sep 14 10:02:11 2026 Summary: Security update for ffmpeg-4 Type: security Severity: important References: 1269550,1272755,1272757,1272759,1272760,1272761,1272762,1272763,1274268,1274270,1274282,1274287,1274289,1276408,1276409,1276410,1276412,CVE-2026-58049,CVE-2026-64833,CVE-2026-64834,CVE-2026-65703,CVE-2026-65704,CVE-2026-65705,CVE-2026-65706,CVE-2026-66036,CVE-2026-70628,CVE-2026-70629,CVE-2026-70630,CVE-2026-70631,CVE-2026-70632,CVE-2026-75142,CVE-2026-75143,CVE-2026-75144,CVE-2026-75146 This update for ffmpeg-4 fixes the following issues: - CVE-2026-58049: incorrect validation in the RASC video decoder can lead to an out-of-bounds heap write and memory corruption (bsc#1269550). - CVE-2026-64833: Out-of-Bounds Read via S/PDIF Muxer spdifenc.c (bsc#1272755). - CVE-2026-64834: Infinite Loop DoS via RTP/ASF Demuxer (bsc#1272757). - CVE-2026-65703: Out-of-Bounds Write in TDSC Video Decoder (bsc#1272759). - CVE-2026-65704: Out-of-Bounds Write via TY Demuxer and Shorten Decoder (bsc#1272760). - CVE-2026-65705: vf_floodfill Out-of-Bounds Write via filter_frame() (bsc#1272761). - CVE-2026-65706: vf_swaprect Out-of-Bounds Write via NV12 Frame Processing (bsc#1272762). - CVE-2026-66036: Heap Out-of-Bounds Write in vf_hqdn3d Filter (bsc#1272763). - CVE-2026-70628: signed integer underflows during subtitle buffer checks can cause heap buffer overflows (bsc#1274268). - CVE-2026-70629: unvalidated decompressed frame sizes in video decoders can cause uninitialized heap memory reads (bsc#1274270). - CVE-2026-70630: unvalidated decompression sizes in Screenpresso frame decoding can cause uninitialized heap memory reads (bsc#1274282). - CVE-2026-70631: unvalidated decompression sizes in TIFF strip decoding can cause uninitialized heap memory reads (bsc#1274287). - CVE-2026-70632: unenforced frame dimensions in CineForm HD decoding can cause heap-based out-of-bounds writes (bsc#1274289). - CVE-2026-75142: stack buffer overflow in the MPEG-PS muxer (bsc#1276408). - CVE-2026-75143: heap buffer overflow in the RIST protocol reader (bsc#1276409). - CVE-2026-75144: heap buffer overflow in the VC-2/Dirac RTP packetizer (bsc#1276410). - CVE-2026-75146: out-of-bounds read in the DASH demuxer (bsc#1276412). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. The following package changes have been done: - mozilla-nspr-4.39-150400.12.3.1 updated - libfreebl3-3.125-150400.3.74.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - libavutil56_70-4.4.8-150600.13.55.1 updated - libswresample3_9-4.4.8-150600.13.55.1 updated - libavcodec58_134-4.4.8-150600.13.55.1 updated - MozillaFirefox-153.2.0-150400.157.5.1 updated - MozillaFirefox-branding-SLE-153-150400.14.3.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:42:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:42:00 +0200 (CEST) Subject: SUSE-CU-2026:10584-1: Security update of suse/kubectl Message-ID: <20260916084200.86E45FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/kubectl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10584-1 Container Tags : suse/kubectl:1.35 , suse/kubectl:1.35.4 , suse/kubectl:1.35.4-2.61.10 , suse/kubectl:oldstable Container Release : 61.10 Severity : important Type : security References : 1276644 1277949 1278270 1278273 1278688 CVE-2026-37236 CVE-2026-41178 CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 ----------------------------------------------------------------- The container suse/kubectl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4175-1 Released: Mon Sep 14 12:27:42 2026 Summary: Security update for helm Type: security Severity: important References: 1276644,1277949,1278270,1278273,1278688,CVE-2026-37236,CVE-2026-41178,CVE-2026-84303,CVE-2026-84304,CVE-2026-84445 This update for helm fixes the following issues: - CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method-Override header and bypass established access control (bsc#1277949). - CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276644). - CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1278270). - CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278273). - CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS servers (bsc#1278688). The following package changes have been done: - helm-3.21.3-150000.1.96.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:43:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:43:08 +0200 (CEST) Subject: SUSE-CU-2026:10585-1: Security update of suse/kubectl Message-ID: <20260916084308.A5490FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/kubectl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10585-1 Container Tags : suse/kubectl:1.37 , suse/kubectl:1.37.0 , suse/kubectl:1.37.0-1.61.10 , suse/kubectl:latest , suse/kubectl:stable Container Release : 61.10 Severity : important Type : security References : 1276644 1277949 1278270 1278273 1278688 CVE-2026-37236 CVE-2026-41178 CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 ----------------------------------------------------------------- The container suse/kubectl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4175-1 Released: Mon Sep 14 12:27:42 2026 Summary: Security update for helm Type: security Severity: important References: 1276644,1277949,1278270,1278273,1278688,CVE-2026-37236,CVE-2026-41178,CVE-2026-84303,CVE-2026-84304,CVE-2026-84445 This update for helm fixes the following issues: - CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method-Override header and bypass established access control (bsc#1277949). - CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276644). - CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1278270). - CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278273). - CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS servers (bsc#1278688). The following package changes have been done: - helm-3.21.3-150000.1.96.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:45:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:45:34 +0200 (CEST) Subject: SUSE-CU-2026:10586-1: Security update of bci/openjdk Message-ID: <20260916084534.3B099FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10586-1 Container Tags : bci/openjdk:17 , bci/openjdk:17-sles15 , bci/openjdk:17.0.20.1 , bci/openjdk:17.0.20.1-20.51 Container Release : 20.51 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:57:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:57:20 +0200 (CEST) Subject: SUSE-CU-2026:10597-1: Security update of bci/rust Message-ID: <20260916085720.A381EFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10597-1 Container Tags : bci/rust:1.97 , bci/rust:1.97-sles15 , bci/rust:1.97.1 , bci/rust:1.97.1-2.2.9 , bci/rust:oldstable Container Release : 2.9 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 08:58:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 10:58:41 +0200 (CEST) Subject: SUSE-CU-2026:10598-1: Security update of bci/rust Message-ID: <20260916085841.6D8E8FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10598-1 Container Tags : bci/rust:1.98 , bci/rust:1.98-sles15 , bci/rust:1.98.0 , bci/rust:1.98.0-1.2.9 , bci/rust:latest , bci/rust:stable Container Release : 2.9 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 09:02:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 11:02:35 +0200 (CEST) Subject: SUSE-CU-2026:10602-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260916090235.370E9FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10602-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-61.16 , bci/bci-sle15-kernel-module-devel:latest Container Release : 61.16 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 09:04:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 11:04:04 +0200 (CEST) Subject: SUSE-CU-2026:10603-1: Security update of bci/spack Message-ID: <20260916090404.DC475FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10603-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.59 , bci/spack:latest Container Release : 25.59 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Wed Sep 16 09:05:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 16 Sep 2026 11:05:03 +0200 (CEST) Subject: SUSE-CU-2026:10605-1: Security update of suse/kiosk/xorg-client Message-ID: <20260916090503.7E2D9FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10605-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-80.15 , suse/kiosk/xorg-client:latest Container Release : 80.15 Severity : important Type : security References : 1226112 1262698 1262701 1266262 1266263 1269550 1271649 1272755 1272757 1272759 1272760 1272761 1272762 1272763 1272772 1272773 1272774 1273243 1274268 1274270 1274282 1274287 1274289 1274867 1276408 1276409 1276410 1276412 1278001 1279863 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16362 CVE-2026-16363 CVE-2026-16364 CVE-2026-16365 CVE-2026-16366 CVE-2026-16367 CVE-2026-16368 CVE-2026-16369 CVE-2026-16370 CVE-2026-16371 CVE-2026-16372 CVE-2026-16373 CVE-2026-16374 CVE-2026-16375 CVE-2026-16376 CVE-2026-16377 CVE-2026-16378 CVE-2026-16379 CVE-2026-16380 CVE-2026-16381 CVE-2026-16382 CVE-2026-16383 CVE-2026-16384 CVE-2026-16385 CVE-2026-16386 CVE-2026-16387 CVE-2026-16388 CVE-2026-16389 CVE-2026-16390 CVE-2026-16391 CVE-2026-16392 CVE-2026-16393 CVE-2026-16394 CVE-2026-16395 CVE-2026-16396 CVE-2026-16397 CVE-2026-16398 CVE-2026-16399 CVE-2026-16400 CVE-2026-16401 CVE-2026-16402 CVE-2026-16403 CVE-2026-16404 CVE-2026-16405 CVE-2026-16406 CVE-2026-16407 CVE-2026-16408 CVE-2026-16409 CVE-2026-16410 CVE-2026-16411 CVE-2026-16412 CVE-2026-58049 CVE-2026-64833 CVE-2026-64834 CVE-2026-65703 CVE-2026-65704 CVE-2026-65705 CVE-2026-65706 CVE-2026-66036 CVE-2026-70628 CVE-2026-70629 CVE-2026-70630 CVE-2026-70631 CVE-2026-70632 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74990 CVE-2026-75142 CVE-2026-75143 CVE-2026-75144 CVE-2026-75146 CVE-2026-75874 CVE-2026-84118 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84123 CVE-2026-84124 CVE-2026-84125 CVE-2026-84129 CVE-2026-84130 CVE-2026-84131 CVE-2026-84132 CVE-2026-84133 CVE-2026-84134 CVE-2026-84136 CVE-2026-84137 CVE-2026-84139 CVE-2026-84140 CVE-2026-84141 CVE-2026-84143 CVE-2026-84144 CVE-2026-84145 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4149-1 Released: Mon Sep 14 10:02:11 2026 Summary: Security update for ffmpeg-4 Type: security Severity: important References: 1269550,1272755,1272757,1272759,1272760,1272761,1272762,1272763,1274268,1274270,1274282,1274287,1274289,1276408,1276409,1276410,1276412,CVE-2026-58049,CVE-2026-64833,CVE-2026-64834,CVE-2026-65703,CVE-2026-65704,CVE-2026-65705,CVE-2026-65706,CVE-2026-66036,CVE-2026-70628,CVE-2026-70629,CVE-2026-70630,CVE-2026-70631,CVE-2026-70632,CVE-2026-75142,CVE-2026-75143,CVE-2026-75144,CVE-2026-75146 This update for ffmpeg-4 fixes the following issues: - CVE-2026-58049: incorrect validation in the RASC video decoder can lead to an out-of-bounds heap write and memory corruption (bsc#1269550). - CVE-2026-64833: Out-of-Bounds Read via S/PDIF Muxer spdifenc.c (bsc#1272755). - CVE-2026-64834: Infinite Loop DoS via RTP/ASF Demuxer (bsc#1272757). - CVE-2026-65703: Out-of-Bounds Write in TDSC Video Decoder (bsc#1272759). - CVE-2026-65704: Out-of-Bounds Write via TY Demuxer and Shorten Decoder (bsc#1272760). - CVE-2026-65705: vf_floodfill Out-of-Bounds Write via filter_frame() (bsc#1272761). - CVE-2026-65706: vf_swaprect Out-of-Bounds Write via NV12 Frame Processing (bsc#1272762). - CVE-2026-66036: Heap Out-of-Bounds Write in vf_hqdn3d Filter (bsc#1272763). - CVE-2026-70628: signed integer underflows during subtitle buffer checks can cause heap buffer overflows (bsc#1274268). - CVE-2026-70629: unvalidated decompressed frame sizes in video decoders can cause uninitialized heap memory reads (bsc#1274270). - CVE-2026-70630: unvalidated decompression sizes in Screenpresso frame decoding can cause uninitialized heap memory reads (bsc#1274282). - CVE-2026-70631: unvalidated decompression sizes in TIFF strip decoding can cause uninitialized heap memory reads (bsc#1274287). - CVE-2026-70632: unenforced frame dimensions in CineForm HD decoding can cause heap-based out-of-bounds writes (bsc#1274289). - CVE-2026-75142: stack buffer overflow in the MPEG-PS muxer (bsc#1276408). - CVE-2026-75143: heap buffer overflow in the RIST protocol reader (bsc#1276409). - CVE-2026-75144: heap buffer overflow in the VC-2/Dirac RTP packetizer (bsc#1276410). - CVE-2026-75146: out-of-bounds read in the DASH demuxer (bsc#1276412). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4156-1 Released: Mon Sep 14 11:06:43 2026 Summary: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Type: security Severity: important References: 1226112,1262698,1262701,1266262,1266263,1271649,1272772,1272773,1272774,1273243,1274867,1278001,1279863,CVE-2026-16349,CVE-2026-16350,CVE-2026-16351,CVE-2026-16352,CVE-2026-16353,CVE-2026-16354,CVE-2026-16355,CVE-2026-16356,CVE-2026-16357,CVE-2026-16358,CVE-2026-16359,CVE-2026-16360,CVE-2026-16362,CVE-2026-16363,CVE-2026-16364,CVE-2026-16365,CVE-2026-16366,CVE-2026-16367,CVE-2026-16368,CVE-2026-16369,CVE-2026-16370,CVE-2026-16371,CVE-2026-16372,CVE-2026-16373,CVE-2026-16374,CVE-2026-16375,CVE-2026-16376,CVE-2026-16377,CVE-2026-16378,CVE-2026-16379,CVE-2026-16380,CVE-2026-16381,CVE-2026-16382,CVE-2026-16383,CVE-2026-16384,CVE-2026-16385,CVE-2026-16386,CVE-2026-16387,CVE-2026-16388,CVE-2026-16389,CVE-2026-16390,CVE-2026-16391,CVE-2026-16392,CVE-2026-16393,CVE-2026-16394,CVE-2026-16395,CVE-2026-16396,CVE-2026-16397,CVE-2026-16398,CVE-2026-16399,CVE-2026-16400,CVE-2026-16401,CVE-2026-16402,CVE-2026-16403,CVE-2026-16404,CVE-2026-16405,CVE-2026-16406,CVE-2026-16407,CVE-2026-16 408,CVE-2026-16409,CVE-2026-16410,CVE-2026-16411,CVE-2026-16412,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74990,CVE-2026-75874,CVE-2026-84118,CVE-2026-84119,CVE-2026-84120,CVE-2026-84121,CVE-2026-84122,CVE-2026-84123,CVE-2026-84124,CVE-2026-84125,CVE -2026-84129,CVE-2026-84130,CVE-2026-84131,CVE-2026-84132,CVE-2026-84133,CVE-2026-84134,CVE-2026-84136,CVE-2026-84137,CVE-2026-84139,CVE-2026-84140,CVE-2026-84141,CVE-2026-84143,CVE-2026-84144,CVE-2026-84145 This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 - Firefox Extended Support Release 153.0esr ESR * New: ## General - Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. - Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. - The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. - Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. - Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs - Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. - Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. - Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. - Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. - A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy - Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. - Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. - Firefox now uses Safe Browsing V5 for phishing and malware protection. - Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. - Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations - Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. - A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility - Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows - Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. - Firefox web apps are also available for Microsoft Store installations. - Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS - Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. - WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux - Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. - Firefox no longer requires a restart after package manager updates and uses less memory on Linux. - Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. - WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. - Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. - Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. - Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: - Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields - Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. - Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove 'display' feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with 'void' default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: - update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig - update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 - update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. - update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char - update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support '%e' format specifier Changes in MozillaFirefox-branding-SLE: - use suse_version for SLE16 (bsc#1273243) - chage version to 153 - Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: - Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). - Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). - Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). - Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). - Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). - Add zeroization for ML-KEM, ported from upstream (bsc#1272774). - Add zeroization for ML-DSA (bsc#1272774). - nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. - Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). - Apply jitter enablement unconditionally (bsc#1262701). - update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ??? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren???t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ???Community ??? Network Security Services (NSS)???. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. - update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix 'testing if key corruption is detected in attribute' failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl - update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o - update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max - update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. - update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. - Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto-non-ec.patch due to upstreamed FIPS patches - update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). - update to NSS 3.120.1 * no upstream releasenotes - update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. - Revert back to original naming scheme of tarballs - update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs - update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. - Adjusted for changed naming scheme of tarballs for this release by upstream - update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* - update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch - update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don???t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function - update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions - update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. - update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions - update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool - rebase FIPS patches to adjust for upstream FIPS work - update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. The following package changes have been done: - mozilla-nspr-4.39-150400.12.3.1 updated - libfreebl3-3.125-150400.3.74.1 updated - mozilla-nss-certs-3.125-150400.3.74.1 updated - libsoftokn3-3.125-150400.3.74.1 updated - mozilla-nss-3.125-150400.3.74.1 updated - libavutil56_70-4.4.8-150600.13.55.1 updated - libswresample3_9-4.4.8-150600.13.55.1 updated - libavcodec58_134-4.4.8-150600.13.55.1 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 07:08:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 09:08:47 +0200 (CEST) Subject: SUSE-IU-2026:7077-1: Security update of suse/sle-micro/base-5.5 Message-ID: <20260917070847.BAF60FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7077-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.319 , suse/sle-micro/base-5.5:latest Image Release : 5.8.319 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4207-1 Released: Wed Sep 16 10:21:54 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-legacy-2.4.0-150400.5.12.1 updated - kbd-2.4.0-150400.5.12.1 updated From sle-container-updates at lists.suse.com Thu Sep 17 07:12:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 09:12:06 +0200 (CEST) Subject: SUSE-IU-2026:7078-1: Security update of suse/sle-micro/kvm-5.5 Message-ID: <20260917071206.C34E5FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/kvm-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7078-1 Image Tags : suse/sle-micro/kvm-5.5:2.0.4 , suse/sle-micro/kvm-5.5:2.0.4-3.5.614 , suse/sle-micro/kvm-5.5:latest Image Release : 3.5.614 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/sle-micro/kvm-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4207-1 Released: Wed Sep 16 10:21:54 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-legacy-2.4.0-150400.5.12.1 updated - kbd-2.4.0-150400.5.12.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.319 updated From sle-container-updates at lists.suse.com Thu Sep 17 07:17:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 09:17:12 +0200 (CEST) Subject: SUSE-IU-2026:7079-1: Security update of suse/sle-micro/rt-5.5 Message-ID: <20260917071712.1EA20FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7079-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.728 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.728 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4207-1 Released: Wed Sep 16 10:21:54 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-legacy-2.4.0-150400.5.12.1 updated - kbd-2.4.0-150400.5.12.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.117 updated From sle-container-updates at lists.suse.com Thu Sep 17 07:21:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 09:21:25 +0200 (CEST) Subject: SUSE-IU-2026:7080-1: Security update of suse/sle-micro/5.5 Message-ID: <20260917072125.0BDACFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7080-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.117 , suse/sle-micro/5.5:latest Image Release : 5.8.117 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4207-1 Released: Wed Sep 16 10:21:54 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-legacy-2.4.0-150400.5.12.1 updated - kbd-2.4.0-150400.5.12.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.319 updated From sle-container-updates at lists.suse.com Thu Sep 17 07:46:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 09:46:42 +0200 (CEST) Subject: SUSE-CU-2026:10642-1: Security update of private-registry/harbor-core Message-ID: <20260917074642.B2A8EFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10642-1 Container Tags : private-registry/harbor-core:2.13 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5-1.75 , private-registry/harbor-core:2.13.5-1.75 , private-registry/harbor-core:latest Container Release : 1.75 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - system-user-harbor-2.13.5-150700.2.3 updated - harbor213-core-2.13.5-150700.2.3 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 07:47:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 09:47:24 +0200 (CEST) Subject: SUSE-CU-2026:10643-1: Security update of private-registry/harbor-exporter Message-ID: <20260917074724.53A7EFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10643-1 Container Tags : private-registry/harbor-exporter:2.13 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5-1.75 , private-registry/harbor-exporter:2.13.5-1.75 , private-registry/harbor-exporter:latest Container Release : 1.75 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - harbor213-exporter-2.13.5-150700.2.3 updated - system-user-harbor-2.13.5-150700.2.3 updated - container:suse-sle15-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-801635b640d9ebe4cae37b0dba77b24cc2957e9a3d2b207373a8084d2860d955-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 08:02:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 10:02:59 +0200 (CEST) Subject: SUSE-CU-2026:10650-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260917080300.08F8BFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10650-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.188 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.188 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4207-1 Released: Wed Sep 16 10:21:54 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-legacy-2.4.0-150400.5.12.1 updated - kbd-2.4.0-150400.5.12.1 updated From sle-container-updates at lists.suse.com Thu Sep 17 08:07:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 10:07:20 +0200 (CEST) Subject: SUSE-IU-2026:7081-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260917080720.18A40FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7081-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.251 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.251 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 903 Released: Wed Sep 16 11:12:51 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-legacy-2.6.4-2.1 updated - kbd-2.6.4-2.1 updated - SL-Micro-release-6.0-25.133 updated - container:SL-Micro-base-container-2.1.3-7.214 updated From sle-container-updates at lists.suse.com Thu Sep 17 08:10:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 10:10:47 +0200 (CEST) Subject: SUSE-IU-2026:7082-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260917081047.13C99FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7082-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.214 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.214 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 903 Released: Wed Sep 16 11:12:51 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-legacy-2.6.4-2.1 updated - kbd-2.6.4-2.1 updated - SL-Micro-release-6.0-25.133 updated - container:suse-toolbox-image-1.0.0-9.167 updated From sle-container-updates at lists.suse.com Thu Sep 17 08:14:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 10:14:36 +0200 (CEST) Subject: SUSE-IU-2026:7083-1: Security update of suse/sl-micro/6.0/kvm-os-container Message-ID: <20260917081436.D0E90FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7083-1 Image Tags : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.223 , suse/sl-micro/6.0/kvm-os-container:latest Image Release : 6.223 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 903 Released: Wed Sep 16 11:12:51 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-legacy-2.6.4-2.1 updated - kbd-2.6.4-2.1 updated - SL-Micro-release-6.0-25.133 updated - container:SL-Micro-base-container-2.1.3-7.214 updated From sle-container-updates at lists.suse.com Thu Sep 17 08:19:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 10:19:02 +0200 (CEST) Subject: SUSE-IU-2026:7084-1: Security update of suse/sl-micro/6.0/rt-os-container Message-ID: <20260917081902.2CF5BFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7084-1 Image Tags : suse/sl-micro/6.0/rt-os-container:2.1.3 , suse/sl-micro/6.0/rt-os-container:2.1.3-7.243 , suse/sl-micro/6.0/rt-os-container:latest Image Release : 7.243 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 903 Released: Wed Sep 16 11:12:51 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-legacy-2.6.4-2.1 updated - kbd-2.6.4-2.1 updated - SL-Micro-release-6.0-25.133 updated - container:SL-Micro-container-2.1.3-6.251 updated From sle-container-updates at lists.suse.com Thu Sep 17 08:37:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 10:37:07 +0200 (CEST) Subject: SUSE-CU-2026:10655-1: Security update of suse/sl-micro/6.0/toolbox Message-ID: <20260917083707.507C3FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10655-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.167 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.167 Severity : important Type : security References : 1267974 1275441 1276223 1276226 CVE-2026-15806 CVE-2026-17084 CVE-2026-72693 CVE-2026-9669 ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 903 Released: Wed Sep 16 11:12:51 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ----------------------------------------------------------------- Advisory ID: 902 Released: Wed Sep 16 11:46:06 2026 Summary: Security update for python311 Type: security Severity: moderate References: 1267974,1276223,1276226,CVE-2026-15806,CVE-2026-17084,CVE-2026-9669 This update for python311 fixes the following issues: - CVE-2026-9669: crafted input can cause a stack buffer overflow (bsc#1267974). - CVE-2026-15806: urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over another scheme (bsc#1276223). - CVE-2026-17084: StringPrep algorithm considered Unicode codepoint attributes outside Unicode 3.2.0 (bsc#1276226). Changes for python311: - Updated to version 3.11.16 The following package changes have been done: - SL-Micro-release-6.0-25.133 updated - kbd-legacy-2.6.4-2.1 updated - kbd-2.6.4-2.1 updated - libpython3_11-1_0-3.11.16-1.1 updated - python311-base-3.11.16-1.1 updated - skelcd-EULA-SL-Micro-2024.01.19-8.132 updated From sle-container-updates at lists.suse.com Thu Sep 17 08:40:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 10:40:22 +0200 (CEST) Subject: SUSE-IU-2026:7085-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260917084022.0F9F8FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7085-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.177 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.177 Severity : important Type : security References : 1237409 1246281 1257065 1259240 1259611 1259734 1259735 1260026 1261969 1261970 1262098 1262319 1263891 1264962 1265268 1265413 1265578 1265580 1265581 1265582 1265583 1265584 1265585 1265586 1265587 1265588 1265589 1265903 1267581 1267821 1267974 1268314 1268977 1269066 1269788 1269959 1271192 1275441 1276223 1276226 CVE-2021-4189 CVE-2025-13462 CVE-2025-4330 CVE-2026-0864 CVE-2026-11940 CVE-2026-11972 CVE-2026-1502 CVE-2026-15308 CVE-2026-15806 CVE-2026-17084 CVE-2026-2297 CVE-2026-3276 CVE-2026-32792 CVE-2026-33278 CVE-2026-3446 CVE-2026-3644 CVE-2026-40622 CVE-2026-41292 CVE-2026-4224 CVE-2026-42534 CVE-2026-42923 CVE-2026-42944 CVE-2026-42959 CVE-2026-42960 CVE-2026-4360 CVE-2026-44390 CVE-2026-44608 CVE-2026-45186 CVE-2026-4519 CVE-2026-45409 CVE-2026-4786 CVE-2026-6100 CVE-2026-7210 CVE-2026-72522 CVE-2026-72693 CVE-2026-7774 CVE-2026-8328 CVE-2026-9669 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 690 Released: Thu Aug 27 15:46:55 2026 Summary: Recommended update for powerpc-utils Type: recommended Severity: important References: 1237409,1246281,1257065,1261970,1263891,1265903,1268314,CVE-2026-3446 This update for powerpc-utils fixes the following issues: - Add timeoout for DLPAR memory remove operation (bsc#1265903, bsc#1268314): * drmgr: Use 30 secs timeout for each LMB removal kernel interface - Fix description of lcpu field in the output of 'lparstat' (bsc#1257065): * lparstat: report virtual cpus as vcpu in non-legacy mode - Fix adding Ethernet entries in bootlist (bsc#1246281): * bootlist: ensure non-nvme devices are processed with add_logical - Bring power mode reporting inline with PAPR and ASMI * ppc64_cpu: bring power mode reporting inline with PAPR and ASMI - Fix: Memory mode mismatch, When HMC Memory mode is set to Dedicated Mode while on LPAR it appears as Shared Mode (bsc#1237409) ----------------------------------------------------------------- Advisory ID: 732 Released: Wed Sep 16 11:16:27 2026 Summary: Security update for kbd Type: security Severity: important References: 1265578,1265580,1265581,1265582,1265583,1265584,1265585,1265586,1265587,1265588,1265589,1275441,CVE-2026-32792,CVE-2026-33278,CVE-2026-40622,CVE-2026-41292,CVE-2026-42534,CVE-2026-42923,CVE-2026-42944,CVE-2026-42959,CVE-2026-42960,CVE-2026-44390,CVE-2026-44608,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ----------------------------------------------------------------- Advisory ID: 733 Released: Wed Sep 16 11:53:12 2026 Summary: Security update for python311 Type: security Severity: important References: 1259240,1259611,1259734,1259735,1260026,1261969,1262098,1262319,1264962,1265268,1265413,1267581,1267821,1267974,1268977,1269066,1269788,1269959,1271192,1276223,1276226,CVE-2021-4189,CVE-2025-13462,CVE-2025-4330,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-1502,CVE-2026-15308,CVE-2026-15806,CVE-2026-17084,CVE-2026-2297,CVE-2026-3276,CVE-2026-3644,CVE-2026-4224,CVE-2026-4360,CVE-2026-45186,CVE-2026-4519,CVE-2026-45409,CVE-2026-4786,CVE-2026-6100,CVE-2026-7210,CVE-2026-72522,CVE-2026-7774,CVE-2026-8328,CVE-2026-9669 This update for python311 fixes the following issues: - CVE-2025-13462: incorrect parsing of TarInfo header when GNU long name and type AREGTYPE are combined (bsc#1259611). - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF (bsc#1261969). - CVE-2026-2297: cpython: incorrectly handled hook in FileLoader can lead to validation bypass (bsc#1259240). - CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581). - CVE-2026-3644: incomplete control character validation in http.cookies (bsc#1259734). - CVE-2026-4224: C stack overflow when parsing XML with deeply nested DTD content models (bsc#1259735). - CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). - CVE-2026-4519: leading dashes in URLs are accepted by the `webbrowser.open()` API and allow for web browser command line option injection (bsc#1260026). - CVE-2026-4786: Incomplete mitigation of %action expansion for command injection to webbrowser.open() (bsc#1262319). - CVE-2026-6100: Arbitrary code execution or information disclosure via use-after-free in decompression modules (bsc#1262098). - CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection (bsc#1264962). - CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-9669: crafted input can cause a stack buffer overflow (bsc#1267974). - CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). - CVE-2026-15806: urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over another scheme (bsc#1276223). - CVE-2026-17084: StringPrep algorithm considered Unicode codepoint attributes outside Unicode 3.2.0 (bsc#1276226). Changes for python311: - Update to 3.11.16: - Build - gh-153438: Update Windows build and installer tooling and documentation to use the current download URL for nuget.exe. - Library - gh-109638: Fix exponential time in csv.Sniffer.sniff() for a sample which contains many quote characters. A doubled quote character is now also detected in a field which contains the delimiter or a line break. - gh-98820: Fix quadratic time in csv.Sniffer.sniff() for a sample which contains quoted fields, in particular for a single column of quoted fields. - gh-149231: In tomllib, the number of parts in TOML keys is now limited. - gh-146083: Update bundled libexpat to version 2.7.5. - gh-141707: Don't change tarfile.TarInfo type from AREGTYPE to DIRTYPE when parsing GNU long name or link headers (bsc#1259611, CVE-2025-13462). - gh-90949: Add SetBillionLaughsAttackProtectionActivationThreshold() and SetBillionLaughsAttackProtectionMaximumAmplification() to xmlparser objects to tune protections against billion laughs attacks. Patch by B?n?dikt Tran. - gh-100372: ssl.SSLContext.load_verify_locations() no longer incorrectly accepts some cases of trailing data when parsing DER. - Security - gh-155558: Update bundled libexpat to version 2.8.3 for the fix to CVE-2026-72522. - gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service (bsc#1271192, CVE-2026-15308). - gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings. - gh-152216: Update bundled libexpat to version 2.8.2. - gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback (bsc#1269959, CVE-2026-4360). - gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached (bsc#1269788, CVE-2026-11972). - gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree. - gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE-2025-4330 (bsc#1268977, CVE-2026-11940). - gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error (bsc#1267974, CVE-2026-9669). - gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @YLChen-007 via GHSA-w4q2-g22w-6fr4. - gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE-2026-45186. - gh-87451: The ftplib module's undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report (bsc#1265268, CVE-2026-8328). - gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink's directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter (bsc#1267821, CVE-2026-7774). - gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs (bsc#1267581, CVE-2026-3276). - gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later (bsc#1264962, CVE-2026-7210). - gh-149017: Update bundled libexpat to version 2.8.0. - gh-148808: Added buffer boundary check when using nbytes parameter with asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and the asyncio.ProactorEventLoop. - gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, and bz2.BZ2Decompressor when memory allocation fails with MemoryError, which could let a subsequent decompress() call read or write through a stale pointer to the already-released caller buffer (bsc#1262098, CVE-2026-6100). - gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass the dash-prefix safety check (bsc#1262319, CVE-2026-4786). - gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing '..' in the name (like 'foo..bar') are no longer skipped. - gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage. - gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method (bsc#1261969, CVE-2026-1502). - gh-145986: xml.parsers.expat: Fixed a crash caused by unbounded C recursion when converting deeply nested XML content models with ElementDeclHandler(). This addresses CVE-2026-4224 (bsc#1259735, CVE-2026-4224). - gh-145599: Reject control characters in http.cookies.Morsel update() and js_output(). This addresses CVE-2026-3644 (bsc#1259734, CVE-2026-3644). - gh-145506: Fixes CVE-2026-2297 by ensuring that SourcelessFileLoader uses io.open_code() when opening .pyc files (bsc#1259240, CVE-2026-2297). - gh-144370: Disallow usage of control characters in status in wsgiref.handlers to prevent HTTP header injections. Patch by Benedikt Johannes. - gh-143930: Reject leading dashes in URLs passed to webbrowser.open() (bsc#1260026, CVE-2026-4519). - gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values (bsc#1269066, CVE-2026-0864). - Tests - gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if it's not supported. Patch by Victor Stinner. The following package changes have been done: - kbd-2.6.4-slfo.1.1_2.1 updated - SL-Micro-release-6.1-slfo.1.12.76 updated - python311-base-3.11.16-slfo.1.1_1.1 updated - libpython3_11-1_0-3.11.16-slfo.1.1_1.1 updated - python311-3.11.16-slfo.1.1_1.1 updated - container:SL-Micro-base-container-2.2.1-5.190 updated From sle-container-updates at lists.suse.com Thu Sep 17 08:43:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 10:43:40 +0200 (CEST) Subject: SUSE-IU-2026:7086-1: Security update of suse/sl-micro/6.1/base-os-container Message-ID: <20260917084340.389ECFF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7086-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.190 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.190 Severity : important Type : security References : 1265578 1265580 1265581 1265582 1265583 1265584 1265585 1265586 1265587 1265588 1265589 1275441 CVE-2026-32792 CVE-2026-33278 CVE-2026-40622 CVE-2026-41292 CVE-2026-42534 CVE-2026-42923 CVE-2026-42944 CVE-2026-42959 CVE-2026-42960 CVE-2026-44390 CVE-2026-44608 CVE-2026-72693 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 732 Released: Wed Sep 16 11:16:27 2026 Summary: Security update for kbd Type: security Severity: important References: 1265578,1265580,1265581,1265582,1265583,1265584,1265585,1265586,1265587,1265588,1265589,1275441,CVE-2026-32792,CVE-2026-33278,CVE-2026-40622,CVE-2026-41292,CVE-2026-42534,CVE-2026-42923,CVE-2026-42944,CVE-2026-42959,CVE-2026-42960,CVE-2026-44390,CVE-2026-44608,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-2.6.4-slfo.1.1_2.1 updated - SL-Micro-release-6.1-slfo.1.12.76 updated - container:suse-toolbox-image-1.0.0-5.106 updated From sle-container-updates at lists.suse.com Thu Sep 17 08:47:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 10:47:05 +0200 (CEST) Subject: SUSE-IU-2026:7087-1: Security update of suse/sl-micro/6.1/kvm-os-container Message-ID: <20260917084705.1BB76FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7087-1 Image Tags : suse/sl-micro/6.1/kvm-os-container:2.2.1 , suse/sl-micro/6.1/kvm-os-container:2.2.1-5.192 , suse/sl-micro/6.1/kvm-os-container:latest Image Release : 5.192 Severity : important Type : security References : 1265578 1265580 1265581 1265582 1265583 1265584 1265585 1265586 1265587 1265588 1265589 1275441 CVE-2026-32792 CVE-2026-33278 CVE-2026-40622 CVE-2026-41292 CVE-2026-42534 CVE-2026-42923 CVE-2026-42944 CVE-2026-42959 CVE-2026-42960 CVE-2026-44390 CVE-2026-44608 CVE-2026-72693 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 732 Released: Wed Sep 16 11:16:27 2026 Summary: Security update for kbd Type: security Severity: important References: 1265578,1265580,1265581,1265582,1265583,1265584,1265585,1265586,1265587,1265588,1265589,1275441,CVE-2026-32792,CVE-2026-33278,CVE-2026-40622,CVE-2026-41292,CVE-2026-42534,CVE-2026-42923,CVE-2026-42944,CVE-2026-42959,CVE-2026-42960,CVE-2026-44390,CVE-2026-44608,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-2.6.4-slfo.1.1_2.1 updated - SL-Micro-release-6.1-slfo.1.12.76 updated - container:SL-Micro-base-container-2.2.1-5.190 updated From sle-container-updates at lists.suse.com Thu Sep 17 08:50:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 10:50:54 +0200 (CEST) Subject: SUSE-IU-2026:7088-1: Security update of suse/sl-micro/6.1/rt-os-container Message-ID: <20260917085054.762A6FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7088-1 Image Tags : suse/sl-micro/6.1/rt-os-container:2.2.1 , suse/sl-micro/6.1/rt-os-container:2.2.1-5.188 , suse/sl-micro/6.1/rt-os-container:latest Image Release : 5.188 Severity : important Type : security References : 1265578 1265580 1265581 1265582 1265583 1265584 1265585 1265586 1265587 1265588 1265589 1275441 CVE-2026-32792 CVE-2026-33278 CVE-2026-40622 CVE-2026-41292 CVE-2026-42534 CVE-2026-42923 CVE-2026-42944 CVE-2026-42959 CVE-2026-42960 CVE-2026-44390 CVE-2026-44608 CVE-2026-72693 ----------------------------------------------------------------- The container suse/sl-micro/6.1/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 732 Released: Wed Sep 16 11:16:27 2026 Summary: Security update for kbd Type: security Severity: important References: 1265578,1265580,1265581,1265582,1265583,1265584,1265585,1265586,1265587,1265588,1265589,1275441,CVE-2026-32792,CVE-2026-33278,CVE-2026-40622,CVE-2026-41292,CVE-2026-42534,CVE-2026-42923,CVE-2026-42944,CVE-2026-42959,CVE-2026-42960,CVE-2026-44390,CVE-2026-44608,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-2.6.4-slfo.1.1_2.1 updated - SL-Micro-release-6.1-slfo.1.12.76 updated - container:SL-Micro-container-2.2.1-7.177 updated From sle-container-updates at lists.suse.com Thu Sep 17 09:07:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 11:07:17 +0200 (CEST) Subject: SUSE-IU-2026:7090-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260917090717.969F2FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7090-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.142 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.142 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated - rpm-plugin-selinux-4.20.1-160000.3.1 added - container:suse-sl-micro-6.2-base-os-container-latest-af13a4151f45c17f074c2e71ec0772a9ffde3e16cadc17abf01ff01373d188e1-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 09:18:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 11:18:47 +0200 (CEST) Subject: SUSE-IU-2026:7097-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260917091847.7E627FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7097-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.75 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.75 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated From sle-container-updates at lists.suse.com Thu Sep 17 09:30:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 11:30:22 +0200 (CEST) Subject: SUSE-IU-2026:7104-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260917093022.66604FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7104-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.124 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.124 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-af13a4151f45c17f074c2e71ec0772a9ffde3e16cadc17abf01ff01373d188e1-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 09:45:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 11:45:32 +0200 (CEST) Subject: SUSE-IU-2026:7114-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260917094532.15031FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7114-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.163 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.163 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-c98e89094608eb4f21dc663ffcfee6f551fdf2f78d064a48b6c0f91dfdf18373-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:04:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:04:18 +0200 (CEST) Subject: SUSE-CU-2026:10661-1: Security update of bci/golang Message-ID: <20260917100418.84362FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10661-1 Container Tags : bci/golang:1.25 , bci/golang:1.25-sles15 , bci/golang:1.25.14 , bci/golang:1.25.14-3.72.12 , bci/golang:oldoldstable Container Release : 72.12 Severity : important Type : security References : 1268867 953659 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2019:44-1 Released: Tue Jan 8 13:07:32 2019 Summary: Recommended update for acl Type: recommended Severity: low References: 953659 This update for acl fixes the following issues: - test: Add helper library to fake passwd/group files. - quote: Escape literal backslashes. (bsc#953659) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:06:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:06:19 +0200 (CEST) Subject: SUSE-CU-2026:10662-1: Security update of bci/golang Message-ID: <20260917100619.A4B0AFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10662-1 Container Tags : bci/golang:1.26 , bci/golang:1.26-sles15 , bci/golang:1.26.8 , bci/golang:1.26.8-2.73.13 , bci/golang:oldstable Container Release : 73.13 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:09:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:09:09 +0200 (CEST) Subject: SUSE-CU-2026:10663-1: Security update of bci/golang Message-ID: <20260917100909.28EB5FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10663-1 Container Tags : bci/golang:1.25-openssl , bci/golang:1.25-sles15-openssl , bci/golang:1.25.14-openssl , bci/golang:1.25.14-openssl-90.16 , bci/golang:oldstable-openssl Container Release : 90.16 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:11:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:11:02 +0200 (CEST) Subject: SUSE-CU-2026:10664-1: Security update of bci/golang Message-ID: <20260917101102.C1BABFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10664-1 Container Tags : bci/golang:1.27 , bci/golang:1.27-sles15 , bci/golang:1.27.1 , bci/golang:1.27.1-1.73.13 , bci/golang:latest , bci/golang:stable Container Release : 73.13 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:13:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:13:17 +0200 (CEST) Subject: SUSE-CU-2026:10665-1: Security update of bci/golang Message-ID: <20260917101317.4C1C6FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10665-1 Container Tags : bci/golang:1.26-openssl , bci/golang:1.26-sles15-openssl , bci/golang:1.26.7-openssl , bci/golang:1.26.7-openssl-90.16 , bci/golang:latest , bci/golang:stable-openssl Container Release : 90.16 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:13:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:13:28 +0200 (CEST) Subject: SUSE-CU-2026:10666-1: Security update of suse/hpc/warewulf4-x86_64/sle-hpc-node Message-ID: <20260917101328.7EAF0FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10666-1 Container Tags : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7.20.8.166 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest Container Release : 20.8.166 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4211-1 Released: Wed Sep 16 13:51:01 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-2.4.0-150700.15.10.1 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:15:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:15:20 +0200 (CEST) Subject: SUSE-CU-2026:10667-1: Security update of bci/bci-init Message-ID: <20260917101520.DED45FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10667-1 Container Tags : bci/bci-init:15.7 , bci/bci-init:15.7-53.53 , bci/bci-init:latest Container Release : 53.53 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4211-1 Released: Wed Sep 16 13:51:01 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-2.4.0-150700.15.10.1 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:17:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:17:44 +0200 (CEST) Subject: SUSE-CU-2026:10668-1: Security update of suse/kiosk/firefox-esr Message-ID: <20260917101745.00E80FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10668-1 Container Tags : suse/kiosk/firefox-esr:153.2 , suse/kiosk/firefox-esr:153.2-75.37 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.37 Severity : low Type : security References : 1264994 CVE-2026-41254 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4205-1 Released: Wed Sep 16 10:20:20 2026 Summary: Security update for lcms2 Type: security Severity: low References: 1264994,CVE-2026-41254 This update for lcms2 fixes the following issue: - CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). The following package changes have been done: - liblcms2-2-2.15-150600.3.6.1 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:19:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:19:29 +0200 (CEST) Subject: SUSE-CU-2026:10669-1: Security update of bci/nodejs Message-ID: <20260917101929.96E76FCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10669-1 Container Tags : bci/node:22 , bci/node:22-sles15 , bci/node:22.23.2 , bci/node:22.23.2-24.52 , bci/nodejs:22 , bci/nodejs:22-sles15 , bci/nodejs:22.23.2 , bci/nodejs:22.23.2-24.52 Container Release : 24.52 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:21:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:21:29 +0200 (CEST) Subject: SUSE-CU-2026:10670-1: Security update of bci/openjdk-devel Message-ID: <20260917102129.1FA70FCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10670-1 Container Tags : bci/openjdk-devel:17 , bci/openjdk-devel:17-sles15 , bci/openjdk-devel:17.0.20.1 , bci/openjdk-devel:17.0.20.1-21.60 Container Release : 21.60 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:bci-openjdk-17-15.7.17-20.51 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:23:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:23:20 +0200 (CEST) Subject: SUSE-CU-2026:10671-1: Security update of bci/openjdk-devel Message-ID: <20260917102320.C8C6DFCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10671-1 Container Tags : bci/openjdk-devel:21 , bci/openjdk-devel:21-sles15 , bci/openjdk-devel:21.0.12.1 , bci/openjdk-devel:21.0.12.1-25.60 Container Release : 25.60 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:bci-openjdk-21-15.7.21-24.50 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:25:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:25:10 +0200 (CEST) Subject: SUSE-CU-2026:10672-1: Security update of bci/openjdk Message-ID: <20260917102510.9AD47FCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10672-1 Container Tags : bci/openjdk:21 , bci/openjdk:21-sles15 , bci/openjdk:21.0.12.1 , bci/openjdk:21.0.12.1-24.50 Container Release : 24.50 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:26:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:26:37 +0200 (CEST) Subject: SUSE-CU-2026:10673-1: Security update of bci/openjdk-devel Message-ID: <20260917102637.B446DFCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10673-1 Container Tags : bci/openjdk-devel:25 , bci/openjdk-devel:25-sles15 , bci/openjdk-devel:25.0.4.1 , bci/openjdk-devel:25.0.4.1-9.61 , bci/openjdk-devel:latest Container Release : 9.61 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:bci-openjdk-25-15.7.25-9.50 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:27:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:27:52 +0200 (CEST) Subject: SUSE-CU-2026:10674-1: Security update of bci/openjdk Message-ID: <20260917102752.EB08FFCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10674-1 Container Tags : bci/openjdk:25 , bci/openjdk:25-sles15 , bci/openjdk:25.0.4.1 , bci/openjdk:25.0.4.1-9.50 , bci/openjdk:latest Container Release : 9.50 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:38:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:38:25 +0200 (CEST) Subject: SUSE-CU-2026:10678-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260917103825.5E2B1FCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10678-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-73.35 , suse/kiosk/pulseaudio:latest Container Release : 73.35 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4211-1 Released: Wed Sep 16 13:51:01 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-2.4.0-150700.15.10.1 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:40:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:40:20 +0200 (CEST) Subject: SUSE-CU-2026:10679-1: Security update of bci/python Message-ID: <20260917104020.2EBC0FCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10679-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.54 Container Release : 85.54 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:42:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:42:15 +0200 (CEST) Subject: SUSE-CU-2026:10680-1: Security update of bci/python Message-ID: <20260917104215.72B5CFCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10680-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.14 , bci/python:3.13.14-88.49 , bci/python:latest Container Release : 88.49 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:44:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:44:11 +0200 (CEST) Subject: SUSE-CU-2026:10681-1: Security update of bci/python Message-ID: <20260917104411.3DB6FFCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10681-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.48 Container Release : 84.48 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:45:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:45:58 +0200 (CEST) Subject: SUSE-CU-2026:10682-1: Security update of bci/ruby Message-ID: <20260917104558.18A4EFCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10682-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-28.1 , bci/ruby:2.5-sles15 Container Release : 28.1 Severity : important Type : security References : 1262144 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 CVE-2026-5958 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1941-1 Released: Mon May 18 09:44:34 2026 Summary: Security update for sed Type: security Severity: moderate References: 1262144,CVE-2026-5958 This update for sed fixes the following issue: - CVE-2026-5958: a TOCTOU race can allow to read attacker-controlled content and write it to an unintended file (bsc#1262144). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - sed-4.9-150600.3.3.1 added - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:48:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:48:12 +0200 (CEST) Subject: SUSE-CU-2026:10683-1: Security update of bci/ruby Message-ID: <20260917104812.CC106FCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10683-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-27.1 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 27.1 Severity : important Type : security References : 1262144 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 CVE-2026-5958 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1941-1 Released: Mon May 18 09:44:34 2026 Summary: Security update for sed Type: security Severity: moderate References: 1262144,CVE-2026-5958 This update for sed fixes the following issue: - CVE-2026-5958: a TOCTOU race can allow to read attacker-controlled content and write it to an unintended file (bsc#1262144). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates The following package changes have been done: - libattr1-2.6.0-150000.4.3.1 updated - libacl1-2.4.0-150000.4.6.1 updated - sed-4.9-150600.3.3.1 added - container:registry.suse.com-bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:48:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:48:31 +0200 (CEST) Subject: SUSE-CU-2026:10684-1: Security update of suse/kiosk/tigervnc-x11vnc Message-ID: <20260917104831.313B5FCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/tigervnc-x11vnc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10684-1 Container Tags : suse/kiosk/tigervnc-x11vnc:1 , suse/kiosk/tigervnc-x11vnc:1.14 , suse/kiosk/tigervnc-x11vnc:1.14-63.37 , suse/kiosk/tigervnc-x11vnc:latest Container Release : 63.37 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/kiosk/tigervnc-x11vnc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4211-1 Released: Wed Sep 16 13:51:01 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-2.4.0-150700.15.10.1 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:49:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:49:49 +0200 (CEST) Subject: SUSE-CU-2026:10685-1: Security update of suse/kiosk/xorg-client Message-ID: <20260917104949.1E967FCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10685-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-80.16 , suse/kiosk/xorg-client:latest Container Release : 80.16 Severity : low Type : security References : 1264994 CVE-2026-41254 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4205-1 Released: Wed Sep 16 10:20:20 2026 Summary: Security update for lcms2 Type: security Severity: low References: 1264994,CVE-2026-41254 This update for lcms2 fixes the following issue: - CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). The following package changes have been done: - liblcms2-2-2.15-150600.3.6.1 updated From sle-container-updates at lists.suse.com Thu Sep 17 10:51:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 12:51:36 +0200 (CEST) Subject: SUSE-CU-2026:10686-1: Security update of suse/kiosk/xorg Message-ID: <20260917105136.B23AEFCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10686-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-83.35 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 83.35 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4211-1 Released: Wed Sep 16 13:51:01 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-2.4.0-150700.15.10.1 updated From sle-container-updates at lists.suse.com Thu Sep 17 11:22:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 13:22:39 +0200 (CEST) Subject: SUSE-CU-2026:10738-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260917112239.73CF8FCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10738-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.122 , suse/sles/16.0/toolbox:latest Container Release : 1.122 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - librpmbuild10-4.20.1-160000.3.1 updated - python313-rpm-4.20.1-160000.3.1 updated - rpm-4.20.1-160000.3.1 updated From sle-container-updates at lists.suse.com Thu Sep 17 11:28:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 17 Sep 2026 13:28:54 +0200 (CEST) Subject: SUSE-CU-2026:10740-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260917112854.97CF4FCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10740-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.38 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.38 Severity : important Type : security References : 1275441 CVE-2026-72693 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4207-1 Released: Wed Sep 16 10:21:54 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - kbd-legacy-2.4.0-150400.5.12.1 updated - kbd-2.4.0-150400.5.12.1 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:14:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:14:07 +0200 (CEST) Subject: SUSE-CU-2026:10750-1: Security update of private-registry/1.2/harbor-core Message-ID: <20260918071407.3316EFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10750-1 Container Tags : private-registry/1.2/harbor-core:1.2.1 , private-registry/1.2/harbor-core:1.2.1-1.109 , private-registry/1.2/harbor-core:latest Container Release : 1.109 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/1.2/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:14:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:14:36 +0200 (CEST) Subject: SUSE-CU-2026:10752-1: Security update of private-registry/1.2/harbor-exporter Message-ID: <20260918071436.4624FFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10752-1 Container Tags : private-registry/1.2/harbor-exporter:1.2.1 , private-registry/1.2/harbor-exporter:1.2.1-1.109 , private-registry/1.2/harbor-exporter:latest Container Release : 1.109 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/1.2/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:15:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:15:13 +0200 (CEST) Subject: SUSE-CU-2026:10754-1: Security update of private-registry/1.2/harbor-jobservice Message-ID: <20260918071513.97641FF1E@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10754-1 Container Tags : private-registry/1.2/harbor-jobservice:1.2.1 , private-registry/1.2/harbor-jobservice:1.2.1-1.107 , private-registry/1.2/harbor-jobservice:latest Container Release : 1.107 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/1.2/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:15:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:15:51 +0200 (CEST) Subject: SUSE-CU-2026:10756-1: Security update of private-registry/1.2/harbor-portal Message-ID: <20260918071551.2E1CAFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10756-1 Container Tags : private-registry/1.2/harbor-portal:1.2.1 , private-registry/1.2/harbor-portal:1.2.1-1.118 , private-registry/1.2/harbor-portal:latest Container Release : 1.118 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:16:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:16:22 +0200 (CEST) Subject: SUSE-CU-2026:10758-1: Security update of private-registry/1.2/harbor-registry Message-ID: <20260918071622.7F8B7FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10758-1 Container Tags : private-registry/1.2/harbor-registry:1.2.1 , private-registry/1.2/harbor-registry:1.2.1-1.109 , private-registry/1.2/harbor-registry:latest Container Release : 1.109 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:16:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:16:56 +0200 (CEST) Subject: SUSE-CU-2026:10760-1: Security update of private-registry/1.2/harbor-registryctl Message-ID: <20260918071656.B1611FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10760-1 Container Tags : private-registry/1.2/harbor-registryctl:1.2.1 , private-registry/1.2/harbor-registryctl:1.2.1-1.109 , private-registry/1.2/harbor-registryctl:latest Container Release : 1.109 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:17:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:17:37 +0200 (CEST) Subject: SUSE-CU-2026:10763-1: Security update of private-registry/1.2/harbor-trivy-adapter Message-ID: <20260918071737.5B0C2FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10763-1 Container Tags : private-registry/1.2/harbor-trivy-adapter:1.2.1 , private-registry/1.2/harbor-trivy-adapter:1.2.1-1.118 , private-registry/1.2/harbor-trivy-adapter:latest Container Release : 1.118 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/1.2/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:19:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:19:16 +0200 (CEST) Subject: SUSE-CU-2026:10764-1: Security update of private-registry/harbor-core Message-ID: <20260918071916.7F829FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10764-1 Container Tags : private-registry/harbor-core:1.1.3 , private-registry/harbor-core:1.1.3-2.125 , private-registry/harbor-core:latest Container Release : 2.125 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - system-user-harbor-2.14.4-150700.1.48 updated - harbor-core-2.14.4-150700.1.48 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:20:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:20:41 +0200 (CEST) Subject: SUSE-CU-2026:10765-1: Security update of private-registry/harbor-exporter Message-ID: <20260918072041.A1755FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10765-1 Container Tags : private-registry/harbor-exporter:1.1.3 , private-registry/harbor-exporter:1.1.3-2.126 , private-registry/harbor-exporter:latest Container Release : 2.126 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - harbor-exporter-2.14.4-150700.1.48 updated - system-user-harbor-2.14.4-150700.1.48 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:22:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:22:11 +0200 (CEST) Subject: SUSE-CU-2026:10766-1: Security update of private-registry/harbor-jobservice Message-ID: <20260918072211.3AEDBFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10766-1 Container Tags : private-registry/harbor-jobservice:1.1.3 , private-registry/harbor-jobservice:1.1.3-2.125 , private-registry/harbor-jobservice:latest Container Release : 2.125 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - system-user-harbor-2.14.4-150700.1.48 updated - harbor-jobservice-2.14.4-150700.1.48 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:24:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:24:04 +0200 (CEST) Subject: SUSE-CU-2026:10767-1: Security update of private-registry/harbor-portal Message-ID: <20260918072404.61A5AFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10767-1 Container Tags : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.138 , private-registry/harbor-portal:latest Container Release : 2.138 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - system-user-harbor-2.14.4-150700.1.48 updated - harbor-portal-2.14.4-150700.1.48 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:24:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:24:48 +0200 (CEST) Subject: SUSE-CU-2026:10768-1: Security update of private-registry/harbor-registry Message-ID: <20260918072448.1628FFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10768-1 Container Tags : private-registry/harbor-registry:1.1.3 , private-registry/harbor-registry:1.1.3-2.126 , private-registry/harbor-registry:latest Container Release : 2.126 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - system-user-harbor-2.14.4-150700.1.48 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:26:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:26:15 +0200 (CEST) Subject: SUSE-CU-2026:10769-1: Security update of private-registry/harbor-registryctl Message-ID: <20260918072615.315D7FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10769-1 Container Tags : private-registry/harbor-registryctl:1.1.3 , private-registry/harbor-registryctl:1.1.3-2.127 , private-registry/harbor-registryctl:latest Container Release : 2.127 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - system-user-harbor-2.14.4-150700.1.48 updated - harbor-registryctl-2.14.4-150700.1.48 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:28:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:28:00 +0200 (CEST) Subject: SUSE-CU-2026:10770-1: Security update of private-registry/harbor-trivy-adapter Message-ID: <20260918072800.F1D76FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10770-1 Container Tags : private-registry/harbor-trivy-adapter:1.1.3 , private-registry/harbor-trivy-adapter:1.1.3-2.139 , private-registry/harbor-trivy-adapter:latest Container Release : 2.139 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - harbor-scanner-trivy-0.36.0-150700.1.30 updated - system-user-harbor-2.14.4-150700.1.48 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:28:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:28:27 +0200 (CEST) Subject: SUSE-CU-2026:10772-1: Security update of private-registry/harbor-core Message-ID: <20260918072827.A391FFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10772-1 Container Tags : private-registry/harbor-core:2.13 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5-1.78 , private-registry/harbor-core:2.13.5-1.78 , private-registry/harbor-core:latest Container Release : 1.78 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:28:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:28:55 +0200 (CEST) Subject: SUSE-CU-2026:10774-1: Security update of private-registry/harbor-exporter Message-ID: <20260918072855.28AF8FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10774-1 Container Tags : private-registry/harbor-exporter:2.13 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5-1.78 , private-registry/harbor-exporter:2.13.5-1.78 , private-registry/harbor-exporter:latest Container Release : 1.78 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:29:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:29:26 +0200 (CEST) Subject: SUSE-CU-2026:10776-1: Security update of private-registry/harbor-jobservice Message-ID: <20260918072926.8CEEEFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10776-1 Container Tags : private-registry/harbor-jobservice:2.13 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5-1.78 , private-registry/harbor-jobservice:2.13.5-1.78 , private-registry/harbor-jobservice:latest Container Release : 1.78 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:29:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:29:58 +0200 (CEST) Subject: SUSE-CU-2026:10778-1: Security update of private-registry/harbor-portal Message-ID: <20260918072958.C5C44FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10778-1 Container Tags : private-registry/harbor-portal:2.13 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5-1.84 , private-registry/harbor-portal:2.13.5-1.84 , private-registry/harbor-portal:latest Container Release : 1.84 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:30:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:30:24 +0200 (CEST) Subject: SUSE-CU-2026:10780-1: Security update of private-registry/harbor-registry Message-ID: <20260918073024.3CA60FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10780-1 Container Tags : private-registry/harbor-registry:2.8.3 , private-registry/harbor-registry:2.8.3-1.79 , private-registry/harbor-registry:latest Container Release : 1.79 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:30:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:30:46 +0200 (CEST) Subject: SUSE-CU-2026:10782-1: Security update of private-registry/harbor-registryctl Message-ID: <20260918073046.B773CFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10782-1 Container Tags : private-registry/harbor-registryctl:2.13 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5-1.78 , private-registry/harbor-registryctl:2.13.5-1.78 , private-registry/harbor-registryctl:latest Container Release : 1.78 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:31:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:31:13 +0200 (CEST) Subject: SUSE-CU-2026:10783-1: Security update of private-registry/harbor-trivy-adapter Message-ID: <20260918073113.8EE5DFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10783-1 Container Tags : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.82 , private-registry/harbor-trivy-adapter:latest Container Release : 1.82 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - system-user-harbor-2.13.5-150700.2.4 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:34:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:34:39 +0200 (CEST) Subject: SUSE-IU-2026:7146-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260918073439.2E77BFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7146-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.253 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.253 Severity : important Type : security References : 1215737 1218034 1218038 1238078 1248600 1262043 1262044 1262046 1262072 1265060 1265061 1265062 1265070 1265071 1265075 1265076 1269220 1269221 1269390 976992 CVE-2015-8863 CVE-2023-50246 CVE-2023-50268 CVE-2024-53427 CVE-2025-9403 CVE-2026-32316 CVE-2026-3392 CVE-2026-33929 CVE-2026-33948 CVE-2026-40164 CVE-2026-40612 CVE-2026-41256 CVE-2026-41257 CVE-2026-43894 CVE-2026-43895 CVE-2026-43896 CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54679 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 905 Released: Thu Sep 17 10:05:35 2026 Summary: Security update for jq Type: security Severity: important References: 1215737,1218034,1218038,1238078,1248600,1262043,1262044,1262046,1262072,1265060,1265061,1265062,1265070,1265071,1265075,1265076,1269220,1269221,1269390,976992,CVE-2015-8863,CVE-2023-50246,CVE-2023-50268,CVE-2024-53427,CVE-2025-9403,CVE-2026-32316,CVE-2026-3392,CVE-2026-33929,CVE-2026-33948,CVE-2026-40164,CVE-2026-40612,CVE-2026-41256,CVE-2026-41257,CVE-2026-43894,CVE-2026-43895,CVE-2026-43896,CVE-2026-44777,CVE-2026-47770,CVE-2026-49839,CVE-2026-54679 This update for jq fixes the following issues: Security issues fixed: - CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992). - CVE-2023-50246: improper memory handling can lead to a heap buffer overflow in `decNumberToString` (bsc#1218034). - CVE-2023-50268: stack-based buffer overflow in builds using decNumber (bsc#1218038). - CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in decNumber.c (bsc#1238078). - CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600). - CVE-2026-32316: denial of Service or potential arbitrary code execution due to integer overflow and heap-based buffer overflow (bsc#1262044). - CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). - CVE-2026-40164: predictable hash collisions can lead to a denial of service (bsc#1262072). - CVE-2026-40612: jv_contains recurses into nested arrays/objects with no depth limit and can cause a stack overflow (bsc#1265060). - CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f and can lead to execution of unintended programs (bsc#1265061). - CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS (bsc#1265062). - CVE-2026-43894: signed integer overflow in `decNumber` can lead to out-of-bounds memory write (bsc#1265070). - CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). - CVE-2026-43896: unbounded recursion in `jv_object_merge_recursive()` can lead to C stack exhaustion and a process crash (bsc#1265075). - CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). - CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). - CVE-2026-49839: `--rawfile` invalid-state reuse after `String too long` can lead to a heap buffer overflow (bsc#1269220). - CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer overrun on 32-bit systems (bsc#1269390). Changes for jq: Update to version 1.7.1: * Make the default background color more suitable for bright backgrounds. * Allow passing the inline jq script after --. * Fix possible uninitialised value dereference if jq_init() fails * Simplify paths/0 and paths/1. * Reject U+001F in string literals. * Remove unused nref accumulator in block_bind_library. * Remove a bunch of unused variables, and useless assignments. * main.c: Remove unused EXIT_STATUS_EXACT option. * Actually use the number correctly casted from double to int as index. * src/builtin.c: remove unnecessary jv_copy-s in type_error/type_error2. * Remove undefined behavior caught by LLVM 10 UBSAN. * Convert decnum to binary64 (double) instead of decimal64. This makes jq behave like the JSON specification suggests and more similar to other languages. * Fix memory leaks on invalid input for ltrimstr/1 and rtrimstr/1. * Fix memory leak on failed get for setpath/2. * Fix nan from json parsing also for nans with payload that start with 'n'. * Allow carriage return characters in comments. * Generate links in the man page. * Add extern C for C++. * Make object key color configurable using JQ_COLORS environment variable. * Change the default color of null to Bright Black. * Respect NO_COLOR environment variable to disable color output. * Improved --help output. Now mentions all options and nicer order. * Fix multiple issues of exit code using --exit-code/-e option. * Add --raw-output0 for NUL (zero byte) separated output. * Fix assert crash and validate JSON for --jsonarg. * Remove deprecated --argfile option. * Use decimal number literals to preserve precision. Comparison operations respects precision but arithmetic operations might truncate. * Adds new builtin pick(stream) to emit a projection of the input object or array. * Adds new builtin debug(msgs) that works like debug but applies a filter on the input before writing to stderr. * Adds new builtin scan($re; $flags). Was documented but not implemented. * Adds new builtin abs to get absolute value. This potentially allows the literal value of numbers to be preserved as length and fabs convert to float. * Allow if without else-branch. When skipped the else-branch will be . (identity). * Allow use of $binding as key in object literals. * Allow dot between chained indexes when using .['index'] * Allow dot for chained value iterator .[], .[]? * Fix try/catch catches more than it should. * Speed up and refactor some builtins, also remove scalars_or_empty/0. * Now halt and halt_error exit immediately instead of continuing to the next input. * Fix issue converting string to number after previous convert error. * Fix issue representing large numbers on some platforms causing invalid JSON output. * Fix deletion using assigning empty against arrays. * Allow keywords to be used as binding name in more places. * Allow using nan as NaN in JSON. * Expose a module's function names in modulemeta. * Fix contains/1 to handle strings with NUL. * Fix stderr/0 to output raw text without any decoration. * Fix nth/2 to emit empty on index out of range. * Fix implode to not assert and instead replace invalid unicode codepoints. * Fix indices/1 and rindex/1 in case of overlapping matches in strings. * Fix sub/3 to resolve issues involving global search-and-replace (gsub) operations. * Fix empty regular expression matches. * Fix overflow exception of the modulo operator. * Fix string multiplication by 0 (and less than 1) to emit empty string. * Fix segfault when using libjq and threads. * Fix constant folding of division and reminder with zero divisor. * Fix error/0, error/1 to throw null error. * Simpler and faster transpose. * Simple and efficient implementation of walk/1. * Remove deprecated filters leaf_paths, recurse_down. The following package changes have been done: - libjq1-1.7.1-1.1 updated - jq-1.7.1-1.1 updated - container:SL-Micro-base-container-2.1.3-7.215 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:37:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:37:23 +0200 (CEST) Subject: SUSE-IU-2026:7147-1: Recommended update of suse/sl-micro/6.0/base-os-container Message-ID: <20260918073723.DAB07FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7147-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.215 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.215 Severity : moderate Type : recommended References : 1278729 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 904 Released: Thu Sep 17 08:55:21 2026 Summary: Recommended update for grub2 Type: recommended Severity: moderate References: 1278729 This update for grub2 fixes the following issues: - Add SBAT Provides to support shim SBAT dependency checks (bsc#1278729) The following package changes have been done: - grub2-2.12~rc1-10.1 updated - grub2-i386-pc-2.12~rc1-10.1 updated - grub2-x86_64-efi-2.12~rc1-10.1 updated From sle-container-updates at lists.suse.com Fri Sep 18 07:57:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 09:57:44 +0200 (CEST) Subject: SUSE-IU-2026:7151-1: Recommended update of suse/sl-micro/6.1/base-os-container Message-ID: <20260918075744.0F127FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7151-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.191 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.191 Severity : moderate Type : recommended References : 1264449 1264450 1265428 1265758 1278729 CVE-2026-33814 CVE-2026-41888 CVE-2026-43284 CVE-2026-43500 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 734 Released: Thu Sep 17 09:07:22 2026 Summary: Recommended update for grub2 Type: recommended Severity: moderate References: 1264449,1264450,1265428,1265758,1278729,CVE-2026-33814,CVE-2026-41888,CVE-2026-43284,CVE-2026-43500 This update for grub2 fixes the following issues: - Add SBAT Provides to support shim SBAT dependency checks (bsc#1278729) The following package changes have been done: - grub2-2.12-slfo.1.1_8.1 updated - grub2-i386-pc-2.12-slfo.1.1_8.1 updated - grub2-x86_64-efi-2.12-slfo.1.1_8.1 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:41:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:41:50 +0200 (CEST) Subject: SUSE-CU-2026:10792-1: Security update of suse/ltss/sle15.6/bci-base-fips Message-ID: <20260918084154.8031BFF24@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10792-1 Container Tags : suse/ltss/sle15.6/bci-base-fips:15.6 , suse/ltss/sle15.6/bci-base-fips:15.6-35.104 , suse/ltss/sle15.6/bci-base-fips:latest Container Release : 35.104 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/ltss/sle15.6/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:sles15-ltss-image-15.6.0-5.95 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:41:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:41:51 +0200 (CEST) Subject: SUSE-CU-2026:10793-1: Security update of suse/ltss/sle15.6/bci-base-fips Message-ID: <20260918084154.84E2BFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10793-1 Container Tags : suse/ltss/sle15.6/bci-base-fips:15.6 , suse/ltss/sle15.6/bci-base-fips:15.6-35.105 , suse/ltss/sle15.6/bci-base-fips:latest Container Release : 35.105 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/ltss/sle15.6/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:sles15-ltss-image-15.6.0-5.96 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:44:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:44:32 +0200 (CEST) Subject: SUSE-CU-2026:10794-1: Security update of suse/ltss/sle15.6/sle15 Message-ID: <20260918084432.37225FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10794-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.95 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.95 , suse/ltss/sle15.6/sle15:latest Container Release : 5.95 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:44:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:44:33 +0200 (CEST) Subject: SUSE-CU-2026:10795-1: Security update of suse/ltss/sle15.6/sle15 Message-ID: <20260918084433.5BBE9FF1F@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10795-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.96 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.96 , suse/ltss/sle15.6/sle15:latest Container Release : 5.96 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:45:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:45:48 +0200 (CEST) Subject: SUSE-CU-2026:10796-1: Security update of bci/dotnet-aspnet Message-ID: <20260918084548.1ACD1FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10796-1 Container Tags : bci/dotnet-aspnet:10.0 , bci/dotnet-aspnet:10.0-sles15 , bci/dotnet-aspnet:10.0.12 , bci/dotnet-aspnet:10.0.12-29.11 , bci/dotnet-aspnet:latest Container Release : 29.11 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:47:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:47:20 +0200 (CEST) Subject: SUSE-CU-2026:10797-1: Security update of bci/dotnet-aspnet Message-ID: <20260918084720.34315FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10797-1 Container Tags : bci/dotnet-aspnet:8.0 , bci/dotnet-aspnet:8.0-sles15 , bci/dotnet-aspnet:8.0.31 , bci/dotnet-aspnet:8.0.31-99.11 Container Release : 99.11 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:48:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:48:53 +0200 (CEST) Subject: SUSE-CU-2026:10798-1: Security update of bci/dotnet-aspnet Message-ID: <20260918084853.3E1C9FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10798-1 Container Tags : bci/dotnet-aspnet:9.0 , bci/dotnet-aspnet:9.0-sles15 , bci/dotnet-aspnet:9.0.20 , bci/dotnet-aspnet:9.0.20-58.11 Container Release : 58.11 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:50:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:50:21 +0200 (CEST) Subject: SUSE-CU-2026:10799-1: Security update of bci/bci-base-fips Message-ID: <20260918085021.AEC2FFF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10799-1 Container Tags : bci/bci-base-fips:15.7 , bci/bci-base-fips:15.7-23.13 , bci/bci-base-fips:latest Container Release : 23.13 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:50:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:50:51 +0200 (CEST) Subject: SUSE-CU-2026:10800-1: Security update of bci/bci-busybox Message-ID: <20260918085051.2E56FFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-busybox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10800-1 Container Tags : bci/bci-busybox:15.7 , bci/bci-busybox:15.7-25.28 , bci/bci-busybox:latest Container Release : 25.28 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/bci-busybox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:50:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:50:52 +0200 (CEST) Subject: SUSE-CU-2026:10801-1: Security update of bci/bci-busybox Message-ID: <20260918085052.8ED86FF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-busybox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10801-1 Container Tags : bci/bci-busybox:15.7 , bci/bci-busybox:15.7-25.30 , bci/bci-busybox:latest Container Release : 25.30 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/bci-busybox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:52:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:52:13 +0200 (CEST) Subject: SUSE-CU-2026:10802-1: Security update of bci/dotnet-sdk Message-ID: <20260918085213.85FE5FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10802-1 Container Tags : bci/dotnet-sdk:10.0 , bci/dotnet-sdk:10.0-sles15 , bci/dotnet-sdk:10.0.12 , bci/dotnet-sdk:10.0.12-29.11 , bci/dotnet-sdk:latest Container Release : 29.11 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:53:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:53:44 +0200 (CEST) Subject: SUSE-CU-2026:10803-1: Security update of bci/dotnet-sdk Message-ID: <20260918085344.476FAFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10803-1 Container Tags : bci/dotnet-sdk:8.0 , bci/dotnet-sdk:8.0-sles15 , bci/dotnet-sdk:8.0.31 , bci/dotnet-sdk:8.0.31-99.11 Container Release : 99.11 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:55:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:55:05 +0200 (CEST) Subject: SUSE-CU-2026:10804-1: Security update of bci/dotnet-sdk Message-ID: <20260918085505.D44DBFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10804-1 Container Tags : bci/dotnet-sdk:9.0 , bci/dotnet-sdk:9.0-sles15 , bci/dotnet-sdk:9.0.20 , bci/dotnet-sdk:9.0.20-59.11 Container Release : 59.11 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:56:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:56:08 +0200 (CEST) Subject: SUSE-CU-2026:10805-1: Security update of bci/dotnet-runtime Message-ID: <20260918085608.DC7D5FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10805-1 Container Tags : bci/dotnet-runtime:10.0 , bci/dotnet-runtime:10.0-sles15 , bci/dotnet-runtime:10.0.12 , bci/dotnet-runtime:10.0.12-29.11 , bci/dotnet-runtime:latest Container Release : 29.11 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:57:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:57:36 +0200 (CEST) Subject: SUSE-CU-2026:10806-1: Security update of bci/dotnet-runtime Message-ID: <20260918085736.E2DD5FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10806-1 Container Tags : bci/dotnet-runtime:8.0 , bci/dotnet-runtime:8.0-sles15 , bci/dotnet-runtime:8.0.31 , bci/dotnet-runtime:8.0.31-99.11 Container Release : 99.11 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:58:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:58:57 +0200 (CEST) Subject: SUSE-CU-2026:10807-1: Security update of bci/dotnet-runtime Message-ID: <20260918085857.770CBFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10807-1 Container Tags : bci/dotnet-runtime:9.0 , bci/dotnet-runtime:9.0-sles15 , bci/dotnet-runtime:9.0.20 , bci/dotnet-runtime:9.0.20-58.11 Container Release : 58.11 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 09:00:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 11:00:13 +0200 (CEST) Subject: SUSE-CU-2026:10809-1: Security update of bci/bci-init Message-ID: <20260918090013.64A70FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10809-1 Container Tags : bci/bci-init:15.7 , bci/bci-init:15.7-53.56 , bci/bci-init:latest Container Release : 53.56 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 09:04:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 11:04:56 +0200 (CEST) Subject: SUSE-CU-2026:10814-1: Security update of bci/bci-micro-fips Message-ID: <20260918090456.A408DFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10814-1 Container Tags : bci/bci-micro-fips:15.7 , bci/bci-micro-fips:15.7-27.20 , bci/bci-micro-fips:latest Container Release : 27.20 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/bci-micro-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 09:04:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 11:04:57 +0200 (CEST) Subject: SUSE-CU-2026:10815-1: Security update of bci/bci-micro-fips Message-ID: <20260918090457.BD0BFFF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10815-1 Container Tags : bci/bci-micro-fips:15.7 , bci/bci-micro-fips:15.7-27.22 , bci/bci-micro-fips:latest Container Release : 27.22 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/bci-micro-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 09:05:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 11:05:32 +0200 (CEST) Subject: SUSE-CU-2026:10816-1: Security update of bci/bci-micro Message-ID: <20260918090532.C67C2FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10816-1 Container Tags : bci/bci-micro:15.7 , bci/bci-micro:15.7-61.9 , bci/bci-micro:latest Container Release : 61.9 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/bci-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - container:bci-bci-base-15.7-aee2aea5cae7cc7db4a416936f9f90b38d1a62fca38d08f925c147369aca7c9a-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 09:05:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 11:05:34 +0200 (CEST) Subject: SUSE-CU-2026:10817-1: Security update of bci/bci-micro Message-ID: <20260918090534.5AD5FFF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10817-1 Container Tags : bci/bci-micro:15.7 , bci/bci-micro:15.7-61.11 , bci/bci-micro:latest Container Release : 61.11 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/bci-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 09:06:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 11:06:24 +0200 (CEST) Subject: SUSE-CU-2026:10818-1: Security update of bci/bci-minimal Message-ID: <20260918090624.65F5EFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-minimal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10818-1 Container Tags : bci/bci-minimal:15.7 , bci/bci-minimal:15.7-26.59 , bci/bci-minimal:latest Container Release : 26.59 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/bci-minimal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated From sle-container-updates at lists.suse.com Fri Sep 18 09:06:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 11:06:25 +0200 (CEST) Subject: SUSE-CU-2026:10819-1: Security update of bci/bci-minimal Message-ID: <20260918090625.CDA52FF1F@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-minimal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10819-1 Container Tags : bci/bci-minimal:15.7 , bci/bci-minimal:15.7-26.60 , bci/bci-minimal:latest Container Release : 26.60 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/bci-minimal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated From sle-container-updates at lists.suse.com Fri Sep 18 09:07:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 11:07:36 +0200 (CEST) Subject: SUSE-CU-2026:10820-1: Security update of suse/postgres Message-ID: <20260918090736.32F3DFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10820-1 Container Tags : suse/postgres:16-contrib , suse/postgres:16.15 , suse/postgres:16.15-contrib , suse/postgres:16.15-contrib-93.38 Container Release : 93.38 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-locale-base-2.38-150600.14.58.1 updated - glibc-locale-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 09:08:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 11:08:06 +0200 (CEST) Subject: SUSE-CU-2026:10821-1: Security update of suse/postgres Message-ID: <20260918090806.7AC21FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10821-1 Container Tags : suse/postgres:16 , suse/postgres:16.15 , suse/postgres:16.15 , suse/postgres:16.15-93.38 Container Release : 93.38 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-locale-base-2.38-150600.14.58.1 updated - glibc-locale-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Fri Sep 18 09:09:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 11:09:05 +0200 (CEST) Subject: SUSE-CU-2026:10822-1: Security update of suse/postgres Message-ID: <20260918090905.9A8A6FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10822-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.11 , suse/postgres:17.11-contrib , suse/postgres:17.11-contrib-83.37 Container Release : 83.37 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-locale-base-2.38-150600.14.58.1 updated - glibc-locale-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:06:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:06:49 +0200 (CEST) Subject: SUSE-CU-2026:10823-1: Security update of private-registry/1.2/harbor-core Message-ID: <20260919070649.DD246FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10823-1 Container Tags : private-registry/1.2/harbor-core:1.2.1 , private-registry/1.2/harbor-core:1.2.1-1.111 , private-registry/1.2/harbor-core:latest Container Release : 1.111 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/1.2/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:07:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:07:17 +0200 (CEST) Subject: SUSE-CU-2026:10824-1: Security update of private-registry/1.2/harbor-exporter Message-ID: <20260919070717.E78D8FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10824-1 Container Tags : private-registry/1.2/harbor-exporter:1.2.1 , private-registry/1.2/harbor-exporter:1.2.1-1.111 , private-registry/1.2/harbor-exporter:latest Container Release : 1.111 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/1.2/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:07:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:07:50 +0200 (CEST) Subject: SUSE-CU-2026:10825-1: Security update of private-registry/1.2/harbor-jobservice Message-ID: <20260919070750.65FBCFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10825-1 Container Tags : private-registry/1.2/harbor-jobservice:1.2.1 , private-registry/1.2/harbor-jobservice:1.2.1-1.109 , private-registry/1.2/harbor-jobservice:latest Container Release : 1.109 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/1.2/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:08:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:08:22 +0200 (CEST) Subject: SUSE-CU-2026:10826-1: Security update of private-registry/1.2/harbor-portal Message-ID: <20260919070822.E8902FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10826-1 Container Tags : private-registry/1.2/harbor-portal:1.2.1 , private-registry/1.2/harbor-portal:1.2.1-1.120 , private-registry/1.2/harbor-portal:latest Container Release : 1.120 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:08:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:08:49 +0200 (CEST) Subject: SUSE-CU-2026:10827-1: Security update of private-registry/1.2/harbor-registry Message-ID: <20260919070849.7AA27FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10827-1 Container Tags : private-registry/1.2/harbor-registry:1.2.1 , private-registry/1.2/harbor-registry:1.2.1-1.111 , private-registry/1.2/harbor-registry:latest Container Release : 1.111 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:09:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:09:16 +0200 (CEST) Subject: SUSE-CU-2026:10828-1: Security update of private-registry/1.2/harbor-registryctl Message-ID: <20260919070916.6CCEEFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10828-1 Container Tags : private-registry/1.2/harbor-registryctl:1.2.1 , private-registry/1.2/harbor-registryctl:1.2.1-1.111 , private-registry/1.2/harbor-registryctl:latest Container Release : 1.111 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:09:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:09:57 +0200 (CEST) Subject: SUSE-CU-2026:10829-1: Security update of private-registry/1.2/harbor-trivy-adapter Message-ID: <20260919070957.9969DFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10829-1 Container Tags : private-registry/1.2/harbor-trivy-adapter:1.2.1 , private-registry/1.2/harbor-trivy-adapter:1.2.1-1.120 , private-registry/1.2/harbor-trivy-adapter:latest Container Release : 1.120 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/1.2/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:11:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:11:33 +0200 (CEST) Subject: SUSE-CU-2026:10830-1: Security update of private-registry/harbor-core Message-ID: <20260919071133.719CBFF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10830-1 Container Tags : private-registry/harbor-core:1.1.3 , private-registry/harbor-core:1.1.3-2.127 , private-registry/harbor-core:latest Container Release : 2.127 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:13:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:13:08 +0200 (CEST) Subject: SUSE-CU-2026:10831-1: Security update of private-registry/harbor-exporter Message-ID: <20260919071308.158EBFF1E@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10831-1 Container Tags : private-registry/harbor-exporter:1.1.3 , private-registry/harbor-exporter:1.1.3-2.128 , private-registry/harbor-exporter:latest Container Release : 2.128 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:15:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:15:04 +0200 (CEST) Subject: SUSE-CU-2026:10832-1: Security update of private-registry/harbor-jobservice Message-ID: <20260919071504.748B8FF1E@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10832-1 Container Tags : private-registry/harbor-jobservice:1.1.3 , private-registry/harbor-jobservice:1.1.3-2.127 , private-registry/harbor-jobservice:latest Container Release : 2.127 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:16:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:16:57 +0200 (CEST) Subject: SUSE-CU-2026:10833-1: Security update of private-registry/harbor-portal Message-ID: <20260919071657.66E63FF19@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10833-1 Container Tags : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.140 , private-registry/harbor-portal:latest Container Release : 2.140 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:17:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:17:57 +0200 (CEST) Subject: SUSE-CU-2026:10834-1: Security update of private-registry/harbor-registry Message-ID: <20260919071757.E3B43FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10834-1 Container Tags : private-registry/harbor-registry:1.1.3 , private-registry/harbor-registry:1.1.3-2.128 , private-registry/harbor-registry:latest Container Release : 2.128 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:19:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:19:38 +0200 (CEST) Subject: SUSE-CU-2026:10835-1: Security update of private-registry/harbor-registryctl Message-ID: <20260919071938.38697FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10835-1 Container Tags : private-registry/harbor-registryctl:1.1.3 , private-registry/harbor-registryctl:1.1.3-2.129 , private-registry/harbor-registryctl:latest Container Release : 2.129 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:21:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:21:33 +0200 (CEST) Subject: SUSE-CU-2026:10836-1: Security update of private-registry/harbor-trivy-adapter Message-ID: <20260919072133.509D5FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10836-1 Container Tags : private-registry/harbor-trivy-adapter:1.1.3 , private-registry/harbor-trivy-adapter:1.1.3-2.141 , private-registry/harbor-trivy-adapter:latest Container Release : 2.141 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:22:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:22:01 +0200 (CEST) Subject: SUSE-CU-2026:10837-1: Security update of private-registry/harbor-core Message-ID: <20260919072201.6AB90FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10837-1 Container Tags : private-registry/harbor-core:2.13 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5-1.80 , private-registry/harbor-core:2.13.5-1.80 , private-registry/harbor-core:latest Container Release : 1.80 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:22:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:22:28 +0200 (CEST) Subject: SUSE-CU-2026:10838-1: Security update of private-registry/harbor-exporter Message-ID: <20260919072228.8F649FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10838-1 Container Tags : private-registry/harbor-exporter:2.13 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5-1.80 , private-registry/harbor-exporter:2.13.5-1.80 , private-registry/harbor-exporter:latest Container Release : 1.80 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:23:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:23:02 +0200 (CEST) Subject: SUSE-CU-2026:10839-1: Security update of private-registry/harbor-portal Message-ID: <20260919072302.E57ECFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10839-1 Container Tags : private-registry/harbor-portal:2.13 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5-1.85 , private-registry/harbor-portal:2.13.5-1.85 , private-registry/harbor-portal:latest Container Release : 1.85 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:23:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:23:35 +0200 (CEST) Subject: SUSE-CU-2026:10840-1: Security update of private-registry/harbor-registry Message-ID: <20260919072335.8E876FF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10840-1 Container Tags : private-registry/harbor-registry:2.8.3 , private-registry/harbor-registry:2.8.3-1.81 , private-registry/harbor-registry:latest Container Release : 1.81 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:24:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:24:06 +0200 (CEST) Subject: SUSE-CU-2026:10841-1: Security update of private-registry/harbor-registryctl Message-ID: <20260919072406.79D0EFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10841-1 Container Tags : private-registry/harbor-registryctl:2.13 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5-1.80 , private-registry/harbor-registryctl:2.13.5-1.80 , private-registry/harbor-registryctl:latest Container Release : 1.80 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:24:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:24:40 +0200 (CEST) Subject: SUSE-CU-2026:10842-1: Security update of private-registry/harbor-trivy-adapter Message-ID: <20260919072440.EFC8BFF17@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10842-1 Container Tags : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.84 , private-registry/harbor-trivy-adapter:latest Container Release : 1.84 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated - container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:28:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:28:45 +0200 (CEST) Subject: SUSE-IU-2026:7156-1: Recommended update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260919072845.1B566FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7156-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.145 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.145 Severity : critical Type : recommended References : 1272616 1277919 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1573 Released: Mon Aug 31 22:36:28 2026 Summary: Recommended update for gcc16 Type: recommended Severity: moderate References: 1272616 This update for gcc16 fixes the following issues: gcc16 is shipped as new package. This update ships the GNU Compiler Collection GCC 16.2. The compiler runtime libraries are provided for SUSE Linux Enterprise 16.0 versions and replace the same named GCC 14 ones. The new compilers are provided in the PackageHub 16.0 only. To use gcc16 compilers use: - install 'gcc16' or 'gcc16-c++' or one of the other 'gcc16-COMPILER' frontend packages. - override your Makefile to use CC=gcc16, CXX=g++16 and similar overrides for the other languages. For a full changelog with all new GCC16 features, check out https://gcc.gnu.org/gcc-16/changes.html - Update to GCC 16.2 release (gcc-16.2.0+git9497) * accumulated bugfixes from the gcc-16 release branch - Disable multilibs for cross-x86_64-gcc ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-fe3e2162f08267bf5409cf1db246c86e702d0f318ab6a05abf023d4099d1cec4-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:38:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:38:18 +0200 (CEST) Subject: SUSE-IU-2026:7160-1: Recommended update of suse/sl-micro/6.2/base-os-container Message-ID: <20260919073818.C000DFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7160-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.77 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.77 Severity : critical Type : recommended References : 1272616 1277919 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1573 Released: Mon Aug 31 22:36:28 2026 Summary: Recommended update for gcc16 Type: recommended Severity: moderate References: 1272616 This update for gcc16 fixes the following issues: gcc16 is shipped as new package. This update ships the GNU Compiler Collection GCC 16.2. The compiler runtime libraries are provided for SUSE Linux Enterprise 16.0 versions and replace the same named GCC 14 ones. The new compilers are provided in the PackageHub 16.0 only. To use gcc16 compilers use: - install 'gcc16' or 'gcc16-c++' or one of the other 'gcc16-COMPILER' frontend packages. - override your Makefile to use CC=gcc16, CXX=g++16 and similar overrides for the other languages. For a full changelog with all new GCC16 features, check out https://gcc.gnu.org/gcc-16/changes.html - Update to GCC 16.2 release (gcc-16.2.0+git9497) * accumulated bugfixes from the gcc-16 release branch - Disable multilibs for cross-x86_64-gcc ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:46:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:46:16 +0200 (CEST) Subject: SUSE-IU-2026:7164-1: Recommended update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260919074616.ECCBCFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7164-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.127 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.127 Severity : critical Type : recommended References : 1272616 1277919 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1573 Released: Mon Aug 31 22:36:28 2026 Summary: Recommended update for gcc16 Type: recommended Severity: moderate References: 1272616 This update for gcc16 fixes the following issues: gcc16 is shipped as new package. This update ships the GNU Compiler Collection GCC 16.2. The compiler runtime libraries are provided for SUSE Linux Enterprise 16.0 versions and replace the same named GCC 14 ones. The new compilers are provided in the PackageHub 16.0 only. To use gcc16 compilers use: - install 'gcc16' or 'gcc16-c++' or one of the other 'gcc16-COMPILER' frontend packages. - override your Makefile to use CC=gcc16, CXX=g++16 and similar overrides for the other languages. For a full changelog with all new GCC16 features, check out https://gcc.gnu.org/gcc-16/changes.html - Update to GCC 16.2 release (gcc-16.2.0+git9497) * accumulated bugfixes from the gcc-16 release branch - Disable multilibs for cross-x86_64-gcc ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-fe3e2162f08267bf5409cf1db246c86e702d0f318ab6a05abf023d4099d1cec4-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 07:54:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 09:54:45 +0200 (CEST) Subject: SUSE-IU-2026:7171-1: Recommended update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260919075445.7848FFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7171-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.167 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.167 Severity : critical Type : recommended References : 1272616 1277919 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1573 Released: Mon Aug 31 22:36:28 2026 Summary: Recommended update for gcc16 Type: recommended Severity: moderate References: 1272616 This update for gcc16 fixes the following issues: gcc16 is shipped as new package. This update ships the GNU Compiler Collection GCC 16.2. The compiler runtime libraries are provided for SUSE Linux Enterprise 16.0 versions and replace the same named GCC 14 ones. The new compilers are provided in the PackageHub 16.0 only. To use gcc16 compilers use: - install 'gcc16' or 'gcc16-c++' or one of the other 'gcc16-COMPILER' frontend packages. - override your Makefile to use CC=gcc16, CXX=g++16 and similar overrides for the other languages. For a full changelog with all new GCC16 features, check out https://gcc.gnu.org/gcc-16/changes.html - Update to GCC 16.2 release (gcc-16.2.0+git9497) * accumulated bugfixes from the gcc-16 release branch - Disable multilibs for cross-x86_64-gcc ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-51fa4dae181d2148b2a35b334d7569dbef4f51c52ea322e2bcc597e7cf5c31f6-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:07:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:07:03 +0200 (CEST) Subject: SUSE-CU-2026:10843-1: Security update of bci/dotnet-aspnet Message-ID: <20260919080703.0452EFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10843-1 Container Tags : bci/dotnet-aspnet:10.0 , bci/dotnet-aspnet:10.0-sles15 , bci/dotnet-aspnet:10.0.12 , bci/dotnet-aspnet:10.0.12-29.12 , bci/dotnet-aspnet:latest Container Release : 29.12 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:08:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:08:31 +0200 (CEST) Subject: SUSE-CU-2026:10844-1: Security update of bci/dotnet-aspnet Message-ID: <20260919080831.2B83AFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10844-1 Container Tags : bci/dotnet-aspnet:8.0 , bci/dotnet-aspnet:8.0-sles15 , bci/dotnet-aspnet:8.0.31 , bci/dotnet-aspnet:8.0.31-99.12 Container Release : 99.12 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:10:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:10:05 +0200 (CEST) Subject: SUSE-CU-2026:10845-1: Security update of bci/dotnet-aspnet Message-ID: <20260919081005.EAF37FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10845-1 Container Tags : bci/dotnet-aspnet:9.0 , bci/dotnet-aspnet:9.0-sles15 , bci/dotnet-aspnet:9.0.20 , bci/dotnet-aspnet:9.0.20-58.12 Container Release : 58.12 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:11:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:11:31 +0200 (CEST) Subject: SUSE-CU-2026:10846-1: Security update of bci/bci-base-fips Message-ID: <20260919081131.6CB73FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10846-1 Container Tags : bci/bci-base-fips:15.7 , bci/bci-base-fips:15.7-23.14 , bci/bci-base-fips:latest Container Release : 23.14 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:12:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:12:41 +0200 (CEST) Subject: SUSE-CU-2026:10847-1: Security update of bci/dotnet-sdk Message-ID: <20260919081241.3457EFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10847-1 Container Tags : bci/dotnet-sdk:10.0 , bci/dotnet-sdk:10.0-sles15 , bci/dotnet-sdk:10.0.12 , bci/dotnet-sdk:10.0.12-29.12 , bci/dotnet-sdk:latest Container Release : 29.12 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:14:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:14:11 +0200 (CEST) Subject: SUSE-CU-2026:10848-1: Security update of bci/dotnet-sdk Message-ID: <20260919081411.2C445FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10848-1 Container Tags : bci/dotnet-sdk:8.0 , bci/dotnet-sdk:8.0-sles15 , bci/dotnet-sdk:8.0.31 , bci/dotnet-sdk:8.0.31-99.12 Container Release : 99.12 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:15:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:15:52 +0200 (CEST) Subject: SUSE-CU-2026:10849-1: Security update of bci/dotnet-sdk Message-ID: <20260919081552.70A80FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10849-1 Container Tags : bci/dotnet-sdk:9.0 , bci/dotnet-sdk:9.0-sles15 , bci/dotnet-sdk:9.0.20 , bci/dotnet-sdk:9.0.20-59.12 Container Release : 59.12 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:17:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:17:18 +0200 (CEST) Subject: SUSE-CU-2026:10850-1: Security update of bci/dotnet-runtime Message-ID: <20260919081718.5C908FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10850-1 Container Tags : bci/dotnet-runtime:10.0 , bci/dotnet-runtime:10.0-sles15 , bci/dotnet-runtime:10.0.12 , bci/dotnet-runtime:10.0.12-29.12 , bci/dotnet-runtime:latest Container Release : 29.12 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:19:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:19:08 +0200 (CEST) Subject: SUSE-CU-2026:10851-1: Security update of bci/dotnet-runtime Message-ID: <20260919081908.DE345FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10851-1 Container Tags : bci/dotnet-runtime:8.0 , bci/dotnet-runtime:8.0-sles15 , bci/dotnet-runtime:8.0.31 , bci/dotnet-runtime:8.0.31-99.12 Container Release : 99.12 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:20:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:20:45 +0200 (CEST) Subject: SUSE-CU-2026:10852-1: Security update of bci/dotnet-runtime Message-ID: <20260919082045.64F3EFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10852-1 Container Tags : bci/dotnet-runtime:9.0 , bci/dotnet-runtime:9.0-sles15 , bci/dotnet-runtime:9.0.20 , bci/dotnet-runtime:9.0.20-58.12 Container Release : 58.12 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:20:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:20:54 +0200 (CEST) Subject: SUSE-CU-2026:10853-1: Recommended update of suse/hpc/warewulf4-x86_64/sle-hpc-node Message-ID: <20260919082054.A0E69FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10853-1 Container Tags : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7.20.8.170 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest Container Release : 20.8.170 Severity : moderate Type : recommended References : 1257055 1262432 ----------------------------------------------------------------- The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4263-1 Released: Fri Sep 18 13:40:22 2026 Summary: Recommended update for suse-module-tools Type: recommended Severity: moderate References: 1257055,1262432 This update for suse-module-tools fixes the following issues: - Update to version 15.7.11: * weak-modules2: don't remove symlinks in the rpm --reinstall case (bsc#1257055, bsc#1262432) The following package changes have been done: - suse-module-tools-15.7.11-150700.3.14.1 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:22:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:22:23 +0200 (CEST) Subject: SUSE-CU-2026:10854-1: Security update of bci/bci-init Message-ID: <20260919082223.F1A65FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10854-1 Container Tags : bci/bci-init:15.7 , bci/bci-init:15.7-53.57 , bci/bci-init:latest Container Release : 53.57 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:25:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:25:55 +0200 (CEST) Subject: SUSE-CU-2026:10857-1: Security update of suse/kiosk/firefox-esr Message-ID: <20260919082555.BF09FFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10857-1 Container Tags : suse/kiosk/firefox-esr:153.3 , suse/kiosk/firefox-esr:153.3-75.41 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.41 Severity : important Type : security References : 1280371 CVE-2026-92005 CVE-2026-92006 CVE-2026-92007 CVE-2026-92008 CVE-2026-92009 CVE-2026-92010 CVE-2026-92011 CVE-2026-92012 CVE-2026-92013 CVE-2026-92015 CVE-2026-92016 CVE-2026-92017 CVE-2026-92018 CVE-2026-92019 CVE-2026-92020 CVE-2026-92022 CVE-2026-92023 CVE-2026-92024 CVE-2026-92025 CVE-2026-92026 CVE-2026-92027 CVE-2026-92028 CVE-2026-92029 CVE-2026-92030 CVE-2026-92031 CVE-2026-92032 CVE-2026-92035 CVE-2026-92038 CVE-2026-92039 CVE-2026-92041 CVE-2026-92042 CVE-2026-92043 CVE-2026-92044 CVE-2026-92045 CVE-2026-92046 CVE-2026-92047 CVE-2026-92048 CVE-2026-92049 CVE-2026-92052 CVE-2026-92053 CVE-2026-92054 CVE-2026-92055 CVE-2026-92056 CVE-2026-92057 CVE-2026-92058 CVE-2026-92059 CVE-2026-92060 CVE-2026-92062 CVE-2026-92064 CVE-2026-92065 CVE-2026-92067 CVE-2026-92068 CVE-2026-92069 CVE-2026-92070 CVE-2026-92071 CVE-2026-92072 CVE-2026-92073 CVE-2026-92074 CVE-2026-92075 CVE-2026-92076 CVE-2026-92077 CVE-2026-92078 CVE-2026-92079 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4264-1 Released: Fri Sep 18 15:54:08 2026 Summary: Security update for MozillaFirefox Type: security Severity: important References: 1280371,CVE-2026-92005,CVE-2026-92006,CVE-2026-92007,CVE-2026-92008,CVE-2026-92009,CVE-2026-92010,CVE-2026-92011,CVE-2026-92012,CVE-2026-92013,CVE-2026-92015,CVE-2026-92016,CVE-2026-92017,CVE-2026-92018,CVE-2026-92019,CVE-2026-92020,CVE-2026-92022,CVE-2026-92023,CVE-2026-92024,CVE-2026-92025,CVE-2026-92026,CVE-2026-92027,CVE-2026-92028,CVE-2026-92029,CVE-2026-92030,CVE-2026-92031,CVE-2026-92032,CVE-2026-92035,CVE-2026-92038,CVE-2026-92039,CVE-2026-92041,CVE-2026-92042,CVE-2026-92043,CVE-2026-92044,CVE-2026-92045,CVE-2026-92046,CVE-2026-92047,CVE-2026-92048,CVE-2026-92049,CVE-2026-92052,CVE-2026-92053,CVE-2026-92054,CVE-2026-92055,CVE-2026-92056,CVE-2026-92057,CVE-2026-92058,CVE-2026-92059,CVE-2026-92060,CVE-2026-92062,CVE-2026-92064,CVE-2026-92065,CVE-2026-92067,CVE-2026-92068,CVE-2026-92069,CVE-2026-92070,CVE-2026-92071,CVE-2026-92072,CVE-2026-92073,CVE-2026-92074,CVE-2026-92075,CVE-2026-92076,CVE-2026-92077,CVE-2026-92078,CVE-2026-92079 This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 153.3.0 ESRi (MFSA 2026-93, bsc#1280371) - CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component. - CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. - CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. - CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. - CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. - CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. - CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. - CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. - CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. - CVE-2026-92015: Privilege escalation in the WebExtensions component. - CVE-2026-92016: Use-after-free in the Disability Access APIs component. - CVE-2026-92017: Privilege escalation in the DOM: Service Workers component. - CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component. - CVE-2026-92019: Mitigation bypass in the Remote Settings Client component. - CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. - CVE-2026-92022: Use-after-free in the DOM: HTML Parser component. - CVE-2026-92023: Use-after-free in the XML component. - CVE-2026-92024: Use-after-free in the SVG component. - CVE-2026-92025: Use-after-free in the DOM: Navigation component. - CVE-2026-92026: Use-after-free in the Networking component. - CVE-2026-92027: Use-after-free in the DOM: Streams component. - CVE-2026-92028: Use-after-free in the DOM: Core & HTML component. - CVE-2026-92029: Use-after-free in the SVG component. - CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. - CVE-2026-92031: Information disclosure in the Graphics: ImageLib component. - CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component. - CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component. - CVE-2026-92038: Mitigation bypass in the Remote Settings Client component. - CVE-2026-92039: Mitigation bypass in the DOM: Notifications component. - CVE-2026-92041: Mitigation bypass in the DOM: Networking component. - CVE-2026-92042: Race condition in the DOM: Content Processes component. - CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component. - CVE-2026-92044: Information disclosure in the Networking: HTTP component. - CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component. - CVE-2026-92046: Use-after-free in the Graphics component. - CVE-2026-92047: Privilege escalation in the Crash Reporting component. - CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. - CVE-2026-92049: Use-after-free in the Widget: Win32 component. - CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. - CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component. - CVE-2026-92054: Privilege escalation in the Memory component. - CVE-2026-92055: Privilege escalation in the DevTools component. - CVE-2026-92056: Use-after-free in the Graphics: Text component. - CVE-2026-92057: Mitigation bypass in the Enterprise Policies component. - CVE-2026-92058: Use-after-free in the Graphics component. - CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component. - CVE-2026-92060: Use-after-free in the Internationalization component. - CVE-2026-92062: Privilege escalation in the Session Restore component. - CVE-2026-92064: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. - CVE-2026-92065: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. - CVE-2026-92067: Use-after-free in the Widget: Gtk component. - CVE-2026-92068: Site isolation issue in the Reader Mode component. - CVE-2026-92069: Spoofing issue in the DOM: Navigation component. - CVE-2026-92070: Information disclosure in the Networking component. - CVE-2026-92071: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. - CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component. - CVE-2026-92073: Privilege escalation in the Enterprise Policies component. - CVE-2026-92074: Mitigation bypass in the Popup Blocker component. - CVE-2026-92075: Mitigation bypass in the Networking component. - CVE-2026-92076: Incorrect boundary conditions in the Networking component. - CVE-2026-92077: Denial-of-service in the SVG component. - CVE-2026-92078: Denial-of-service in the Security component. - CVE-2026-92079: Mitigation bypass in the Widget: Win32 component. The following package changes have been done: - MozillaFirefox-153.3.0-150400.157.8.1 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:29:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:29:01 +0200 (CEST) Subject: SUSE-CU-2026:10860-1: Security update of bci/nodejs Message-ID: <20260919082901.CBA4EFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10860-1 Container Tags : bci/node:22 , bci/node:22-sles15 , bci/node:22.23.2 , bci/node:22.23.2-24.56 , bci/nodejs:22 , bci/nodejs:22-sles15 , bci/nodejs:22.23.2 , bci/nodejs:22.23.2-24.56 Container Release : 24.56 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:30:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:30:42 +0200 (CEST) Subject: SUSE-CU-2026:10861-1: Security update of bci/openjdk-devel Message-ID: <20260919083042.8353AFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10861-1 Container Tags : bci/openjdk-devel:17 , bci/openjdk-devel:17-sles15 , bci/openjdk-devel:17.0.20.1 , bci/openjdk-devel:17.0.20.1-21.65 Container Release : 21.65 Severity : important Type : security References : 1264994 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-41254 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4205-1 Released: Wed Sep 16 10:20:20 2026 Summary: Security update for lcms2 Type: security Severity: low References: 1264994,CVE-2026-41254 This update for lcms2 fixes the following issue: - CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - liblcms2-2-2.15-150600.3.6.1 updated - container:bci-openjdk-17-15.7.17-20.56 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:32:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:32:07 +0200 (CEST) Subject: SUSE-CU-2026:10862-1: Security update of bci/openjdk Message-ID: <20260919083207.3E3B7FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10862-1 Container Tags : bci/openjdk:17 , bci/openjdk:17-sles15 , bci/openjdk:17.0.20.1 , bci/openjdk:17.0.20.1-20.56 Container Release : 20.56 Severity : important Type : security References : 1264994 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-41254 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4205-1 Released: Wed Sep 16 10:20:20 2026 Summary: Security update for lcms2 Type: security Severity: low References: 1264994,CVE-2026-41254 This update for lcms2 fixes the following issue: - CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - liblcms2-2-2.15-150600.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:33:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:33:32 +0200 (CEST) Subject: SUSE-CU-2026:10863-1: Security update of bci/openjdk-devel Message-ID: <20260919083332.07128FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10863-1 Container Tags : bci/openjdk-devel:21 , bci/openjdk-devel:21-sles15 , bci/openjdk-devel:21.0.12.1 , bci/openjdk-devel:21.0.12.1-25.65 Container Release : 25.65 Severity : important Type : security References : 1264994 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-41254 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4205-1 Released: Wed Sep 16 10:20:20 2026 Summary: Security update for lcms2 Type: security Severity: low References: 1264994,CVE-2026-41254 This update for lcms2 fixes the following issue: - CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - liblcms2-2-2.15-150600.3.6.1 updated - container:bci-openjdk-21-15.7.21-24.55 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:35:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:35:12 +0200 (CEST) Subject: SUSE-CU-2026:10864-1: Security update of bci/openjdk Message-ID: <20260919083513.066C5FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10864-1 Container Tags : bci/openjdk:21 , bci/openjdk:21-sles15 , bci/openjdk:21.0.12.1 , bci/openjdk:21.0.12.1-24.55 Container Release : 24.55 Severity : important Type : security References : 1264994 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-41254 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4205-1 Released: Wed Sep 16 10:20:20 2026 Summary: Security update for lcms2 Type: security Severity: low References: 1264994,CVE-2026-41254 This update for lcms2 fixes the following issue: - CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - liblcms2-2-2.15-150600.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:36:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:36:14 +0200 (CEST) Subject: SUSE-CU-2026:10865-1: Security update of bci/openjdk-devel Message-ID: <20260919083614.A3118FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10865-1 Container Tags : bci/openjdk-devel:25 , bci/openjdk-devel:25-sles15 , bci/openjdk-devel:25.0.4.1 , bci/openjdk-devel:25.0.4.1-9.66 , bci/openjdk-devel:latest Container Release : 9.66 Severity : important Type : security References : 1264994 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-41254 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4205-1 Released: Wed Sep 16 10:20:20 2026 Summary: Security update for lcms2 Type: security Severity: low References: 1264994,CVE-2026-41254 This update for lcms2 fixes the following issue: - CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - liblcms2-2-2.15-150600.3.6.1 updated - container:bci-openjdk-25-15.7.25-9.55 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:37:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:37:26 +0200 (CEST) Subject: SUSE-CU-2026:10866-1: Security update of bci/openjdk Message-ID: <20260919083726.33CCAFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10866-1 Container Tags : bci/openjdk:25 , bci/openjdk:25-sles15 , bci/openjdk:25.0.4.1 , bci/openjdk:25.0.4.1-9.55 , bci/openjdk:latest Container Release : 9.55 Severity : important Type : security References : 1264994 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-41254 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4205-1 Released: Wed Sep 16 10:20:20 2026 Summary: Security update for lcms2 Type: security Severity: low References: 1264994,CVE-2026-41254 This update for lcms2 fixes the following issue: - CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - liblcms2-2-2.15-150600.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:39:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:39:56 +0200 (CEST) Subject: SUSE-CU-2026:10822-1: Security update of suse/postgres Message-ID: <20260919083956.87713FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10822-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.11 , suse/postgres:17.11-contrib , suse/postgres:17.11-contrib-83.37 Container Release : 83.37 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-locale-base-2.38-150600.14.58.1 updated - glibc-locale-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:40:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:40:32 +0200 (CEST) Subject: SUSE-CU-2026:10870-1: Security update of suse/postgres Message-ID: <20260919084032.922D6FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10870-1 Container Tags : suse/postgres:17 , suse/postgres:17.11 , suse/postgres:17.11 , suse/postgres:17.11-83.37 Container Release : 83.37 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-locale-base-2.38-150600.14.58.1 updated - glibc-locale-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:41:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:41:17 +0200 (CEST) Subject: SUSE-CU-2026:10872-1: Security update of suse/postgres Message-ID: <20260919084117.1560AFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10872-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.6 , suse/postgres:18.6-contrib , suse/postgres:18.6-contrib-73.37 , suse/postgres:latest Container Release : 73.37 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-locale-base-2.38-150600.14.58.1 updated - glibc-locale-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:41:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:41:51 +0200 (CEST) Subject: SUSE-CU-2026:10874-1: Security update of suse/postgres Message-ID: <20260919084151.DA940FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10874-1 Container Tags : suse/postgres:18 , suse/postgres:18.6 , suse/postgres:18.6 , suse/postgres:18.6-73.37 , suse/postgres:latest Container Release : 73.37 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-locale-base-2.38-150600.14.58.1 updated - glibc-locale-2.38-150600.14.58.1 updated - container:suse-sle15-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-c6459cbe96d138754f827c384f9d8c6c3338fd38e0dd73b9aa3fcd67297b0981-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:43:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:43:11 +0200 (CEST) Subject: SUSE-CU-2026:10878-1: Recommended update of suse/kiosk/pulseaudio Message-ID: <20260919084311.87AC4FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10878-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-73.39 , suse/kiosk/pulseaudio:latest Container Release : 73.39 Severity : moderate Type : recommended References : 1257055 1262432 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4263-1 Released: Fri Sep 18 13:40:22 2026 Summary: Recommended update for suse-module-tools Type: recommended Severity: moderate References: 1257055,1262432 This update for suse-module-tools fixes the following issues: - Update to version 15.7.11: * weak-modules2: don't remove symlinks in the rpm --reinstall case (bsc#1257055, bsc#1262432) The following package changes have been done: - suse-module-tools-15.7.11-150700.3.14.1 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:44:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:44:37 +0200 (CEST) Subject: SUSE-CU-2026:10879-1: Security update of bci/python Message-ID: <20260919084437.5A762FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10879-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.14 , bci/python:3.13.14-88.53 , bci/python:latest Container Release : 88.53 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 08:45:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 10:45:19 +0200 (CEST) Subject: SUSE-CU-2026:10880-1: Security update of suse/mariadb-client Message-ID: <20260919084519.5CA0AFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10880-1 Container Tags : suse/mariadb-client:11.8 , suse/mariadb-client:11.8.8 , suse/mariadb-client:11.8.8-72.28 , suse/mariadb-client:latest Container Release : 72.28 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/mariadb-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-posix3-10.42-150600.3.3.1 updated From sle-container-updates at lists.suse.com Sat Sep 19 09:45:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 11:45:16 +0200 (CEST) Subject: SUSE-CU-2026:10881-1: Security update of bci/golang Message-ID: <20260919094516.E52EEFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10881-1 Container Tags : bci/golang:1.25 , bci/golang:1.25-sles15 , bci/golang:1.25.14 , bci/golang:1.25.14-3.72.16 , bci/golang:oldoldstable Container Release : 72.16 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - glibc-devel-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 09:46:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 11:46:25 +0200 (CEST) Subject: SUSE-CU-2026:10882-1: Security update of bci/golang Message-ID: <20260919094625.7F99BFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10882-1 Container Tags : bci/golang:1.26 , bci/golang:1.26-sles15 , bci/golang:1.26.8 , bci/golang:1.26.8-2.73.17 , bci/golang:oldstable Container Release : 73.17 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - glibc-devel-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 09:47:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 11:47:50 +0200 (CEST) Subject: SUSE-CU-2026:10883-1: Security update of bci/golang Message-ID: <20260919094750.9E3C7FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10883-1 Container Tags : bci/golang:1.25-openssl , bci/golang:1.25-sles15-openssl , bci/golang:1.25.14-openssl , bci/golang:1.25.14-openssl-90.20 , bci/golang:oldstable-openssl Container Release : 90.20 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - glibc-devel-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 09:49:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 11:49:04 +0200 (CEST) Subject: SUSE-CU-2026:10884-1: Security update of bci/golang Message-ID: <20260919094904.13450FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10884-1 Container Tags : bci/golang:1.27 , bci/golang:1.27-sles15 , bci/golang:1.27.1 , bci/golang:1.27.1-1.73.17 , bci/golang:latest , bci/golang:stable Container Release : 73.17 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - glibc-devel-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 09:50:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 11:50:16 +0200 (CEST) Subject: SUSE-CU-2026:10885-1: Security update of bci/golang Message-ID: <20260919095016.10C71FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10885-1 Container Tags : bci/golang:1.26-openssl , bci/golang:1.26-sles15-openssl , bci/golang:1.26.7-openssl , bci/golang:1.26.7-openssl-90.20 , bci/golang:latest , bci/golang:stable-openssl Container Release : 90.20 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - glibc-devel-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 09:57:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 11:57:28 +0200 (CEST) Subject: SUSE-CU-2026:10889-1: Security update of bci/python Message-ID: <20260919095728.59441FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10889-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.58 Container Release : 85.58 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 09:58:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 11:58:42 +0200 (CEST) Subject: SUSE-CU-2026:10890-1: Security update of bci/python Message-ID: <20260919095842.BD5FEFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10890-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.52 Container Release : 84.52 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 09:59:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 11:59:16 +0200 (CEST) Subject: SUSE-CU-2026:10880-1: Security update of suse/mariadb-client Message-ID: <20260919095916.0FCA6FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10880-1 Container Tags : suse/mariadb-client:11.8 , suse/mariadb-client:11.8.8 , suse/mariadb-client:11.8.8-72.28 , suse/mariadb-client:latest Container Release : 72.28 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/mariadb-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-posix3-10.42-150600.3.3.1 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:00:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:00:02 +0200 (CEST) Subject: SUSE-CU-2026:10893-1: Security update of suse/mariadb Message-ID: <20260919100002.EAB7BFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10893-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-79.36 , suse/mariadb:latest Container Release : 79.36 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-posix3-10.42-150600.3.3.1 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:02:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:02:32 +0200 (CEST) Subject: SUSE-CU-2026:10897-1: Security update of bci/ruby Message-ID: <20260919100232.9CC06FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10897-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-28.5 , bci/ruby:2.5-sles15 Container Release : 28.5 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - glibc-devel-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:03:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:03:41 +0200 (CEST) Subject: SUSE-CU-2026:10898-1: Security update of bci/ruby Message-ID: <20260919100341.23640FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10898-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-27.5 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 27.5 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - glibc-devel-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:04:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:04:29 +0200 (CEST) Subject: SUSE-CU-2026:10899-1: Security update of bci/rust Message-ID: <20260919100429.A21E0FF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10899-1 Container Tags : bci/rust:1.97 , bci/rust:1.97-sles15 , bci/rust:1.97.1 , bci/rust:1.97.1-2.2.13 , bci/rust:oldstable Container Release : 2.13 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - glibc-devel-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:05:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:05:30 +0200 (CEST) Subject: SUSE-CU-2026:10900-1: Security update of bci/rust Message-ID: <20260919100530.B0ACAFF1E@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10900-1 Container Tags : bci/rust:1.98 , bci/rust:1.98-sles15 , bci/rust:1.98.0 , bci/rust:1.98.0-1.2.13 , bci/rust:latest , bci/rust:stable Container Release : 2.13 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - glibc-devel-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:10:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:10:12 +0200 (CEST) Subject: SUSE-CU-2026:10908-1: Security update of suse/sle15 Message-ID: <20260919101012.704BFFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10908-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.23.38 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.23.38 , suse/sle15:latest Container Release : 5.23.38 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277713 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:10:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:10:13 +0200 (CEST) Subject: SUSE-CU-2026:10909-1: Security update of suse/sle15 Message-ID: <20260919101013.64BBEFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10909-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.23.39 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.23.39 , suse/sle15:latest Container Release : 5.23.39 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:11:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:11:53 +0200 (CEST) Subject: SUSE-CU-2026:10910-1: Security update of bci/spack Message-ID: <20260919101153.EE41EFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10910-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.62 , bci/spack:latest Container Release : 25.62 Severity : important Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277707 1277708 1277709 1277710 1277711 1277713 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - libpcre2-8-0-10.42-150600.3.3.1 updated - glibc-devel-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-45f0e5557c7736b336b2befb7031e3f2d0326abd4d2adaabcc6ac9ac16bdc30c-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:14:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:14:28 +0200 (CEST) Subject: SUSE-CU-2026:10918-1: Recommended update of suse/kiosk/xorg Message-ID: <20260919101428.A0BB4FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10918-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-83.39 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 83.39 Severity : moderate Type : recommended References : 1257055 1262432 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4263-1 Released: Fri Sep 18 13:40:22 2026 Summary: Recommended update for suse-module-tools Type: recommended Severity: moderate References: 1257055,1262432 This update for suse-module-tools fixes the following issues: - Update to version 15.7.11: * weak-modules2: don't remove symlinks in the rpm --reinstall case (bsc#1257055, bsc#1262432) The following package changes have been done: - suse-module-tools-15.7.11-150700.3.14.1 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:18:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:18:25 +0200 (CEST) Subject: SUSE-CU-2026:10919-1: Security update of bci/gcc Message-ID: <20260919101825.2F3BFFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/gcc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10919-1 Container Tags : bci/gcc:15 , bci/gcc:15.3 , bci/gcc:15.3-13.19 Container Release : 13.19 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/gcc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1661 Released: Fri Sep 11 13:45:57 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent The following package changes have been done: - libattr1-2.6.0-160000.1.1 updated - libacl1-2.4.0-160000.1.1 updated - container:registry.suse.com-bci-bci-base-16.0-4e6baf5e20a374e515580441ed10778b88813915f61ee12cc28563acdfcb5552-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:19:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:19:15 +0200 (CEST) Subject: SUSE-CU-2026:10920-1: Security update of bci/kiwi Message-ID: <20260919101915.777FEFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/kiwi ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10920-1 Container Tags : bci/kiwi:10 , bci/kiwi:10.2 , bci/kiwi:10.2.33 , bci/kiwi:10.2.33-20.6 Container Release : 20.6 Severity : critical Type : security References : 1257249 1268867 1271730 1272534 1273242 1274091 1274579 1274625 1277790 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/kiwi was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1639 Released: Tue Sep 8 17:42:08 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). Changes for libzypp: Update to version 17.38.1: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Log all solver problem rules (bsc#1277790) The log contains the most relevant problem rule, but sometimes it helps to know all rules associated with this problem. zypper shows them on demand as 'detail'. The log now remembers them as well. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - repoGpgCheck: Strictly follow the repo_gpgcheck setting (bsc#1274625) There's been a legacy exception for unsigned repositories which were explicitly accepted in the past. After switching the repo_gpgcheck from off to on, they were allowed to stay unsigned until a first signed version was retrieved. From there on the handling was strict. Now the handling is strict as soon as the repo_gpgcheck turned on. The next set of metadata retrieved must be signed. - Iniparser: each new file starts in the unnamed section (bsc#1272534) - Fix hasCredentials() to require both username AND password to be non-empty (bsc#1273242) This avoids an unnecessary 2nd 401 response sending just the username in case the username but no password is known. Now it immediately fetches the credentials from disk if no password is known. - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730) The short Id (32bit/8byte) is not considered to be a safe identifier for a gpg key. A long id (64bit/16byte) or even better the full fingerprint is needed to identify the key. - zypp: Improve Testcase Loading for MCP Tools. Changes for zypper: Update to version 1.14.99: - Show solver problem details per default in not-interactive mode (bsc#1277790) This way they see all details when capturing zypper's output because the (d)etail button can't be pressed in not-interactive mode. - Add --servicesd-dir global option to relocate /etc/zypp/services.d (bsc#1257249) - info: check for missing positional args before systemSetup (bsc#1274091) - Remove deprecated installRecommends option from zypper.conf. The system wide default for all libzypp based applications is defined in zypp.conf(5). It is not recommended to define this in zypper exclusively. ----------------------------------------------------------------- Advisory ID: 1645 Released: Wed Sep 9 10:09:38 2026 Summary: Recommended update for qemu Type: recommended Severity: important References: 1274579 This update for qemu fixes the following issues: Changes in qemu: - Fix: Live migration does not work in 16.0/virt-operator:1.8.3-2.2 (bsc#1274579): * target/i386: Add compatibility property for pdcm feature - Update to version 10.0.13: * target/riscv/tcg: sret in virtual user mode raises virtual instruction exception * target/riscv: + Enforce even register constraints for Zdinx fcvt pairs + Reject FMV.X.W/FMV.W.X under Zfinx + Honor zicbo* envcfg gating in linux-user mode + Allow menvcfg/henvcfg LPE and SSE bits on RV32 + Use SXL instead of MXL for read_sstatus + Fix PC sync in trans_sspopchk for CFI exception handling * disas/riscv: + Fix typo in th.lbib format + Fix isa decoding of rev8 + Fix rv32 encoding of zext.h * hw/riscv/riscv-iommu: + Preserve requested perm in spa_fetch() + Fix U-bit check to apply only to leaf S/VS-stage PTEs * disas/riscv: + Decode unsigned vector immediates as unsigned + Use signed type for vector immediates + Fix 6-bit immediate extraction + Fix th.srri decoding * hw/watchdog: Add lower bound check for watchdogNumber * tcg: + Export tcg_gen_ussub_i{32,64,tl} + Defer tb_flush when initial thread region alloc fails + Return success from tcg_region_alloc + Return success from tcg_region_alloc__locked * target/loongarch: Check FPE before reading fcc in bceqz/bcnez * meson: Make linker warnings non-fatal on Linux * serial: Clear transmit retry callback on unrealize * target/i386: + Decode opcode extensions group 3 /1 as TEST + Allow transition to virtual-8086 mode only if CPL == 0 and CPU is not in long mode + Fix long mode segment override prefix decoding + Fix incorrect decoding of EXTRQ_i + Clear OF, SF, and AF for fcomi/fucomi + Use correct type for get_float_exception_flags() values * tcg/optimize: + Fix s_mask computation for shifts + INDEX_op_mul is commutative * hw/elf_ops: Defend against weird elf headers * hw/nvme: Add SPDM_SOCKET Kconfig dependency * hw/block/pflash_cfi01: Restore ROMD mode after migration * hw/net/rtl8139: + Send whole of vlan-tagged packet when doing loopback + Fix handling of VLAN tags on incoming short packets * tests/qtest/ahci: Regression test for ATAPI read vs. drain * hw/ide/atapi: Read the whole elementary transfer asynchronously * tests/qtest/ahci: Cover raw (2352-byte) ATAPI CD reads * tests/qtest/libqos/ahci: Support raw (2352-byte) READ CD * tests/qtest/ide-test: + Cover raw (2352-byte) ATAPI CD reads + Add a multi-sector ATAPI DMA read test + Parametrize the ATAPI CD-ROM read test ----------------------------------------------------------------- Advisory ID: 1661 Released: Fri Sep 11 13:45:57 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent The following package changes have been done: - libattr1-2.6.0-160000.1.1 updated - libacl1-2.4.0-160000.1.1 updated - libzypp-17.38.15-160000.1.1 updated - zypper-1.14.101-160000.1.1 updated - qemu-vmsr-helper-10.0.13-160000.1.1 updated - qemu-pr-helper-10.0.13-160000.1.1 updated - qemu-img-10.0.13-160000.1.1 updated - qemu-tools-10.0.13-160000.1.1 updated - container:registry.suse.com-bci-bci-base-16.0-4e6baf5e20a374e515580441ed10778b88813915f61ee12cc28563acdfcb5552-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:24:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:24:58 +0200 (CEST) Subject: SUSE-CU-2026:10921-1: Security update of bci/nodejs Message-ID: <20260919102458.E7F3CFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10921-1 Container Tags : bci/node:24 , bci/node:24-base , bci/node:24.18.1-base , bci/node:24.18.1-base-10.9 , bci/node:latest , bci/nodejs:24 , bci/nodejs:24-base , bci/nodejs:24.18.1-base , bci/nodejs:24.18.1-base-10.9 , bci/nodejs:latest Container Release : 10.9 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1661 Released: Fri Sep 11 13:45:57 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent The following package changes have been done: - libattr1-2.6.0-160000.1.1 updated - libacl1-2.4.0-160000.1.1 updated - container:registry.suse.com-bci-bci-base-16.0-4e6baf5e20a374e515580441ed10778b88813915f61ee12cc28563acdfcb5552-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:25:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:25:14 +0200 (CEST) Subject: SUSE-CU-2026:10922-1: Recommended update of bci/nodejs Message-ID: <20260919102514.0B17AFF17@maintenance.suse.de> SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10922-1 Container Tags : bci/node:24-micro , bci/node:24.18.1-micro , bci/node:24.18.1-micro-10.9 , bci/nodejs:24-micro , bci/nodejs:24.18.1-micro , bci/nodejs:24.18.1-micro-10.9 Container Release : 10.9 Severity : important Type : recommended References : 1239787 1272547 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1647 Released: Wed Sep 9 15:16:45 2026 Summary: Recommended update for libssh Type: recommended Severity: moderate References: 1272547 This update for libssh fixes the following issues: Changes in libssh: - Fix: libssh ignores system wide crypto policies (bsc#1272547) ----------------------------------------------------------------- Advisory ID: 1658 Released: Thu Sep 10 15:05:39 2026 Summary: Recommended update for openldap2_6 Type: recommended Severity: important References: 1239787 This update for openldap2_6 fixes the following issues: Changes in openldap2_6: - Update to version 2.6.13+157: * Add export symbols related to LDAP_CONNECTIONLESS * Clear after free: + Cleaning up memory and immediately erasing the pointer's memory address * prevent double free: + Ensuring the application never releases the exact same block of memory twice * liblber calloc: + OpenLDAP's specialized memory allocator that automatically wipes memory clean * Fix: openldap2_5: segfault when try to add bad escaped regex (bsc#1239787): + prevent double free in info rewrite * Set default ldapi path to be consistent for SUSE * guide.html file cherry-picked from https://src.opensuse.org/jengelh/openldap2/src/branch/master/openldap-2.6.8.tgz * Use OpenSSL API to verify host * Change malloc to use calloc to prevent memory reuse corruption * Return to release engineering The following package changes have been done: - libldap-data-2.6.13+157-160000.1.1 updated - libssh-config-0.11.5-160000.2.1 updated - libldap-2-2.6.13+157-160000.1.1 updated - libssh4-0.11.5-160000.2.1 updated - container:bci-bci-base-16.0-4e6baf5e20a374e515580441ed10778b88813915f61ee12cc28563acdfcb5552-0 updated - container:registry.suse.com-bci-bci-micro-16.0-41cf07d1bfacf3030652a17bddc907f8c6cdb73e47efc51e5d3ab73a50ffcb8b-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:25:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:25:43 +0200 (CEST) Subject: SUSE-CU-2026:10923-1: Security update of suse/pcp Message-ID: <20260919102543.668D7FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/pcp ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10923-1 Container Tags : suse/pcp:6 , suse/pcp:6.2 , suse/pcp:6.2.0 , suse/pcp:6.2.0-12.23 , suse/pcp:latest Container Release : 12.23 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container suse/pcp was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1661 Released: Fri Sep 11 13:45:57 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent The following package changes have been done: - libattr1-2.6.0-160000.1.1 updated - libacl1-2.4.0-160000.1.1 updated - container:bci-bci-init-16.0-328e5d68a1e2de0f5efb43d04ca997193f116911f3cc2035d0129f8c080f04c5-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:26:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:26:29 +0200 (CEST) Subject: SUSE-CU-2026:10924-1: Security update of bci/bci-sle16-kernel-module-devel Message-ID: <20260919102629.8C211FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle16-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10924-1 Container Tags : bci/bci-sle16-kernel-module-devel:16.0 , bci/bci-sle16-kernel-module-devel:16.0-32.6 Container Release : 32.6 Severity : important Type : security References : 1268867 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 ----------------------------------------------------------------- The container bci/bci-sle16-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1661 Released: Fri Sep 11 13:45:57 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent The following package changes have been done: - libattr1-2.6.0-160000.1.1 updated - libacl1-2.4.0-160000.1.1 updated - container:registry.suse.com-bci-bci-base-16.0-4e6baf5e20a374e515580441ed10778b88813915f61ee12cc28563acdfcb5552-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:27:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:27:28 +0200 (CEST) Subject: SUSE-CU-2026:10925-1: Recommended update of suse/sles/16.0/toolbox Message-ID: <20260919102728.2B754FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10925-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.123 , suse/sles/16.0/toolbox:latest Container Release : 1.123 Severity : critical Type : recommended References : 1272616 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1573 Released: Mon Aug 31 22:36:28 2026 Summary: Recommended update for gcc16 Type: recommended Severity: moderate References: 1272616 This update for gcc16 fixes the following issues: gcc16 is shipped as new package. This update ships the GNU Compiler Collection GCC 16.2. The compiler runtime libraries are provided for SUSE Linux Enterprise 16.0 versions and replace the same named GCC 14 ones. The new compilers are provided in the PackageHub 16.0 only. To use gcc16 compilers use: - install 'gcc16' or 'gcc16-c++' or one of the other 'gcc16-COMPILER' frontend packages. - override your Makefile to use CC=gcc16, CXX=g++16 and similar overrides for the other languages. For a full changelog with all new GCC16 features, check out https://gcc.gnu.org/gcc-16/changes.html - Update to GCC 16.2 release (gcc-16.2.0+git9497) * accumulated bugfixes from the gcc-16 release branch - Disable multilibs for cross-x86_64-gcc ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libgomp1-16.2.0+git9497-160000.2.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:31:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:31:49 +0200 (CEST) Subject: SUSE-CU-2026:10941-1: Security update of trento/mcp-server-trento Message-ID: <20260919103149.B8D02FF17@maintenance.suse.de> SUSE Container Update Advisory: trento/mcp-server-trento ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10941-1 Container Tags : trento/mcp-server-trento:1.1.1 , trento/mcp-server-trento:1.1.1-build1.10.28 , trento/mcp-server-trento:latest Container Release : 1.10.28 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container trento/mcp-server-trento was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:32:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:32:00 +0200 (CEST) Subject: SUSE-CU-2026:10943-1: Security update of trento/trento-checks Message-ID: <20260919103200.9B71BFF17@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-checks ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10943-1 Container Tags : trento/trento-checks:1.3.1 , trento/trento-checks:1.3.1-build1.20.28 , trento/trento-checks:latest Container Release : 1.20.28 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container trento/trento-checks was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:32:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:32:13 +0200 (CEST) Subject: SUSE-CU-2026:10945-1: Security update of trento/trento-wanda Message-ID: <20260919103213.54CBBFF17@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-wanda ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10945-1 Container Tags : trento/trento-wanda:2.1.0 , trento/trento-wanda:2.1.0-build1.35.42 , trento/trento-wanda:latest Container Release : 1.35.42 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container trento/trento-wanda was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:32:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:32:14 +0200 (CEST) Subject: SUSE-CU-2026:10946-1: Security update of trento/trento-wanda Message-ID: <20260919103214.83DFBFF1E@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-wanda ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10946-1 Container Tags : trento/trento-wanda:2.1.0 , trento/trento-wanda:2.1.0-build1.35.43 , trento/trento-wanda:latest Container Release : 1.35.43 Severity : important Type : security References : 1212476 1221107 1227370 1236165 1239009 1242233 1243830 1246697 1246934 1250232 1250782 1250782 1252696 1253025 1256834 1256835 1256836 1256837 1256838 1256839 1256840 1258311 1259825 1260441 1260442 1260443 1260444 1261678 1262315 1262684 1266340 1266341 1266342 1266349 1266357 1271712 1274774 1274788 1274795 1275660 CVE-2024-2236 CVE-2025-68160 CVE-2025-69418 CVE-2025-69419 CVE-2025-69420 CVE-2025-69421 CVE-2025-9230 CVE-2026-22795 CVE-2026-22796 CVE-2026-28387 CVE-2026-28388 CVE-2026-28389 CVE-2026-28390 CVE-2026-31789 CVE-2026-34180 CVE-2026-41989 CVE-2026-42766 CVE-2026-45447 CVE-2026-54874 CVE-2026-63072 CVE-2026-7383 CVE-2026-9076 ----------------------------------------------------------------- The container trento/trento-wanda was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2719-1 Released: Thu Aug 7 05:38:32 2025 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1221107,1246934,CVE-2024-2236 This update for libgcrypt fixes the following issues: - CVE-2024-2236: timing-based side-channel flaw in RSA implementation can lead to decryption of RSA ciphertexts (bsc#1221107). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2890-1 Released: Tue Aug 19 09:54:32 2025 Summary: Recommended update for openssl-1_1 Type: recommended Severity: moderate References: 1246697 This update for openssl-1_1 fixes the following issues: - FIPS: Use the NID_X9_62_prime256v1 curve in ECDSA KAT test instead of NID_secp256k1. [bsc#1246697] ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3635-1 Released: Fri Oct 17 16:33:06 2025 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1250232,CVE-2025-9230 This update for openssl-1_1 fixes the following issues: - CVE-2025-9230: fixed out of bounds read and write in RFC 3211 KEK unwrap (bsc#1250232) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:331-1 Released: Wed Jan 28 18:12:49 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1256834,1256835,1256836,1256837,1256838,1256839,1256840,CVE-2025-68160,CVE-2025-69418,CVE-2025-69419,CVE-2025-69420,CVE-2025-69421,CVE-2026-22795,CVE-2026-22796 This update for openssl-1_1 fixes the following issues: - CVE-2026-22795: Missing ASN1_TYPE validation in PKCS#12 parsing (bsc#1256839). - CVE-2025-69420: Missing ASN1_TYPE validation in TS_RESP_verify_response() function (bsc#1256837). - CVE-2025-69421: NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function (bsc#1256838). - CVE-2026-22796: ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function (bsc#1256840). - CVE-2025-68160: Heap out-of-bounds write in BIO_f_linebuffer on short writes (bsc#1256834). - CVE-2025-69418: Unauthenticated/unencrypted trailing bytes with low-level OCB function calls (bsc#1256835). - CVE-2025-69419: Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversion (bsc#1256836). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1386-1 Released: Thu Apr 16 11:17:06 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260441,1260442,1260443,1260444,1261678,CVE-2026-28387,CVE-2026-28388,CVE-2026-28389,CVE-2026-28390,CVE-2026-31789 This update for openssl-1_1 fixes the following issues: - CVE-2026-28387: Potential use-after-free in DANE client code (bsc#1260441). - CVE-2026-28388: NULL Pointer Dereference When Processing a Delta CRL (bsc#1260442). - CVE-2026-28389: Possible NULL dereference when processing CMS KeyAgreeRecipientInfo (bsc#1260443). - CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678). - CVE-2026-31789: Heap buffer overflow in hexadecimal conversion (bsc#1260444). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2041-1 Released: Thu May 21 16:29:18 2026 Summary: Recommended update for openssl-1_1 Type: recommended Severity: moderate References: 1250782 This update for openssl-1_1 fixes the following issues: - Fix 30-test_fips_sli.t fails intermittently on s390x (bsc#1250782): * Fix AES_GCM IV test sometimes failing on s390x. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2392-1 Released: Mon Jun 15 10:05:31 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1250782,1266340,1266341,1266342,1266349,1266357,CVE-2026-34180,CVE-2026-42766,CVE-2026-45447,CVE-2026-7383,CVE-2026-9076 This update for openssl-1_1 fixes the following issues - CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340). - CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341). - CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342). - CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349). - CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - libopenssl1_1-1.1.1w-150700.11.30.1 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:32:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:32:37 +0200 (CEST) Subject: SUSE-CU-2026:10948-1: Security update of trento/trento-web Message-ID: <20260919103237.3E748FF17@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-web ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10948-1 Container Tags : trento/trento-web:3.1.5 , trento/trento-web:3.1.5-build4.62.19 , trento/trento-web:latest Container Release : 4.62.19 Severity : moderate Type : security References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 ----------------------------------------------------------------- The container trento/trento-web was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:32:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:32:38 +0200 (CEST) Subject: SUSE-CU-2026:10949-1: Security update of trento/trento-web Message-ID: <20260919103238.766FFFF1E@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-web ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10949-1 Container Tags : trento/trento-web:3.1.5 , trento/trento-web:3.1.5-build4.62.20 , trento/trento-web:latest Container Release : 4.62.20 Severity : important Type : security References : 1212476 1221107 1227370 1236165 1239009 1242233 1243830 1246697 1246934 1250232 1250782 1250782 1252696 1253025 1256834 1256835 1256836 1256837 1256838 1256839 1256840 1258311 1259825 1260441 1260442 1260443 1260444 1261678 1262315 1262684 1266340 1266341 1266342 1266349 1266357 1271712 1274774 1274788 1274795 1275660 CVE-2024-2236 CVE-2025-68160 CVE-2025-69418 CVE-2025-69419 CVE-2025-69420 CVE-2025-69421 CVE-2025-9230 CVE-2026-22795 CVE-2026-22796 CVE-2026-28387 CVE-2026-28388 CVE-2026-28389 CVE-2026-28390 CVE-2026-31789 CVE-2026-34180 CVE-2026-41989 CVE-2026-42766 CVE-2026-45447 CVE-2026-54874 CVE-2026-63072 CVE-2026-7383 CVE-2026-9076 ----------------------------------------------------------------- The container trento/trento-web was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2719-1 Released: Thu Aug 7 05:38:32 2025 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1221107,1246934,CVE-2024-2236 This update for libgcrypt fixes the following issues: - CVE-2024-2236: timing-based side-channel flaw in RSA implementation can lead to decryption of RSA ciphertexts (bsc#1221107). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2890-1 Released: Tue Aug 19 09:54:32 2025 Summary: Recommended update for openssl-1_1 Type: recommended Severity: moderate References: 1246697 This update for openssl-1_1 fixes the following issues: - FIPS: Use the NID_X9_62_prime256v1 curve in ECDSA KAT test instead of NID_secp256k1. [bsc#1246697] ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3635-1 Released: Fri Oct 17 16:33:06 2025 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1250232,CVE-2025-9230 This update for openssl-1_1 fixes the following issues: - CVE-2025-9230: fixed out of bounds read and write in RFC 3211 KEK unwrap (bsc#1250232) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:331-1 Released: Wed Jan 28 18:12:49 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1256834,1256835,1256836,1256837,1256838,1256839,1256840,CVE-2025-68160,CVE-2025-69418,CVE-2025-69419,CVE-2025-69420,CVE-2025-69421,CVE-2026-22795,CVE-2026-22796 This update for openssl-1_1 fixes the following issues: - CVE-2026-22795: Missing ASN1_TYPE validation in PKCS#12 parsing (bsc#1256839). - CVE-2025-69420: Missing ASN1_TYPE validation in TS_RESP_verify_response() function (bsc#1256837). - CVE-2025-69421: NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function (bsc#1256838). - CVE-2026-22796: ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function (bsc#1256840). - CVE-2025-68160: Heap out-of-bounds write in BIO_f_linebuffer on short writes (bsc#1256834). - CVE-2025-69418: Unauthenticated/unencrypted trailing bytes with low-level OCB function calls (bsc#1256835). - CVE-2025-69419: Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversion (bsc#1256836). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1386-1 Released: Thu Apr 16 11:17:06 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260441,1260442,1260443,1260444,1261678,CVE-2026-28387,CVE-2026-28388,CVE-2026-28389,CVE-2026-28390,CVE-2026-31789 This update for openssl-1_1 fixes the following issues: - CVE-2026-28387: Potential use-after-free in DANE client code (bsc#1260441). - CVE-2026-28388: NULL Pointer Dereference When Processing a Delta CRL (bsc#1260442). - CVE-2026-28389: Possible NULL dereference when processing CMS KeyAgreeRecipientInfo (bsc#1260443). - CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678). - CVE-2026-31789: Heap buffer overflow in hexadecimal conversion (bsc#1260444). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2041-1 Released: Thu May 21 16:29:18 2026 Summary: Recommended update for openssl-1_1 Type: recommended Severity: moderate References: 1250782 This update for openssl-1_1 fixes the following issues: - Fix 30-test_fips_sli.t fails intermittently on s390x (bsc#1250782): * Fix AES_GCM IV test sometimes failing on s390x. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2392-1 Released: Mon Jun 15 10:05:31 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1250782,1266340,1266341,1266342,1266349,1266357,CVE-2026-34180,CVE-2026-42766,CVE-2026-45447,CVE-2026-7383,CVE-2026-9076 This update for openssl-1_1 fixes the following issues - CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340). - CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341). - CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342). - CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349). - CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4041-1 Released: Mon Sep 7 10:29:44 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: August 2026 release. - CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4110-1 Released: Wed Sep 9 17:00:16 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660 This update for crypto-policies fixes the following issues: - Update crypto-policies for Post-Quantum Cryptography (PQC) TLS support in SLE-15-SP7 (jsc#PED-16072): * Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660) * Add support for python36 (jsc#PED-16072) * Add support for sntrup761x25519-sha512 at openssh.com and remove it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7 as it only lists the former (bsc#1258311, bsc#1259825) - Allow X25519 as required for sntrup761x25519-sha512 at openssh.com and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825) - Add PQC support for OpenSSH (bsc#1258311, bsc#1259825) * Enable sntrup761x25519-sha512 for OpenSSH by default - Modify the output of fips-mode-setup to hint the user when setting the FIPS mode in transactional systems to use the command 'transactional-update setup-fips'. (bsc#1262315) - Adapt the manpages to SUSE/openSUSE: * Compress all the man pages for update-crypto-policies.8.gz, crypto-policies.7.gz, fips-finish-install.8.gz and fips-mode-setup.8.gz into man-crypto-policies.tar.xz - Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696] * gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert * python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519 * FIPS: disable MLKEM768-X25519 for openssh (no-op) * FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl... * TEST-PQ: be more careful with the ordering * openssl: send one PQ and one classic key_share; prioritize PQ groups * sequoia: Generate AEAD policy * Do not include EdDSA in FIPS policy * sequoia: Add PQC algorithm * sequoia: Run tests against PQC capable policy-config-check * Revert 'openssl, policies: implement group_key_share option' * openssl, policies: implement group_key_share option * FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA * python/build-crypto-policies: output diffs on --test mismatches * sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ... * policies, alg_lists, openssl: remove KYBER from allowed values * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * nss: be stricter with new purposes * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-crypto-policy-overlay: automount FIPS policy * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * TEST-PQ: disable pure Kyber768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 - Update to version 20250425.9267dee: * openssl: fix mistakes in integrity-only cipher definitions * NO-PQ, cryptopolicies: add experimental value suppression * nss: add mlkem768x25519 and mlkem768secp256r1 * gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY * TEST-PQ, openssh: add support for MLKEM768 key_exchange * LEGACY: drop cipher at pkcs12 = SEED-CBC * fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes * nss: TLS-REQUIRE-EMS in FIPS * DEFAULT: disable RSA key exchange * LEGACY: disable sign = *-SHA1 * nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768 - Add the FIPS scripts fips-finish-install and fips-mode-setup as sources in the spec file as they have been removed upstream. * We will maintain these scripts downstream. * Update the man pages for update-crypto-policies.8.gz * Add man pages in text file in compressed form in the file man-fips-scripts.tar.xz and add them to the Makefile. - Update to version 20250324.3714354: * NO-PQ: introduce * LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA * _openssl_block_sha1_signatures: flip the default to 1 * sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia * sequoia: refactor a bit * openssl: specify default key size for req * gnutls: support P384-MLKEM1024 * openssl: stop generating `openssl` in favour of `opensslcnf` * gnutls: drop kyber (switching to leancrypto took it away) * openssl: use both names for P384-MLKEM1024 * Detect the presence of nss-policy-check * Don't use hardcoded python3 path * Make xsltproc settable as XSLTPROC * python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021 * Update the info in the README.SUSE file * Remove the FEDORA policies and directories - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. [bsc#1243830, bsc#1242233] - Relax the nss version requirement since the mlkem768secp256r1 enablement has been reverted. - Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370] - Enable SHA1 sigver in the DEFAULT policy. - Remove also sequoia config and generator files - Remove not needed fips bind mount service - Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165] * openssl: stricter enabling of Ciphersuites * openssl: make use of -CBC and -AESGCM keywords * openssl: add TLS 1.3 Brainpool identifiers * fix warning on using experimental key_exchanges * update-crypto-policies: don't output FIPS warning in fips mode * openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256 * openssh, libssh: refactor kx maps to use tuples * alg_lists: mark MLKEM768/SNTRUP kex experimental * nss: revert enabling mlkem768secp256r1 * nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber * gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768 * openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768 * openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768 * openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256 * openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384... * python/update-crypto-policies: pacify pylint * fips-mode-setup: tolerate fips dracut module presence w/o FIPS * fips-mode-setup: small Argon2 detection fix * SHA1: add __openssl_block_sha1_signatures = 0 * fips-mode-setup: block if LUKS devices using Argon2 are detected * update-crypto-policies: skip warning on --set=FIPS if bootc * fips-setup-helper: skip warning, BTW * fips-mode-setup: force --no-bootcfg when UKI is detected * fips-setup-helper: add a libexec helper for anaconda * fips-crypto-policy-overlay: automount FIPS policy * openssh: make dss no longer enableble, support is dropped * gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768 * DEFAULT: switch to rh-allow-sha1-signatures = no... * java: drop unused javasystem backend * java: stop specifying jdk.tls.namedGroups in javasystem * ec_min_size: introduce and use in java, default to 256 * java: use and include jdk.disabled.namedCurves * BSI: Update BSI policy for new 2024 minimum recommendations * fips-mode-setup: flashy ticking warning upon use * fips-mode-setup: add another scary 'unsupported' * CONTRIBUTING.md: add a small section on updating policies * CONTRIBUTING.md: remove trailing punctuation from headers * BSI: switch to 3072 minimum RSA key size * java: make hash, mac and sign more orthogonal * java: specify jdk.tls.namedGroups system property * java: respect more key size restrictions * java: disable anon ciphersuites, tying them to NULL... * java: start controlling / disable DTLSv1.0 * nss: wire KYBER768 to XYBER768D00 * nss: unconditionally load p11-kit-proxy.so * gnutls: make DTLS0.9 controllable again * gnutls: retire GNUTLS_NO_TLS_SESSION_HASH * openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE * gnutls: remove extraneous newline * sequoia: move away from subprocess.getstatusoutput * python/cryptopolicies/cryptopolicies.py: add trailing commas * python, tests: rename MalformedLine to MalformedLineError * Makefile: introduce SKIP_LINTING flag for packagers to use * Makefile: run ruff * tests: use pathlib * tests: run(check=True) + CalledProcessError where convenient * tests: use subprocess.run * tests/krb5.py: check all generated policies * tests: print to stderr on error paths * tests/nss.py: also use encoding='utf-8' * tests/nss.py: also use removesuffix * tests/nss.py: skip creating tempfiles * tests/java.pl -> tests/java.py * tests/gnutls.pl -> tests/gnutls.py * tests/openssl.pl -> tests/openssl.py * tests/verify-output.pl: remove * libreswan: do not use up pfs= / ikev2= keywords for default behaviour - Update to version 20241010.5930b9a: * LEGACY: enable 192-bit ciphers for nss pkcs12/smime * nss: be stricter with new purposes * nss: rewrite backend for 3.101 * cryptopolicies: parent scopes for dumping purposes * policygenerators: move scoping inside generators * TEST-PQ: disable pure Kyber768 * nss: wire XYBER768D00 to X25519-KYBER768 * TEST-PQ: update * TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com * TEST-PQ, alg_lists, openssl: enable more experimental `sign` values * TEST-PQ, python: add more groups, mark experimental * openssl: mark liboqsprovider groups optional with ? - Update to version 20240201.9f501f3: * .gitlab-ci.yml: install sequoia-policy-config * java: disable ChaCha20-Poly1305 where applicable * fips-mode-setup: make sure ostree is detected in chroot * fips-finish-install: make sure ostree is detected in chroot * TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl * TEST-PQ: add a no-op subpolicy * update-crypto-policies: Keep mid-sentence upper case * fips-mode-setup: Write error messages to stderr * fips-mode-setup: Fix some shellcheck warnings * fips-mode-setup: Fix test for empty /boot * fips-mode-setup: Avoid 'boot=UUID=' if /boot == / * Update man pages - Update to version 20231108.adb5572b: * Print matches in syntax deprecation warnings * Restore support for scoped ssh_etm directives * fips-mode-setup: Fix usage with --no-bootcfg * turn ssh_etm into an etm at SSH tri-state * fips-mode-setup: increase chroot-friendliness * bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx * pylintrc: use-implicit-booleaness-not-comparison-to-* - avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros: we only need python3-base here, we don't need the python macros as no module is being built - Remove dependency on /usr/bin/python3, making scripts to depends on the real python3 binary, not the link. bsc#1212476 The following package changes have been done: - libopenssl1_1-1.1.1w-150700.11.30.1 updated From sle-container-updates at lists.suse.com Mon Sep 21 07:59:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 21 Sep 2026 09:59:16 +0200 (CEST) Subject: SUSE-CU-2026:10989-1: Security update of bci/bci-base Message-ID: <20260921075916.A22F6FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10989-1 Container Tags : bci/bci-base:16.0 , bci/bci-base:16.0-23.5 Container Release : 23.5 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container bci/bci-base was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated - skelcd-EULA-BCI-20250701-160000.3.29 updated From sle-container-updates at lists.suse.com Mon Sep 21 08:09:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 21 Sep 2026 10:09:37 +0200 (CEST) Subject: SUSE-CU-2026:11006-1: Security update of bci/kiwi Message-ID: <20260921080937.25E21FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/kiwi ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11006-1 Container Tags : bci/kiwi:10 , bci/kiwi:10.2 , bci/kiwi:10.2.33 , bci/kiwi:10.2.33-20.8 Container Release : 20.8 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container bci/kiwi was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated - container:registry.suse.com-bci-bci-base-16.0-8186d3723a7484023a824b099e3aa11df82a9bac4538d2d6ab58fe8227ad0939-0 updated From sle-container-updates at lists.suse.com Mon Sep 21 08:12:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 21 Sep 2026 10:12:31 +0200 (CEST) Subject: SUSE-CU-2026:11017-1: Security update of suse/sles/16.0/virt-launcher Message-ID: <20260921081231.7A79AFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-launcher ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11017-1 Container Tags : suse/sles/16.0/virt-launcher:1.8 , suse/sles/16.0/virt-launcher:1.8.4 , suse/sles/16.0/virt-launcher:1.8.4-9.9 Container Release : 9.9 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sles/16.0/virt-launcher was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1683 Released: Tue Sep 15 12:14:12 2026 Summary: Recommended update for dmidecode Type: recommended Severity: moderate References: This update for dmidecode fixes the following issues: Changes in dmidecode: - Display slot information for EDSFF (jsc#PED-16127) ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - dmidecode-3.7-160000.2.1 updated - rpm-4.20.1-160000.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 21 08:13:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 21 Sep 2026 10:13:00 +0200 (CEST) Subject: SUSE-CU-2026:11019-1: Security update of suse/sles/16.0/libguestfs-tools Message-ID: <20260921081300.7EB87FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/libguestfs-tools ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11019-1 Container Tags : suse/sles/16.0/libguestfs-tools:1.8 , suse/sles/16.0/libguestfs-tools:1.8.4 , suse/sles/16.0/libguestfs-tools:1.8.4-9.9 Container Release : 9.9 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sles/16.0/libguestfs-tools was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 21 08:21:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 21 Sep 2026 10:21:06 +0200 (CEST) Subject: SUSE-CU-2026:11029-1: Security update of bci/bci-minimal Message-ID: <20260921082106.DE911FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-minimal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11029-1 Container Tags : bci/bci-minimal:16.0 , bci/bci-minimal:16.0-18.10 Container Release : 18.10 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container bci/bci-minimal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated - skelcd-EULA-BCI-20250701-160000.3.29 updated From sle-container-updates at lists.suse.com Mon Sep 21 08:24:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 21 Sep 2026 10:24:37 +0200 (CEST) Subject: SUSE-CU-2026:11035-1: Security update of bci/bci-sle16-kernel-module-devel Message-ID: <20260921082437.0DBC9FF17@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle16-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11035-1 Container Tags : bci/bci-sle16-kernel-module-devel:16.0 , bci/bci-sle16-kernel-module-devel:16.0-32.8 Container Release : 32.8 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container bci/bci-sle16-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated - librpmbuild10-4.20.1-160000.3.1 updated - rpm-build-4.20.1-160000.3.1 updated - container:registry.suse.com-bci-bci-base-16.0-8186d3723a7484023a824b099e3aa11df82a9bac4538d2d6ab58fe8227ad0939-0 updated From sle-container-updates at lists.suse.com Mon Sep 21 08:26:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 21 Sep 2026 10:26:19 +0200 (CEST) Subject: SUSE-CU-2026:11037-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260921082619.CE347FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11037-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.124 , suse/sles/16.0/toolbox:latest Container Release : 1.124 Severity : important Type : security References : 1277757 CVE-2026-13732 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1717 Released: Sun Sep 20 15:28:23 2026 Summary: Security update for gdb Type: security Severity: important References: 1277757,CVE-2026-13732 This update for gdb fixes the following issue: - CVE-2026-13732: out-of-bounds write in STABS parser read_member_functions() via crafted ELF (bsc#1277757). The following package changes have been done: - gdb-16.3-160000.6.1 updated From sle-container-updates at lists.suse.com Mon Sep 21 08:28:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 21 Sep 2026 10:28:40 +0200 (CEST) Subject: SUSE-CU-2026:11045-1: Security update of third-party/amd/amdgpu-driver Message-ID: <20260921082840.4513CFF17@maintenance.suse.de> SUSE Container Update Advisory: third-party/amd/amdgpu-driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11045-1 Container Tags : third-party/amd/amdgpu-driver:sles-16.0-31.10 , third-party/amd/amdgpu-driver:sles-16.0-31.10-13.9 , third-party/amd/amdgpu-driver:sles-16.0-6.12.0-160000.5-default-31.10 Container Release : 13.9 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container third-party/amd/amdgpu-driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 21 08:29:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 21 Sep 2026 10:29:04 +0200 (CEST) Subject: SUSE-CU-2026:11047-1: Security update of third-party/amd/amdgpu-driver Message-ID: <20260921082904.F3E99FF17@maintenance.suse.de> SUSE Container Update Advisory: third-party/amd/amdgpu-driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11047-1 Container Tags : third-party/amd/amdgpu-driver:sles-16.0-31.20 , third-party/amd/amdgpu-driver:sles-16.0-31.20-13.9 , third-party/amd/amdgpu-driver:sles-16.0-6.12.0-160000.5-default-31.20 Container Release : 13.9 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container third-party/amd/amdgpu-driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 21 08:29:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 21 Sep 2026 10:29:31 +0200 (CEST) Subject: SUSE-CU-2026:11049-1: Security update of third-party/amd/amdgpu-driver Message-ID: <20260921082931.D6600FF17@maintenance.suse.de> SUSE Container Update Advisory: third-party/amd/amdgpu-driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11049-1 Container Tags : third-party/amd/amdgpu-driver:sles-16.0-31.30 , third-party/amd/amdgpu-driver:sles-16.0-31.30-13.9 , third-party/amd/amdgpu-driver:sles-16.0-6.12.0-160000.5-default-31.30 Container Release : 13.9 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container third-party/amd/amdgpu-driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 21 08:29:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 21 Sep 2026 10:29:43 +0200 (CEST) Subject: SUSE-CU-2026:11051-1: Security update of third-party/amd/amdgpu-driver Message-ID: <20260921082943.D490BFF17@maintenance.suse.de> SUSE Container Update Advisory: third-party/amd/amdgpu-driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11051-1 Container Tags : third-party/amd/amdgpu-driver:sles-16.0-31.40.1 , third-party/amd/amdgpu-driver:sles-16.0-31.40.1-13.9 , third-party/amd/amdgpu-driver:sles-16.0-6.12.0-160000.5-default-31.40.1 Container Release : 13.9 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container third-party/amd/amdgpu-driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 21 08:30:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 21 Sep 2026 10:30:22 +0200 (CEST) Subject: SUSE-CU-2026:11053-1: Security update of third-party/nvidia/driver Message-ID: <20260921083022.34BA2FF1E@maintenance.suse.de> SUSE Container Update Advisory: third-party/nvidia/driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11053-1 Container Tags : third-party/nvidia/driver:595-6.12.0-160000.29-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.30-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.32-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.33-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.34-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.35-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.36-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.37-default-sles16.0 , third-party/nvidia/driver:595-sles16.0 , third-party/nvidia/driver:595-sles16.0-46.7 Container Release : 46.7 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container third-party/nvidia/driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated From sle-container-updates at lists.suse.com Mon Sep 21 08:30:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 21 Sep 2026 10:30:45 +0200 (CEST) Subject: SUSE-CU-2026:11055-1: Security update of third-party/nvidia/driver Message-ID: <20260921083045.466C3FF19@maintenance.suse.de> SUSE Container Update Advisory: third-party/nvidia/driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11055-1 Container Tags : third-party/nvidia/driver:610-6.12.0-160000.37-default-sles16.0 , third-party/nvidia/driver:610-sles16.0 , third-party/nvidia/driver:610-sles16.0-46.7 Container Release : 46.7 Severity : important Type : security References : 1218459 1253139 1259215 1268747 1269150 1269571 1269584 CVE-2026-44604 CVE-2026-44605 ----------------------------------------------------------------- The container third-party/nvidia/driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1688 Released: Wed Sep 16 16:28:22 2026 Summary: Security update for rpm Type: security Severity: important References: 1218459,1253139,1259215,1268747,1269150,1269571,1269584,CVE-2026-44604,CVE-2026-44605 This update for rpm fixes the following issues: Changes in rpm: - split imaevmsign plugin into a multibuild flavor Changes in rpm: - Add Requires: (rpm-plugin-selinux if selinux-policy) - harden ndb code [bsc#1269584] [CVE-2026-44605] - split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do - make the imaevmsign plugin build in a multibuild flavor - rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] - backport fix for add_sysuser macro [bsc#1269571] - backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] - switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures - turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new 'rpm-imaevmsign' subpackage. [jsc#PED-7246] - Fix 'unexpected EOF' when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) - Remove /var/lib/rpm migration scripting, retain an error if old location is found - Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) - flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added 'rpm_flushes_runposttrans' provides for libzypp The following package changes have been done: - rpm-4.20.1-160000.3.1 updated From sle-container-updates at lists.suse.com Tue Sep 22 07:14:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 22 Sep 2026 09:14:17 +0200 (CEST) Subject: SUSE-IU-2026:7226-1: Security update of suse/sle-micro/5.5 Message-ID: <20260922071417.229CDFF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7226-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.118 , suse/sle-micro/5.5:latest Image Release : 5.8.118 Severity : important Type : security References : 1215737 1218034 1218038 1238078 1248600 1262043 1262072 1265060 1265061 1265062 1265070 1265071 1265075 1265076 1269220 1269221 1269390 976992 CVE-2015-8863 CVE-2023-50246 CVE-2023-50268 CVE-2024-53427 CVE-2025-9403 CVE-2026-33948 CVE-2026-40164 CVE-2026-40612 CVE-2026-41256 CVE-2026-41257 CVE-2026-43894 CVE-2026-43895 CVE-2026-43896 CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54679 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4275-1 Released: Mon Sep 21 09:32:08 2026 Summary: Security update for jq Type: security Severity: important References: 1215737,1218034,1218038,1238078,1248600,1262043,1262072,1265060,1265061,1265062,1265070,1265071,1265075,1265076,1269220,1269221,1269390,976992,CVE-2015-8863,CVE-2023-50246,CVE-2023-50268,CVE-2024-53427,CVE-2025-9403,CVE-2026-33948,CVE-2026-40164,CVE-2026-40612,CVE-2026-41256,CVE-2026-41257,CVE-2026-43894,CVE-2026-43895,CVE-2026-43896,CVE-2026-44777,CVE-2026-47770,CVE-2026-49839,CVE-2026-54679 This update for jq fixes the following issues: Security issues fixed: - CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992). - CVE-2023-50246: improper memory handling can lead to a heap buffer overflow in `decNumberToString` (bsc#1218034). - CVE-2023-50268: stack-based buffer overflow in builds using decNumber (bsc#1218038). - CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in decNumber.c (bsc#1238078). - CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600). - CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). - CVE-2026-40164: predictable hash collisions can lead to a denial of service (bsc#1262072). - CVE-2026-40612: jv_contains recurses into nested arrays/objects with no depth limit and can cause a stack overflow (bsc#1265060). - CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f and can lead to execution of unintended programs (bsc#1265061). - CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS (bsc#1265062). - CVE-2026-43894: signed integer overflow in `decNumber` can lead to out-of-bounds memory write (bsc#1265070). - CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). - CVE-2026-43896: unbounded recursion in `jv_object_merge_recursive()` can lead to C stack exhaustion and a process crash (bsc#1265075). - CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). - CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). - CVE-2026-49839: `--rawfile` invalid-state reuse after `String too long` can lead to a heap buffer overflow (bsc#1269220). - CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer overrun on 32-bit systems (bsc#1269390). Changes for jq: Update to version 1.7.1: * Make the default background color more suitable for bright backgrounds. * Allow passing the inline jq script after --. * Fix possible uninitialised value dereference if jq_init() fails * Simplify paths/0 and paths/1. * Reject U+001F in string literals. * Remove unused nref accumulator in block_bind_library. * Remove a bunch of unused variables, and useless assignments. * main.c: Remove unused EXIT_STATUS_EXACT option. * Actually use the number correctly casted from double to int as index. * src/builtin.c: remove unnecessary jv_copy-s in type_error/type_error2. * Remove undefined behavior caught by LLVM 10 UBSAN. * Convert decnum to binary64 (double) instead of decimal64. This makes jq behave like the JSON specification suggests and more similar to other languages. * Fix memory leaks on invalid input for ltrimstr/1 and rtrimstr/1. * Fix memory leak on failed get for setpath/2. * Fix nan from json parsing also for nans with payload that start with 'n'. * Allow carriage return characters in comments. * Generate links in the man page. * Add extern C for C++. * Make object key color configurable using JQ_COLORS environment variable. * Change the default color of null to Bright Black. * Respect NO_COLOR environment variable to disable color output. * Improved --help output. Now mentions all options and nicer order. * Fix multiple issues of exit code using --exit-code/-e option. * Add --raw-output0 for NUL (zero byte) separated output. * Fix assert crash and validate JSON for --jsonarg. * Remove deprecated --argfile option. * Use decimal number literals to preserve precision. Comparison operations respects precision but arithmetic operations might truncate. * Adds new builtin pick(stream) to emit a projection of the input object or array. * Adds new builtin debug(msgs) that works like debug but applies a filter on the input before writing to stderr. * Adds new builtin scan($re; $flags). Was documented but not implemented. * Adds new builtin abs to get absolute value. This potentially allows the literal value of numbers to be preserved as length and fabs convert to float. * Allow if without else-branch. When skipped the else-branch will be . (identity). * Allow use of $binding as key in object literals. * Allow dot between chained indexes when using .['index'] * Allow dot for chained value iterator .[], .[]? * Fix try/catch catches more than it should. * Speed up and refactor some builtins, also remove scalars_or_empty/0. * Now halt and halt_error exit immediately instead of continuing to the next input. * Fix issue converting string to number after previous convert error. * Fix issue representing large numbers on some platforms causing invalid JSON output. * Fix deletion using assigning empty against arrays. * Allow keywords to be used as binding name in more places. * Allow using nan as NaN in JSON. * Expose a module's function names in modulemeta. * Fix contains/1 to handle strings with NUL. * Fix stderr/0 to output raw text without any decoration. * Fix nth/2 to emit empty on index out of range. * Fix implode to not assert and instead replace invalid unicode codepoints. * Fix indices/1 and rindex/1 in case of overlapping matches in strings. * Fix sub/3 to resolve issues involving global search-and-replace (gsub) operations. * Fix empty regular expression matches. * Fix overflow exception of the modulo operator. * Fix string multiplication by 0 (and less than 1) to emit empty string. * Fix segfault when using libjq and threads. * Fix constant folding of division and reminder with zero divisor. * Fix error/0, error/1 to throw null error. * Simpler and faster transpose. * Simple and efficient implementation of walk/1. * Remove deprecated filters leaf_paths, recurse_down. The following package changes have been done: - libjq1-1.7.1-150000.3.25.1 updated - jq-1.7.1-150000.3.25.1 updated From sle-container-updates at lists.suse.com Tue Sep 22 07:32:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 22 Sep 2026 09:32:20 +0200 (CEST) Subject: SUSE-CU-2026:11060-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260922073220.19205FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11060-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.190 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.190 Severity : important Type : security References : 1215737 1218034 1218038 1238078 1248600 1262043 1262072 1265060 1265061 1265062 1265070 1265071 1265075 1265076 1269220 1269221 1269390 976992 CVE-2015-8863 CVE-2023-50246 CVE-2023-50268 CVE-2024-53427 CVE-2025-9403 CVE-2026-33948 CVE-2026-40164 CVE-2026-40612 CVE-2026-41256 CVE-2026-41257 CVE-2026-43894 CVE-2026-43895 CVE-2026-43896 CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54679 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4275-1 Released: Mon Sep 21 09:32:08 2026 Summary: Security update for jq Type: security Severity: important References: 1215737,1218034,1218038,1238078,1248600,1262043,1262072,1265060,1265061,1265062,1265070,1265071,1265075,1265076,1269220,1269221,1269390,976992,CVE-2015-8863,CVE-2023-50246,CVE-2023-50268,CVE-2024-53427,CVE-2025-9403,CVE-2026-33948,CVE-2026-40164,CVE-2026-40612,CVE-2026-41256,CVE-2026-41257,CVE-2026-43894,CVE-2026-43895,CVE-2026-43896,CVE-2026-44777,CVE-2026-47770,CVE-2026-49839,CVE-2026-54679 This update for jq fixes the following issues: Security issues fixed: - CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992). - CVE-2023-50246: improper memory handling can lead to a heap buffer overflow in `decNumberToString` (bsc#1218034). - CVE-2023-50268: stack-based buffer overflow in builds using decNumber (bsc#1218038). - CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in decNumber.c (bsc#1238078). - CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600). - CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). - CVE-2026-40164: predictable hash collisions can lead to a denial of service (bsc#1262072). - CVE-2026-40612: jv_contains recurses into nested arrays/objects with no depth limit and can cause a stack overflow (bsc#1265060). - CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f and can lead to execution of unintended programs (bsc#1265061). - CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS (bsc#1265062). - CVE-2026-43894: signed integer overflow in `decNumber` can lead to out-of-bounds memory write (bsc#1265070). - CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). - CVE-2026-43896: unbounded recursion in `jv_object_merge_recursive()` can lead to C stack exhaustion and a process crash (bsc#1265075). - CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). - CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). - CVE-2026-49839: `--rawfile` invalid-state reuse after `String too long` can lead to a heap buffer overflow (bsc#1269220). - CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer overrun on 32-bit systems (bsc#1269390). Changes for jq: Update to version 1.7.1: * Make the default background color more suitable for bright backgrounds. * Allow passing the inline jq script after --. * Fix possible uninitialised value dereference if jq_init() fails * Simplify paths/0 and paths/1. * Reject U+001F in string literals. * Remove unused nref accumulator in block_bind_library. * Remove a bunch of unused variables, and useless assignments. * main.c: Remove unused EXIT_STATUS_EXACT option. * Actually use the number correctly casted from double to int as index. * src/builtin.c: remove unnecessary jv_copy-s in type_error/type_error2. * Remove undefined behavior caught by LLVM 10 UBSAN. * Convert decnum to binary64 (double) instead of decimal64. This makes jq behave like the JSON specification suggests and more similar to other languages. * Fix memory leaks on invalid input for ltrimstr/1 and rtrimstr/1. * Fix memory leak on failed get for setpath/2. * Fix nan from json parsing also for nans with payload that start with 'n'. * Allow carriage return characters in comments. * Generate links in the man page. * Add extern C for C++. * Make object key color configurable using JQ_COLORS environment variable. * Change the default color of null to Bright Black. * Respect NO_COLOR environment variable to disable color output. * Improved --help output. Now mentions all options and nicer order. * Fix multiple issues of exit code using --exit-code/-e option. * Add --raw-output0 for NUL (zero byte) separated output. * Fix assert crash and validate JSON for --jsonarg. * Remove deprecated --argfile option. * Use decimal number literals to preserve precision. Comparison operations respects precision but arithmetic operations might truncate. * Adds new builtin pick(stream) to emit a projection of the input object or array. * Adds new builtin debug(msgs) that works like debug but applies a filter on the input before writing to stderr. * Adds new builtin scan($re; $flags). Was documented but not implemented. * Adds new builtin abs to get absolute value. This potentially allows the literal value of numbers to be preserved as length and fabs convert to float. * Allow if without else-branch. When skipped the else-branch will be . (identity). * Allow use of $binding as key in object literals. * Allow dot between chained indexes when using .['index'] * Allow dot for chained value iterator .[], .[]? * Fix try/catch catches more than it should. * Speed up and refactor some builtins, also remove scalars_or_empty/0. * Now halt and halt_error exit immediately instead of continuing to the next input. * Fix issue converting string to number after previous convert error. * Fix issue representing large numbers on some platforms causing invalid JSON output. * Fix deletion using assigning empty against arrays. * Allow keywords to be used as binding name in more places. * Allow using nan as NaN in JSON. * Expose a module's function names in modulemeta. * Fix contains/1 to handle strings with NUL. * Fix stderr/0 to output raw text without any decoration. * Fix nth/2 to emit empty on index out of range. * Fix implode to not assert and instead replace invalid unicode codepoints. * Fix indices/1 and rindex/1 in case of overlapping matches in strings. * Fix sub/3 to resolve issues involving global search-and-replace (gsub) operations. * Fix empty regular expression matches. * Fix overflow exception of the modulo operator. * Fix string multiplication by 0 (and less than 1) to emit empty string. * Fix segfault when using libjq and threads. * Fix constant folding of division and reminder with zero divisor. * Fix error/0, error/1 to throw null error. * Simpler and faster transpose. * Simple and efficient implementation of walk/1. * Remove deprecated filters leaf_paths, recurse_down. The following package changes have been done: - jq-1.7.1-150000.3.25.1 updated - libjq1-1.7.1-150000.3.25.1 updated From sle-container-updates at lists.suse.com Tue Sep 22 07:54:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 22 Sep 2026 09:54:59 +0200 (CEST) Subject: SUSE-CU-2026:11065-1: Security update of suse/sl-micro/6.0/toolbox Message-ID: <20260922075459.34F6BFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11065-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.169 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.169 Severity : important Type : security References : 1277757 CVE-2026-13732 ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 910 Released: Mon Sep 21 11:50:14 2026 Summary: Security update for gdb Type: security Severity: important References: 1277757,CVE-2026-13732 This update for gdb fixes the following issue: - CVE-2026-13732: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF (bsc#1277757). The following package changes have been done: - SL-Micro-release-6.0-25.134 updated - gdb-13.2-3.1 updated - skelcd-EULA-SL-Micro-2024.01.19-8.133 updated From sle-container-updates at lists.suse.com Tue Sep 22 08:19:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 22 Sep 2026 10:19:56 +0200 (CEST) Subject: SUSE-IU-2026:7236-1: Recommended update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260922081956.3B0C4FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7236-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.148 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.148 Severity : moderate Type : recommended References : 1262698 1266262 1279863 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1722 Released: Mon Sep 21 11:58:27 2026 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1262698,1266262,1279863 This update for mozilla-nss fixes the following issues: Changes in mozilla-nss: - Fix potential crash when verifying password length in PBKDF2 (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). The following package changes have been done: - libfreebl3-3.125-160000.2.1 updated - mozilla-nss-certs-3.125-160000.2.1 updated - mozilla-nss-3.125-160000.2.1 updated - libsoftokn3-3.125-160000.2.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-cb2b459fd41cab1c0781c00030dca5a01daf5644b073c82eecde27145f19c31d-0 updated From sle-container-updates at lists.suse.com Tue Sep 22 08:29:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 22 Sep 2026 10:29:41 +0200 (CEST) Subject: SUSE-IU-2026:7241-1: Recommended update of suse/sl-micro/6.2/base-os-container Message-ID: <20260922082941.65D22FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7241-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.79 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.79 Severity : moderate Type : recommended References : 1262698 1266262 1279863 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1722 Released: Mon Sep 21 11:58:27 2026 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1262698,1266262,1279863 This update for mozilla-nss fixes the following issues: Changes in mozilla-nss: - Fix potential crash when verifying password length in PBKDF2 (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). The following package changes have been done: - libfreebl3-3.125-160000.2.1 updated - mozilla-nss-certs-3.125-160000.2.1 updated - mozilla-nss-3.125-160000.2.1 updated - libsoftokn3-3.125-160000.2.1 updated From sle-container-updates at lists.suse.com Tue Sep 22 08:39:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 22 Sep 2026 10:39:52 +0200 (CEST) Subject: SUSE-IU-2026:7245-1: Recommended update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260922083952.7056BFF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7245-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.130 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.130 Severity : moderate Type : recommended References : 1262698 1266262 1279863 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1722 Released: Mon Sep 21 11:58:27 2026 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1262698,1266262,1279863 This update for mozilla-nss fixes the following issues: Changes in mozilla-nss: - Fix potential crash when verifying password length in PBKDF2 (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). The following package changes have been done: - libfreebl3-3.125-160000.2.1 updated - mozilla-nss-certs-3.125-160000.2.1 updated - mozilla-nss-3.125-160000.2.1 updated - libsoftokn3-3.125-160000.2.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-cb2b459fd41cab1c0781c00030dca5a01daf5644b073c82eecde27145f19c31d-0 updated From sle-container-updates at lists.suse.com Tue Sep 22 08:51:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 22 Sep 2026 10:51:02 +0200 (CEST) Subject: SUSE-IU-2026:7252-1: Recommended update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260922085102.BF449FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7252-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.171 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.171 Severity : moderate Type : recommended References : 1262698 1266262 1279863 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1722 Released: Mon Sep 21 11:58:27 2026 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1262698,1266262,1279863 This update for mozilla-nss fixes the following issues: Changes in mozilla-nss: - Fix potential crash when verifying password length in PBKDF2 (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). The following package changes have been done: - libfreebl3-3.125-160000.2.1 updated - mozilla-nss-certs-3.125-160000.2.1 updated - mozilla-nss-3.125-160000.2.1 updated - libsoftokn3-3.125-160000.2.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-cc106e659e4eb14ffcbcb1c00421985915ae3726c983232eb53573dd4275224f-0 updated From sle-container-updates at lists.suse.com Wed Sep 23 07:17:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 09:17:04 +0200 (CEST) Subject: SUSE-CU-2026:11106-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260923071704.8106CFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11106-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.191 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.191 Severity : important Type : security References : 1235944 1242405 1261604 1263072 1264734 1266008 1267023 1268659 1269000 1269004 1269238 1269242 1269306 1269655 1269731 1271825 1271830 1272179 1272182 1272230 1272385 1272390 1272868 1272877 1273060 1273105 1273251 1273276 1273303 1273311 1273422 1273484 1273488 1273523 1273555 1273742 1273745 1273748 1273762 1273774 1273869 1273882 1273891 1273930 1273944 1273966 1273995 1274014 1274041 1274208 1274274 1274497 1274547 1274550 1274696 1274705 1274752 1274753 1274754 1274859 1274888 1274898 1274902 1274908 1274941 1275161 1275304 1275307 1275470 1275472 1275474 1275506 1275528 1275535 1275540 1275687 1275696 1275784 1275798 1275827 1275867 1275886 1275905 1275985 1276006 1276350 1276395 1276665 1276931 1277073 1277285 1277391 1277408 1277523 1277553 1277561 1277571 1277813 1277837 1277901 1277908 1278088 1278233 1278236 1278253 1278294 1279422 1279487 1279813 CVE-2023-53109 CVE-2024-57841 CVE-2026-23451 CVE-2026-31502 CVE-2026-43456 CVE-2026-43502 CVE-2026-45968 CVE-2026-52910 CVE-2026-52912 CVE-2026-52929 CVE-2026-52977 CVE-2026-53059 CVE-2026-53163 CVE-2026-53260 CVE-2026-53264 CVE-2026-53381 CVE-2026-53388 CVE-2026-63801 CVE-2026-63823 CVE-2026-63827 CVE-2026-63887 CVE-2026-63888 CVE-2026-63920 CVE-2026-63992 CVE-2026-64002 CVE-2026-64007 CVE-2026-64010 CVE-2026-64011 CVE-2026-64015 CVE-2026-64047 CVE-2026-64048 CVE-2026-64098 CVE-2026-64109 CVE-2026-64114 CVE-2026-64115 CVE-2026-64137 CVE-2026-64266 CVE-2026-64268 CVE-2026-64304 CVE-2026-64355 CVE-2026-64423 CVE-2026-64450 CVE-2026-64481 CVE-2026-64541 CVE-2026-64543 CVE-2026-64556 CVE-2026-64562 CVE-2026-64563 CVE-2026-64572 CVE-2026-64581 CVE-2026-64593 CVE-2026-68121 CVE-2026-68136 CVE-2026-68138 CVE-2026-68155 CVE-2026-68158 CVE-2026-68159 CVE-2026-68160 CVE-2026-68202 CVE-2026-68397 CVE-2026-68398 CVE-2026-68417 CVE-2026-68426 CVE-2026-68480 CVE-2026-72020 CVE-2026-72069 CVE-2026-72083 CVE-2026-72084 CVE-2026-72123 CVE-2026-72135 CVE-2026-72164 CVE-2026-72251 CVE-2026-72288 CVE-2026-72289 CVE-2026-72323 CVE-2026-72339 CVE-2026-72389 CVE-2026-74345 CVE-2026-74377 CVE-2026-74378 CVE-2026-74388 CVE-2026-74390 CVE-2026-74394 CVE-2026-74406 CVE-2026-74454 CVE-2026-74488 CVE-2026-74496 CVE-2026-74518 CVE-2026-74537 CVE-2026-74556 CVE-2026-74582 CVE-2026-74615 CVE-2026-74616 CVE-2026-74669 CVE-2026-74695 CVE-2026-74743 CVE-2026-80580 CVE-2026-80714 CVE-2026-80716 CVE-2026-80737 CVE-2026-80909 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4284-1 Released: Tue Sep 22 18:07:33 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1235944,1242405,1261604,1263072,1264734,1266008,1267023,1268659,1269000,1269004,1269238,1269242,1269306,1269655,1269731,1271825,1271830,1272179,1272182,1272230,1272385,1272390,1272868,1272877,1273060,1273105,1273251,1273276,1273303,1273311,1273422,1273484,1273488,1273523,1273555,1273742,1273745,1273748,1273762,1273774,1273869,1273882,1273891,1273930,1273944,1273966,1273995,1274014,1274041,1274208,1274274,1274497,1274547,1274550,1274696,1274705,1274752,1274753,1274754,1274859,1274888,1274898,1274902,1274908,1274941,1275161,1275304,1275307,1275470,1275472,1275474,1275506,1275528,1275535,1275540,1275687,1275696,1275784,1275798,1275827,1275867,1275886,1275905,1275985,1276006,1276350,1276395,1276665,1276931,1277073,1277285,1277391,1277408,1277523,1277553,1277561,1277571,1277813,1277837,1277901,1277908,1278088,1278233,1278236,1278253,1278294,1279422,1279487,1279813,CVE-2023-53109,CVE-2024-57841,CVE-2026-23451,CVE-2026-31502,CVE-2026-43456,CVE-2026-43502,CVE-2026-45968,CVE-2026 -52910,CVE-2026-52912,CVE-2026-52929,CVE-2026-52977,CVE-2026-53059,CVE-2026-53163,CVE-2026-53260,CVE-2026-53264,CVE-2026-53381,CVE-2026-53388,CVE-2026-63801,CVE-2026-63823,CVE-2026-63827,CVE-2026-63887,CVE-2026-63888,CVE-2026-63920,CVE-2026-63992,CVE-2026-64002,CVE-2026-64007,CVE-2026-64010,CVE-2026-64011,CVE-2026-64015,CVE-2026-64047,CVE-2026-64048,CVE-2026-64098,CVE-2026-64109,CVE-2026-64114,CVE-2026-64115,CVE-2026-64137,CVE-2026-64266,CVE-2026-64268,CVE-2026-64304,CVE-2026-64355,CVE-2026-64423,CVE-2026-64450,CVE-2026-64481,CVE-2026-64541,CVE-2026-64543,CVE-2026-64556,CVE-2026-64562,CVE-2026-64563,CVE-2026-64572,CVE-2026-64581,CVE-2026-64593,CVE-2026-68121,CVE-2026-68136,CVE-2026-68138,CVE-2026-68155,CVE-2026-68158,CVE-2026-68159,CVE-2026-68160,CVE-2026-68202,CVE-2026-68397,CVE-2026-68398,CVE-2026-68417,CVE-2026-68426,CVE-2026-68480,CVE-2026-72020,CVE-2026-72069,CVE-2026-72083,CVE-2026-72084,CVE-2026-72123,CVE-2026-72135,CVE-2026-72164,CVE-2026-72251,CVE-2026-72288,CVE-2026-72289, CVE-2026-72323,CVE-2026-72339,CVE-2026-72389,CVE-2026-74345,CVE-2026-74377,CVE-2026-74378,CVE-2026-74388,CVE-2026-74390,CVE-2026-74394,CVE-2026-74406,CVE-2026-74454,CVE-2026-74488,CVE-2026-74496,CVE-2026-74518,CVE-2026-74537,CVE-2026-74556,CVE-2026-74582,CVE-2026-74615,CVE-2026-74616,CVE-2026-74669,CVE-2026-74695,CVE-2026-74743,CVE-2026-80580,CVE-2026-80714,CVE-2026-80716,CVE-2026-80737,CVE-2026-80909 The SUSE Linux Enterprise 15 SP4 kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2023-53109: net: tunnels: annotate lockless accesses to dev->needed_headroom (bsc#1242405 bsc#1275784). - CVE-2024-57841: net: fix memory leak in tcp_conn_request() (bsc#1235944). - CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731). - CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). - CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). - CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). - CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). - CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). - CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period (bsc#1268659). - CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000). - CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). - CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). - CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). - CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). - CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). - CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). - CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). - CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). - CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). - CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). - CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). - CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). - CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). - CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). - CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). - CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). - CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). - CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). - CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). - CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). - CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). - CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). - CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). - CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). - CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). - CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). - CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). - CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). - CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). - CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). - CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). - CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). - CVE-2026-64556: perf/core: Detach event groups during remove_on_exec (bsc#1273251). - CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). - CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). - CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). - CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). - CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). - CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). - CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). - CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). - CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). - CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). - CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). - CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). - CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). - CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). - CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). - CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). - CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). - CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). - CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). - CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). - CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). - CVE-2026-72084: scsi: target: core: Generate correct identifiers for PR OUT transport IDs (bsc#1275540). - CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). - CVE-2026-72135: tpm: Make the TPM character devices non-seekable (bsc#1277571). - CVE-2026-72164: ocfs2: avoid moving extents to occupied clusters (bsc#1277553). - CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). - CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). - CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). - CVE-2026-72323: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (bsc#1275985). - CVE-2026-72339: qede: fix off-by-one in BD ring consumption on build_skb failure (bsc#1276006). - CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). - CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). - CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236). - CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233). - CVE-2026-74388: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data (bsc#1278253). - CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (bsc#1278088). - CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). - CVE-2026-74406: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() (bsc#1276395). - CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). - CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). - CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). - CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). - CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). - CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). - CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). - CVE-2026-74615: vxlan: do not arm the ageing timer on a device that is down (bsc#1277901). - CVE-2026-74616: xdp: reject clones that overrun skb_shared_info tailroom (bsc#1277813). - CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). - CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). - CVE-2026-74743: macvlan: inherit needed_headroom and needed_tailroom from lowerdev (bsc#1277908). - CVE-2026-80580: fbdev: bound mode sysfs output to the sysfs buffer (bsc#1278294). - CVE-2026-80714: ipvs: do not propagate one-packet flag to synced conns (bsc#1277561). - CVE-2026-80716: ALSA: pcm: wake linked drain waiters on unlink (bsc#1277837). - CVE-2026-80737: serial: amba-pl011: synchronize DMA teardown (bsc#1279487). - CVE-2026-80909: drm/amdgpu: Reject UVD message with invalid number of h265 refs (bsc#1279422). The following non security issues were fixed: - mkspec-dtb: Move DTS prefix into package list. - mkspec-dtb: Move provides-obsoletes to package list. - mkspec-dtb: Put per-architecture package lists into a hash. - mkspec-dtb: re-indent. - net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). - perf: Reject exited events as group leaders (git-fixes). - powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). - RDMA/siw: Introduce siw_cep_set_free_and_put (git-fixes). - RDMA/siw: Introduce siw_destroy_cep_sock (git-fixes). - RDMA/siw: Introduce siw_free_cm_id (git-fixes). - RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp (git-fixes). - smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). - smb: client: require net admin for CIFS SWN netlink (bsc#1273966). The following package changes have been done: - kernel-default-5.14.21-150400.24.240.2 updated From sle-container-updates at lists.suse.com Wed Sep 23 07:19:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 09:19:54 +0200 (CEST) Subject: SUSE-IU-2026:7278-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260923071954.C1E0AFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7278-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.256 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.256 Severity : moderate Type : security References : 1259176 1261413 1266435 1266437 1266438 1266439 1266440 1266441 1266442 1266814 1266815 1267542 1272206 CVE-2026-15588 CVE-2026-34303 CVE-2026-3494 CVE-2026-35549 CVE-2026-44168 CVE-2026-44169 CVE-2026-44170 CVE-2026-44171 CVE-2026-44172 CVE-2026-44173 CVE-2026-48163 CVE-2026-48165 CVE-2026-49261 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 913 Released: Tue Sep 22 14:42:27 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1259176,1261413,1266435,1266437,1266438,1266439,1266440,1266441,1266442,1266814,1266815,1267542,1272206,CVE-2026-15588,CVE-2026-34303,CVE-2026-3494,CVE-2026-35549,CVE-2026-44168,CVE-2026-44169,CVE-2026-44170,CVE-2026-44171,CVE-2026-44172,CVE-2026-44173,CVE-2026-48163,CVE-2026-48165,CVE-2026-49261 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - SL-Micro-release-6.0-25.135 updated - libglib-2_0-0-2.76.2-14.1 updated - libgobject-2_0-0-2.76.2-14.1 updated - libgmodule-2_0-0-2.76.2-14.1 updated - libgio-2_0-0-2.76.2-14.1 updated - glib2-tools-2.76.2-14.1 updated - container:SL-Micro-base-container-2.1.3-7.218 updated From sle-container-updates at lists.suse.com Wed Sep 23 07:22:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 09:22:40 +0200 (CEST) Subject: SUSE-IU-2026:7279-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260923072240.98B34FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7279-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.218 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.218 Severity : moderate Type : security References : 1259176 1261413 1266435 1266437 1266438 1266439 1266440 1266441 1266442 1266814 1266815 1267542 1272206 CVE-2026-15588 CVE-2026-34303 CVE-2026-3494 CVE-2026-35549 CVE-2026-44168 CVE-2026-44169 CVE-2026-44170 CVE-2026-44171 CVE-2026-44172 CVE-2026-44173 CVE-2026-48163 CVE-2026-48165 CVE-2026-49261 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 913 Released: Tue Sep 22 14:42:27 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1259176,1261413,1266435,1266437,1266438,1266439,1266440,1266441,1266442,1266814,1266815,1267542,1272206,CVE-2026-15588,CVE-2026-34303,CVE-2026-3494,CVE-2026-35549,CVE-2026-44168,CVE-2026-44169,CVE-2026-44170,CVE-2026-44171,CVE-2026-44172,CVE-2026-44173,CVE-2026-48163,CVE-2026-48165,CVE-2026-49261 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - SL-Micro-release-6.0-25.135 updated - libglib-2_0-0-2.76.2-14.1 updated - libgobject-2_0-0-2.76.2-14.1 updated - libgmodule-2_0-0-2.76.2-14.1 updated - libgio-2_0-0-2.76.2-14.1 updated - glib2-tools-2.76.2-14.1 updated - container:suse-toolbox-image-1.0.0-9.170 updated From sle-container-updates at lists.suse.com Wed Sep 23 07:25:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 09:25:37 +0200 (CEST) Subject: SUSE-IU-2026:7280-1: Security update of suse/sl-micro/6.0/kvm-os-container Message-ID: <20260923072537.5A40AFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7280-1 Image Tags : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.227 , suse/sl-micro/6.0/kvm-os-container:latest Image Release : 6.227 Severity : moderate Type : security References : 1259176 1261413 1266435 1266437 1266438 1266439 1266440 1266441 1266442 1266814 1266815 1267542 1272206 CVE-2026-15588 CVE-2026-34303 CVE-2026-3494 CVE-2026-35549 CVE-2026-44168 CVE-2026-44169 CVE-2026-44170 CVE-2026-44171 CVE-2026-44172 CVE-2026-44173 CVE-2026-48163 CVE-2026-48165 CVE-2026-49261 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 913 Released: Tue Sep 22 14:42:27 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1259176,1261413,1266435,1266437,1266438,1266439,1266440,1266441,1266442,1266814,1266815,1267542,1272206,CVE-2026-15588,CVE-2026-34303,CVE-2026-3494,CVE-2026-35549,CVE-2026-44168,CVE-2026-44169,CVE-2026-44170,CVE-2026-44171,CVE-2026-44172,CVE-2026-44173,CVE-2026-48163,CVE-2026-48165,CVE-2026-49261 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - SL-Micro-release-6.0-25.135 updated - libglib-2_0-0-2.76.2-14.1 updated - libgobject-2_0-0-2.76.2-14.1 updated - libgmodule-2_0-0-2.76.2-14.1 updated - libgio-2_0-0-2.76.2-14.1 updated - glib2-tools-2.76.2-14.1 updated - container:SL-Micro-base-container-2.1.3-7.218 updated From sle-container-updates at lists.suse.com Wed Sep 23 07:28:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 09:28:52 +0200 (CEST) Subject: SUSE-IU-2026:7281-1: Security update of suse/sl-micro/6.0/rt-os-container Message-ID: <20260923072852.36A4AFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7281-1 Image Tags : suse/sl-micro/6.0/rt-os-container:2.1.3 , suse/sl-micro/6.0/rt-os-container:2.1.3-7.247 , suse/sl-micro/6.0/rt-os-container:latest Image Release : 7.247 Severity : moderate Type : security References : 1259176 1261413 1266435 1266437 1266438 1266439 1266440 1266441 1266442 1266814 1266815 1267542 1272206 CVE-2026-15588 CVE-2026-34303 CVE-2026-3494 CVE-2026-35549 CVE-2026-44168 CVE-2026-44169 CVE-2026-44170 CVE-2026-44171 CVE-2026-44172 CVE-2026-44173 CVE-2026-48163 CVE-2026-48165 CVE-2026-49261 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 913 Released: Tue Sep 22 14:42:27 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1259176,1261413,1266435,1266437,1266438,1266439,1266440,1266441,1266442,1266814,1266815,1267542,1272206,CVE-2026-15588,CVE-2026-34303,CVE-2026-3494,CVE-2026-35549,CVE-2026-44168,CVE-2026-44169,CVE-2026-44170,CVE-2026-44171,CVE-2026-44172,CVE-2026-44173,CVE-2026-48163,CVE-2026-48165,CVE-2026-49261 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - SL-Micro-release-6.0-25.135 updated - libglib-2_0-0-2.76.2-14.1 updated - libgobject-2_0-0-2.76.2-14.1 updated - libgmodule-2_0-0-2.76.2-14.1 updated - libgio-2_0-0-2.76.2-14.1 updated - glib2-tools-2.76.2-14.1 updated - container:SL-Micro-container-2.1.3-6.256 updated From sle-container-updates at lists.suse.com Wed Sep 23 07:38:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 09:38:44 +0200 (CEST) Subject: SUSE-CU-2026:11111-1: Security update of suse/sl-micro/6.0/toolbox Message-ID: <20260923073844.AEFD7FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11111-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.170 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.170 Severity : moderate Type : security References : 1259176 1261413 1266435 1266437 1266438 1266439 1266440 1266441 1266442 1266814 1266815 1267542 1272206 CVE-2026-15588 CVE-2026-34303 CVE-2026-3494 CVE-2026-35549 CVE-2026-44168 CVE-2026-44169 CVE-2026-44170 CVE-2026-44171 CVE-2026-44172 CVE-2026-44173 CVE-2026-48163 CVE-2026-48165 CVE-2026-49261 ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 913 Released: Tue Sep 22 14:42:27 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1259176,1261413,1266435,1266437,1266438,1266439,1266440,1266441,1266442,1266814,1266815,1267542,1272206,CVE-2026-15588,CVE-2026-34303,CVE-2026-3494,CVE-2026-35549,CVE-2026-44168,CVE-2026-44169,CVE-2026-44170,CVE-2026-44171,CVE-2026-44172,CVE-2026-44173,CVE-2026-48163,CVE-2026-48165,CVE-2026-49261 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - SL-Micro-release-6.0-25.135 updated - libglib-2_0-0-2.76.2-14.1 updated - libgmodule-2_0-0-2.76.2-14.1 updated - skelcd-EULA-SL-Micro-2024.01.19-8.134 updated From sle-container-updates at lists.suse.com Wed Sep 23 07:43:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 09:43:52 +0200 (CEST) Subject: SUSE-IU-2026:7283-1: Security update of suse/sl-micro/6.1/base-os-container Message-ID: <20260923074352.63643FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7283-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.194 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.194 Severity : moderate Type : security References : 1117217 1235517 1235834 1247812 1257934 1258251 1262487 1265001 1265002 1265003 1265004 1265006 1267212 1272206 CVE-2026-15588 CVE-2026-2291 CVE-2026-4890 CVE-2026-4891 CVE-2026-4892 CVE-2026-4893 CVE-2026-5172 CVE-2026-6507 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 742 Released: Tue Sep 22 13:56:40 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1117217,1235517,1235834,1247812,1257934,1258251,1262487,1265001,1265002,1265003,1265004,1265006,1267212,1272206,CVE-2026-15588,CVE-2026-2291,CVE-2026-4890,CVE-2026-4891,CVE-2026-4892,CVE-2026-4893,CVE-2026-5172,CVE-2026-6507 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - SL-Micro-release-6.1-slfo.1.12.78 updated - libglib-2_0-0-2.78.6-slfo.1.1_8.1 updated - libgobject-2_0-0-2.78.6-slfo.1.1_8.1 updated - libgmodule-2_0-0-2.78.6-slfo.1.1_8.1 updated - libgio-2_0-0-2.78.6-slfo.1.1_8.1 updated - glib2-tools-2.78.6-slfo.1.1_8.1 updated - container:suse-toolbox-image-1.0.0-5.109 updated From sle-container-updates at lists.suse.com Wed Sep 23 07:46:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 09:46:40 +0200 (CEST) Subject: SUSE-IU-2026:7284-1: Security update of suse/sl-micro/6.1/kvm-os-container Message-ID: <20260923074640.B941AFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7284-1 Image Tags : suse/sl-micro/6.1/kvm-os-container:2.2.1 , suse/sl-micro/6.1/kvm-os-container:2.2.1-5.196 , suse/sl-micro/6.1/kvm-os-container:latest Image Release : 5.196 Severity : moderate Type : security References : 1117217 1235517 1235834 1247812 1257934 1258251 1262487 1265001 1265002 1265003 1265004 1265006 1267212 1272206 CVE-2026-15588 CVE-2026-2291 CVE-2026-4890 CVE-2026-4891 CVE-2026-4892 CVE-2026-4893 CVE-2026-5172 CVE-2026-6507 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 742 Released: Tue Sep 22 13:56:40 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1117217,1235517,1235834,1247812,1257934,1258251,1262487,1265001,1265002,1265003,1265004,1265006,1267212,1272206,CVE-2026-15588,CVE-2026-2291,CVE-2026-4890,CVE-2026-4891,CVE-2026-4892,CVE-2026-4893,CVE-2026-5172,CVE-2026-6507 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - SL-Micro-release-6.1-slfo.1.12.78 updated - libglib-2_0-0-2.78.6-slfo.1.1_8.1 updated - libgobject-2_0-0-2.78.6-slfo.1.1_8.1 updated - libgmodule-2_0-0-2.78.6-slfo.1.1_8.1 updated - libgio-2_0-0-2.78.6-slfo.1.1_8.1 updated - glib2-tools-2.78.6-slfo.1.1_8.1 updated - container:SL-Micro-base-container-2.2.1-5.194 updated From sle-container-updates at lists.suse.com Wed Sep 23 07:49:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 09:49:45 +0200 (CEST) Subject: SUSE-IU-2026:7285-1: Security update of suse/sl-micro/6.1/rt-os-container Message-ID: <20260923074945.6ECA7FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7285-1 Image Tags : suse/sl-micro/6.1/rt-os-container:2.2.1 , suse/sl-micro/6.1/rt-os-container:2.2.1-5.191 , suse/sl-micro/6.1/rt-os-container:latest Image Release : 5.191 Severity : moderate Type : security References : 1117217 1235517 1235834 1247812 1257934 1258251 1262487 1265001 1265002 1265003 1265004 1265006 1267212 1272206 CVE-2026-15588 CVE-2026-2291 CVE-2026-4890 CVE-2026-4891 CVE-2026-4892 CVE-2026-4893 CVE-2026-5172 CVE-2026-6507 ----------------------------------------------------------------- The container suse/sl-micro/6.1/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 742 Released: Tue Sep 22 13:56:40 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1117217,1235517,1235834,1247812,1257934,1258251,1262487,1265001,1265002,1265003,1265004,1265006,1267212,1272206,CVE-2026-15588,CVE-2026-2291,CVE-2026-4890,CVE-2026-4891,CVE-2026-4892,CVE-2026-4893,CVE-2026-5172,CVE-2026-6507 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - SL-Micro-release-6.1-slfo.1.12.78 updated - libglib-2_0-0-2.78.6-slfo.1.1_8.1 updated - libgobject-2_0-0-2.78.6-slfo.1.1_8.1 updated - libgmodule-2_0-0-2.78.6-slfo.1.1_8.1 updated - libgio-2_0-0-2.78.6-slfo.1.1_8.1 updated - glib2-tools-2.78.6-slfo.1.1_8.1 updated - container:SL-Micro-container-2.2.1-7.181 updated From sle-container-updates at lists.suse.com Wed Sep 23 08:02:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 10:02:48 +0200 (CEST) Subject: SUSE-IU-2026:7287-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260923080248.51763FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7287-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.150 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.150 Severity : important Type : security References : 1261606 1268886 1269583 1270219 1275441 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libuuid1-2.41.1-160000.5.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - liblastlog2-2-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - util-linux-systemd-2.41.1-160000.5.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-b418d673df310746ae418b83e1018dbff86b101a3ce3219953a070a6b628fe18-0 updated From sle-container-updates at lists.suse.com Wed Sep 23 08:12:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 10:12:39 +0200 (CEST) Subject: SUSE-IU-2026:7294-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260923081239.461C8FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7294-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.80 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.80 Severity : important Type : security References : 1261606 1268886 1269583 1270219 1275441 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libuuid1-2.41.1-160000.5.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - liblastlog2-2-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - util-linux-systemd-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Wed Sep 23 08:45:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 10:45:38 +0200 (CEST) Subject: SUSE-CU-2026:11116-1: Security update of suse/kiosk/firefox-esr Message-ID: <20260923084538.5D2DAFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11116-1 Container Tags : suse/kiosk/firefox-esr:153.3 , suse/kiosk/firefox-esr:153.3-75.42 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.42 Severity : moderate Type : security References : 1279945 CVE-2026-87875 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4281-1 Released: Tue Sep 22 10:32:46 2026 Summary: Security update for cups Type: security Severity: moderate References: 1279945,CVE-2026-87875 This update for cups fixes the following issue: - CVE-2026-87875,GHSA-559w-7676-3xrq: heap out-of-bounds read in `cupsUTF32ToUTF8()` due to missing source-length bound can be reached via the SNMP supply-description parsing (bsc#1279945). The following package changes have been done: - cups-config-2.2.7-150000.3.96.1 updated - libcups2-2.2.7-150000.3.96.1 updated From sle-container-updates at lists.suse.com Wed Sep 23 08:47:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 10:47:14 +0200 (CEST) Subject: SUSE-CU-2026:11118-1: Security update of bci/php-apache Message-ID: <20260923084714.BB6ADFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/php-apache ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11118-1 Container Tags : bci/php-apache:8 , bci/php-apache:8-sles15 , bci/php-apache:8.3.33 , bci/php-apache:8.3.33-28.2 , bci/php-apache:latest Container Release : 28.2 Severity : moderate Type : security References : 1279898 1280019 CVE-2026-45793 CVE-2026-59944 CVE-2026-59947 ----------------------------------------------------------------- The container bci/php-apache was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4288-1 Released: Tue Sep 22 18:09:47 2026 Summary: Security update for php-composer2 Type: security Severity: moderate References: 1279898,1280019,CVE-2026-45793,CVE-2026-59944,CVE-2026-59947 This update for php-composer2 fixes the following issues: - CVE-2026-59944: path traversal and link following issue can make files world readable and executable (bsc#1279898). The following package changes have been done: - php-composer2-2.6.4-150600.3.23.1 updated From sle-container-updates at lists.suse.com Wed Sep 23 08:48:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 10:48:42 +0200 (CEST) Subject: SUSE-CU-2026:11120-1: Security update of bci/php-fpm Message-ID: <20260923084842.06D85FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/php-fpm ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11120-1 Container Tags : bci/php-fpm:8 , bci/php-fpm:8-sles15 , bci/php-fpm:8.3.33 , bci/php-fpm:8.3.33-28.2 , bci/php-fpm:latest Container Release : 28.2 Severity : moderate Type : security References : 1279898 1280019 CVE-2026-45793 CVE-2026-59944 CVE-2026-59947 ----------------------------------------------------------------- The container bci/php-fpm was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4288-1 Released: Tue Sep 22 18:09:47 2026 Summary: Security update for php-composer2 Type: security Severity: moderate References: 1279898,1280019,CVE-2026-45793,CVE-2026-59944,CVE-2026-59947 This update for php-composer2 fixes the following issues: - CVE-2026-59944: path traversal and link following issue can make files world readable and executable (bsc#1279898). The following package changes have been done: - php-composer2-2.6.4-150600.3.23.1 updated From sle-container-updates at lists.suse.com Wed Sep 23 08:50:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 10:50:07 +0200 (CEST) Subject: SUSE-CU-2026:11122-1: Security update of bci/php Message-ID: <20260923085007.BE404FF19@maintenance.suse.de> SUSE Container Update Advisory: bci/php ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11122-1 Container Tags : bci/php:8 , bci/php:8-sles15 , bci/php:8.3.33 , bci/php:8.3.33-28.2 , bci/php:latest Container Release : 28.2 Severity : moderate Type : security References : 1279898 1280019 CVE-2026-45793 CVE-2026-59944 CVE-2026-59947 ----------------------------------------------------------------- The container bci/php was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4288-1 Released: Tue Sep 22 18:09:47 2026 Summary: Security update for php-composer2 Type: security Severity: moderate References: 1279898,1280019,CVE-2026-45793,CVE-2026-59944,CVE-2026-59947 This update for php-composer2 fixes the following issues: - CVE-2026-59944: path traversal and link following issue can make files world readable and executable (bsc#1279898). The following package changes have been done: - php-composer2-2.6.4-150600.3.23.1 updated From sle-container-updates at lists.suse.com Wed Sep 23 08:54:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 10:54:04 +0200 (CEST) Subject: SUSE-CU-2026:11123-1: Security update of suse/samba-server Message-ID: <20260923085404.303CAFF17@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11123-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-76.35 , suse/samba-server:latest Container Release : 76.35 Severity : moderate Type : security References : 1279945 CVE-2026-87875 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4281-1 Released: Tue Sep 22 10:32:46 2026 Summary: Security update for cups Type: security Severity: moderate References: 1279945,CVE-2026-87875 This update for cups fixes the following issue: - CVE-2026-87875,GHSA-559w-7676-3xrq: heap out-of-bounds read in `cupsUTF32ToUTF8()` due to missing source-length bound can be reached via the SNMP supply-description parsing (bsc#1279945). The following package changes have been done: - cups-config-2.2.7-150000.3.96.1 updated - libcups2-2.2.7-150000.3.96.1 updated From sle-container-updates at lists.suse.com Wed Sep 23 08:55:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 10:55:07 +0200 (CEST) Subject: SUSE-CU-2026:11124-1: Security update of suse/kiosk/xorg-client Message-ID: <20260923085507.77CF2FF17@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11124-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-81.4 , suse/kiosk/xorg-client:latest Container Release : 81.4 Severity : moderate Type : security References : 1279945 CVE-2026-87875 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4281-1 Released: Tue Sep 22 10:32:46 2026 Summary: Security update for cups Type: security Severity: moderate References: 1279945,CVE-2026-87875 This update for cups fixes the following issue: - CVE-2026-87875,GHSA-559w-7676-3xrq: heap out-of-bounds read in `cupsUTF32ToUTF8()` due to missing source-length bound can be reached via the SNMP supply-description parsing (bsc#1279945). The following package changes have been done: - cups-config-2.2.7-150000.3.96.1 updated - libcups2-2.2.7-150000.3.96.1 updated From sle-container-updates at lists.suse.com Wed Sep 23 09:08:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 11:08:29 +0200 (CEST) Subject: SUSE-CU-2026:11149-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260923090829.776D4FF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11149-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.125 , suse/sles/16.0/toolbox:latest Container Release : 1.125 Severity : important Type : security References : 1261606 1268886 1269583 1270219 1275441 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libuuid1-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Thu Sep 24 07:10:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 09:10:41 +0200 (CEST) Subject: SUSE-IU-2026:7349-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260924071041.D26E9FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7349-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.154 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.154 Severity : important Type : security References : 1275441 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1279893 1280049 1280050 1280051 1280052 1280053 1280054 CVE-2026-72693 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1747 Released: Wed Sep 23 21:42:24 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). - CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049). ----------------------------------------------------------------- Advisory ID: 1748 Released: Wed Sep 23 21:47:23 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - libpcre2-8-0-10.45-160000.4.1 updated - libkbdfile1-2.7.1-160000.3.1 updated - libkfont0-2.7.1-160000.3.1 updated - libkeymap1-2.7.1-160000.3.1 updated - kbd-2.7.1-160000.3.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-d5e468d857bf796d6c1c90b974b063bc5ad18c5f752409bf959ab26344f6b1d6-0 updated From sle-container-updates at lists.suse.com Thu Sep 24 07:15:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 09:15:46 +0200 (CEST) Subject: SUSE-IU-2026:7350-1: Security update of suse/sl-micro/6.2/baremetal-iso-image Message-ID: <20260924071546.E0127FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-iso-image ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7350-1 Image Tags : suse/sl-micro/6.2/baremetal-iso-image:2.3.1 , suse/sl-micro/6.2/baremetal-iso-image:2.3.1-8.139 , suse/sl-micro/6.2/baremetal-iso-image:latest Image Release : 8.139 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1279893 1280049 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1747 Released: Wed Sep 23 21:42:24 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). - CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049). The following package changes have been done: - libpcre2-8-0-10.45-160000.4.1 updated From sle-container-updates at lists.suse.com Thu Sep 24 07:19:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 09:19:19 +0200 (CEST) Subject: SUSE-IU-2026:7354-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260924071919.C507FFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7354-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.82 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.82 Severity : important Type : security References : 1275441 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1279893 1280049 1280050 1280051 1280052 1280053 1280054 CVE-2026-72693 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1747 Released: Wed Sep 23 21:42:24 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). - CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049). ----------------------------------------------------------------- Advisory ID: 1748 Released: Wed Sep 23 21:47:23 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - libpcre2-8-0-10.45-160000.4.1 updated - libkbdfile1-2.7.1-160000.3.1 updated - libkfont0-2.7.1-160000.3.1 updated - libkeymap1-2.7.1-160000.3.1 updated - kbd-2.7.1-160000.3.1 updated From sle-container-updates at lists.suse.com Thu Sep 24 07:24:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 09:24:07 +0200 (CEST) Subject: SUSE-IU-2026:7355-1: Security update of suse/sl-micro/6.2/base-iso-image Message-ID: <20260924072407.CF869FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-iso-image ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7355-1 Image Tags : suse/sl-micro/6.2/base-iso-image:2.3.1 , suse/sl-micro/6.2/base-iso-image:2.3.1-8.73 , suse/sl-micro/6.2/base-iso-image:latest Image Release : 8.73 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1279893 1280049 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1747 Released: Wed Sep 23 21:42:24 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). - CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049). The following package changes have been done: - libpcre2-8-0-10.45-160000.4.1 updated From sle-container-updates at lists.suse.com Thu Sep 24 07:27:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 09:27:04 +0200 (CEST) Subject: SUSE-IU-2026:7359-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260924072704.846D8FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7359-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.140 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.140 Severity : important Type : security References : 1275441 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1279893 1280049 1280050 1280051 1280052 1280053 1280054 CVE-2026-72693 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1747 Released: Wed Sep 23 21:42:24 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). - CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049). ----------------------------------------------------------------- Advisory ID: 1748 Released: Wed Sep 23 21:47:23 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - libpcre2-8-0-10.45-160000.4.1 updated - libkbdfile1-2.7.1-160000.3.1 updated - libkfont0-2.7.1-160000.3.1 updated - libkeymap1-2.7.1-160000.3.1 updated - kbd-2.7.1-160000.3.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-d5e468d857bf796d6c1c90b974b063bc5ad18c5f752409bf959ab26344f6b1d6-0 updated From sle-container-updates at lists.suse.com Thu Sep 24 07:31:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 09:31:02 +0200 (CEST) Subject: SUSE-IU-2026:7360-1: Security update of suse/sl-micro/6.2/kvm-iso-image Message-ID: <20260924073102.1AC6AFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-iso-image ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7360-1 Image Tags : suse/sl-micro/6.2/kvm-iso-image:2.3.1 , suse/sl-micro/6.2/kvm-iso-image:2.3.1-8.123 , suse/sl-micro/6.2/kvm-iso-image:latest Image Release : 8.123 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1279893 1280049 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1747 Released: Wed Sep 23 21:42:24 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). - CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049). The following package changes have been done: - libpcre2-8-0-10.45-160000.4.1 updated From sle-container-updates at lists.suse.com Thu Sep 24 07:41:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 09:41:33 +0200 (CEST) Subject: SUSE-IU-2026:7366-1: Security update of suse/sl-micro/6.2/rt-iso-image Message-ID: <20260924074133.802E7FF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-iso-image ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7366-1 Image Tags : suse/sl-micro/6.2/rt-iso-image:2.3.1 , suse/sl-micro/6.2/rt-iso-image:2.3.1-7.155 , suse/sl-micro/6.2/rt-iso-image:latest Image Release : 7.155 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1279893 1280049 1280050 1280051 1280052 1280053 1280054 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1747 Released: Wed Sep 23 21:42:24 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). - CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049). The following package changes have been done: - libpcre2-8-0-10.45-160000.4.1 updated From sle-container-updates at lists.suse.com Thu Sep 24 08:02:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 10:02:13 +0200 (CEST) Subject: SUSE-CU-2026:11154-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260924080213.5E90EFF19@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11154-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.126 , suse/sles/16.0/toolbox:latest Container Release : 1.126 Severity : important Type : security References : 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1279584 1279588 1279593 1279595 1279782 1279783 1279784 1279893 1280049 1280050 1280051 1280052 1280053 1280054 CVE-2026-0799 CVE-2026-18238 CVE-2026-18313 CVE-2026-31911 CVE-2026-31912 CVE-2026-6244 CVE-2026-6554 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1747 Released: Wed Sep 23 21:42:24 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). - CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049). ----------------------------------------------------------------- Advisory ID: 1749 Released: Wed Sep 23 21:44:23 2026 Summary: Security update for libpcap Type: security Severity: important References: 1279584,1279588,1279593,1279595,1279782,1279783,1279784,CVE-2026-0799,CVE-2026-18238,CVE-2026-18313,CVE-2026-31911,CVE-2026-31912,CVE-2026-6244,CVE-2026-6554 This update for libpcap fixes the following issues: - CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). - CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). - CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). - CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). - CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ` message received from the client and never frees the memory (bsc#1279784). - CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). - CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). The following package changes have been done: - libpcap1-1.10.5-160000.5.1 updated - libpcre2-8-0-10.45-160000.4.1 updated From sle-container-updates at lists.suse.com Thu Sep 24 08:05:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 10:05:23 +0200 (CEST) Subject: SUSE-CU-2026:11156-1: Recommended update of trento/mcp-server-trento Message-ID: <20260924080523.35D8DFF19@maintenance.suse.de> SUSE Container Update Advisory: trento/mcp-server-trento ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11156-1 Container Tags : trento/mcp-server-trento:1.1.2 , trento/mcp-server-trento:1.1.2-build1.12.1 , trento/mcp-server-trento:latest Container Release : 1.12.1 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container trento/mcp-server-trento was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4289-1 Released: Wed Sep 23 07:34:08 2026 Summary: Recommended update for Trento Type: recommended Severity: moderate References: This update for Trento fixes the following issues: ansible-trento was updated to version 1.0.1: - Changes and Bugs Fixed: * Added the option to change the monitoring network port * Allowed the support utility tool to be installed on SUSE Linux Enterprise Server 15 SP4 * Added password protection to the monitoring data receiver * Fixed folder permissions settings to prevent access issues * Fixed a startup crash by creating temporary system files before the monitoring service starts - New Features: * Enabled a backup network port for monitoring on SUSE Linux Enterprise Server 16 * Added the ability to adjust logging levels for the web interface and backend services * Added a diagnostic support tool plugin for the server * Allowed the web routing system to automatically find the monitoring service location * Added secure connection support (SSL/TLS encryption) to the monitoring service * Enabled configuration support for the telemetry data collector (Alloy) * Shared secure server certificates with monitoring agents * Automatically installed required background tools on monitoring agents * Added a configuration switch to turn the monitoring data receiver on or off - Dependency updates: * Bumped the common-workflows group with 3 updates * Bumped ansible/ansible-lint from 26.4.0 to 26.6.0 * Bumped actions/checkout from 6.0.3 to 7.0.1 * Bumped actions/checkout from 6.0.2 to 6.0.3 * Bumped dawidd6/action-ansible-playbook from 2.8.0 to 9 * Bumped ansible/ansible-lint from 25.12.2 to 26.4.0 * Bumped the common-workflows group across 1 directory with 3 updates **Full Changelog**: https://github.com/trento-project/ansible/compare/1.0.0...1.0.1 mcp-server-trento was updated to version 1.1.2: - Changes and Bugs Fixed: * Fixed a crash caused by incorrectly handling lists of settings - Dependency updates: * Bumped github.com/getkin/kin-openapi from 0.146.0 to 0.147.0 * Bumped github.com/stretchr/testify from 1.12.0 to 1.12.1 * Bumped the common-workflows group with 3 updates * Bumped github.com/getkin/kin-openapi from 0.145.0 to 0.146.0 * Bumped github.com/stretchr/testify from 1.11.1 to 1.12.0 * Bumped actions/setup-go from 6.5.0 to 7.0.0 * Bumped actions/checkout from 7.0.0 to 7.0.1 * Removed go patch version in go.mod * Updated dependencies * Bumped github.com/getkin/kin-openapi from 0.140.0 to 0.142.0 * Bumped actions/checkout from 6.0.3 to 7.0.0 * Bumped awalsh128/cache-apt-pkgs-action from 1.6.2 to 1.6.3 * Bumped golangci/golangci-lint-action from 9.2.1 to 9.3.0 * Bumped actions/cache from 5.0.5 to 6.1.0 * Bumped actions/setup-go from 6.4.0 to 6.5.0 * Bumped awalsh128/cache-apt-pkgs-action from 1.6.0 to 1.6.2 * Bumped github.com/getkin/kin-openapi from 0.137.0 to 0.140.0 * Bumped actions/checkout from 6.0.2 to 6.0.3 * Bumped endorama/asdf-parse-tool-versions from 1.5.1 to 1.6.0 * Bumped golangci/golangci-lint-action from 9.2.0 to 9.2.1 * Bumped github.com/modelcontextprotocol/go-sdk from 1.6.0 to 1.6.1 * Bumped github.com/modelcontextprotocol/go-sdk from 1.5.0 to 1.6.0 **Full Changelog**: https://github.com/trento-project/mcp-server/compare/1.1.0...1.1.2 trento-agent was updated to version 3.1.3: - Changes and Bugs Fixed: * Fixed a parsing error when reading colorful outputs from the SAP tuning tool (saptune) * Fixed a memory leak issue to improve system stability and performance * Fixed log messages not displaying correctly during startup * Improved the SAP system profile reader to support different configurations - Dependency updates: * Bumped golang.org/x/mod from 0.38.0 to 0.40.0 * Bumped google.golang.org/grpc from 1.83.1 to 1.83.2 in the go_modules group across 1 directory * Bumped github.com/rabbitmq/amqp091-go from 1.12.0 to 1.13.0 in the go_modules group across 1 directory * Bumped google.golang.org/grpc from 1.82.1 to 1.83.1 in the go_modules group across 1 directory * Bumped golang.org/x/text from v0.38.0 to v0.39.0 * Bumped golang.org/x/mod from 0.37.0 to 0.38.0 * Bumped google.golang.org/grpc from 1.79.3 to 1.82.1 in the go_modules group across 1 directory * Bumped golang.org/x/sync from 0.21.0 to 0.22.0 * Bumped golangci/golangci-lint-action from 9.2.1 to 9.3.0 * Bumped github.com/prometheus-community/pro-bing from 0.9.0 to 0.9.1 **Full Changelog**: https://github.com/trento-project/agent/compare/3.1.2...3.1.3 trento-checks was updated to version 1.3.2: - Changes and Bugs Fixed: * Update documentation links in checks: SAPHanaSR-angi * Fixed metadata typo: hana-scale_out to hana_scale_out **Full Changelog**: https://github.com/trento-project/checks/compare/1.3.1...1.3.2 trento-server-helm was updated to version 2.1.1: - Changes and Bugs Fixed: * Added a configuration option to choose between IPv4 and IPv6 network protocols * Improved how excluded check rules are handled during system evaluations - New Features: * Added the ability to change logging detail levels while the application is running * Fixed an installation error where background software packages clashed with each other - Dependency updates: * Bumped ecto from 3.14.1 to 3.14.2 * Bumped httpoison from 2.2.3 to 2.3.0 * Bumped phoenix from 1.7.23 to 1.8.11 * Bumped plug_cowboy from 2.8.1 to 2.9.0 * Bumped ecto from 3.14.0 to 3.14.1 * Bumped postgrex from 0.22.2 to 0.22.3 * Bumped yaml_elixir from 2.12.1 to 2.12.2 * Bumped erlef/setup-beam from 1.24.0 to 1.24.1 **Full Changelog**: https://github.com/trento-project/wanda/compare/2.1.0...2.1.1 trento-wanda was updated to version 2.1.1: - Changes and Bugs Fixed: * Added a configuration option to choose between IPv4 and IPv6 network protocols * Improved how excluded check rules are handled during system evaluations * Added the ability to change logging detail levels while the application is running * Fixed an installation error where background software packages clashed with each other - Dependency updates: * Bumped ecto from 3.14.1 to 3.14.2 * Bumped httpoison from 2.2.3 to 2.3.0 * Bumped phoenix from 1.7.23 to 1.8.11 * Bumped plug_cowboy from 2.8.1 to 2.9.0 * Bumped ecto from 3.14.0 to 3.14.1 * Bumped postgrex from 0.22.2 to 0.22.3 * Bumped yaml_elixir from 2.12.1 to 2.12.2 * Bumped erlef/setup-beam from 1.24.0 to 1.24.1 **Full Changelog**: https://github.com/trento-project/wanda/compare/2.1.0...2.1.1 trento-web was updated to version 3.1.6: - New Features: * Added a new system configuration setting for network options * Fixed an installation error where background software packages clashed with each other * Added the ability to change logging detail levels while the application is running - Changes and Bugs Fixed: * Fixed an issue where cluster check rules failed if the SAP system was not fully registered * Improved cleanup performance by deleting old system events in groups - Dependency updates: * Bumped ex_machina from 2.8.1 to 2.8.2 * Bumped browserslist from 4.28.2 to 4.28.8 in /assets * Ran npm audit * Bumped axios from 1.18.1 to 1.19.0 in /assets * Bumped prettier from 3.8.5 to 3.9.6 in /assets * Bumped pegasus from 0.2.6 to 1.0.0 * Bumped brace-expansion in /assets * Bumped phoenix from 1.7.23 to 1.7.24 * Bumped swoosh from 1.26.3 to 1.27.0 * Bumped flop from 0.25.0 to 0.26.5 * Bumped httpoison from 2.2.3 to 2.3.0 * Bumped cloak_ecto from 1.2.0 to 1.3.0 * Bumped ex_machina from 2.8.0 to 2.8.1 * Bumped tzdata from 1.1.4, gettext to 0.26 * Bumped commanded from 1.4.10 to 1.4.11 * Bumped postgrex from 0.22.2 to 0.22.3 * Bumped babel-jest from 30.3.0 to 30.4.1 in /assets * Bumped process_tree from 0.2.1 to 0.3.0 * Bumped faker from 0.18.0 to 0.19.0 * Bumped swoosh from 1.26.0 to 1.26.3 * Bumped joken from 2.5.0 to 2.6.2 * Bumped dompurify from 3.4.11 to 3.4.13 in /assets * Bumped floki from 0.38.3 to 0.38.4 * Bumped fast-uri from 3.1.2 to 3.1.5 in /assets * Bumped fast-uri from 3.1.3 to 3.1.5 in /test/e2e * Bumped postcss from 8.5.12 to 8.5.26 in /assets * Bumped nanoid in /assets * Bumped react-router from 7.15.1 to 7.18.2 * Bumped semver from 7.7.4 to 7.8.5 in /assets * Bumped tar and npm in /test/e2e * Bumped dorny/paths-filter from 4.0.1 to 4.0.2 * Bumped axios from 1.16.1 to 1.18.1 in /assets * Bumped brace-expansion from 5.0.5 to 5.0.7 in /test/e2e * Bumped erlef/setup-beam from 1.24.0 to 1.24.1 **Full Changelog**: https://github.com/trento-project/web/compare/3.1.5...3.1.6 The following package changes have been done: - mcp-server-trento-1.1.2-150300.1.12.1 updated From sle-container-updates at lists.suse.com Thu Sep 24 08:05:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 10:05:51 +0200 (CEST) Subject: SUSE-CU-2026:11158-1: Recommended update of trento/trento-wanda Message-ID: <20260924080551.263EFFF19@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-wanda ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11158-1 Container Tags : trento/trento-wanda:2.1.1 , trento/trento-wanda:2.1.1-build1.37.1 , trento/trento-wanda:latest Container Release : 1.37.1 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container trento/trento-wanda was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4289-1 Released: Wed Sep 23 07:34:08 2026 Summary: Recommended update for Trento Type: recommended Severity: moderate References: This update for Trento fixes the following issues: ansible-trento was updated to version 1.0.1: - Changes and Bugs Fixed: * Added the option to change the monitoring network port * Allowed the support utility tool to be installed on SUSE Linux Enterprise Server 15 SP4 * Added password protection to the monitoring data receiver * Fixed folder permissions settings to prevent access issues * Fixed a startup crash by creating temporary system files before the monitoring service starts - New Features: * Enabled a backup network port for monitoring on SUSE Linux Enterprise Server 16 * Added the ability to adjust logging levels for the web interface and backend services * Added a diagnostic support tool plugin for the server * Allowed the web routing system to automatically find the monitoring service location * Added secure connection support (SSL/TLS encryption) to the monitoring service * Enabled configuration support for the telemetry data collector (Alloy) * Shared secure server certificates with monitoring agents * Automatically installed required background tools on monitoring agents * Added a configuration switch to turn the monitoring data receiver on or off - Dependency updates: * Bumped the common-workflows group with 3 updates * Bumped ansible/ansible-lint from 26.4.0 to 26.6.0 * Bumped actions/checkout from 6.0.3 to 7.0.1 * Bumped actions/checkout from 6.0.2 to 6.0.3 * Bumped dawidd6/action-ansible-playbook from 2.8.0 to 9 * Bumped ansible/ansible-lint from 25.12.2 to 26.4.0 * Bumped the common-workflows group across 1 directory with 3 updates **Full Changelog**: https://github.com/trento-project/ansible/compare/1.0.0...1.0.1 mcp-server-trento was updated to version 1.1.2: - Changes and Bugs Fixed: * Fixed a crash caused by incorrectly handling lists of settings - Dependency updates: * Bumped github.com/getkin/kin-openapi from 0.146.0 to 0.147.0 * Bumped github.com/stretchr/testify from 1.12.0 to 1.12.1 * Bumped the common-workflows group with 3 updates * Bumped github.com/getkin/kin-openapi from 0.145.0 to 0.146.0 * Bumped github.com/stretchr/testify from 1.11.1 to 1.12.0 * Bumped actions/setup-go from 6.5.0 to 7.0.0 * Bumped actions/checkout from 7.0.0 to 7.0.1 * Removed go patch version in go.mod * Updated dependencies * Bumped github.com/getkin/kin-openapi from 0.140.0 to 0.142.0 * Bumped actions/checkout from 6.0.3 to 7.0.0 * Bumped awalsh128/cache-apt-pkgs-action from 1.6.2 to 1.6.3 * Bumped golangci/golangci-lint-action from 9.2.1 to 9.3.0 * Bumped actions/cache from 5.0.5 to 6.1.0 * Bumped actions/setup-go from 6.4.0 to 6.5.0 * Bumped awalsh128/cache-apt-pkgs-action from 1.6.0 to 1.6.2 * Bumped github.com/getkin/kin-openapi from 0.137.0 to 0.140.0 * Bumped actions/checkout from 6.0.2 to 6.0.3 * Bumped endorama/asdf-parse-tool-versions from 1.5.1 to 1.6.0 * Bumped golangci/golangci-lint-action from 9.2.0 to 9.2.1 * Bumped github.com/modelcontextprotocol/go-sdk from 1.6.0 to 1.6.1 * Bumped github.com/modelcontextprotocol/go-sdk from 1.5.0 to 1.6.0 **Full Changelog**: https://github.com/trento-project/mcp-server/compare/1.1.0...1.1.2 trento-agent was updated to version 3.1.3: - Changes and Bugs Fixed: * Fixed a parsing error when reading colorful outputs from the SAP tuning tool (saptune) * Fixed a memory leak issue to improve system stability and performance * Fixed log messages not displaying correctly during startup * Improved the SAP system profile reader to support different configurations - Dependency updates: * Bumped golang.org/x/mod from 0.38.0 to 0.40.0 * Bumped google.golang.org/grpc from 1.83.1 to 1.83.2 in the go_modules group across 1 directory * Bumped github.com/rabbitmq/amqp091-go from 1.12.0 to 1.13.0 in the go_modules group across 1 directory * Bumped google.golang.org/grpc from 1.82.1 to 1.83.1 in the go_modules group across 1 directory * Bumped golang.org/x/text from v0.38.0 to v0.39.0 * Bumped golang.org/x/mod from 0.37.0 to 0.38.0 * Bumped google.golang.org/grpc from 1.79.3 to 1.82.1 in the go_modules group across 1 directory * Bumped golang.org/x/sync from 0.21.0 to 0.22.0 * Bumped golangci/golangci-lint-action from 9.2.1 to 9.3.0 * Bumped github.com/prometheus-community/pro-bing from 0.9.0 to 0.9.1 **Full Changelog**: https://github.com/trento-project/agent/compare/3.1.2...3.1.3 trento-checks was updated to version 1.3.2: - Changes and Bugs Fixed: * Update documentation links in checks: SAPHanaSR-angi * Fixed metadata typo: hana-scale_out to hana_scale_out **Full Changelog**: https://github.com/trento-project/checks/compare/1.3.1...1.3.2 trento-server-helm was updated to version 2.1.1: - Changes and Bugs Fixed: * Added a configuration option to choose between IPv4 and IPv6 network protocols * Improved how excluded check rules are handled during system evaluations - New Features: * Added the ability to change logging detail levels while the application is running * Fixed an installation error where background software packages clashed with each other - Dependency updates: * Bumped ecto from 3.14.1 to 3.14.2 * Bumped httpoison from 2.2.3 to 2.3.0 * Bumped phoenix from 1.7.23 to 1.8.11 * Bumped plug_cowboy from 2.8.1 to 2.9.0 * Bumped ecto from 3.14.0 to 3.14.1 * Bumped postgrex from 0.22.2 to 0.22.3 * Bumped yaml_elixir from 2.12.1 to 2.12.2 * Bumped erlef/setup-beam from 1.24.0 to 1.24.1 **Full Changelog**: https://github.com/trento-project/wanda/compare/2.1.0...2.1.1 trento-wanda was updated to version 2.1.1: - Changes and Bugs Fixed: * Added a configuration option to choose between IPv4 and IPv6 network protocols * Improved how excluded check rules are handled during system evaluations * Added the ability to change logging detail levels while the application is running * Fixed an installation error where background software packages clashed with each other - Dependency updates: * Bumped ecto from 3.14.1 to 3.14.2 * Bumped httpoison from 2.2.3 to 2.3.0 * Bumped phoenix from 1.7.23 to 1.8.11 * Bumped plug_cowboy from 2.8.1 to 2.9.0 * Bumped ecto from 3.14.0 to 3.14.1 * Bumped postgrex from 0.22.2 to 0.22.3 * Bumped yaml_elixir from 2.12.1 to 2.12.2 * Bumped erlef/setup-beam from 1.24.0 to 1.24.1 **Full Changelog**: https://github.com/trento-project/wanda/compare/2.1.0...2.1.1 trento-web was updated to version 3.1.6: - New Features: * Added a new system configuration setting for network options * Fixed an installation error where background software packages clashed with each other * Added the ability to change logging detail levels while the application is running - Changes and Bugs Fixed: * Fixed an issue where cluster check rules failed if the SAP system was not fully registered * Improved cleanup performance by deleting old system events in groups - Dependency updates: * Bumped ex_machina from 2.8.1 to 2.8.2 * Bumped browserslist from 4.28.2 to 4.28.8 in /assets * Ran npm audit * Bumped axios from 1.18.1 to 1.19.0 in /assets * Bumped prettier from 3.8.5 to 3.9.6 in /assets * Bumped pegasus from 0.2.6 to 1.0.0 * Bumped brace-expansion in /assets * Bumped phoenix from 1.7.23 to 1.7.24 * Bumped swoosh from 1.26.3 to 1.27.0 * Bumped flop from 0.25.0 to 0.26.5 * Bumped httpoison from 2.2.3 to 2.3.0 * Bumped cloak_ecto from 1.2.0 to 1.3.0 * Bumped ex_machina from 2.8.0 to 2.8.1 * Bumped tzdata from 1.1.4, gettext to 0.26 * Bumped commanded from 1.4.10 to 1.4.11 * Bumped postgrex from 0.22.2 to 0.22.3 * Bumped babel-jest from 30.3.0 to 30.4.1 in /assets * Bumped process_tree from 0.2.1 to 0.3.0 * Bumped faker from 0.18.0 to 0.19.0 * Bumped swoosh from 1.26.0 to 1.26.3 * Bumped joken from 2.5.0 to 2.6.2 * Bumped dompurify from 3.4.11 to 3.4.13 in /assets * Bumped floki from 0.38.3 to 0.38.4 * Bumped fast-uri from 3.1.2 to 3.1.5 in /assets * Bumped fast-uri from 3.1.3 to 3.1.5 in /test/e2e * Bumped postcss from 8.5.12 to 8.5.26 in /assets * Bumped nanoid in /assets * Bumped react-router from 7.15.1 to 7.18.2 * Bumped semver from 7.7.4 to 7.8.5 in /assets * Bumped tar and npm in /test/e2e * Bumped dorny/paths-filter from 4.0.1 to 4.0.2 * Bumped axios from 1.16.1 to 1.18.1 in /assets * Bumped brace-expansion from 5.0.5 to 5.0.7 in /test/e2e * Bumped erlef/setup-beam from 1.24.0 to 1.24.1 **Full Changelog**: https://github.com/trento-project/web/compare/3.1.5...3.1.6 The following package changes have been done: - trento-checks-1.3.2-150300.1.18.1 updated - trento-wanda-2.1.1-150300.1.20.2 updated From sle-container-updates at lists.suse.com Thu Sep 24 08:06:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 10:06:14 +0200 (CEST) Subject: SUSE-CU-2026:11159-1: Recommended update of trento/trento-web Message-ID: <20260924080614.25814FF19@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-web ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11159-1 Container Tags : trento/trento-web:3.1.6 , trento/trento-web:3.1.6-build4.64.1 , trento/trento-web:latest Container Release : 4.64.1 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container trento/trento-web was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4289-1 Released: Wed Sep 23 07:34:08 2026 Summary: Recommended update for Trento Type: recommended Severity: moderate References: This update for Trento fixes the following issues: ansible-trento was updated to version 1.0.1: - Changes and Bugs Fixed: * Added the option to change the monitoring network port * Allowed the support utility tool to be installed on SUSE Linux Enterprise Server 15 SP4 * Added password protection to the monitoring data receiver * Fixed folder permissions settings to prevent access issues * Fixed a startup crash by creating temporary system files before the monitoring service starts - New Features: * Enabled a backup network port for monitoring on SUSE Linux Enterprise Server 16 * Added the ability to adjust logging levels for the web interface and backend services * Added a diagnostic support tool plugin for the server * Allowed the web routing system to automatically find the monitoring service location * Added secure connection support (SSL/TLS encryption) to the monitoring service * Enabled configuration support for the telemetry data collector (Alloy) * Shared secure server certificates with monitoring agents * Automatically installed required background tools on monitoring agents * Added a configuration switch to turn the monitoring data receiver on or off - Dependency updates: * Bumped the common-workflows group with 3 updates * Bumped ansible/ansible-lint from 26.4.0 to 26.6.0 * Bumped actions/checkout from 6.0.3 to 7.0.1 * Bumped actions/checkout from 6.0.2 to 6.0.3 * Bumped dawidd6/action-ansible-playbook from 2.8.0 to 9 * Bumped ansible/ansible-lint from 25.12.2 to 26.4.0 * Bumped the common-workflows group across 1 directory with 3 updates **Full Changelog**: https://github.com/trento-project/ansible/compare/1.0.0...1.0.1 mcp-server-trento was updated to version 1.1.2: - Changes and Bugs Fixed: * Fixed a crash caused by incorrectly handling lists of settings - Dependency updates: * Bumped github.com/getkin/kin-openapi from 0.146.0 to 0.147.0 * Bumped github.com/stretchr/testify from 1.12.0 to 1.12.1 * Bumped the common-workflows group with 3 updates * Bumped github.com/getkin/kin-openapi from 0.145.0 to 0.146.0 * Bumped github.com/stretchr/testify from 1.11.1 to 1.12.0 * Bumped actions/setup-go from 6.5.0 to 7.0.0 * Bumped actions/checkout from 7.0.0 to 7.0.1 * Removed go patch version in go.mod * Updated dependencies * Bumped github.com/getkin/kin-openapi from 0.140.0 to 0.142.0 * Bumped actions/checkout from 6.0.3 to 7.0.0 * Bumped awalsh128/cache-apt-pkgs-action from 1.6.2 to 1.6.3 * Bumped golangci/golangci-lint-action from 9.2.1 to 9.3.0 * Bumped actions/cache from 5.0.5 to 6.1.0 * Bumped actions/setup-go from 6.4.0 to 6.5.0 * Bumped awalsh128/cache-apt-pkgs-action from 1.6.0 to 1.6.2 * Bumped github.com/getkin/kin-openapi from 0.137.0 to 0.140.0 * Bumped actions/checkout from 6.0.2 to 6.0.3 * Bumped endorama/asdf-parse-tool-versions from 1.5.1 to 1.6.0 * Bumped golangci/golangci-lint-action from 9.2.0 to 9.2.1 * Bumped github.com/modelcontextprotocol/go-sdk from 1.6.0 to 1.6.1 * Bumped github.com/modelcontextprotocol/go-sdk from 1.5.0 to 1.6.0 **Full Changelog**: https://github.com/trento-project/mcp-server/compare/1.1.0...1.1.2 trento-agent was updated to version 3.1.3: - Changes and Bugs Fixed: * Fixed a parsing error when reading colorful outputs from the SAP tuning tool (saptune) * Fixed a memory leak issue to improve system stability and performance * Fixed log messages not displaying correctly during startup * Improved the SAP system profile reader to support different configurations - Dependency updates: * Bumped golang.org/x/mod from 0.38.0 to 0.40.0 * Bumped google.golang.org/grpc from 1.83.1 to 1.83.2 in the go_modules group across 1 directory * Bumped github.com/rabbitmq/amqp091-go from 1.12.0 to 1.13.0 in the go_modules group across 1 directory * Bumped google.golang.org/grpc from 1.82.1 to 1.83.1 in the go_modules group across 1 directory * Bumped golang.org/x/text from v0.38.0 to v0.39.0 * Bumped golang.org/x/mod from 0.37.0 to 0.38.0 * Bumped google.golang.org/grpc from 1.79.3 to 1.82.1 in the go_modules group across 1 directory * Bumped golang.org/x/sync from 0.21.0 to 0.22.0 * Bumped golangci/golangci-lint-action from 9.2.1 to 9.3.0 * Bumped github.com/prometheus-community/pro-bing from 0.9.0 to 0.9.1 **Full Changelog**: https://github.com/trento-project/agent/compare/3.1.2...3.1.3 trento-checks was updated to version 1.3.2: - Changes and Bugs Fixed: * Update documentation links in checks: SAPHanaSR-angi * Fixed metadata typo: hana-scale_out to hana_scale_out **Full Changelog**: https://github.com/trento-project/checks/compare/1.3.1...1.3.2 trento-server-helm was updated to version 2.1.1: - Changes and Bugs Fixed: * Added a configuration option to choose between IPv4 and IPv6 network protocols * Improved how excluded check rules are handled during system evaluations - New Features: * Added the ability to change logging detail levels while the application is running * Fixed an installation error where background software packages clashed with each other - Dependency updates: * Bumped ecto from 3.14.1 to 3.14.2 * Bumped httpoison from 2.2.3 to 2.3.0 * Bumped phoenix from 1.7.23 to 1.8.11 * Bumped plug_cowboy from 2.8.1 to 2.9.0 * Bumped ecto from 3.14.0 to 3.14.1 * Bumped postgrex from 0.22.2 to 0.22.3 * Bumped yaml_elixir from 2.12.1 to 2.12.2 * Bumped erlef/setup-beam from 1.24.0 to 1.24.1 **Full Changelog**: https://github.com/trento-project/wanda/compare/2.1.0...2.1.1 trento-wanda was updated to version 2.1.1: - Changes and Bugs Fixed: * Added a configuration option to choose between IPv4 and IPv6 network protocols * Improved how excluded check rules are handled during system evaluations * Added the ability to change logging detail levels while the application is running * Fixed an installation error where background software packages clashed with each other - Dependency updates: * Bumped ecto from 3.14.1 to 3.14.2 * Bumped httpoison from 2.2.3 to 2.3.0 * Bumped phoenix from 1.7.23 to 1.8.11 * Bumped plug_cowboy from 2.8.1 to 2.9.0 * Bumped ecto from 3.14.0 to 3.14.1 * Bumped postgrex from 0.22.2 to 0.22.3 * Bumped yaml_elixir from 2.12.1 to 2.12.2 * Bumped erlef/setup-beam from 1.24.0 to 1.24.1 **Full Changelog**: https://github.com/trento-project/wanda/compare/2.1.0...2.1.1 trento-web was updated to version 3.1.6: - New Features: * Added a new system configuration setting for network options * Fixed an installation error where background software packages clashed with each other * Added the ability to change logging detail levels while the application is running - Changes and Bugs Fixed: * Fixed an issue where cluster check rules failed if the SAP system was not fully registered * Improved cleanup performance by deleting old system events in groups - Dependency updates: * Bumped ex_machina from 2.8.1 to 2.8.2 * Bumped browserslist from 4.28.2 to 4.28.8 in /assets * Ran npm audit * Bumped axios from 1.18.1 to 1.19.0 in /assets * Bumped prettier from 3.8.5 to 3.9.6 in /assets * Bumped pegasus from 0.2.6 to 1.0.0 * Bumped brace-expansion in /assets * Bumped phoenix from 1.7.23 to 1.7.24 * Bumped swoosh from 1.26.3 to 1.27.0 * Bumped flop from 0.25.0 to 0.26.5 * Bumped httpoison from 2.2.3 to 2.3.0 * Bumped cloak_ecto from 1.2.0 to 1.3.0 * Bumped ex_machina from 2.8.0 to 2.8.1 * Bumped tzdata from 1.1.4, gettext to 0.26 * Bumped commanded from 1.4.10 to 1.4.11 * Bumped postgrex from 0.22.2 to 0.22.3 * Bumped babel-jest from 30.3.0 to 30.4.1 in /assets * Bumped process_tree from 0.2.1 to 0.3.0 * Bumped faker from 0.18.0 to 0.19.0 * Bumped swoosh from 1.26.0 to 1.26.3 * Bumped joken from 2.5.0 to 2.6.2 * Bumped dompurify from 3.4.11 to 3.4.13 in /assets * Bumped floki from 0.38.3 to 0.38.4 * Bumped fast-uri from 3.1.2 to 3.1.5 in /assets * Bumped fast-uri from 3.1.3 to 3.1.5 in /test/e2e * Bumped postcss from 8.5.12 to 8.5.26 in /assets * Bumped nanoid in /assets * Bumped react-router from 7.15.1 to 7.18.2 * Bumped semver from 7.7.4 to 7.8.5 in /assets * Bumped tar and npm in /test/e2e * Bumped dorny/paths-filter from 4.0.1 to 4.0.2 * Bumped axios from 1.16.1 to 1.18.1 in /assets * Bumped brace-expansion from 5.0.5 to 5.0.7 in /test/e2e * Bumped erlef/setup-beam from 1.24.0 to 1.24.1 **Full Changelog**: https://github.com/trento-project/web/compare/3.1.5...3.1.6 The following package changes have been done: - trento-web-3.1.6-150300.1.31.2 updated From sle-container-updates at lists.suse.com Fri Sep 18 08:59:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 18 Sep 2026 10:59:05 +0200 (CEST) Subject: SUSE-CU-2026:10808-1: Security update of suse/hpc/warewulf4-x86_64/sle-hpc-node Message-ID: <20260918085905.8BC5BFF1E@maintenance.suse.de> SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10808-1 Container Tags : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7.20.8.168 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest Container Release : 20.8.168 Severity : important Type : security References : 1230238 1235944 1236344 1240957 1241363 1247180 1247455 1249104 1250748 1251130 1251966 1252682 1253454 1254306 1255225 1255250 1256629 1256708 1257154 1258430 1258472 1258517 1260522 1261562 1261780 1262073 1263004 1263052 1263061 1263133 1263864 1264010 1264012 1264335 1264446 1264541 1264587 1264619 1264643 1264740 1264807 1265068 1265121 1265220 1265449 1265928 1266402 1266860 1266874 1266897 1267023 1267236 1267238 1267501 1267505 1267610 1267612 1268276 1268972 1268979 1268987 1269004 1269013 1269108 1269113 1269114 1269126 1269140 1269167 1269234 1269238 1269242 1269256 1269301 1269306 1269313 1269381 1269388 1269402 1269412 1269530 1269579 1269590 1269635 1269647 1269655 1269665 1269686 1269695 1269713 1269731 1269774 1269783 1269792 1269815 1269888 1269965 1269969 1269981 1269985 1270090 1270108 1270111 1270251 1270263 1270268 1271256 1271365 1271366 1271825 1271830 1272150 1272175 1272179 1272182 1272200 1272210 1272213 1272230 1272260 1272261 1272262 1272297 1272346 1272351 1272359 1272381 1272383 1272385 1272390 1272423 1272429 1272484 1272486 1272497 1272502 1272516 1272569 1272571 1272618 1272641 1272643 1272662 1272673 1272680 1272682 1272756 1272786 1272788 1272798 1272799 1272804 1272868 1272877 1272891 1272893 1272963 1272983 1272993 1273005 1273008 1273019 1273027 1273028 1273030 1273032 1273033 1273036 1273037 1273038 1273053 1273054 1273060 1273105 1273134 1273249 1273250 1273260 1273273 1273274 1273276 1273277 1273280 1273281 1273284 1273285 1273289 1273291 1273294 1273302 1273303 1273305 1273310 1273311 1273316 1273318 1273319 1273323 1273325 1273327 1273334 1273335 1273336 1273337 1273338 1273340 1273341 1273346 1273422 1273426 1273443 1273460 1273463 1273465 1273468 1273469 1273471 1273479 1273480 1273482 1273484 1273488 1273490 1273501 1273503 1273504 1273506 1273523 1273525 1273533 1273536 1273542 1273555 1273578 1273579 1273581 1273582 1273596 1273597 1273598 1273600 1273601 1273602 1273603 1273679 1273681 1273682 1273734 1273738 1273739 1273741 1273742 1273743 1273745 1273748 1273749 1273755 1273762 1273765 1273766 1273769 1273774 1273778 1273780 1273790 1273796 1273797 1273801 1273804 1273810 1273811 1273812 1273813 1273817 1273822 1273824 1273831 1273832 1273834 1273838 1273844 1273849 1273859 1273860 1273862 1273867 1273868 1273869 1273872 1273876 1273877 1273880 1273882 1273890 1273891 1273892 1273895 1273896 1273903 1273905 1273930 1273933 1273934 1273935 1273936 1273939 1273940 1273941 1273942 1273944 1273945 1273946 1273956 1273957 1273958 1273966 1273967 1273968 1273972 1273974 1273975 1273977 1273982 1273988 1273990 1273991 1273995 1274001 1274003 1274006 1274008 1274009 1274010 1274011 1274012 1274014 1274017 1274019 1274020 1274026 1274028 1274030 1274031 1274035 1274040 1274041 1274055 1274057 1274058 1274061 1274063 1274065 1274067 1274071 1274075 1274076 1274077 1274078 1274208 1274226 1274239 1274243 1274258 1274264 1274265 1274267 1274274 1274277 1274278 1274281 1274283 1274286 1274290 1274294 1274295 1274296 1274297 1274298 1274314 1274321 1274491 1274497 1274539 1274541 1274543 1274545 1274547 1274550 1274573 1274578 1274580 1274581 1274620 1274622 1274624 1274629 1274632 1274636 1274639 1274640 1274642 1274644 1274645 1274646 1274649 1274650 1274651 1274656 1274659 1274662 1274663 1274665 1274667 1274670 1274675 1274677 1274678 1274679 1274681 1274682 1274690 1274694 1274696 1274698 1274699 1274700 1274702 1274703 1274705 1274706 1274709 1274710 1274713 1274716 1274721 1274723 1274725 1274726 1274737 1274738 1274749 1274752 1274753 1274754 1274755 1274756 1274764 1274768 1274770 1274783 1274787 1274800 1274801 1274802 1274804 1274805 1274807 1274808 1274811 1274813 1274814 1274831 1274834 1274835 1274847 1274849 1274853 1274868 1274869 1274872 1274873 1274874 1274876 1274877 1274879 1274881 1274883 1274886 1274888 1274891 1274892 1274893 1274894 1274895 1274896 1274897 1274898 1274899 1274901 1274902 1274905 1274906 1274907 1274908 1274913 1274914 1274920 1274921 1274924 1274925 1274929 1274930 1274933 1274934 1274935 1274941 1274945 1274947 1274951 1274953 1274958 1274968 1274981 1275040 1275069 1275071 1275073 1275076 1275080 1275081 1275083 1275088 1275091 1275125 1275126 1275131 1275132 1275139 1275141 1275146 1275148 1275149 1275150 1275152 1275154 1275155 1275156 1275157 1275158 1275161 1275163 1275164 1275169 1275173 1275176 1275185 1275190 1275192 1275236 1275237 1275239 1275294 1275300 1275301 1275303 1275304 1275305 1275306 1275307 1275470 1275472 1275474 1275479 1275483 1275486 1275487 1275506 1275509 1275511 1275517 1275519 1275528 1275535 1275540 1275553 1275555 1275557 1275561 1275566 1275569 1275572 1275574 1275578 1275582 1275583 1275584 1275591 1275595 1275633 1275636 1275650 1275656 1275659 1275665 1275669 1275687 1275688 1275695 1275696 1275704 1275737 1275782 1275784 1275787 1275788 1275789 1275790 1275797 1275798 1275805 1275817 1275818 1275819 1275820 1275821 1275822 1275823 1275827 1275864 1275867 1275869 1275870 1275871 1275872 1275886 1275905 1275923 1275925 1275928 1275946 1275950 1275954 1275970 1275973 1275975 1275976 1276029 1276257 1276263 1276270 1276273 1276277 1276335 1276346 1276350 1276355 1276446 1276452 1276500 1276507 1276542 1276546 1276551 1276552 1276561 1276569 1276577 1276665 1276864 1276892 1276912 1276913 1276927 1276931 1276937 1276941 1276943 1276944 1276946 1276955 1276961 1277022 1277034 1277037 1277047 1277054 1277057 1277059 1277064 1277066 1277069 1277073 1277077 1277095 1277155 1277159 1277160 1277202 1277204 1277262 1277275 1277285 1277391 1277408 1277516 1277523 1277551 1277625 1277660 1277678 1277688 1277707 1277708 1277709 1277710 1277711 1277713 1277775 1277776 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2024-44981 CVE-2024-57841 CVE-2025-23137 CVE-2025-38469 CVE-2025-39939 CVE-2025-39964 CVE-2025-40022 CVE-2025-40199 CVE-2025-68179 CVE-2025-68214 CVE-2025-71075 CVE-2025-71104 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-23210 CVE-2026-23227 CVE-2026-23230 CVE-2026-23454 CVE-2026-31418 CVE-2026-31531 CVE-2026-31557 CVE-2026-31658 CVE-2026-31663 CVE-2026-43014 CVE-2026-43015 CVE-2026-43116 CVE-2026-43125 CVE-2026-43163 CVE-2026-43213 CVE-2026-43271 CVE-2026-43273 CVE-2026-43363 CVE-2026-43386 CVE-2026-43416 CVE-2026-43448 CVE-2026-45897 CVE-2026-45968 CVE-2026-46070 CVE-2026-46078 CVE-2026-46091 CVE-2026-46107 CVE-2026-46115 CVE-2026-46127 CVE-2026-46195 CVE-2026-52920 CVE-2026-52925 CVE-2026-52929 CVE-2026-52935 CVE-2026-52939 CVE-2026-52946 CVE-2026-52975 CVE-2026-52977 CVE-2026-52990 CVE-2026-52994 CVE-2026-53001 CVE-2026-53033 CVE-2026-53034 CVE-2026-53059 CVE-2026-53076 CVE-2026-53077 CVE-2026-53089 CVE-2026-53091 CVE-2026-53094 CVE-2026-53096 CVE-2026-53110 CVE-2026-53111 CVE-2026-53126 CVE-2026-53142 CVE-2026-53154 CVE-2026-53163 CVE-2026-53180 CVE-2026-53207 CVE-2026-53219 CVE-2026-53220 CVE-2026-53223 CVE-2026-53228 CVE-2026-53238 CVE-2026-53260 CVE-2026-53263 CVE-2026-53264 CVE-2026-53269 CVE-2026-53273 CVE-2026-53309 CVE-2026-53330 CVE-2026-53336 CVE-2026-53337 CVE-2026-53353 CVE-2026-53365 CVE-2026-53366 CVE-2026-53381 CVE-2026-53388 CVE-2026-6368 CVE-2026-63801 CVE-2026-63808 CVE-2026-63810 CVE-2026-63823 CVE-2026-63827 CVE-2026-63828 CVE-2026-63842 CVE-2026-63850 CVE-2026-63860 CVE-2026-63865 CVE-2026-63868 CVE-2026-63879 CVE-2026-63881 CVE-2026-63886 CVE-2026-63887 CVE-2026-63888 CVE-2026-63889 CVE-2026-63891 CVE-2026-63898 CVE-2026-63920 CVE-2026-63923 CVE-2026-63925 CVE-2026-63926 CVE-2026-63928 CVE-2026-63937 CVE-2026-63944 CVE-2026-63969 CVE-2026-63970 CVE-2026-63972 CVE-2026-63973 CVE-2026-63980 CVE-2026-63985 CVE-2026-63990 CVE-2026-63992 CVE-2026-63995 CVE-2026-63996 CVE-2026-63997 CVE-2026-63998 CVE-2026-63999 CVE-2026-64000 CVE-2026-64001 CVE-2026-64002 CVE-2026-64004 CVE-2026-64005 CVE-2026-64006 CVE-2026-64007 CVE-2026-64010 CVE-2026-64011 CVE-2026-64014 CVE-2026-64015 CVE-2026-64018 CVE-2026-64021 CVE-2026-64029 CVE-2026-64033 CVE-2026-64034 CVE-2026-64039 CVE-2026-64047 CVE-2026-64048 CVE-2026-64051 CVE-2026-64052 CVE-2026-64055 CVE-2026-64056 CVE-2026-64073 CVE-2026-64083 CVE-2026-64084 CVE-2026-64085 CVE-2026-64086 CVE-2026-64087 CVE-2026-64088 CVE-2026-64097 CVE-2026-64098 CVE-2026-64099 CVE-2026-64102 CVE-2026-64109 CVE-2026-64112 CVE-2026-64113 CVE-2026-64114 CVE-2026-64115 CVE-2026-64118 CVE-2026-64121 CVE-2026-64125 CVE-2026-64126 CVE-2026-64127 CVE-2026-64128 CVE-2026-64131 CVE-2026-64133 CVE-2026-64134 CVE-2026-64135 CVE-2026-64136 CVE-2026-64137 CVE-2026-64144 CVE-2026-64146 CVE-2026-64148 CVE-2026-64155 CVE-2026-64164 CVE-2026-64166 CVE-2026-64168 CVE-2026-64178 CVE-2026-64180 CVE-2026-64185 CVE-2026-64188 CVE-2026-64190 CVE-2026-64192 CVE-2026-64214 CVE-2026-64217 CVE-2026-64218 CVE-2026-64219 CVE-2026-64222 CVE-2026-64224 CVE-2026-64225 CVE-2026-64237 CVE-2026-64243 CVE-2026-64244 CVE-2026-64245 CVE-2026-64246 CVE-2026-64247 CVE-2026-64249 CVE-2026-64257 CVE-2026-64266 CVE-2026-64268 CVE-2026-64269 CVE-2026-64271 CVE-2026-64273 CVE-2026-64274 CVE-2026-64275 CVE-2026-64276 CVE-2026-64277 CVE-2026-64286 CVE-2026-64287 CVE-2026-64294 CVE-2026-64296 CVE-2026-64303 CVE-2026-64304 CVE-2026-64305 CVE-2026-64306 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64316 CVE-2026-64317 CVE-2026-64322 CVE-2026-64323 CVE-2026-64329 CVE-2026-64331 CVE-2026-64332 CVE-2026-64333 CVE-2026-64334 CVE-2026-64335 CVE-2026-64337 CVE-2026-64338 CVE-2026-64340 CVE-2026-64341 CVE-2026-64342 CVE-2026-64343 CVE-2026-64344 CVE-2026-64346 CVE-2026-64348 CVE-2026-64350 CVE-2026-64351 CVE-2026-64355 CVE-2026-64358 CVE-2026-64362 CVE-2026-64365 CVE-2026-64375 CVE-2026-64376 CVE-2026-64378 CVE-2026-64381 CVE-2026-64382 CVE-2026-64383 CVE-2026-64384 CVE-2026-64385 CVE-2026-64386 CVE-2026-64387 CVE-2026-64388 CVE-2026-64401 CVE-2026-64403 CVE-2026-64406 CVE-2026-64407 CVE-2026-64408 CVE-2026-64409 CVE-2026-64411 CVE-2026-64412 CVE-2026-64420 CVE-2026-64421 CVE-2026-64423 CVE-2026-64427 CVE-2026-64429 CVE-2026-64433 CVE-2026-64434 CVE-2026-64436 CVE-2026-64440 CVE-2026-64442 CVE-2026-64443 CVE-2026-64444 CVE-2026-64445 CVE-2026-64448 CVE-2026-64450 CVE-2026-64452 CVE-2026-64454 CVE-2026-64455 CVE-2026-64463 CVE-2026-64470 CVE-2026-64471 CVE-2026-64472 CVE-2026-64477 CVE-2026-64478 CVE-2026-64479 CVE-2026-64480 CVE-2026-64481 CVE-2026-64482 CVE-2026-64483 CVE-2026-64484 CVE-2026-64486 CVE-2026-64487 CVE-2026-64489 CVE-2026-64494 CVE-2026-64495 CVE-2026-64496 CVE-2026-64497 CVE-2026-64500 CVE-2026-64503 CVE-2026-64504 CVE-2026-64505 CVE-2026-64511 CVE-2026-64512 CVE-2026-64513 CVE-2026-64515 CVE-2026-64517 CVE-2026-64524 CVE-2026-64527 CVE-2026-64536 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539 CVE-2026-64540 CVE-2026-64541 CVE-2026-64543 CVE-2026-64544 CVE-2026-64545 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64551 CVE-2026-64552 CVE-2026-64553 CVE-2026-64554 CVE-2026-64558 CVE-2026-64559 CVE-2026-64562 CVE-2026-64563 CVE-2026-64565 CVE-2026-64567 CVE-2026-64568 CVE-2026-64569 CVE-2026-64570 CVE-2026-64571 CVE-2026-64572 CVE-2026-64573 CVE-2026-64574 CVE-2026-64576 CVE-2026-64577 CVE-2026-64581 CVE-2026-64582 CVE-2026-64583 CVE-2026-64584 CVE-2026-64585 CVE-2026-64593 CVE-2026-64597 CVE-2026-64598 CVE-2026-64599 CVE-2026-64602 CVE-2026-64603 CVE-2026-64604 CVE-2026-6791 CVE-2026-68081 CVE-2026-68082 CVE-2026-68085 CVE-2026-68086 CVE-2026-68088 CVE-2026-68091 CVE-2026-68093 CVE-2026-68102 CVE-2026-68104 CVE-2026-68105 CVE-2026-68106 CVE-2026-68107 CVE-2026-68108 CVE-2026-68110 CVE-2026-68111 CVE-2026-68112 CVE-2026-68113 CVE-2026-68115 CVE-2026-68116 CVE-2026-68117 CVE-2026-68121 CVE-2026-68123 CVE-2026-68124 CVE-2026-68125 CVE-2026-68126 CVE-2026-68127 CVE-2026-68129 CVE-2026-68132 CVE-2026-68133 CVE-2026-68135 CVE-2026-68136 CVE-2026-68137 CVE-2026-68138 CVE-2026-68139 CVE-2026-68142 CVE-2026-68143 CVE-2026-68145 CVE-2026-68149 CVE-2026-68152 CVE-2026-68153 CVE-2026-68154 CVE-2026-68155 CVE-2026-68156 CVE-2026-68157 CVE-2026-68158 CVE-2026-68159 CVE-2026-68160 CVE-2026-68161 CVE-2026-68162 CVE-2026-68166 CVE-2026-68180 CVE-2026-68181 CVE-2026-68182 CVE-2026-68184 CVE-2026-68188 CVE-2026-68189 CVE-2026-68192 CVE-2026-68193 CVE-2026-68194 CVE-2026-68195 CVE-2026-68196 CVE-2026-68197 CVE-2026-68199 CVE-2026-68202 CVE-2026-68204 CVE-2026-68205 CVE-2026-68206 CVE-2026-68207 CVE-2026-68209 CVE-2026-68210 CVE-2026-68212 CVE-2026-68213 CVE-2026-68214 CVE-2026-68215 CVE-2026-68216 CVE-2026-68217 CVE-2026-68218 CVE-2026-68219 CVE-2026-68220 CVE-2026-68222 CVE-2026-68223 CVE-2026-68226 CVE-2026-68227 CVE-2026-68229 CVE-2026-68231 CVE-2026-68234 CVE-2026-68235 CVE-2026-68236 CVE-2026-68238 CVE-2026-68243 CVE-2026-68244 CVE-2026-68245 CVE-2026-68246 CVE-2026-68247 CVE-2026-68248 CVE-2026-68249 CVE-2026-68250 CVE-2026-68251 CVE-2026-68252 CVE-2026-68253 CVE-2026-68254 CVE-2026-68255 CVE-2026-68256 CVE-2026-68257 CVE-2026-68259 CVE-2026-68260 CVE-2026-68261 CVE-2026-68262 CVE-2026-68263 CVE-2026-68267 CVE-2026-68269 CVE-2026-68271 CVE-2026-68272 CVE-2026-68277 CVE-2026-68278 CVE-2026-68279 CVE-2026-68280 CVE-2026-68281 CVE-2026-68284 CVE-2026-68286 CVE-2026-68288 CVE-2026-68289 CVE-2026-68293 CVE-2026-68297 CVE-2026-68299 CVE-2026-68300 CVE-2026-68302 CVE-2026-68303 CVE-2026-68304 CVE-2026-68306 CVE-2026-68308 CVE-2026-68309 CVE-2026-68310 CVE-2026-68312 CVE-2026-68313 CVE-2026-68315 CVE-2026-68320 CVE-2026-68322 CVE-2026-68324 CVE-2026-68325 CVE-2026-68326 CVE-2026-68327 CVE-2026-68328 CVE-2026-68329 CVE-2026-68331 CVE-2026-68333 CVE-2026-68335 CVE-2026-68336 CVE-2026-68339 CVE-2026-68340 CVE-2026-68343 CVE-2026-68346 CVE-2026-68348 CVE-2026-68349 CVE-2026-68350 CVE-2026-68351 CVE-2026-68352 CVE-2026-68353 CVE-2026-68354 CVE-2026-68355 CVE-2026-68357 CVE-2026-68359 CVE-2026-68360 CVE-2026-68361 CVE-2026-68362 CVE-2026-68363 CVE-2026-68365 CVE-2026-68366 CVE-2026-68368 CVE-2026-68369 CVE-2026-68370 CVE-2026-68372 CVE-2026-68373 CVE-2026-68375 CVE-2026-68377 CVE-2026-68386 CVE-2026-68389 CVE-2026-68391 CVE-2026-68392 CVE-2026-68394 CVE-2026-68397 CVE-2026-68398 CVE-2026-68399 CVE-2026-68402 CVE-2026-68403 CVE-2026-68405 CVE-2026-68406 CVE-2026-68407 CVE-2026-68408 CVE-2026-68410 CVE-2026-68413 CVE-2026-68414 CVE-2026-68417 CVE-2026-68418 CVE-2026-68419 CVE-2026-68422 CVE-2026-68425 CVE-2026-68426 CVE-2026-68427 CVE-2026-68428 CVE-2026-68429 CVE-2026-68430 CVE-2026-68432 CVE-2026-68433 CVE-2026-68434 CVE-2026-68437 CVE-2026-68444 CVE-2026-68445 CVE-2026-68446 CVE-2026-68450 CVE-2026-68470 CVE-2026-68480 CVE-2026-72020 CVE-2026-72032 CVE-2026-72035 CVE-2026-72036 CVE-2026-72046 CVE-2026-72069 CVE-2026-72072 CVE-2026-72083 CVE-2026-72084 CVE-2026-72123 CVE-2026-72132 CVE-2026-72221 CVE-2026-72222 CVE-2026-72251 CVE-2026-72254 CVE-2026-72262 CVE-2026-72288 CVE-2026-72289 CVE-2026-72296 CVE-2026-72307 CVE-2026-72308 CVE-2026-72317 CVE-2026-72341 CVE-2026-72342 CVE-2026-72343 CVE-2026-72389 CVE-2026-72463 CVE-2026-72464 CVE-2026-72466 CVE-2026-72467 CVE-2026-72469 CVE-2026-72473 CVE-2026-72494 CVE-2026-72495 CVE-2026-72496 CVE-2026-72497 CVE-2026-72498 CVE-2026-72499 CVE-2026-72500 CVE-2026-72501 CVE-2026-72502 CVE-2026-74269 CVE-2026-74296 CVE-2026-74297 CVE-2026-74318 CVE-2026-74321 CVE-2026-74334 CVE-2026-74345 CVE-2026-74394 CVE-2026-74395 CVE-2026-74454 CVE-2026-74474 CVE-2026-74481 CVE-2026-74482 CVE-2026-74488 CVE-2026-74495 CVE-2026-74496 CVE-2026-74509 CVE-2026-74510 CVE-2026-74512 CVE-2026-74516 CVE-2026-74518 CVE-2026-74527 CVE-2026-74537 CVE-2026-74548 CVE-2026-74550 CVE-2026-74556 CVE-2026-74563 CVE-2026-74566 CVE-2026-74567 CVE-2026-74571 CVE-2026-74577 CVE-2026-74581 CVE-2026-74582 CVE-2026-74584 CVE-2026-74610 CVE-2026-74669 CVE-2026-74692 CVE-2026-74694 CVE-2026-74695 CVE-2026-74712 CVE-2026-74717 CVE-2026-74722 CVE-2026-77117 CVE-2026-80489 CVE-2026-80529 CVE-2026-80534 CVE-2026-80590 CVE-2026-80654 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4254-1 Released: Thu Sep 17 18:03:10 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1230238,1235944,1236344,1240957,1241363,1247180,1247455,1249104,1250748,1251130,1251966,1252682,1253454,1254306,1255225,1255250,1256629,1256708,1257154,1258430,1258472,1258517,1260522,1261562,1261780,1262073,1263004,1263052,1263061,1263133,1263864,1264010,1264012,1264335,1264446,1264541,1264587,1264619,1264643,1264740,1264807,1265068,1265121,1265220,1265449,1265928,1266402,1266860,1266874,1266897,1267023,1267236,1267238,1267501,1267505,1267612,1268276,1268972,1268979,1268987,1269004,1269013,1269108,1269113,1269114,1269126,1269140,1269167,1269234,1269238,1269242,1269256,1269301,1269306,1269313,1269381,1269388,1269402,1269412,1269530,1269579,1269590,1269635,1269647,1269655,1269665,1269686,1269695,1269713,1269731,1269774,1269783,1269792,1269815,1269888,1269965,1269969,1269981,1269985,1270090,1270108,1270111,1270251,1270263,1270268,1271256,1271365,1271366,1271825,1271830,1272150,1272175,1272179,1272182,1272200,1272210,1272213,1272230,1272260,1272261,1272262,1272297,1272346,1 272351,1272359,1272381,1272383,1272385,1272390,1272423,1272429,1272484,1272486,1272497,1272502,1272516,1272569,1272571,1272618,1272641,1272643,1272662,1272673,1272680,1272682,1272756,1272786,1272788,1272798,1272799,1272804,1272868,1272877,1272891,1272893,1272963,1272983,1272993,1273005,1273008,1273019,1273027,1273028,1273030,1273032,1273033,1273036,1273037,1273038,1273053,1273054,1273060,1273105,1273134,1273249,1273250,1273260,1273273,1273274,1273276,1273277,1273280,1273281,1273284,1273285,1273289,1273291,1273294,1273302,1273303,1273305,1273310,1273311,1273316,1273318,1273319,1273323,1273325,1273327,1273334,1273335,1273336,1273337,1273338,1273340,1273341,1273346,1273422,1273426,1273443,1273460,1273463,1273465,1273468,1273469,1273471,1273479,1273480,1273482,1273484,1273488,1273490,1273501,1273503,1273504,1273506,1273523,1273525,1273533,1273536,1273542,1273555,1273578,1273579,1273581,1273582,1273596,1273597,1273598,1273600,1273601,1273602,1273603,1273679,1273681,1273682,1273734,127373 8,1273739,1273741,1273742,1273743,1273745,1273748,1273749,1273755,1273762,1273765,1273766,1273769,1273774,1273778,1273780,1273790,1273796,1273797,1273801,1273804,1273810,1273811,1273812,1273813,1273817,1273822,1273824,1273831,1273832,1273834,1273838,1273844,1273849,1273859,1273860,1273862,1273867,1273868,1273869,1273872,1273876,1273877,1273880,1273882,1273890,1273891,1273892,1273895,1273896,1273903,1273905,1273930,1273933,1273934,1273935,1273936,1273939,1273940,1273941,1273942,1273944,1273945,1273946,1273956,1273957,1273958,1273966,1273967,1273968,1273972,1273974,1273975,1273977,1273982,1273988,1273990,1273991,1273995,1274001,1274003,1274006,1274008,1274009,1274010,1274011,1274012,1274014,1274017,1274019,1274020,1274026,1274028,1274030,1274031,1274035,1274040,1274041,1274055,1274057,1274058,1274061,1274063,1274065,1274067,1274071,1274075,1274076,1274077,1274078,1274208,1274226,1274239,1274243,1274258,1274264,1274265,1274267,1274274,1274277,1274278,1274281,1274283,1274286,1274290,127 4294,1274295,1274296,1274297,1274298,1274314,1274321,1274491,1274497,1274539,1274541,1274543,1274545,1274547,1274550,1274573,1274578,1274580,1274581,1274620,1274622,1274624,1274629,1274632,1274636,1274639,1274640,1274642,1274644,1274645,1274646,1274649,1274650,1274651,1274656,1274659,1274662,1274663,1274665,1274667,1274670,1274675,1274677,1274678,1274679,1274681,1274682,1274690,1274694,1274696,1274698,1274699,1274700,1274702,1274703,1274705,1274706,1274709,1274710,1274713,1274716,1274721,1274725,1274737,1274738,1274749,1274752,1274753,1274754,1274755,1274756,1274764,1274768,1274770,1274783,1274787,1274800,1274801,1274802,1274804,1274805,1274807,1274808,1274811,1274813,1274814,1274831,1274834,1274835,1274847,1274849,1274853,1274868,1274869,1274872,1274873,1274874,1274876,1274877,1274879,1274881,1274883,1274886,1274888,1274891,1274892,1274893,1274894,1274895,1274896,1274897,1274898,1274899,1274901,1274902,1274905,1274906,1274907,1274908,1274913,1274914,1274920,1274921,1274924,1274925, 1274929,1274930,1274933,1274934,1274935,1274941,1274945,1274947,1274951,1274953,1274958,1274968,1274981,1275040,1275069,1275071,1275073,1275076,1275080,1275081,1275083,1275088,1275091,1275125,1275126,1275131,1275132,1275139,1275141,1275146,1275148,1275149,1275150,1275152,1275154,1275155,1275156,1275157,1275158,1275161,1275163,1275164,1275169,1275173,1275176,1275185,1275190,1275192,1275236,1275237,1275239,1275294,1275300,1275301,1275303,1275304,1275305,1275306,1275307,1275470,1275472,1275474,1275479,1275483,1275486,1275487,1275506,1275509,1275511,1275517,1275519,1275528,1275535,1275540,1275553,1275555,1275557,1275561,1275566,1275569,1275572,1275574,1275578,1275582,1275583,1275584,1275591,1275595,1275633,1275636,1275650,1275656,1275659,1275665,1275669,1275687,1275688,1275695,1275696,1275704,1275737,1275782,1275784,1275787,1275788,1275789,1275790,1275797,1275798,1275805,1275817,1275818,1275819,1275820,1275821,1275822,1275823,1275827,1275864,1275867,1275869,1275870,1275871,1275872,12758 86,1275905,1275923,1275925,1275928,1275946,1275950,1275954,1275970,1275973,1275975,1275976,1276029,1276257,1276263,1276270,1276273,1276277,1276335,1276346,1276350,1276355,1276446,1276452,1276500,1276507,1276542,1276546,1276551,1276552,1276561,1276569,1276577,1276665,1276864,1276912,1276913,1276927,1276931,1276937,1276941,1276943,1276944,1276955,1276961,1277022,1277034,1277037,1277047,1277054,1277057,1277059,1277064,1277066,1277069,1277073,1277077,1277095,1277155,1277159,1277160,1277202,1277204,1277275,1277285,1277391,1277408,1277516,1277523,1277551,1277625,1277660,1277678,1277688,1277775,1277776,CVE-2024-44981,CVE-2024-57841,CVE-2025-23137,CVE-2025-38469,CVE-2025-39939,CVE-2025-39964,CVE-2025-40022,CVE-2025-40199,CVE-2025-68179,CVE-2025-68214,CVE-2025-71075,CVE-2025-71104,CVE-2026-23210,CVE-2026-23227,CVE-2026-23230,CVE-2026-23454,CVE-2026-31418,CVE-2026-31531,CVE-2026-31557,CVE-2026-31658,CVE-2026-31663,CVE-2026-43014,CVE-2026-43015,CVE-2026-43116,CVE-2026-43125,CVE-2026-43163,CVE- 2026-43213,CVE-2026-43271,CVE-2026-43273,CVE-2026-43363,CVE-2026-43386,CVE-2026-43416,CVE-2026-43448,CVE-2026-45897,CVE-2026-45968,CVE-2026-46070,CVE-2026-46078,CVE-2026-46091,CVE-2026-46107,CVE-2026-46115,CVE-2026-46127,CVE-2026-46195,CVE-2026-52920,CVE-2026-52925,CVE-2026-52929,CVE-2026-52935,CVE-2026-52939,CVE-2026-52946,CVE-2026-52975,CVE-2026-52977,CVE-2026-52990,CVE-2026-52994,CVE-2026-53001,CVE-2026-53033,CVE-2026-53034,CVE-2026-53059,CVE-2026-53076,CVE-2026-53077,CVE-2026-53089,CVE-2026-53091,CVE-2026-53094,CVE-2026-53096,CVE-2026-53110,CVE-2026-53111,CVE-2026-53126,CVE-2026-53142,CVE-2026-53154,CVE-2026-53163,CVE-2026-53180,CVE-2026-53207,CVE-2026-53219,CVE-2026-53220,CVE-2026-53223,CVE-2026-53228,CVE-2026-53238,CVE-2026-53260,CVE-2026-53263,CVE-2026-53264,CVE-2026-53269,CVE-2026-53273,CVE-2026-53309,CVE-2026-53330,CVE-2026-53336,CVE-2026-53337,CVE-2026-53353,CVE-2026-53365,CVE-2026-53366,CVE-2026-53381,CVE-2026-53388,CVE-2026-63801,CVE-2026-63808,CVE-2026-63810,CVE-2026-63 823,CVE-2026-63827,CVE-2026-63828,CVE-2026-63842,CVE-2026-63850,CVE-2026-63860,CVE-2026-63865,CVE-2026-63868,CVE-2026-63879,CVE-2026-63881,CVE-2026-63886,CVE-2026-63887,CVE-2026-63888,CVE-2026-63889,CVE-2026-63891,CVE-2026-63898,CVE-2026-63920,CVE-2026-63923,CVE-2026-63925,CVE-2026-63926,CVE-2026-63928,CVE-2026-63937,CVE-2026-63944,CVE-2026-63969,CVE-2026-63970,CVE-2026-63972,CVE-2026-63973,CVE-2026-63980,CVE-2026-63985,CVE-2026-63990,CVE-2026-63992,CVE-2026-63995,CVE-2026-63996,CVE-2026-63997,CVE-2026-63998,CVE-2026-63999,CVE-2026-64000,CVE-2026-64001,CVE-2026-64002,CVE-2026-64004,CVE-2026-64005,CVE-2026-64006,CVE-2026-64007,CVE-2026-64010,CVE-2026-64011,CVE-2026-64014,CVE-2026-64015,CVE-2026-64018,CVE-2026-64021,CVE-2026-64029,CVE-2026-64033,CVE-2026-64034,CVE-2026-64039,CVE-2026-64047,CVE-2026-64048,CVE-2026-64051,CVE-2026-64052,CVE-2026-64055,CVE-2026-64056,CVE-2026-64073,CVE-2026-64083,CVE-2026-64084,CVE-2026-64085,CVE-2026-64086,CVE-2026-64087,CVE-2026-64088,CVE-2026-64097,CVE -2026-64098,CVE-2026-64099,CVE-2026-64102,CVE-2026-64109,CVE-2026-64112,CVE-2026-64113,CVE-2026-64114,CVE-2026-64115,CVE-2026-64118,CVE-2026-64121,CVE-2026-64125,CVE-2026-64126,CVE-2026-64127,CVE-2026-64128,CVE-2026-64131,CVE-2026-64133,CVE-2026-64134,CVE-2026-64135,CVE-2026-64136,CVE-2026-64137,CVE-2026-64144,CVE-2026-64146,CVE-2026-64148,CVE-2026-64155,CVE-2026-64164,CVE-2026-64166,CVE-2026-64168,CVE-2026-64178,CVE-2026-64180,CVE-2026-64185,CVE-2026-64188,CVE-2026-64190,CVE-2026-64192,CVE-2026-64214,CVE-2026-64217,CVE-2026-64218,CVE-2026-64219,CVE-2026-64222,CVE-2026-64224,CVE-2026-64225,CVE-2026-64237,CVE-2026-64243,CVE-2026-64244,CVE-2026-64245,CVE-2026-64246,CVE-2026-64247,CVE-2026-64249,CVE-2026-64257,CVE-2026-64266,CVE-2026-64268,CVE-2026-64269,CVE-2026-64271,CVE-2026-64273,CVE-2026-64274,CVE-2026-64275,CVE-2026-64276,CVE-2026-64277,CVE-2026-64286,CVE-2026-64287,CVE-2026-64294,CVE-2026-64296,CVE-2026-64303,CVE-2026-64304,CVE-2026-64305,CVE-2026-64306,CVE-2026-64312,CVE-2026-6 4313,CVE-2026-64315,CVE-2026-64316,CVE-2026-64317,CVE-2026-64322,CVE-2026-64323,CVE-2026-64329,CVE-2026-64331,CVE-2026-64332,CVE-2026-64333,CVE-2026-64334,CVE-2026-64335,CVE-2026-64337,CVE-2026-64338,CVE-2026-64340,CVE-2026-64341,CVE-2026-64342,CVE-2026-64343,CVE-2026-64344,CVE-2026-64346,CVE-2026-64348,CVE-2026-64350,CVE-2026-64351,CVE-2026-64355,CVE-2026-64358,CVE-2026-64362,CVE-2026-64365,CVE-2026-64375,CVE-2026-64376,CVE-2026-64378,CVE-2026-64381,CVE-2026-64382,CVE-2026-64383,CVE-2026-64384,CVE-2026-64385,CVE-2026-64386,CVE-2026-64387,CVE-2026-64388,CVE-2026-64401,CVE-2026-64403,CVE-2026-64406,CVE-2026-64407,CVE-2026-64408,CVE-2026-64409,CVE-2026-64411,CVE-2026-64412,CVE-2026-64420,CVE-2026-64421,CVE-2026-64423,CVE-2026-64427,CVE-2026-64429,CVE-2026-64433,CVE-2026-64434,CVE-2026-64436,CVE-2026-64440,CVE-2026-64442,CVE-2026-64443,CVE-2026-64444,CVE-2026-64445,CVE-2026-64448,CVE-2026-64450,CVE-2026-64452,CVE-2026-64454,CVE-2026-64455,CVE-2026-64463,CVE-2026-64470,CVE-2026-64471,CV E-2026-64472,CVE-2026-64477,CVE-2026-64478,CVE-2026-64479,CVE-2026-64480,CVE-2026-64481,CVE-2026-64482,CVE-2026-64483,CVE-2026-64484,CVE-2026-64486,CVE-2026-64487,CVE-2026-64489,CVE-2026-64494,CVE-2026-64495,CVE-2026-64496,CVE-2026-64497,CVE-2026-64500,CVE-2026-64503,CVE-2026-64504,CVE-2026-64505,CVE-2026-64511,CVE-2026-64512,CVE-2026-64513,CVE-2026-64515,CVE-2026-64517,CVE-2026-64524,CVE-2026-64527,CVE-2026-64536,CVE-2026-64537,CVE-2026-64538,CVE-2026-64539,CVE-2026-64540,CVE-2026-64541,CVE-2026-64543,CVE-2026-64544,CVE-2026-64545,CVE-2026-64546,CVE-2026-64547,CVE-2026-64548,CVE-2026-64549,CVE-2026-64551,CVE-2026-64552,CVE-2026-64553,CVE-2026-64554,CVE-2026-64558,CVE-2026-64559,CVE-2026-64562,CVE-2026-64563,CVE-2026-64565,CVE-2026-64567,CVE-2026-64568,CVE-2026-64569,CVE-2026-64570,CVE-2026-64571,CVE-2026-64572,CVE-2026-64573,CVE-2026-64574,CVE-2026-64576,CVE-2026-64577,CVE-2026-64581,CVE-2026-64582,CVE-2026-64583,CVE-2026-64584,CVE-2026-64585,CVE-2026-64593,CVE-2026-64597,CVE-2026- 64598,CVE-2026-64599,CVE-2026-64602,CVE-2026-64603,CVE-2026-64604,CVE-2026-68081,CVE-2026-68082,CVE-2026-68085,CVE-2026-68086,CVE-2026-68088,CVE-2026-68091,CVE-2026-68093,CVE-2026-68102,CVE-2026-68104,CVE-2026-68105,CVE-2026-68106,CVE-2026-68107,CVE-2026-68108,CVE-2026-68110,CVE-2026-68111,CVE-2026-68112,CVE-2026-68113,CVE-2026-68115,CVE-2026-68116,CVE-2026-68117,CVE-2026-68121,CVE-2026-68123,CVE-2026-68124,CVE-2026-68125,CVE-2026-68126,CVE-2026-68127,CVE-2026-68129,CVE-2026-68132,CVE-2026-68133,CVE-2026-68135,CVE-2026-68136,CVE-2026-68137,CVE-2026-68138,CVE-2026-68139,CVE-2026-68142,CVE-2026-68143,CVE-2026-68145,CVE-2026-68149,CVE-2026-68152,CVE-2026-68153,CVE-2026-68154,CVE-2026-68155,CVE-2026-68156,CVE-2026-68157,CVE-2026-68158,CVE-2026-68159,CVE-2026-68160,CVE-2026-68161,CVE-2026-68162,CVE-2026-68166,CVE-2026-68180,CVE-2026-68181,CVE-2026-68182,CVE-2026-68184,CVE-2026-68188,CVE-2026-68189,CVE-2026-68192,CVE-2026-68193,CVE-2026-68194,CVE-2026-68195,CVE-2026-68196,CVE-2026-68197,C VE-2026-68199,CVE-2026-68202,CVE-2026-68204,CVE-2026-68205,CVE-2026-68206,CVE-2026-68207,CVE-2026-68209,CVE-2026-68210,CVE-2026-68212,CVE-2026-68213,CVE-2026-68214,CVE-2026-68215,CVE-2026-68216,CVE-2026-68217,CVE-2026-68218,CVE-2026-68219,CVE-2026-68220,CVE-2026-68222,CVE-2026-68223,CVE-2026-68226,CVE-2026-68227,CVE-2026-68229,CVE-2026-68231,CVE-2026-68234,CVE-2026-68235,CVE-2026-68236,CVE-2026-68238,CVE-2026-68243,CVE-2026-68244,CVE-2026-68245,CVE-2026-68246,CVE-2026-68247,CVE-2026-68248,CVE-2026-68249,CVE-2026-68250,CVE-2026-68251,CVE-2026-68252,CVE-2026-68253,CVE-2026-68254,CVE-2026-68255,CVE-2026-68256,CVE-2026-68257,CVE-2026-68259,CVE-2026-68260,CVE-2026-68261,CVE-2026-68262,CVE-2026-68263,CVE-2026-68267,CVE-2026-68269,CVE-2026-68271,CVE-2026-68272,CVE-2026-68277,CVE-2026-68278,CVE-2026-68279,CVE-2026-68280,CVE-2026-68281,CVE-2026-68284,CVE-2026-68286,CVE-2026-68288,CVE-2026-68289,CVE-2026-68293,CVE-2026-68297,CVE-2026-68299,CVE-2026-68300,CVE-2026-68302,CVE-2026-68303,CVE-2026 -68304,CVE-2026-68306,CVE-2026-68308,CVE-2026-68309,CVE-2026-68310,CVE-2026-68312,CVE-2026-68313,CVE-2026-68315,CVE-2026-68320,CVE-2026-68322,CVE-2026-68324,CVE-2026-68325,CVE-2026-68326,CVE-2026-68327,CVE-2026-68328,CVE-2026-68329,CVE-2026-68331,CVE-2026-68333,CVE-2026-68335,CVE-2026-68336,CVE-2026-68339,CVE-2026-68340,CVE-2026-68343,CVE-2026-68346,CVE-2026-68348,CVE-2026-68349,CVE-2026-68350,CVE-2026-68351,CVE-2026-68352,CVE-2026-68353,CVE-2026-68354,CVE-2026-68355,CVE-2026-68357,CVE-2026-68359,CVE-2026-68360,CVE-2026-68361,CVE-2026-68362,CVE-2026-68363,CVE-2026-68365,CVE-2026-68366,CVE-2026-68368,CVE-2026-68369,CVE-2026-68370,CVE-2026-68372,CVE-2026-68373,CVE-2026-68375,CVE-2026-68377,CVE-2026-68386,CVE-2026-68389,CVE-2026-68391,CVE-2026-68392,CVE-2026-68394,CVE-2026-68397,CVE-2026-68398,CVE-2026-68399,CVE-2026-68402,CVE-2026-68403,CVE-2026-68405,CVE-2026-68406,CVE-2026-68407,CVE-2026-68408,CVE-2026-68410,CVE-2026-68413,CVE-2026-68414,CVE-2026-68417,CVE-2026-68418,CVE-2026-68419, CVE-2026-68422,CVE-2026-68425,CVE-2026-68426,CVE-2026-68427,CVE-2026-68428,CVE-2026-68429,CVE-2026-68430,CVE-2026-68432,CVE-2026-68433,CVE-2026-68434,CVE-2026-68437,CVE-2026-68444,CVE-2026-68445,CVE-2026-68446,CVE-2026-68450,CVE-2026-68470,CVE-2026-68480,CVE-2026-72020,CVE-2026-72032,CVE-2026-72035,CVE-2026-72036,CVE-2026-72046,CVE-2026-72069,CVE-2026-72072,CVE-2026-72083,CVE-2026-72084,CVE-2026-72123,CVE-2026-72132,CVE-2026-72221,CVE-2026-72222,CVE-2026-72251,CVE-2026-72254,CVE-2026-72262,CVE-2026-72288,CVE-2026-72289,CVE-2026-72296,CVE-2026-72307,CVE-2026-72308,CVE-2026-72317,CVE-2026-72341,CVE-2026-72342,CVE-2026-72343,CVE-2026-72389,CVE-2026-72463,CVE-2026-72464,CVE-2026-72466,CVE-2026-72467,CVE-2026-72469,CVE-2026-72473,CVE-2026-72494,CVE-2026-72495,CVE-2026-72496,CVE-2026-72497,CVE-2026-72498,CVE-2026-72499,CVE-2026-72500,CVE-2026-72501,CVE-2026-72502,CVE-2026-74269,CVE-2026-74296,CVE-2026-74297,CVE-2026-74318,CVE-2026-74321,CVE-2026-74334,CVE-2026-74345,CVE-2026-74394,CVE-202 6-74395,CVE-2026-74454,CVE-2026-74474,CVE-2026-74481,CVE-2026-74482,CVE-2026-74488,CVE-2026-74495,CVE-2026-74496,CVE-2026-74509,CVE-2026-74510,CVE-2026-74512,CVE-2026-74516,CVE-2026-74518,CVE-2026-74527,CVE-2026-74537,CVE-2026-74548,CVE-2026-74550,CVE-2026-74556,CVE-2026-74563,CVE-2026-74566,CVE-2026-74567,CVE-2026-74571,CVE-2026-74577,CVE-2026-74581,CVE-2026-74582,CVE-2026-74584,CVE-2026-74610,CVE-2026-74669,CVE-2026-74692,CVE-2026-74694,CVE-2026-74695,CVE-2026-74712,CVE-2026-74717,CVE-2026-74722,CVE-2026-80529,CVE-2026-80534,CVE-2026-80590,CVE-2026-80654 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2024-57841,CVE-2026-53260: net: fix memory leak in tcp_conn_request() (bsc#1235944 bsc#1269731). - CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). - CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). - CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). - CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). - CVE-2026-31557: nvmet: move async event work off nvmet-wq (bsc#1263061). - CVE-2026-31658: net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (bsc#1263052). - CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). - CVE-2026-43014,CVE-2026-43015: net: macb: fix clk handling on PCI glue driver removal (bsc#1264010 bsc#1264012). - CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). - CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). - CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). - CVE-2026-43213: wifi: rtw89: pci: validate sequence number of TX release report (bsc#1264643). - CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). - CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446). - CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). - CVE-2026-43386: staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie (bsc#1264740). - CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). - CVE-2026-43448: nvme-pci: Fix race bug in nvme_poll_irqdisable() (bsc#1264807). - CVE-2026-45897: bpf: Fix UAF in sock clone early bailouts (bsc#1266897). - CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). - CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). - CVE-2026-46078: erofs: fix the out-of-bounds nameoff handling for trailing dirents (bsc#1267505). - CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). - CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). - CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). - CVE-2026-46127: RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() (bsc#1267236). - CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). - CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). - CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). - CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). - CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). - CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). - CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). - CVE-2026-52975: bonding: 802.3ad replace MAC_ADDRESS_EQUAL with __agg_has_partner (bsc#1269234). - CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). - CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). - CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). - CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). - CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). - CVE-2026-53034: bpf, sockmap: Fix af_unix null-ptr-deref in proto update (bsc#1269140). - CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). - CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). - CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). - CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). - CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). - CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). - CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). - CVE-2026-53110: selftests/bpf: Add ASSERT_OK_FD macro (bsc#1269985). - CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). - CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). - CVE-2026-53142: drm/xe/display: fix oops in suspend/shutdown without display (bsc#1269402). - CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). - CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). - CVE-2026-53180: timers/migration: Fix livelock in tmigr_handle_remote_up() (bsc#1269888). - CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). - CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). - CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). - CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). - CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). - CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). - CVE-2026-53263: 6lowpan: fix off-by-one in multicast context address compression (bsc#1269647). - CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). - CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). - CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713). - CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). - CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). - CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). - CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). - CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). - CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). - CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). - CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). - CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). - CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). - CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). - CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). - CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). - CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). - CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). - CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). - CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). - CVE-2026-63881: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (bsc#1272571). - CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). - CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). - CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). - CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). - CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). - CVE-2026-63923: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify (bsc#1273005). - CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). - CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). - CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1272662). - CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). - CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). - CVE-2026-63980: net/handshake: Use spin_lock_bh for hn_lock (bsc#1273028). - CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). - CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). - CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). - CVE-2026-63995: ethtool: cmis: validate start_cmd_payload_size from module (bsc#1273033). - CVE-2026-63996: ethtool: cmis: require exact CDB reply length (bsc#1273032). - CVE-2026-63997: ethtool: module: avoid leaking a netdev ref on module flash errors (bsc#1273036). - CVE-2026-63998: ethtool: module: call ethnl_ops_complete() on module flash errors (bsc#1273037). - CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). - CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). - CVE-2026-64001: ALSA: pcm: oss: Fix setup list UAF on proc write error (bsc#1273734). - CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). - CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). - CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). - CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). - CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). - CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). - CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). - CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). - CVE-2026-64029: ALSA: seq: Serialize UMP output teardown with event_input (bsc#1273766). - CVE-2026-64033: RDMA/rtrs: Fix use-after-free in path file creation cleanup (bsc#1273134). - CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). - CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). - CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). - CVE-2026-64055,CVE-2026-64056: net: ethernet: cortina: Make RX SKB per-port (bsc#1272502 bsc#1272893). - CVE-2026-64055: net: ethernet: cortina: Drop half-assembled SKB (bsc#1272893). - CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). - CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). - CVE-2026-64099: drm/v3d: Fix use-after-free of CPU job query arrays on error path (bsc#1273465). - CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). - CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). - CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). - CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). - CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). - CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). - CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). - CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). - CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). - CVE-2026-64131: mm/memory: fix spurious warning when unmapping device-private/exclusive pages (bsc#1274063). - CVE-2026-64136: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (bsc#1272351). - CVE-2026-64146: erofs: fix metabuf leak in inode xattr initialization (bsc#1273681). - CVE-2026-64148: pds_core: check health in devcmd wait (bsc#1273956). - CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). - CVE-2026-64180: mm/memory_hotplug: fix memory block reference leak on remove (bsc#1273679). - CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). - CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (bsc#1272150). - CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). - CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). - CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). - CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). - CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). - CVE-2026-64224: octeontx2-pf: fix double free in rvu_rep_rsrc_init() (bsc#1272804). - CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). - CVE-2026-64244: drivers/base/memory: set mem->altmap after successful device registration (bsc#1273812). - CVE-2026-64245: fbdev: modedb: fix a possible UAF in fb_find_mode() (bsc#1273905). - CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). - CVE-2026-64269: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg (bsc#1273280). - CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). - CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). - CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). - CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). - CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). - CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968). - CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). - CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). - CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). - CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). - CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). - CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). - CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). - CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). - CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). - CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). - CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). - CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). - CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). - CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). - CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). - CVE-2026-64388: smb/client: fix chown/chgrp with SMB3 POSIX Extensions (bsc#1274061). - CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). - CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). - CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). - CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). - CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). - CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area (bsc#1273982). - CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). - CVE-2026-64452: 6lowpan: fix NHC entry use-after-free on error path (bsc#1273460). - CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). - CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). - CVE-2026-64477: x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled (bsc#1274264). - CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). - CVE-2026-64515: wifi: mac80211: fix MLE defragmentation (bsc#1273859). - CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). - CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). - CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). - CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). - CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). - CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). - CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). - CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). - CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). - CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). - CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). - CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). - CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). - CVE-2026-64569: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (bsc#1274009). - CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). - CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). - CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). - CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). - CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). - CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). - CVE-2026-64597: smb: client: fix double-free in SMB2_close() replay (bsc#1274297). - CVE-2026-64598: smb/client: Fix error code in smb2_aead_req_alloc() (bsc#1274298). - CVE-2026-68081: KVM: nVMX: Add helper to put (unmap) vmcs12 pages (bsc#1274580). - CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). - CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). - CVE-2026-68105: drm/amdgpu: Fix kernel panic during driver load failure (bsc#1274849). - CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). - CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). - CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). - CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). - CVE-2026-68124: mctp: serial: handle zero-length frames to prevent rx buffer overflow (bsc#1275192). - CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). - CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). - CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). - CVE-2026-68135: net: hip04: fix RX buffer leak on build_skb failure (bsc#1275557). - CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). - CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). - CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). - CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). - CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). - CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). - CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). - CVE-2026-68152: amt: fix use-after-free in AMT delayed works (bsc#1275300). - CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). - CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). - CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). - CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). - CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). - CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). - CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). - CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). - CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). - CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). - CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). - CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). - CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). - CVE-2026-68247: drm/i915/bios: range check LFP Data Block panel_type2 (bsc#1275817). - CVE-2026-68254: drm/i915/vrr: require valid min/max vfreq for VRR (bsc#1275150). - CVE-2026-68267: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (bsc#1275139). - CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). - CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). - CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). - CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). - CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). - CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). - CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). - CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). - CVE-2026-68302: amt: re-read skb header pointers after every pull (bsc#1275081). - CVE-2026-68312: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths (bsc#1274663). - CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). - CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). - CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). - CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). - CVE-2026-68324: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (bsc#1274649). - CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). - CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). - CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). - CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). - CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). - CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). - CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). - CVE-2026-68343: smb: client: validate DFS referral PathConsumed (bsc#1274629). - CVE-2026-68375: bnxt_en: Handle partially initialized auxiliary devices (bsc#1274835). - CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). - CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). - CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). - CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). - CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). - CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). - CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). - CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). - CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). - CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). - CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). - CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). - CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). - CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). - CVE-2026-68470: wifi: cfg80211/mac80211: correctly parse S1G beacon optional elements (bsc#1276500). - CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). - CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). - CVE-2026-72032: net/mlx5: HWS, fix matcher leak on resize target setup failure (bsc#1276955). - CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). - CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). - CVE-2026-72046: gve: fix header buffer corruption with header-split and HW-GRO (bsc#1275519). - CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). - CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). - CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). - CVE-2026-72084: scsi: target: Bound PR-OUT TransportID parsing to the received buffer (bsc#1275540). - CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). - CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). - CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). - CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). - CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). - CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). - CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678). - CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). - CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). - CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). - CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). - CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). - CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). - CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). - CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). - CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). - CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). - CVE-2026-72463: xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276 bsc#1277064). - CVE-2026-72464: xprtrdma: Remove temp allocation of rpcrdma_rep objects (bsc#1277069). - CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). - CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). - CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). - CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). - CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). - CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). - CVE-2026-72496: RDMA/bnxt_re: Proper rollback if the ioremap fails (bsc#1276943). - CVE-2026-72497: RDMA/bnxt_re: Add a max slot check for SQ (bsc#1276913). - CVE-2026-72498: RDMA/bnxt_re: Avoid displaying the kernel pointer (bsc#1276912). - CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). - CVE-2026-72500: RDMA/bnxt_re: Free SRQ toggle page after firmware teardown (bsc#1276552). - CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). - CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). - CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). - CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). - CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). - CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). - CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). - CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). - CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). - CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). - CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). - CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). - CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). - CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). - CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (bsc#1276346). - CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). - CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). - CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). - CVE-2026-74509: Bluetooth: hci_sync: Fix advertising data UAFs (bsc#1275946). - CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). - CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). - CVE-2026-74516: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (bsc#1275797). - CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). - CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). - CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). - CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). - CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). - CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). - CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). - CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). - CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). - CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). - CVE-2026-74577: net: mpls: initialize rtm_tos in mpls_getroute() (bsc#1275572). - CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). - CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). - CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). - CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). - CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). - CVE-2026-74692: net/smc: fix TOCTOU race between smc_listen_out() and listener close (bsc#1276927). - CVE-2026-74694: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (bsc#1277625). - CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). - CVE-2026-74712: vdpa/mlx5: Fix buffer length in create_direct_keys() (bsc#1276577). - CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). - CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). - CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). - CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). - CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). - CVE-2026-80654: soc: xilinx: Shutdown and free rx mailbox channel (bsc#1277516). The following non security issues were fixed: - accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). - accessibility: speakup: unregister tty ldisc on later init failures (git-fixes). - ACPI: APEI: Fix ERST timeout unit conversion (git-fixes). - ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). - ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git-fixes). - ACPI: pfr_update: fix stack buffer overflow in query_capability() (git-fixes). - ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). - ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). - ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). - ACPI: video: Release PCI device reference after lookup (git-fixes). - add my missing Reviewed-by: tag. - ALSA: 6fire: bound the MIDI event length from the device (git-fixes). - ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). - ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). - ALSA: control: Don't add invalid kcontrols to LED layer (git-fixes). - ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). - ALSA: dummy: Check card index validity at probe (stable-fixes). - ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). - ALSA: hda: Fix connection list comparison in proc output (git-fixes). - ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). - ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). - ALSA: scarlett2: Use a private URB for the notification endpoint (git-fixes). - ALSA: seq: Don't leak the extension cell pointer in the bounce payload (git-fixes). - ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). - ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). - ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). - ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). - ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). - ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). - ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). - ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git-fixes). - apparmor: advertise the tcp fast open fix is applied (git-fixes). - arm64: Exclude nohz_full CPUs from 32bits el0 support (bsc#1269313). - ASoC: adau1761: sort the register default table (git-fixes). - ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). - ASoC: apple: mca: increase SERDES reset delay (git-fixes). - ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). - ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). - ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). - ASoC: cs35l41: sort the register default table (git-fixes). - ASoC: cs35l45: sort the register default table (git-fixes). - ASoC: cs4265: sort the register default table (git-fixes). - ASoC: cx2072x: sort the register default table (git-fixes). - ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). - ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git-fixes). - ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git-fixes). - ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). - ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). - ASoC: fsl_easrc: sort the register default table (git-fixes). - ASoC: hdac_hda: Fix hlink refcount leak on component registration failure (git-fixes). - AsoC: intel: sst: fix PCI device reference leak on probe failure (git-fixes). - ASoC: max9860: sort the register default table (git-fixes). - ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). - ASoC: ml26124: sort the register default table (git-fixes). - ASoC: pcm512x: sort the register default table (git-fixes). - ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). - ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git-fixes). - ASoC: rt274: sort the register default table (git-fixes). - ASoC: rt286: sort the register default table (git-fixes). - ASoC: rt298: sort the register default table (git-fixes). - ASoC: rt700-sdw: always drain jack work on remove (git-fixes). - ASoC: rt700: drop duplicate reg_default entry (git-fixes). - ASoC: rt700: sort the register default table (git-fixes). - ASoC: rt711-sdca: sort the register default tables (git-fixes). - ASoC: rt711: sort the register default table (git-fixes). - ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). - ASoC: rt712-sdca-sdw: sort the register default table (git-fixes). - ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). - ASoC: rt715-sdca: sort the register default tables (git-fixes). - ASoC: rt715: sort the register default table (git-fixes). - ASoC: rt1017-sdca-sdw: sort the register default table (git-fixes). - ASoC: rt1316-sdw: sort the register default table (git-fixes). - ASoC: rt1318-sdw: sort the register default table (git-fixes). - ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). - ASoC: sgtl5000: sort the register default table (git-fixes). - ASoC: SOF: pcm: Move period/buffer configuration print after platform open (stable-fixes). - ASoC: sof: pcm: use snd_pcm_direction_name() (stable-fixes). - ASoC: SOF: Relocate and rework functionality for PCM stream freeing (stable-fixes). - ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git-fixes). - ASoC: SOF: validate topology volume range before allocation (git-fixes). - ASoC: sti-sas: sort the register default table (git-fixes). - ASoC: tas2552: sort the register default table (git-fixes). - ASoC: tas2764: sort the register default table (git-fixes). - ASoC: tas2780: sort the register default table (git-fixes). - ASoC: tegra210_i2s: sort the register default table (git-fixes). - ASoC: tegra210_mixer: sort the register default table (git-fixes). - ASoC: tegra: Fix the MIXER enable default value (git-fixes). - ASoC: tegra: Sort MBDRC register defaults (git-fixes). - ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). - ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). - batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). - batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). - batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). - batman-adv: fix stale receive device on merged fragments (git-fixes). - Bluetooth: btintel: Fix diagnostics event detection (git-fixes). - Bluetooth: btmtk: Do not discard the subsystem reset timeout (git-fixes). - Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() (stable-fixes). - Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). - Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git-fixes). - Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git-fixes). - Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git-fixes). - Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). - Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). - Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378 (git-fixes). - Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_conn: fix the SCO setup context lifetime (git-fixes). - Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). - Bluetooth: hci_conn: re-enable advertising only for peripheral role (git-fixes). - Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb (git-fixes). - Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git-fixes). - Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). - Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). - Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request (git-fixes). - Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). - Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). - Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git-fixes). - Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). - Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). - Bluetooth: MSFT: validate evt_prefix_len against the response length (git-fixes). - Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). - Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git-fixes). - Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). - Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). - bnxt_en: Adjust TX rings if reservation is less than requested (jsc#PED-16798). - bnxt_en: Delay for 5 seconds after AER DPC for all chips (jsc#PED-16798). - bnxt_en: Don't assume XDP is never enabled in bnxt_init_dflt_ring_mode() (jsc#PED-16798). - bnxt_en: Drop pci_save_state() after pci_restore_state() (jsc#PED-16798). - bnxt_en: Implement XDP RSS hash metadata extraction (jsc#PED-16798). - bnxt_en: Implement XDP RSS hash metadata extraction for V3_CMP (jsc#PED-16798). - bnxt_en: Move bnxt_rss_ext_op into header (jsc#PED-16798). - bnxt_en: Refactor some basic ring setup and adjustment logic (jsc#PED-16798). - bnxt_en: Restore default stat ctxs for ULP when resource is available (jsc#PED-16798). - bnxt_en: Set bp->max_tpa according to what the FW supports (jsc#PED-16798). - bnxt_en: Use absolute target ns from ptp_clock_request (jsc#PED-16798). - bnxt_en: use bnxt_xdp_buff for xdp context (jsc#PED-16798). - bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). - bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). - bus: ti-sysc: Fix /chosen node reference leak (git-fixes). - cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). - can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). - cpufreq: intel_pstate: Use correct scaling factor on Raptor Lake-E (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Use CPPC to get scaling factors (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Use HYBRID_SCALING_FACTOR_ADL for Bartlett Lake (bsc#1240957 bsc#1249104 bsc#1265220). - crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). - crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git-fixes). - crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). - crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). - crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). - crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). - crypto: doc - Remove extra parenthesis (git-fixes). - crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). - crypto: keembay - Initialize completion before requesting IRQ (git-fixes). - crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). - crypto: mxs-dcp - fix source scatterlist length access (git-fixes). - crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). - crypto: qat - clear AES key schedule from stack (git-fixes). - crypto: qce - fix CCM AAD buffer underallocation (git-fixes). - crypto: qce - fix error path in devm_qce_register_algs (git-fixes). - crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). - crypto: sa2ul - stop probe if context pool creation fails (git-fixes). - crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git-fixes). - device property: fix infinite loop in fwnode_for_each_child_node() (git-fixes). - dmaengine: dw-edma: Clear stale requests on termination (git-fixes). - dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). - dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). - dmaengine: dw-edma: Serialize abort state updates (git-fixes). - dmaengine: dw-edma: Serialize channel state checks (git-fixes). - dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). - dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). - dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). - dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). - dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). - driver core: soc: Unregister bus on early device registration failure (git-fixes). - drm/amd/display: Add AV mute wait frames to dce110_set_avmute (stable-fixes). - drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). - drm/amd/display: Check for tg ops in dce110_set_avmute (git-fixes). - drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix (git-fixes). - drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE (git-fixes). - drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank() (git-fixes). - drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames (stable-fixes). - drm/amd/display: Remove unused-but-set variable hubp from (git-fixes). - drm/amd/display: validate plane degamma LUT size for private color prop (git-fixes). - drm/amd/pm: adjust the visibility of pp_table sysfs node (stable-fixes). - drm/amd/pm: Use same metric table for APU (stable-fixes). - drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git-fixes). - drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). - drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). - drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). - drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git-fixes). - drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git-fixes). - drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git-fixes). - drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). - drm/amdgpu: check ASPM on the dGPU host link (git-fixes). - drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). - drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). - drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). - drm/amdgpu: fix nbif 6.3.1 l1 low power not functional (git-fixes). - drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). - drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). - drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). - drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). - drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). - drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini (git-fixes). - drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 (git-fixes). - drm/amdgpu: reject oversized IBs with per-ring packet limits (stable-fixes). - drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). - drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable-fixes). - drm/amdgpu: remove unused function parameter (stable-fixes). - drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). - drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). - drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). - drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). - drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore (git-fixes). - drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). - drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). - drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). - drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). - drm/bridge: tc358767: clamp the reported AUX read size to the request (git-fixes). - drm/connector/hdmi: Fix out of bounds memory read (git-fixes). - drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). - drm/hibmc: Fix list of formats on the primary plane (git-fixes). - drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). - drm/i915/fbc: Extract intel_fbc_has_fences() (stable-fixes). - drm/i915/hdcp: check streams bounds before overflow (git-fixes). - drm/i915/hdcp: Move to using intel_display in intel_hdcp (stable-fixes). - drm/i915/hdcp: require monotonically increasing seq_num_v (git-fixes). - drm/i915/hdcp: Skip inactive MST connectors when building stream list (stable-fixes). - drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() (stable-fixes). - drm/i915/vrr: require valid min/max vfreq for VRR (git-fixes). - drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). - drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg (git-fixes). - drm/msm/a6xx: Fix stale rpmh votes after suspend (git-fixes). - drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). - drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). - drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git-fixes). - drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). - drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). - drm/panthor: fix firmware control interface bounds checks (git-fixes). - drm/panthor: return PTR_ERR() from devm_drm_dev_alloc() (git-fixes). - drm/panthor: skip zero-sized firmware sections (git-fixes). - drm/radeon: fix autosuspend cleanup during teardown (git-fixes). - drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). - drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). - drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). - drm/ssd130x: fix column and row end address in partial updates in ssd133x (git-fixes). - drm/sun4i: crtc: Propagate layer initialization error (git-fixes). - drm/sun4i: Drop node references while building component list (git-fixes). - drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). - drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). - drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). - drm/sun4i: hdmi: Don't leak sync polarity bits into packet control (git-fixes). - drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). - drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). - drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). - drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). - drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). - drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info (git-fixes). - drm/tve200: add OF module alias for autoloading (git-fixes). - drm/xe/oa: Check managed mutex initialization errors (git-fixes). - drm/xe/oa: Fix sync entry leak on OA config emit failure (git-fixes). - drm/xe: Introduce xe_gt_dbg_printer() (stable-fixes). - drm/xe: Order ring writes before ring tail updates (git-fixes). - drm/xe: Stub out new pagefault layer (stable-fixes). - drm/xe: tests: fix error message in xe_migrate_sanity_test() (git-fixes). - drm: fix race between partial drm_dev_register() failure and ioctl (git-fixes). - drm: lcdif: Wait for vblank before disabling DMA (git-fixes). - drm: Remove unused header in drm_dumb_buffers.c (git-fixes). - ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). - fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). - fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). - fbdev: kyro: Validate overlay viewport coordinates (git-fixes). - fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). - fbdev: ssd1307fb: defer I2C transfers from damage callbacks (git-fixes). - fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). - fbdev: uvesafb: unregister connector callback on init failure (git-fixes). - firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). - firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). - firmware: arm_scmi: Fix requested device removal race (git-fixes). - firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). - firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). - firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). - firmware: arm_scmi: Unregister device notifier before IDR teardown (git-fixes). - firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). - firmware_loader: do not queue completed sysfs fallback requests (git-fixes). - fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git-fixes). - fpga: dfl: fme: add error handling (git-fixes). - fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git-fixes). - gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). - gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). - HID: core: fix number/pointer type confusion on long items (git-fixes). - HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). - HID: hyperv: validate initial device info bounds (git-fixes). - HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). - HID: lg4ff: validate report length before fixed offsets (git-fixes). - HID: logitech-dj: Fix maxfield check in DJ short report validation (git-fixes). - HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git-fixes). - HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). - HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable-fixes). - HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). - HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git-fixes). - HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). - HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). - HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git-fixes). - HID: picolcd: clamp eeprom debugfs read to bytes actually received (git-fixes). - HID: roccat: bound device-supplied profile index (git-fixes). - HID: roccat: free buffered reports when destroying device (git-fixes). - HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git-fixes). - HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). - HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). - HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). - hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). - hwmon: (lm25066) Use i2c_get_match_data() (stable-fixes). - hwmon: (max6621) fix negative temperature offset and crit readings (git-fixes). - hwmon: (max6621) fix temperature clamp range (git-fixes). - hwmon: (nzxt-smart2) Check return value of init_device() in probe (git-fixes). - hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). - hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). - hwrng: omap - Fix probe error path cleanup (git-fixes). - hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git-fixes). - i2c: bcm-iproc: remove printout on handled timeouts (stable-fixes). - i2c: core: fix debugfs UAF on adapter removal (git-fixes). - i2c: iproc: reset bus after timeout if START_BUSY is stuck (git-fixes). - i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). - i2c: mux: Fix channel node leak on adapter add failure (git-fixes). - i2c: ocores: Disable clock on failed resume (git-fixes). - i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). - i3c: master: Fix device_register() error path (git-fixes). - i3c: master: Fix info leak and UAF in device unregister path (git-fixes). - i3c: master: Fix potential UAF in i3c_device_uevent() (git-fixes). - i3c: master: svc: bound IBI payload to the requested max_payload_len (git-fixes). - ibmvnic: Only record tx completed bytes once per handler (bsc#1274620). - iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). - iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). - iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). - iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). - iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). - iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). - iio: light: cm32181: return zero after writing calibscale (git-fixes). - iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). - iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). - iio: light: isl29028: return zero in write_raw() on success (git-fixes). - iio: light: tsl2583: return zero in write_raw() on success (git-fixes). - iio: light: tsl2772: fix ALS calibscale readback (git-fixes). - iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). - iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git-fixes). - iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). - iio: srf04: fix pm_runtime handling on probe error path (git-fixes). - iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). - Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). - Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). - Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). - Input: evdev - sanitize event type index when fetching event masks (stable-fixes). - Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). - Input: focaltech - use signed coordinates to prevent underflow (git-fixes). - Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). - Input: iforce - validate input packet lengths (stable-fixes). - Input: iqs5xx - validate firmware record destination span (git-fixes). - Input: mms114 - fix Y-resolution configuration (git-fixes). - Input: psxpad-spi - set driver data before use (git-fixes). - Input: sur40 - fix input device registration ordering (stable-fixes). - Input: sur40 - fix V4L error path cleanup (stable-fixes). - Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). - Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). - Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git-fixes). - Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git-fixes). - Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). - Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). - interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). - ipmi: ipmb: validate write message length (git-fixes). - ipmi: si: Fix NULL pointer dereference after failed registration (git-fixes). - kthread: Default affine kthread to its preferred NUMA node (bsc#1269313). - kthread: Make sure kthread hasn't started while binding it (bsc#1269313). - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - KVM: PPC: Book3S HV: Add support for compat CPU capabilities for KVM on PowerNV (bsc#1263864 ltc#217835). - KVM: PPC: Book3S HV: Implement compat CPU capability retrieval for KVM on PowerVM (bsc#1263864 ltc#217835). - KVM: PPC: Book3S HV: Validate arch_compat against host compatibility mode (bsc#1263864 ltc#217835). - KVM: PPC: Document KVM_PPC_GET_COMPAT_CAPS ioctl (bsc#1263864 ltc#217835). - KVM: PPC: Introduce KVM_CAP_PPC_COMPAT_CAPS and wire up ioctl (bsc#1263864 ltc#217835). - KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). - leds: pca9532: Fix inverted GPIO output polarity (git-fixes). - leds: pca9532: Fix phantom device registration on missing hardware (git-fixes). - lib/string: fix memchr_inv() for large ranges (git-fixes). - lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). - mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git-fixes). - mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). - maple_tree: fix argument name in header (git-fixes). - md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). - media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). - media: amphion: Remove obsolete frame_count check in venc_start_session (git-fixes). - media: cec-pin: Fix event FIFO ordering (git-fixes). - media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). - media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). - media: cec: Serialize exclusive follower delivery (git-fixes). - media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). - media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). - media: cobalt: Avoid freeing ALSA private data twice (git-fixes). - media: cx231xx: reject geometry changes while the VBI queue is busy (git-fixes). - media: cx23885: cancel NetUP CI work before teardown (git-fixes). - media: em28xx: defer audio-only extension registration (git-fixes). - media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git-fixes). - media: go7007: defer the ALSA v4l2 put until card release (git-fixes). - media: i2c: imx219: Rename VTS to FRM_LENGTH (stable-fixes). - media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). - media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). - media: i2c: rdacm21: Fix missing media_entity_cleanup() (git-fixes). - media: imx219: Fix maximum frame length in lines (git-fixes). - media: intel/ipu6: fix async notifier cleanup leak on parse error (git-fixes). - media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git-fixes). - media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). - media: mc-entity: Add missing kerneldoc (git-fixes). - media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git-fixes). - media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). - media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). - media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). - media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). - media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). - media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). - media: s2255: bound JPEG frame size before copying into the buffer (git-fixes). - media: s2255: check firmware size before reading trailing marker (git-fixes). - media: saa7164: fix cleanup on resource allocation failure (git-fixes). - media: tda18250: fix possible integer overflow (git-fixes). - media: usbtv: keep device alive while ALSA card exists (git-fixes). - media: v4l2-async: avoid deleting unlinked ASC entry on link error (git-fixes). - media: v4l2-async: Unregister sub-device if asc_list is empty (git-fixes). - media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git-fixes). - media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). - media: venus: fix payload size calculation in parse_raw_formats() (git-fixes). - media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). - media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). - media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). - media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). - media: zoran: Avoid freeing a registered video_device twice (git-fixes). - mei: pull kvfree out of spinlock (git-fixes). - mfd: iqs62x: Reject zero-length firmware records (git-fixes). - mfd: rave-sp: validate received frame payload lengths (git-fixes). - misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). - misc: fastrpc: fix channel ctx ref leak when session alloc fails (git-fixes). - misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). - misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). - misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git-fixes). - misc: rtsx: add missing write register handling (git-fixes). - misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git-fixes). - mkspec-dtb: Move DTS prefix into package list. - mkspec-dtb: Move provides-obsoletes to package list. - mkspec-dtb: Put per-architecture package lists into a hash. - mkspec-dtb: re-indent. - mm: Create/affine kcompactd to its preferred node (bsc#1269313). - mm: Create/affine kswapd to its preferred node (bsc#1269313). - mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git-fixes). - mmc: sdhci: unmap the bounce buffer before device release (git-fixes). - mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). - mtd: afs: validate v2 image info bounds (git-fixes). - mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). - mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). - mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). - mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). - net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). - net: mana: Add handler for sriov configure (bsc#1272756). - net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). - net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). - net: mana: Fall back to scattered pages for GDMA queues (git-fixes). - net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). - net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). - net: mana: Route ring-buffer access through offset-based helpers (git-fixes). - net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). - net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git-fixes). - net: thunderbolt: Mark the connection down when bringing it up fails (git-fixes). - net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git-fixes). - net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). - net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). - net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). - nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). - nfc: digital: Do not dump a NULL response in command completion (git-fixes). - nfc: fdp: bound the device-reported read length and fix an skb leak (git-fixes). - nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). - nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git-fixes). - nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). - nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). - nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git-fixes). - nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). - nfc: microread: validate target discovery payload lengths (git-fixes). - nfc: nci: fix double completion race in nci_data_exchange_complete (git-fixes). - nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git-fixes). - nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git-fixes). - nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git-fixes). - nfc: nci: free destination parameters when closing a connection (git-fixes). - nfc: pn533: hold a reference to the request skb during send_frame (git-fixes). - nfc: pn533: purge fragmented skbs during cleanup (git-fixes). - nfc: st21nfca: validate ATR_REQ length against the received frame (git-fixes). - nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git-fixes). - of: fix out-of-bounds read in of_alias_scan() stem parser (git-fixes). - PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). - PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk (git-fixes). - PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git-fixes). - PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). - PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). - phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs (git-fixes). - phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (git-fixes). - phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table (git-fixes). - phy: sunplus: fix error handling in sp_uphy_init() (git-fixes). - pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). - pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). - pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). - pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). - pinctrl: rockchip: Reset the pin count when recalculating SoC data (git-fixes). - platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). - platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). - platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git-fixes). - platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). - platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git-fixes). - platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). - platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git-fixes). - platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). - platform/x86/amd/hsmp: Reject negative power cap writes in hwmon (git-fixes). - platform/x86: dell-privacy: Fix race condition (git-fixes). - platform/x86: dell-wmi-base: Fix resource leak on module load failure (git-fixes). - platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). - platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). - platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS (git-fixes). - platform/x86: hp-bioscfg: advance elem past consumed array elements (git-fixes). - platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() (git-fixes). - platform/x86: hp-bioscfg: fix heap OOB read on empty password write (git-fixes). - platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password (git-fixes). - platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() (git-fixes). - platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed (git-fixes). - platform/x86: hp-bioscfg: fix password encoding bounds check (git-fixes). - platform/x86: hp-bioscfg: warn on element type mismatch instead of failing (git-fixes). - platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). - platform/x86: ISST: Add a NULL check for sst_inst (git-fixes). - platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). - platform/x86: ISST: Return error during profile addition (git-fixes). - platform/x86: ISST: Use PP level enable mask (git-fixes). - platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). - platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). - platform/x86: ISST: Validate parameter for core power state (git-fixes). - platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). - PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). - power: supply: bd99954: Drop bad register fields (git-fixes). - power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git-fixes). - power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git-fixes). - power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). - power: supply: bq256xx: drain usb_work before freeing the charger (git-fixes). - power: supply: bq24257: fix use-after-free on remove (git-fixes). - power: supply: bq25890: Fix power_supply reference leak (git-fixes). - power: supply: cros_usbpd-charger: bound the EC-reported port count (git-fixes). - power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git-fixes). - power: supply: isp1704_charger: cancel work on remove (git-fixes). - power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git-fixes). - power: supply: max17040: drop incorrect I2C functionality check (git-fixes). - power: supply: max17040: synchronize work cancellation on suspend (git-fixes). - power: supply: qcom_battmgr: terminate the strings from firmware (git-fixes). - power: supply: rt9455: quiesce delayed work before teardown (git-fixes). - power: supply: sbs-battery: Use a per-device serial number buffer (git-fixes). - power: supply: twl4030_charger: cancel workers via devm (git-fixes). - power: supply: ucs1002: fix use-after-free on remove (git-fixes). - powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). - powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors (bsc#1263864 ltc#217835). - powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). - powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). - powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). - powerpc: Replace __ASSEMBLY__ with __ASSEMBLER__ in non-uapi headers (bsc#1263864 ltc#217835). - powerpc: Replace __ASSEMBLY__ with __ASSEMBLER__ in uapi headers (bsc#1263864 ltc#217835). - ppdev: prevent overflow when setting port timeout (git-fixes). - qede: fix out-of-bounds check for cqe->len_list (git-fixes). - rapidio: clear mport->net when rio_add_net() fails (git-fixes). - rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). - RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). - RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). - RDMA/mana_ib: unify QP lookup table (git-fixes). - RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). - regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). - regulator: core: use system_freezable_wq for init complete work (git-fixes). - regulator: devres: add API for reference voltage supplies (stable-fixes). - regulator: devres: fix devm_regulator_get_enable_read_voltage() return (git-fixes). - regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). - regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). - remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). - remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). - remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). - Revert 'drm/amdgpu: fix aperture mapping leak' (git-fixes). - Revert 'media: v4l2-dev: fix error handling in __video_register_device()' (git-fixes). - Revert 'thermal/drivers/hwmon: Cleanup coding style a bit' (stable-fixes). - rpmsg: core: Fix incorrect return value documentation (git-fixes). - rpmsg: glink: smem: order FIFO read after availability check (git-fixes). - rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). - rtc: pcf8563: fix clock provider leak on unbind (git-fixes). - rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). - rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). - rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git-fixes). - rtc: zynqmp: Return optional clock lookup errors (git-fixes). - sched,arm64: Handle CPU isolation on last resort fallback rq (bsc#1269313). - scsi: fnic: Abort timed-out NVMe LS requests (bsc#1236344). - scsi: fnic: Add FDLS role handling for NVMe initiators (bsc#1236344). - scsi: fnic: Add the NVMe/FC transport path (bsc#1236344). - scsi: fnic: Advertise NVMe initiator service parameters (bsc#1236344). - scsi: fnic: Bump up version number (bsc#1236344). - scsi: fnic: Decode firmware role configuration (bsc#1236344). - scsi: fnic: Do not use GFP_ZERO for mempools (bsc#1236344). - scsi: fnic: Expose NVMe transport state in debugfs (bsc#1236344). - scsi: fnic: Handle NVMe LS frames in FDLS (bsc#1236344). - scsi: fnic: Make debug logging protocol independent (bsc#1236344). - scsi: fnic: Make fnic_queuecommand() easier to analyze (bsc#1236344). - scsi: fnic: Refactor in_remove flag and call to fnic_fcpio_reset() (bsc#1236344). - scsi: fnic: Remove a useless struct mempool forward declaration (bsc#1236344). - scsi: fnic: Rename fnic_scsi_fcpio_reset() (bsc#1236344). - scsi: fnic: Route completions and resets by initiator role (bsc#1236344). - scsi: fnic: Self-assignment of intr_time_type has no effect (bsc#1236344). - scsi: fnic: Send NVMe LS requests through FDLS (bsc#1236344). - scsi: fnic: Switch to use %ptSp (bsc#1236344). - scsi: fnic: Track NVMe transport statistics (bsc#1236344). - scsi: fnic: Use fnic_num for non-SCSI identifiers (bsc#1236344). - scsi: fnic: Use mempool for receive frames (bsc#1236344). - scsi: qla2xxx: Declare qla2xxx_mqueuecommand() static (bsc#1275737). - scsi: qla2xxx: Use nr_cpu_ids instead of NR_CPUS for qp_cpu_map allocation (bsc#1275737). - scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). - sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). - serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). - serial: amba-pl011: unprepare console clock on unregister (git-fixes). - serial: core: clear freed pointers on uart_register_driver() failure (git-fixes). - serial: qcom-geni: fix TX DMA buffer flush (git-fixes). - serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants (stable-fixes). - smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). - smb: client: reject overlapping data areas in SMB2 responses (git-fixes). - smb: client: require net admin for CIFS SWN netlink (bsc#1273966). - smb: client: resolve SWN tcon from live registrations (bsc#1273872). - soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git-fixes). - soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). - soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). - software node: Fix software_node_get_reference_args() with index -1 (git-fixes). - soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git-fixes). - speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git-fixes). - spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). - spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). - spi: sprd-adi: Fix probe succeeding without registering the controller (git-fixes). - staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). - staging: media: tegra-video: fix of_node_put() on VIP parse errors (git-fixes). - staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). - staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git-fixes). - staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). - staging: rtl8723bs: fix missing shared-key auth challenge length check (git-fixes). - staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). - staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). - staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). - staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). - staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). - thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). - thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). - thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). - thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). - thunderbolt: Fix bandwidth group reservation indexing (git-fixes). - thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). - tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). - tpm: st33zp24: Return zero on status read failure (git-fixes). - tpm: st33zp24: Validate locality read result (git-fixes). - tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). - tty: clear cdev pointer after cdev_add() failure (git-fixes). - tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). - tty: skip cdev_del() when no cdev is registered (git-fixes). - uaccess: add copy_struct_to_user helper (bsc#1263864 ltc#217835). - uaccess: fix ignored_trailing logic in copy_struct_to_user() (bsc#1263864 ltc#217835). - uio: Fix stale info pointer in failed registration path (git-fixes). - usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). - usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). - USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). - usb: cdnsp: fix incorrect endian conversions for APB timeout register (git-fixes). - usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). - usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). - usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). - usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). - usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). - usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). - usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git-fixes). - usb: gadget: pch_udc: remove excess kernel-doc member for registered (git-fixes). - usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). - usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). - usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git-fixes). - usb: gadget: uac: validate rate list length before storing (git-fixes). - usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). - usb: mtu3: allow system suspend during active gadget connection (git-fixes). - usb: musb: omap2430: clean up probe error handling (stable-fixes). - USB: phy: fsl-usb: fix missing static keywords (git-fixes). - usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). - USB: serial: digi_acceleport: fix port registration order (git-fixes). - USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). - USB: serial: option: add TDTECH MT5710-CN (stable-fixes). - USB: serial: option: fix slab OOB read in interrupt URB callback (git-fixes). - USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). - USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). - usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive() (git-fixes). - usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). - usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git-fixes). - usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). - vt: add permission check for KDSKBMETA ioctl (stable-fixes). - vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable-fixes). - w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). - w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). - wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). - wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). - wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). - wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). - wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git-fixes). - wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). - wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). - wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). - wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). - wifi: brcmfmac: fix P2P action frame handling without device vif (git-fixes). - wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). - wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). - wifi: iwlwifi: mei: check SAP message length before reading it (git-fixes). - wifi: iwlwifi: mei: pass correct argument to function (git-fixes). - wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). - wifi: mac80211: disconnect on CSA to channel 0 (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix per-STA profile length in cross-link CSA parsing (git-fixes). - wifi: mac80211: send TWT teardown to peer after setup TX failure (git-fixes). - wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). - wifi: mac80211: skip unused probe response countdown offsets (git-fixes). - wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). - wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). - wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). - wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git-fixes). - wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). - wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git-fixes). - wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git-fixes). - wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). - wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git-fixes). - wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git-fixes). - wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). - wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). - wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git-fixes). - wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). - wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git-fixes). - wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). - wifi: mt76: mt7921: validate CLC firmware records (git-fixes). - wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git-fixes). - wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git-fixes). - wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git-fixes). - wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). - wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU (git-fixes). - wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). - wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git-fixes). - wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). - wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git-fixes). - wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). - wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). - wifi: rtl818x: initialize eeprom_93cx6 struct to zero (git-fixes). - wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). - wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). - wifi: rtw89: fix HE extended capability length check (git-fixes). - wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git-fixes). - x86/bugs: Clarify that syscall hardening isn't a BHI mitigation (git-fixes). - x86/cpu: Add CPU model number for Bartlett Lake CPUs with Raptor Cove cores (bsc#1240957 bsc#1249104 bsc#1265220). - xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). - xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). The following package changes have been done: - glibc-locale-base-2.38-150600.14.58.1 updated - glibc-2.38-150600.14.58.1 updated - kernel-default-6.4.0-150700.53.81.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated From sle-container-updates at lists.suse.com Sat Sep 19 10:09:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 19 Sep 2026 12:09:13 +0200 (CEST) Subject: SUSE-CU-2026:10907-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260919100913.4C6AAFF19@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:10907-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-61.21 , bci/bci-sle15-kernel-module-devel:latest Container Release : 61.21 Severity : important Type : security References : 1230238 1235944 1236344 1240957 1241363 1247180 1247455 1249104 1250748 1251130 1251966 1252682 1253454 1254306 1255225 1255250 1256629 1256708 1257055 1257154 1258430 1258472 1258517 1260522 1261562 1261780 1262073 1262432 1263004 1263052 1263061 1263133 1263864 1264010 1264012 1264335 1264446 1264541 1264587 1264619 1264643 1264740 1264807 1265068 1265121 1265220 1265449 1265928 1266402 1266860 1266874 1266897 1267023 1267236 1267238 1267501 1267505 1267610 1267612 1268276 1268972 1268979 1268987 1269004 1269013 1269108 1269113 1269114 1269126 1269140 1269167 1269234 1269238 1269242 1269256 1269301 1269306 1269313 1269381 1269388 1269402 1269412 1269530 1269579 1269590 1269635 1269647 1269655 1269665 1269686 1269695 1269713 1269731 1269774 1269783 1269792 1269815 1269888 1269965 1269969 1269981 1269985 1270090 1270108 1270111 1270251 1270263 1270268 1271256 1271365 1271366 1271825 1271830 1272150 1272175 1272179 1272182 1272200 1272210 1272213 1272230 1272260 1272261 1272262 1272297 1272346 1272351 1272359 1272381 1272383 1272385 1272390 1272423 1272429 1272484 1272486 1272497 1272502 1272516 1272569 1272571 1272618 1272641 1272643 1272662 1272673 1272680 1272682 1272756 1272786 1272788 1272798 1272799 1272804 1272868 1272877 1272891 1272893 1272963 1272983 1272993 1273005 1273008 1273019 1273027 1273028 1273030 1273032 1273033 1273036 1273037 1273038 1273053 1273054 1273060 1273105 1273134 1273249 1273250 1273260 1273273 1273274 1273276 1273277 1273280 1273281 1273284 1273285 1273289 1273291 1273294 1273302 1273303 1273305 1273310 1273311 1273316 1273318 1273319 1273323 1273325 1273327 1273334 1273335 1273336 1273337 1273338 1273340 1273341 1273346 1273422 1273426 1273443 1273460 1273463 1273465 1273468 1273469 1273471 1273479 1273480 1273482 1273484 1273488 1273490 1273501 1273503 1273504 1273506 1273523 1273525 1273533 1273536 1273542 1273555 1273578 1273579 1273581 1273582 1273596 1273597 1273598 1273600 1273601 1273602 1273603 1273679 1273681 1273682 1273734 1273738 1273739 1273741 1273742 1273743 1273745 1273748 1273749 1273755 1273762 1273765 1273766 1273769 1273774 1273778 1273780 1273790 1273796 1273797 1273801 1273804 1273810 1273811 1273812 1273813 1273817 1273822 1273824 1273831 1273832 1273834 1273838 1273844 1273849 1273859 1273860 1273862 1273867 1273868 1273869 1273872 1273876 1273877 1273880 1273882 1273890 1273891 1273892 1273895 1273896 1273903 1273905 1273930 1273933 1273934 1273935 1273936 1273939 1273940 1273941 1273942 1273944 1273945 1273946 1273956 1273957 1273958 1273966 1273967 1273968 1273972 1273974 1273975 1273977 1273982 1273988 1273990 1273991 1273995 1274001 1274003 1274006 1274008 1274009 1274010 1274011 1274012 1274014 1274017 1274019 1274020 1274026 1274028 1274030 1274031 1274035 1274040 1274041 1274055 1274057 1274058 1274061 1274063 1274065 1274067 1274071 1274075 1274076 1274077 1274078 1274208 1274226 1274239 1274243 1274258 1274264 1274265 1274267 1274274 1274277 1274278 1274281 1274283 1274286 1274290 1274294 1274295 1274296 1274297 1274298 1274314 1274321 1274491 1274497 1274539 1274541 1274543 1274545 1274547 1274550 1274573 1274578 1274580 1274581 1274620 1274622 1274624 1274629 1274632 1274636 1274639 1274640 1274642 1274644 1274645 1274646 1274649 1274650 1274651 1274656 1274659 1274662 1274663 1274665 1274667 1274670 1274675 1274677 1274678 1274679 1274681 1274682 1274690 1274694 1274696 1274698 1274699 1274700 1274702 1274703 1274705 1274706 1274709 1274710 1274713 1274716 1274721 1274723 1274725 1274726 1274737 1274738 1274749 1274752 1274753 1274754 1274755 1274756 1274764 1274768 1274770 1274783 1274787 1274800 1274801 1274802 1274804 1274805 1274807 1274808 1274811 1274813 1274814 1274831 1274834 1274835 1274847 1274849 1274853 1274868 1274869 1274872 1274873 1274874 1274876 1274877 1274879 1274881 1274883 1274886 1274888 1274891 1274892 1274893 1274894 1274895 1274896 1274897 1274898 1274899 1274901 1274902 1274905 1274906 1274907 1274908 1274913 1274914 1274920 1274921 1274924 1274925 1274929 1274930 1274933 1274934 1274935 1274941 1274945 1274947 1274951 1274953 1274958 1274968 1274981 1275040 1275069 1275071 1275073 1275076 1275080 1275081 1275083 1275088 1275091 1275125 1275126 1275131 1275132 1275139 1275141 1275146 1275148 1275149 1275150 1275152 1275154 1275155 1275156 1275157 1275158 1275161 1275163 1275164 1275169 1275173 1275176 1275185 1275190 1275192 1275236 1275237 1275239 1275294 1275300 1275301 1275303 1275304 1275305 1275306 1275307 1275470 1275472 1275474 1275479 1275483 1275486 1275487 1275506 1275509 1275511 1275517 1275519 1275528 1275535 1275540 1275553 1275555 1275557 1275561 1275566 1275569 1275572 1275574 1275578 1275582 1275583 1275584 1275591 1275595 1275633 1275636 1275650 1275656 1275659 1275665 1275669 1275687 1275688 1275695 1275696 1275704 1275737 1275782 1275784 1275787 1275788 1275789 1275790 1275797 1275798 1275805 1275817 1275818 1275819 1275820 1275821 1275822 1275823 1275827 1275864 1275867 1275869 1275870 1275871 1275872 1275886 1275905 1275923 1275925 1275928 1275946 1275950 1275954 1275970 1275973 1275975 1275976 1276029 1276257 1276263 1276270 1276273 1276277 1276335 1276346 1276350 1276355 1276446 1276452 1276500 1276507 1276542 1276546 1276551 1276552 1276561 1276569 1276577 1276665 1276864 1276892 1276912 1276913 1276927 1276931 1276937 1276941 1276943 1276944 1276946 1276955 1276961 1277022 1277034 1277037 1277047 1277054 1277057 1277059 1277064 1277066 1277069 1277073 1277077 1277095 1277155 1277159 1277160 1277202 1277204 1277262 1277275 1277285 1277391 1277408 1277516 1277523 1277551 1277625 1277660 1277678 1277688 1277707 1277708 1277709 1277710 1277711 1277713 1277775 1277776 1277921 1277922 1279893 1280050 1280051 1280052 1280053 1280054 CVE-2024-44981 CVE-2024-57841 CVE-2025-23137 CVE-2025-38469 CVE-2025-39939 CVE-2025-39964 CVE-2025-40022 CVE-2025-40199 CVE-2025-68179 CVE-2025-68214 CVE-2025-71075 CVE-2025-71104 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-23210 CVE-2026-23227 CVE-2026-23230 CVE-2026-23454 CVE-2026-31418 CVE-2026-31531 CVE-2026-31557 CVE-2026-31658 CVE-2026-31663 CVE-2026-43014 CVE-2026-43015 CVE-2026-43116 CVE-2026-43125 CVE-2026-43163 CVE-2026-43213 CVE-2026-43271 CVE-2026-43273 CVE-2026-43363 CVE-2026-43386 CVE-2026-43416 CVE-2026-43448 CVE-2026-45897 CVE-2026-45968 CVE-2026-46070 CVE-2026-46078 CVE-2026-46091 CVE-2026-46107 CVE-2026-46115 CVE-2026-46127 CVE-2026-46195 CVE-2026-52920 CVE-2026-52925 CVE-2026-52929 CVE-2026-52935 CVE-2026-52939 CVE-2026-52946 CVE-2026-52975 CVE-2026-52977 CVE-2026-52990 CVE-2026-52994 CVE-2026-53001 CVE-2026-53033 CVE-2026-53034 CVE-2026-53059 CVE-2026-53076 CVE-2026-53077 CVE-2026-53089 CVE-2026-53091 CVE-2026-53094 CVE-2026-53096 CVE-2026-53110 CVE-2026-53111 CVE-2026-53126 CVE-2026-53142 CVE-2026-53154 CVE-2026-53163 CVE-2026-53180 CVE-2026-53207 CVE-2026-53219 CVE-2026-53220 CVE-2026-53223 CVE-2026-53228 CVE-2026-53238 CVE-2026-53260 CVE-2026-53263 CVE-2026-53264 CVE-2026-53269 CVE-2026-53273 CVE-2026-53309 CVE-2026-53330 CVE-2026-53336 CVE-2026-53337 CVE-2026-53353 CVE-2026-53365 CVE-2026-53366 CVE-2026-53381 CVE-2026-53388 CVE-2026-6368 CVE-2026-63801 CVE-2026-63808 CVE-2026-63810 CVE-2026-63823 CVE-2026-63827 CVE-2026-63828 CVE-2026-63842 CVE-2026-63850 CVE-2026-63860 CVE-2026-63865 CVE-2026-63868 CVE-2026-63879 CVE-2026-63881 CVE-2026-63886 CVE-2026-63887 CVE-2026-63888 CVE-2026-63889 CVE-2026-63891 CVE-2026-63898 CVE-2026-63920 CVE-2026-63923 CVE-2026-63925 CVE-2026-63926 CVE-2026-63928 CVE-2026-63937 CVE-2026-63944 CVE-2026-63969 CVE-2026-63970 CVE-2026-63972 CVE-2026-63973 CVE-2026-63980 CVE-2026-63985 CVE-2026-63990 CVE-2026-63992 CVE-2026-63995 CVE-2026-63996 CVE-2026-63997 CVE-2026-63998 CVE-2026-63999 CVE-2026-64000 CVE-2026-64001 CVE-2026-64002 CVE-2026-64004 CVE-2026-64005 CVE-2026-64006 CVE-2026-64007 CVE-2026-64010 CVE-2026-64011 CVE-2026-64014 CVE-2026-64015 CVE-2026-64018 CVE-2026-64021 CVE-2026-64029 CVE-2026-64033 CVE-2026-64034 CVE-2026-64039 CVE-2026-64047 CVE-2026-64048 CVE-2026-64051 CVE-2026-64052 CVE-2026-64055 CVE-2026-64056 CVE-2026-64073 CVE-2026-64083 CVE-2026-64084 CVE-2026-64085 CVE-2026-64086 CVE-2026-64087 CVE-2026-64088 CVE-2026-64097 CVE-2026-64098 CVE-2026-64099 CVE-2026-64102 CVE-2026-64109 CVE-2026-64112 CVE-2026-64113 CVE-2026-64114 CVE-2026-64115 CVE-2026-64118 CVE-2026-64121 CVE-2026-64125 CVE-2026-64126 CVE-2026-64127 CVE-2026-64128 CVE-2026-64131 CVE-2026-64133 CVE-2026-64134 CVE-2026-64135 CVE-2026-64136 CVE-2026-64137 CVE-2026-64144 CVE-2026-64146 CVE-2026-64148 CVE-2026-64155 CVE-2026-64164 CVE-2026-64166 CVE-2026-64168 CVE-2026-64178 CVE-2026-64180 CVE-2026-64185 CVE-2026-64188 CVE-2026-64190 CVE-2026-64192 CVE-2026-64214 CVE-2026-64217 CVE-2026-64218 CVE-2026-64219 CVE-2026-64222 CVE-2026-64224 CVE-2026-64225 CVE-2026-64237 CVE-2026-64243 CVE-2026-64244 CVE-2026-64245 CVE-2026-64246 CVE-2026-64247 CVE-2026-64249 CVE-2026-64257 CVE-2026-64266 CVE-2026-64268 CVE-2026-64269 CVE-2026-64271 CVE-2026-64273 CVE-2026-64274 CVE-2026-64275 CVE-2026-64276 CVE-2026-64277 CVE-2026-64286 CVE-2026-64287 CVE-2026-64294 CVE-2026-64296 CVE-2026-64303 CVE-2026-64304 CVE-2026-64305 CVE-2026-64306 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64316 CVE-2026-64317 CVE-2026-64322 CVE-2026-64323 CVE-2026-64329 CVE-2026-64331 CVE-2026-64332 CVE-2026-64333 CVE-2026-64334 CVE-2026-64335 CVE-2026-64337 CVE-2026-64338 CVE-2026-64340 CVE-2026-64341 CVE-2026-64342 CVE-2026-64343 CVE-2026-64344 CVE-2026-64346 CVE-2026-64348 CVE-2026-64350 CVE-2026-64351 CVE-2026-64355 CVE-2026-64358 CVE-2026-64362 CVE-2026-64365 CVE-2026-64375 CVE-2026-64376 CVE-2026-64378 CVE-2026-64381 CVE-2026-64382 CVE-2026-64383 CVE-2026-64384 CVE-2026-64385 CVE-2026-64386 CVE-2026-64387 CVE-2026-64388 CVE-2026-64401 CVE-2026-64403 CVE-2026-64406 CVE-2026-64407 CVE-2026-64408 CVE-2026-64409 CVE-2026-64411 CVE-2026-64412 CVE-2026-64420 CVE-2026-64421 CVE-2026-64423 CVE-2026-64427 CVE-2026-64429 CVE-2026-64433 CVE-2026-64434 CVE-2026-64436 CVE-2026-64440 CVE-2026-64442 CVE-2026-64443 CVE-2026-64444 CVE-2026-64445 CVE-2026-64448 CVE-2026-64450 CVE-2026-64452 CVE-2026-64454 CVE-2026-64455 CVE-2026-64463 CVE-2026-64470 CVE-2026-64471 CVE-2026-64472 CVE-2026-64477 CVE-2026-64478 CVE-2026-64479 CVE-2026-64480 CVE-2026-64481 CVE-2026-64482 CVE-2026-64483 CVE-2026-64484 CVE-2026-64486 CVE-2026-64487 CVE-2026-64489 CVE-2026-64494 CVE-2026-64495 CVE-2026-64496 CVE-2026-64497 CVE-2026-64500 CVE-2026-64503 CVE-2026-64504 CVE-2026-64505 CVE-2026-64511 CVE-2026-64512 CVE-2026-64513 CVE-2026-64515 CVE-2026-64517 CVE-2026-64524 CVE-2026-64527 CVE-2026-64536 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539 CVE-2026-64540 CVE-2026-64541 CVE-2026-64543 CVE-2026-64544 CVE-2026-64545 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64551 CVE-2026-64552 CVE-2026-64553 CVE-2026-64554 CVE-2026-64558 CVE-2026-64559 CVE-2026-64562 CVE-2026-64563 CVE-2026-64565 CVE-2026-64567 CVE-2026-64568 CVE-2026-64569 CVE-2026-64570 CVE-2026-64571 CVE-2026-64572 CVE-2026-64573 CVE-2026-64574 CVE-2026-64576 CVE-2026-64577 CVE-2026-64581 CVE-2026-64582 CVE-2026-64583 CVE-2026-64584 CVE-2026-64585 CVE-2026-64593 CVE-2026-64597 CVE-2026-64598 CVE-2026-64599 CVE-2026-64602 CVE-2026-64603 CVE-2026-64604 CVE-2026-6791 CVE-2026-68081 CVE-2026-68082 CVE-2026-68085 CVE-2026-68086 CVE-2026-68088 CVE-2026-68091 CVE-2026-68093 CVE-2026-68102 CVE-2026-68104 CVE-2026-68105 CVE-2026-68106 CVE-2026-68107 CVE-2026-68108 CVE-2026-68110 CVE-2026-68111 CVE-2026-68112 CVE-2026-68113 CVE-2026-68115 CVE-2026-68116 CVE-2026-68117 CVE-2026-68121 CVE-2026-68123 CVE-2026-68124 CVE-2026-68125 CVE-2026-68126 CVE-2026-68127 CVE-2026-68129 CVE-2026-68132 CVE-2026-68133 CVE-2026-68135 CVE-2026-68136 CVE-2026-68137 CVE-2026-68138 CVE-2026-68139 CVE-2026-68142 CVE-2026-68143 CVE-2026-68145 CVE-2026-68149 CVE-2026-68152 CVE-2026-68153 CVE-2026-68154 CVE-2026-68155 CVE-2026-68156 CVE-2026-68157 CVE-2026-68158 CVE-2026-68159 CVE-2026-68160 CVE-2026-68161 CVE-2026-68162 CVE-2026-68166 CVE-2026-68180 CVE-2026-68181 CVE-2026-68182 CVE-2026-68184 CVE-2026-68188 CVE-2026-68189 CVE-2026-68192 CVE-2026-68193 CVE-2026-68194 CVE-2026-68195 CVE-2026-68196 CVE-2026-68197 CVE-2026-68199 CVE-2026-68202 CVE-2026-68204 CVE-2026-68205 CVE-2026-68206 CVE-2026-68207 CVE-2026-68209 CVE-2026-68210 CVE-2026-68212 CVE-2026-68213 CVE-2026-68214 CVE-2026-68215 CVE-2026-68216 CVE-2026-68217 CVE-2026-68218 CVE-2026-68219 CVE-2026-68220 CVE-2026-68222 CVE-2026-68223 CVE-2026-68226 CVE-2026-68227 CVE-2026-68229 CVE-2026-68231 CVE-2026-68234 CVE-2026-68235 CVE-2026-68236 CVE-2026-68238 CVE-2026-68243 CVE-2026-68244 CVE-2026-68245 CVE-2026-68246 CVE-2026-68247 CVE-2026-68248 CVE-2026-68249 CVE-2026-68250 CVE-2026-68251 CVE-2026-68252 CVE-2026-68253 CVE-2026-68254 CVE-2026-68255 CVE-2026-68256 CVE-2026-68257 CVE-2026-68259 CVE-2026-68260 CVE-2026-68261 CVE-2026-68262 CVE-2026-68263 CVE-2026-68267 CVE-2026-68269 CVE-2026-68271 CVE-2026-68272 CVE-2026-68277 CVE-2026-68278 CVE-2026-68279 CVE-2026-68280 CVE-2026-68281 CVE-2026-68284 CVE-2026-68286 CVE-2026-68288 CVE-2026-68289 CVE-2026-68293 CVE-2026-68297 CVE-2026-68299 CVE-2026-68300 CVE-2026-68302 CVE-2026-68303 CVE-2026-68304 CVE-2026-68306 CVE-2026-68308 CVE-2026-68309 CVE-2026-68310 CVE-2026-68312 CVE-2026-68313 CVE-2026-68315 CVE-2026-68320 CVE-2026-68322 CVE-2026-68324 CVE-2026-68325 CVE-2026-68326 CVE-2026-68327 CVE-2026-68328 CVE-2026-68329 CVE-2026-68331 CVE-2026-68333 CVE-2026-68335 CVE-2026-68336 CVE-2026-68339 CVE-2026-68340 CVE-2026-68343 CVE-2026-68346 CVE-2026-68348 CVE-2026-68349 CVE-2026-68350 CVE-2026-68351 CVE-2026-68352 CVE-2026-68353 CVE-2026-68354 CVE-2026-68355 CVE-2026-68357 CVE-2026-68359 CVE-2026-68360 CVE-2026-68361 CVE-2026-68362 CVE-2026-68363 CVE-2026-68365 CVE-2026-68366 CVE-2026-68368 CVE-2026-68369 CVE-2026-68370 CVE-2026-68372 CVE-2026-68373 CVE-2026-68375 CVE-2026-68377 CVE-2026-68386 CVE-2026-68389 CVE-2026-68391 CVE-2026-68392 CVE-2026-68394 CVE-2026-68397 CVE-2026-68398 CVE-2026-68399 CVE-2026-68402 CVE-2026-68403 CVE-2026-68405 CVE-2026-68406 CVE-2026-68407 CVE-2026-68408 CVE-2026-68410 CVE-2026-68413 CVE-2026-68414 CVE-2026-68417 CVE-2026-68418 CVE-2026-68419 CVE-2026-68422 CVE-2026-68425 CVE-2026-68426 CVE-2026-68427 CVE-2026-68428 CVE-2026-68429 CVE-2026-68430 CVE-2026-68432 CVE-2026-68433 CVE-2026-68434 CVE-2026-68437 CVE-2026-68444 CVE-2026-68445 CVE-2026-68446 CVE-2026-68450 CVE-2026-68470 CVE-2026-68480 CVE-2026-72020 CVE-2026-72032 CVE-2026-72035 CVE-2026-72036 CVE-2026-72046 CVE-2026-72069 CVE-2026-72072 CVE-2026-72083 CVE-2026-72084 CVE-2026-72123 CVE-2026-72132 CVE-2026-72221 CVE-2026-72222 CVE-2026-72251 CVE-2026-72254 CVE-2026-72262 CVE-2026-72288 CVE-2026-72289 CVE-2026-72296 CVE-2026-72307 CVE-2026-72308 CVE-2026-72317 CVE-2026-72341 CVE-2026-72342 CVE-2026-72343 CVE-2026-72389 CVE-2026-72463 CVE-2026-72464 CVE-2026-72466 CVE-2026-72467 CVE-2026-72469 CVE-2026-72473 CVE-2026-72494 CVE-2026-72495 CVE-2026-72496 CVE-2026-72497 CVE-2026-72498 CVE-2026-72499 CVE-2026-72500 CVE-2026-72501 CVE-2026-72502 CVE-2026-74269 CVE-2026-74296 CVE-2026-74297 CVE-2026-74318 CVE-2026-74321 CVE-2026-74334 CVE-2026-74345 CVE-2026-74394 CVE-2026-74395 CVE-2026-74454 CVE-2026-74474 CVE-2026-74481 CVE-2026-74482 CVE-2026-74488 CVE-2026-74495 CVE-2026-74496 CVE-2026-74509 CVE-2026-74510 CVE-2026-74512 CVE-2026-74516 CVE-2026-74518 CVE-2026-74527 CVE-2026-74537 CVE-2026-74548 CVE-2026-74550 CVE-2026-74556 CVE-2026-74563 CVE-2026-74566 CVE-2026-74567 CVE-2026-74571 CVE-2026-74577 CVE-2026-74581 CVE-2026-74582 CVE-2026-74584 CVE-2026-74610 CVE-2026-74669 CVE-2026-74692 CVE-2026-74694 CVE-2026-74695 CVE-2026-74712 CVE-2026-74717 CVE-2026-74722 CVE-2026-77117 CVE-2026-80489 CVE-2026-80529 CVE-2026-80534 CVE-2026-80590 CVE-2026-80654 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4254-1 Released: Thu Sep 17 18:03:10 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1230238,1235944,1236344,1240957,1241363,1247180,1247455,1249104,1250748,1251130,1251966,1252682,1253454,1254306,1255225,1255250,1256629,1256708,1257154,1258430,1258472,1258517,1260522,1261562,1261780,1262073,1263004,1263052,1263061,1263133,1263864,1264010,1264012,1264335,1264446,1264541,1264587,1264619,1264643,1264740,1264807,1265068,1265121,1265220,1265449,1265928,1266402,1266860,1266874,1266897,1267023,1267236,1267238,1267501,1267505,1267612,1268276,1268972,1268979,1268987,1269004,1269013,1269108,1269113,1269114,1269126,1269140,1269167,1269234,1269238,1269242,1269256,1269301,1269306,1269313,1269381,1269388,1269402,1269412,1269530,1269579,1269590,1269635,1269647,1269655,1269665,1269686,1269695,1269713,1269731,1269774,1269783,1269792,1269815,1269888,1269965,1269969,1269981,1269985,1270090,1270108,1270111,1270251,1270263,1270268,1271256,1271365,1271366,1271825,1271830,1272150,1272175,1272179,1272182,1272200,1272210,1272213,1272230,1272260,1272261,1272262,1272297,1272346,1 272351,1272359,1272381,1272383,1272385,1272390,1272423,1272429,1272484,1272486,1272497,1272502,1272516,1272569,1272571,1272618,1272641,1272643,1272662,1272673,1272680,1272682,1272756,1272786,1272788,1272798,1272799,1272804,1272868,1272877,1272891,1272893,1272963,1272983,1272993,1273005,1273008,1273019,1273027,1273028,1273030,1273032,1273033,1273036,1273037,1273038,1273053,1273054,1273060,1273105,1273134,1273249,1273250,1273260,1273273,1273274,1273276,1273277,1273280,1273281,1273284,1273285,1273289,1273291,1273294,1273302,1273303,1273305,1273310,1273311,1273316,1273318,1273319,1273323,1273325,1273327,1273334,1273335,1273336,1273337,1273338,1273340,1273341,1273346,1273422,1273426,1273443,1273460,1273463,1273465,1273468,1273469,1273471,1273479,1273480,1273482,1273484,1273488,1273490,1273501,1273503,1273504,1273506,1273523,1273525,1273533,1273536,1273542,1273555,1273578,1273579,1273581,1273582,1273596,1273597,1273598,1273600,1273601,1273602,1273603,1273679,1273681,1273682,1273734,127373 8,1273739,1273741,1273742,1273743,1273745,1273748,1273749,1273755,1273762,1273765,1273766,1273769,1273774,1273778,1273780,1273790,1273796,1273797,1273801,1273804,1273810,1273811,1273812,1273813,1273817,1273822,1273824,1273831,1273832,1273834,1273838,1273844,1273849,1273859,1273860,1273862,1273867,1273868,1273869,1273872,1273876,1273877,1273880,1273882,1273890,1273891,1273892,1273895,1273896,1273903,1273905,1273930,1273933,1273934,1273935,1273936,1273939,1273940,1273941,1273942,1273944,1273945,1273946,1273956,1273957,1273958,1273966,1273967,1273968,1273972,1273974,1273975,1273977,1273982,1273988,1273990,1273991,1273995,1274001,1274003,1274006,1274008,1274009,1274010,1274011,1274012,1274014,1274017,1274019,1274020,1274026,1274028,1274030,1274031,1274035,1274040,1274041,1274055,1274057,1274058,1274061,1274063,1274065,1274067,1274071,1274075,1274076,1274077,1274078,1274208,1274226,1274239,1274243,1274258,1274264,1274265,1274267,1274274,1274277,1274278,1274281,1274283,1274286,1274290,127 4294,1274295,1274296,1274297,1274298,1274314,1274321,1274491,1274497,1274539,1274541,1274543,1274545,1274547,1274550,1274573,1274578,1274580,1274581,1274620,1274622,1274624,1274629,1274632,1274636,1274639,1274640,1274642,1274644,1274645,1274646,1274649,1274650,1274651,1274656,1274659,1274662,1274663,1274665,1274667,1274670,1274675,1274677,1274678,1274679,1274681,1274682,1274690,1274694,1274696,1274698,1274699,1274700,1274702,1274703,1274705,1274706,1274709,1274710,1274713,1274716,1274721,1274725,1274737,1274738,1274749,1274752,1274753,1274754,1274755,1274756,1274764,1274768,1274770,1274783,1274787,1274800,1274801,1274802,1274804,1274805,1274807,1274808,1274811,1274813,1274814,1274831,1274834,1274835,1274847,1274849,1274853,1274868,1274869,1274872,1274873,1274874,1274876,1274877,1274879,1274881,1274883,1274886,1274888,1274891,1274892,1274893,1274894,1274895,1274896,1274897,1274898,1274899,1274901,1274902,1274905,1274906,1274907,1274908,1274913,1274914,1274920,1274921,1274924,1274925, 1274929,1274930,1274933,1274934,1274935,1274941,1274945,1274947,1274951,1274953,1274958,1274968,1274981,1275040,1275069,1275071,1275073,1275076,1275080,1275081,1275083,1275088,1275091,1275125,1275126,1275131,1275132,1275139,1275141,1275146,1275148,1275149,1275150,1275152,1275154,1275155,1275156,1275157,1275158,1275161,1275163,1275164,1275169,1275173,1275176,1275185,1275190,1275192,1275236,1275237,1275239,1275294,1275300,1275301,1275303,1275304,1275305,1275306,1275307,1275470,1275472,1275474,1275479,1275483,1275486,1275487,1275506,1275509,1275511,1275517,1275519,1275528,1275535,1275540,1275553,1275555,1275557,1275561,1275566,1275569,1275572,1275574,1275578,1275582,1275583,1275584,1275591,1275595,1275633,1275636,1275650,1275656,1275659,1275665,1275669,1275687,1275688,1275695,1275696,1275704,1275737,1275782,1275784,1275787,1275788,1275789,1275790,1275797,1275798,1275805,1275817,1275818,1275819,1275820,1275821,1275822,1275823,1275827,1275864,1275867,1275869,1275870,1275871,1275872,12758 86,1275905,1275923,1275925,1275928,1275946,1275950,1275954,1275970,1275973,1275975,1275976,1276029,1276257,1276263,1276270,1276273,1276277,1276335,1276346,1276350,1276355,1276446,1276452,1276500,1276507,1276542,1276546,1276551,1276552,1276561,1276569,1276577,1276665,1276864,1276912,1276913,1276927,1276931,1276937,1276941,1276943,1276944,1276955,1276961,1277022,1277034,1277037,1277047,1277054,1277057,1277059,1277064,1277066,1277069,1277073,1277077,1277095,1277155,1277159,1277160,1277202,1277204,1277275,1277285,1277391,1277408,1277516,1277523,1277551,1277625,1277660,1277678,1277688,1277775,1277776,CVE-2024-44981,CVE-2024-57841,CVE-2025-23137,CVE-2025-38469,CVE-2025-39939,CVE-2025-39964,CVE-2025-40022,CVE-2025-40199,CVE-2025-68179,CVE-2025-68214,CVE-2025-71075,CVE-2025-71104,CVE-2026-23210,CVE-2026-23227,CVE-2026-23230,CVE-2026-23454,CVE-2026-31418,CVE-2026-31531,CVE-2026-31557,CVE-2026-31658,CVE-2026-31663,CVE-2026-43014,CVE-2026-43015,CVE-2026-43116,CVE-2026-43125,CVE-2026-43163,CVE- 2026-43213,CVE-2026-43271,CVE-2026-43273,CVE-2026-43363,CVE-2026-43386,CVE-2026-43416,CVE-2026-43448,CVE-2026-45897,CVE-2026-45968,CVE-2026-46070,CVE-2026-46078,CVE-2026-46091,CVE-2026-46107,CVE-2026-46115,CVE-2026-46127,CVE-2026-46195,CVE-2026-52920,CVE-2026-52925,CVE-2026-52929,CVE-2026-52935,CVE-2026-52939,CVE-2026-52946,CVE-2026-52975,CVE-2026-52977,CVE-2026-52990,CVE-2026-52994,CVE-2026-53001,CVE-2026-53033,CVE-2026-53034,CVE-2026-53059,CVE-2026-53076,CVE-2026-53077,CVE-2026-53089,CVE-2026-53091,CVE-2026-53094,CVE-2026-53096,CVE-2026-53110,CVE-2026-53111,CVE-2026-53126,CVE-2026-53142,CVE-2026-53154,CVE-2026-53163,CVE-2026-53180,CVE-2026-53207,CVE-2026-53219,CVE-2026-53220,CVE-2026-53223,CVE-2026-53228,CVE-2026-53238,CVE-2026-53260,CVE-2026-53263,CVE-2026-53264,CVE-2026-53269,CVE-2026-53273,CVE-2026-53309,CVE-2026-53330,CVE-2026-53336,CVE-2026-53337,CVE-2026-53353,CVE-2026-53365,CVE-2026-53366,CVE-2026-53381,CVE-2026-53388,CVE-2026-63801,CVE-2026-63808,CVE-2026-63810,CVE-2026-63 823,CVE-2026-63827,CVE-2026-63828,CVE-2026-63842,CVE-2026-63850,CVE-2026-63860,CVE-2026-63865,CVE-2026-63868,CVE-2026-63879,CVE-2026-63881,CVE-2026-63886,CVE-2026-63887,CVE-2026-63888,CVE-2026-63889,CVE-2026-63891,CVE-2026-63898,CVE-2026-63920,CVE-2026-63923,CVE-2026-63925,CVE-2026-63926,CVE-2026-63928,CVE-2026-63937,CVE-2026-63944,CVE-2026-63969,CVE-2026-63970,CVE-2026-63972,CVE-2026-63973,CVE-2026-63980,CVE-2026-63985,CVE-2026-63990,CVE-2026-63992,CVE-2026-63995,CVE-2026-63996,CVE-2026-63997,CVE-2026-63998,CVE-2026-63999,CVE-2026-64000,CVE-2026-64001,CVE-2026-64002,CVE-2026-64004,CVE-2026-64005,CVE-2026-64006,CVE-2026-64007,CVE-2026-64010,CVE-2026-64011,CVE-2026-64014,CVE-2026-64015,CVE-2026-64018,CVE-2026-64021,CVE-2026-64029,CVE-2026-64033,CVE-2026-64034,CVE-2026-64039,CVE-2026-64047,CVE-2026-64048,CVE-2026-64051,CVE-2026-64052,CVE-2026-64055,CVE-2026-64056,CVE-2026-64073,CVE-2026-64083,CVE-2026-64084,CVE-2026-64085,CVE-2026-64086,CVE-2026-64087,CVE-2026-64088,CVE-2026-64097,CVE -2026-64098,CVE-2026-64099,CVE-2026-64102,CVE-2026-64109,CVE-2026-64112,CVE-2026-64113,CVE-2026-64114,CVE-2026-64115,CVE-2026-64118,CVE-2026-64121,CVE-2026-64125,CVE-2026-64126,CVE-2026-64127,CVE-2026-64128,CVE-2026-64131,CVE-2026-64133,CVE-2026-64134,CVE-2026-64135,CVE-2026-64136,CVE-2026-64137,CVE-2026-64144,CVE-2026-64146,CVE-2026-64148,CVE-2026-64155,CVE-2026-64164,CVE-2026-64166,CVE-2026-64168,CVE-2026-64178,CVE-2026-64180,CVE-2026-64185,CVE-2026-64188,CVE-2026-64190,CVE-2026-64192,CVE-2026-64214,CVE-2026-64217,CVE-2026-64218,CVE-2026-64219,CVE-2026-64222,CVE-2026-64224,CVE-2026-64225,CVE-2026-64237,CVE-2026-64243,CVE-2026-64244,CVE-2026-64245,CVE-2026-64246,CVE-2026-64247,CVE-2026-64249,CVE-2026-64257,CVE-2026-64266,CVE-2026-64268,CVE-2026-64269,CVE-2026-64271,CVE-2026-64273,CVE-2026-64274,CVE-2026-64275,CVE-2026-64276,CVE-2026-64277,CVE-2026-64286,CVE-2026-64287,CVE-2026-64294,CVE-2026-64296,CVE-2026-64303,CVE-2026-64304,CVE-2026-64305,CVE-2026-64306,CVE-2026-64312,CVE-2026-6 4313,CVE-2026-64315,CVE-2026-64316,CVE-2026-64317,CVE-2026-64322,CVE-2026-64323,CVE-2026-64329,CVE-2026-64331,CVE-2026-64332,CVE-2026-64333,CVE-2026-64334,CVE-2026-64335,CVE-2026-64337,CVE-2026-64338,CVE-2026-64340,CVE-2026-64341,CVE-2026-64342,CVE-2026-64343,CVE-2026-64344,CVE-2026-64346,CVE-2026-64348,CVE-2026-64350,CVE-2026-64351,CVE-2026-64355,CVE-2026-64358,CVE-2026-64362,CVE-2026-64365,CVE-2026-64375,CVE-2026-64376,CVE-2026-64378,CVE-2026-64381,CVE-2026-64382,CVE-2026-64383,CVE-2026-64384,CVE-2026-64385,CVE-2026-64386,CVE-2026-64387,CVE-2026-64388,CVE-2026-64401,CVE-2026-64403,CVE-2026-64406,CVE-2026-64407,CVE-2026-64408,CVE-2026-64409,CVE-2026-64411,CVE-2026-64412,CVE-2026-64420,CVE-2026-64421,CVE-2026-64423,CVE-2026-64427,CVE-2026-64429,CVE-2026-64433,CVE-2026-64434,CVE-2026-64436,CVE-2026-64440,CVE-2026-64442,CVE-2026-64443,CVE-2026-64444,CVE-2026-64445,CVE-2026-64448,CVE-2026-64450,CVE-2026-64452,CVE-2026-64454,CVE-2026-64455,CVE-2026-64463,CVE-2026-64470,CVE-2026-64471,CV E-2026-64472,CVE-2026-64477,CVE-2026-64478,CVE-2026-64479,CVE-2026-64480,CVE-2026-64481,CVE-2026-64482,CVE-2026-64483,CVE-2026-64484,CVE-2026-64486,CVE-2026-64487,CVE-2026-64489,CVE-2026-64494,CVE-2026-64495,CVE-2026-64496,CVE-2026-64497,CVE-2026-64500,CVE-2026-64503,CVE-2026-64504,CVE-2026-64505,CVE-2026-64511,CVE-2026-64512,CVE-2026-64513,CVE-2026-64515,CVE-2026-64517,CVE-2026-64524,CVE-2026-64527,CVE-2026-64536,CVE-2026-64537,CVE-2026-64538,CVE-2026-64539,CVE-2026-64540,CVE-2026-64541,CVE-2026-64543,CVE-2026-64544,CVE-2026-64545,CVE-2026-64546,CVE-2026-64547,CVE-2026-64548,CVE-2026-64549,CVE-2026-64551,CVE-2026-64552,CVE-2026-64553,CVE-2026-64554,CVE-2026-64558,CVE-2026-64559,CVE-2026-64562,CVE-2026-64563,CVE-2026-64565,CVE-2026-64567,CVE-2026-64568,CVE-2026-64569,CVE-2026-64570,CVE-2026-64571,CVE-2026-64572,CVE-2026-64573,CVE-2026-64574,CVE-2026-64576,CVE-2026-64577,CVE-2026-64581,CVE-2026-64582,CVE-2026-64583,CVE-2026-64584,CVE-2026-64585,CVE-2026-64593,CVE-2026-64597,CVE-2026- 64598,CVE-2026-64599,CVE-2026-64602,CVE-2026-64603,CVE-2026-64604,CVE-2026-68081,CVE-2026-68082,CVE-2026-68085,CVE-2026-68086,CVE-2026-68088,CVE-2026-68091,CVE-2026-68093,CVE-2026-68102,CVE-2026-68104,CVE-2026-68105,CVE-2026-68106,CVE-2026-68107,CVE-2026-68108,CVE-2026-68110,CVE-2026-68111,CVE-2026-68112,CVE-2026-68113,CVE-2026-68115,CVE-2026-68116,CVE-2026-68117,CVE-2026-68121,CVE-2026-68123,CVE-2026-68124,CVE-2026-68125,CVE-2026-68126,CVE-2026-68127,CVE-2026-68129,CVE-2026-68132,CVE-2026-68133,CVE-2026-68135,CVE-2026-68136,CVE-2026-68137,CVE-2026-68138,CVE-2026-68139,CVE-2026-68142,CVE-2026-68143,CVE-2026-68145,CVE-2026-68149,CVE-2026-68152,CVE-2026-68153,CVE-2026-68154,CVE-2026-68155,CVE-2026-68156,CVE-2026-68157,CVE-2026-68158,CVE-2026-68159,CVE-2026-68160,CVE-2026-68161,CVE-2026-68162,CVE-2026-68166,CVE-2026-68180,CVE-2026-68181,CVE-2026-68182,CVE-2026-68184,CVE-2026-68188,CVE-2026-68189,CVE-2026-68192,CVE-2026-68193,CVE-2026-68194,CVE-2026-68195,CVE-2026-68196,CVE-2026-68197,C VE-2026-68199,CVE-2026-68202,CVE-2026-68204,CVE-2026-68205,CVE-2026-68206,CVE-2026-68207,CVE-2026-68209,CVE-2026-68210,CVE-2026-68212,CVE-2026-68213,CVE-2026-68214,CVE-2026-68215,CVE-2026-68216,CVE-2026-68217,CVE-2026-68218,CVE-2026-68219,CVE-2026-68220,CVE-2026-68222,CVE-2026-68223,CVE-2026-68226,CVE-2026-68227,CVE-2026-68229,CVE-2026-68231,CVE-2026-68234,CVE-2026-68235,CVE-2026-68236,CVE-2026-68238,CVE-2026-68243,CVE-2026-68244,CVE-2026-68245,CVE-2026-68246,CVE-2026-68247,CVE-2026-68248,CVE-2026-68249,CVE-2026-68250,CVE-2026-68251,CVE-2026-68252,CVE-2026-68253,CVE-2026-68254,CVE-2026-68255,CVE-2026-68256,CVE-2026-68257,CVE-2026-68259,CVE-2026-68260,CVE-2026-68261,CVE-2026-68262,CVE-2026-68263,CVE-2026-68267,CVE-2026-68269,CVE-2026-68271,CVE-2026-68272,CVE-2026-68277,CVE-2026-68278,CVE-2026-68279,CVE-2026-68280,CVE-2026-68281,CVE-2026-68284,CVE-2026-68286,CVE-2026-68288,CVE-2026-68289,CVE-2026-68293,CVE-2026-68297,CVE-2026-68299,CVE-2026-68300,CVE-2026-68302,CVE-2026-68303,CVE-2026 -68304,CVE-2026-68306,CVE-2026-68308,CVE-2026-68309,CVE-2026-68310,CVE-2026-68312,CVE-2026-68313,CVE-2026-68315,CVE-2026-68320,CVE-2026-68322,CVE-2026-68324,CVE-2026-68325,CVE-2026-68326,CVE-2026-68327,CVE-2026-68328,CVE-2026-68329,CVE-2026-68331,CVE-2026-68333,CVE-2026-68335,CVE-2026-68336,CVE-2026-68339,CVE-2026-68340,CVE-2026-68343,CVE-2026-68346,CVE-2026-68348,CVE-2026-68349,CVE-2026-68350,CVE-2026-68351,CVE-2026-68352,CVE-2026-68353,CVE-2026-68354,CVE-2026-68355,CVE-2026-68357,CVE-2026-68359,CVE-2026-68360,CVE-2026-68361,CVE-2026-68362,CVE-2026-68363,CVE-2026-68365,CVE-2026-68366,CVE-2026-68368,CVE-2026-68369,CVE-2026-68370,CVE-2026-68372,CVE-2026-68373,CVE-2026-68375,CVE-2026-68377,CVE-2026-68386,CVE-2026-68389,CVE-2026-68391,CVE-2026-68392,CVE-2026-68394,CVE-2026-68397,CVE-2026-68398,CVE-2026-68399,CVE-2026-68402,CVE-2026-68403,CVE-2026-68405,CVE-2026-68406,CVE-2026-68407,CVE-2026-68408,CVE-2026-68410,CVE-2026-68413,CVE-2026-68414,CVE-2026-68417,CVE-2026-68418,CVE-2026-68419, CVE-2026-68422,CVE-2026-68425,CVE-2026-68426,CVE-2026-68427,CVE-2026-68428,CVE-2026-68429,CVE-2026-68430,CVE-2026-68432,CVE-2026-68433,CVE-2026-68434,CVE-2026-68437,CVE-2026-68444,CVE-2026-68445,CVE-2026-68446,CVE-2026-68450,CVE-2026-68470,CVE-2026-68480,CVE-2026-72020,CVE-2026-72032,CVE-2026-72035,CVE-2026-72036,CVE-2026-72046,CVE-2026-72069,CVE-2026-72072,CVE-2026-72083,CVE-2026-72084,CVE-2026-72123,CVE-2026-72132,CVE-2026-72221,CVE-2026-72222,CVE-2026-72251,CVE-2026-72254,CVE-2026-72262,CVE-2026-72288,CVE-2026-72289,CVE-2026-72296,CVE-2026-72307,CVE-2026-72308,CVE-2026-72317,CVE-2026-72341,CVE-2026-72342,CVE-2026-72343,CVE-2026-72389,CVE-2026-72463,CVE-2026-72464,CVE-2026-72466,CVE-2026-72467,CVE-2026-72469,CVE-2026-72473,CVE-2026-72494,CVE-2026-72495,CVE-2026-72496,CVE-2026-72497,CVE-2026-72498,CVE-2026-72499,CVE-2026-72500,CVE-2026-72501,CVE-2026-72502,CVE-2026-74269,CVE-2026-74296,CVE-2026-74297,CVE-2026-74318,CVE-2026-74321,CVE-2026-74334,CVE-2026-74345,CVE-2026-74394,CVE-202 6-74395,CVE-2026-74454,CVE-2026-74474,CVE-2026-74481,CVE-2026-74482,CVE-2026-74488,CVE-2026-74495,CVE-2026-74496,CVE-2026-74509,CVE-2026-74510,CVE-2026-74512,CVE-2026-74516,CVE-2026-74518,CVE-2026-74527,CVE-2026-74537,CVE-2026-74548,CVE-2026-74550,CVE-2026-74556,CVE-2026-74563,CVE-2026-74566,CVE-2026-74567,CVE-2026-74571,CVE-2026-74577,CVE-2026-74581,CVE-2026-74582,CVE-2026-74584,CVE-2026-74610,CVE-2026-74669,CVE-2026-74692,CVE-2026-74694,CVE-2026-74695,CVE-2026-74712,CVE-2026-74717,CVE-2026-74722,CVE-2026-80529,CVE-2026-80534,CVE-2026-80590,CVE-2026-80654 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2024-57841,CVE-2026-53260: net: fix memory leak in tcp_conn_request() (bsc#1235944 bsc#1269731). - CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). - CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). - CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). - CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). - CVE-2026-31557: nvmet: move async event work off nvmet-wq (bsc#1263061). - CVE-2026-31658: net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (bsc#1263052). - CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). - CVE-2026-43014,CVE-2026-43015: net: macb: fix clk handling on PCI glue driver removal (bsc#1264010 bsc#1264012). - CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). - CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). - CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). - CVE-2026-43213: wifi: rtw89: pci: validate sequence number of TX release report (bsc#1264643). - CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). - CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446). - CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). - CVE-2026-43386: staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie (bsc#1264740). - CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). - CVE-2026-43448: nvme-pci: Fix race bug in nvme_poll_irqdisable() (bsc#1264807). - CVE-2026-45897: bpf: Fix UAF in sock clone early bailouts (bsc#1266897). - CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). - CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). - CVE-2026-46078: erofs: fix the out-of-bounds nameoff handling for trailing dirents (bsc#1267505). - CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). - CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). - CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). - CVE-2026-46127: RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() (bsc#1267236). - CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). - CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). - CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). - CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). - CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). - CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). - CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). - CVE-2026-52975: bonding: 802.3ad replace MAC_ADDRESS_EQUAL with __agg_has_partner (bsc#1269234). - CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). - CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). - CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). - CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). - CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). - CVE-2026-53034: bpf, sockmap: Fix af_unix null-ptr-deref in proto update (bsc#1269140). - CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). - CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). - CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). - CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). - CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). - CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). - CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). - CVE-2026-53110: selftests/bpf: Add ASSERT_OK_FD macro (bsc#1269985). - CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). - CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). - CVE-2026-53142: drm/xe/display: fix oops in suspend/shutdown without display (bsc#1269402). - CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). - CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). - CVE-2026-53180: timers/migration: Fix livelock in tmigr_handle_remote_up() (bsc#1269888). - CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). - CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). - CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). - CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). - CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). - CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). - CVE-2026-53263: 6lowpan: fix off-by-one in multicast context address compression (bsc#1269647). - CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). - CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). - CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713). - CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). - CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). - CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). - CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). - CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). - CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). - CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). - CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). - CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). - CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). - CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). - CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). - CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). - CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). - CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). - CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). - CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). - CVE-2026-63881: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (bsc#1272571). - CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). - CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). - CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). - CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). - CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). - CVE-2026-63923: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify (bsc#1273005). - CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). - CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). - CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1272662). - CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). - CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). - CVE-2026-63980: net/handshake: Use spin_lock_bh for hn_lock (bsc#1273028). - CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). - CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). - CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). - CVE-2026-63995: ethtool: cmis: validate start_cmd_payload_size from module (bsc#1273033). - CVE-2026-63996: ethtool: cmis: require exact CDB reply length (bsc#1273032). - CVE-2026-63997: ethtool: module: avoid leaking a netdev ref on module flash errors (bsc#1273036). - CVE-2026-63998: ethtool: module: call ethnl_ops_complete() on module flash errors (bsc#1273037). - CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). - CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). - CVE-2026-64001: ALSA: pcm: oss: Fix setup list UAF on proc write error (bsc#1273734). - CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). - CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). - CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). - CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). - CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). - CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). - CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). - CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). - CVE-2026-64029: ALSA: seq: Serialize UMP output teardown with event_input (bsc#1273766). - CVE-2026-64033: RDMA/rtrs: Fix use-after-free in path file creation cleanup (bsc#1273134). - CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). - CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). - CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). - CVE-2026-64055,CVE-2026-64056: net: ethernet: cortina: Make RX SKB per-port (bsc#1272502 bsc#1272893). - CVE-2026-64055: net: ethernet: cortina: Drop half-assembled SKB (bsc#1272893). - CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). - CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). - CVE-2026-64099: drm/v3d: Fix use-after-free of CPU job query arrays on error path (bsc#1273465). - CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). - CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). - CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). - CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). - CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). - CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). - CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). - CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). - CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). - CVE-2026-64131: mm/memory: fix spurious warning when unmapping device-private/exclusive pages (bsc#1274063). - CVE-2026-64136: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (bsc#1272351). - CVE-2026-64146: erofs: fix metabuf leak in inode xattr initialization (bsc#1273681). - CVE-2026-64148: pds_core: check health in devcmd wait (bsc#1273956). - CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). - CVE-2026-64180: mm/memory_hotplug: fix memory block reference leak on remove (bsc#1273679). - CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). - CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (bsc#1272150). - CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). - CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). - CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). - CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). - CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). - CVE-2026-64224: octeontx2-pf: fix double free in rvu_rep_rsrc_init() (bsc#1272804). - CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). - CVE-2026-64244: drivers/base/memory: set mem->altmap after successful device registration (bsc#1273812). - CVE-2026-64245: fbdev: modedb: fix a possible UAF in fb_find_mode() (bsc#1273905). - CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). - CVE-2026-64269: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg (bsc#1273280). - CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). - CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). - CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). - CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). - CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). - CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968). - CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). - CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). - CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). - CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). - CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). - CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). - CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). - CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). - CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). - CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). - CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). - CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). - CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). - CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). - CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). - CVE-2026-64388: smb/client: fix chown/chgrp with SMB3 POSIX Extensions (bsc#1274061). - CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). - CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). - CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). - CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). - CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). - CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area (bsc#1273982). - CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). - CVE-2026-64452: 6lowpan: fix NHC entry use-after-free on error path (bsc#1273460). - CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). - CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). - CVE-2026-64477: x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled (bsc#1274264). - CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). - CVE-2026-64515: wifi: mac80211: fix MLE defragmentation (bsc#1273859). - CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). - CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). - CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). - CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). - CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). - CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). - CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). - CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). - CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). - CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). - CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). - CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). - CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). - CVE-2026-64569: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (bsc#1274009). - CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). - CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). - CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). - CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). - CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). - CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). - CVE-2026-64597: smb: client: fix double-free in SMB2_close() replay (bsc#1274297). - CVE-2026-64598: smb/client: Fix error code in smb2_aead_req_alloc() (bsc#1274298). - CVE-2026-68081: KVM: nVMX: Add helper to put (unmap) vmcs12 pages (bsc#1274580). - CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). - CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). - CVE-2026-68105: drm/amdgpu: Fix kernel panic during driver load failure (bsc#1274849). - CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). - CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). - CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). - CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). - CVE-2026-68124: mctp: serial: handle zero-length frames to prevent rx buffer overflow (bsc#1275192). - CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). - CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). - CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). - CVE-2026-68135: net: hip04: fix RX buffer leak on build_skb failure (bsc#1275557). - CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). - CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). - CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). - CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). - CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). - CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). - CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). - CVE-2026-68152: amt: fix use-after-free in AMT delayed works (bsc#1275300). - CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). - CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). - CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). - CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). - CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). - CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). - CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). - CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). - CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). - CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). - CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). - CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). - CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). - CVE-2026-68247: drm/i915/bios: range check LFP Data Block panel_type2 (bsc#1275817). - CVE-2026-68254: drm/i915/vrr: require valid min/max vfreq for VRR (bsc#1275150). - CVE-2026-68267: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (bsc#1275139). - CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). - CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). - CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). - CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). - CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). - CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). - CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). - CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). - CVE-2026-68302: amt: re-read skb header pointers after every pull (bsc#1275081). - CVE-2026-68312: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths (bsc#1274663). - CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). - CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). - CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). - CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). - CVE-2026-68324: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (bsc#1274649). - CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). - CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). - CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). - CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). - CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). - CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). - CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). - CVE-2026-68343: smb: client: validate DFS referral PathConsumed (bsc#1274629). - CVE-2026-68375: bnxt_en: Handle partially initialized auxiliary devices (bsc#1274835). - CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). - CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). - CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). - CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). - CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). - CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). - CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). - CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). - CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). - CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). - CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). - CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). - CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). - CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). - CVE-2026-68470: wifi: cfg80211/mac80211: correctly parse S1G beacon optional elements (bsc#1276500). - CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). - CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). - CVE-2026-72032: net/mlx5: HWS, fix matcher leak on resize target setup failure (bsc#1276955). - CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). - CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). - CVE-2026-72046: gve: fix header buffer corruption with header-split and HW-GRO (bsc#1275519). - CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). - CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). - CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). - CVE-2026-72084: scsi: target: Bound PR-OUT TransportID parsing to the received buffer (bsc#1275540). - CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). - CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). - CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). - CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). - CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). - CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). - CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678). - CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). - CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). - CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). - CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). - CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). - CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). - CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). - CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). - CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). - CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). - CVE-2026-72463: xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276 bsc#1277064). - CVE-2026-72464: xprtrdma: Remove temp allocation of rpcrdma_rep objects (bsc#1277069). - CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). - CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). - CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). - CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). - CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). - CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). - CVE-2026-72496: RDMA/bnxt_re: Proper rollback if the ioremap fails (bsc#1276943). - CVE-2026-72497: RDMA/bnxt_re: Add a max slot check for SQ (bsc#1276913). - CVE-2026-72498: RDMA/bnxt_re: Avoid displaying the kernel pointer (bsc#1276912). - CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). - CVE-2026-72500: RDMA/bnxt_re: Free SRQ toggle page after firmware teardown (bsc#1276552). - CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). - CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). - CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). - CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). - CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). - CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). - CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). - CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). - CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). - CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). - CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). - CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). - CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). - CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). - CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (bsc#1276346). - CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). - CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). - CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). - CVE-2026-74509: Bluetooth: hci_sync: Fix advertising data UAFs (bsc#1275946). - CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). - CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). - CVE-2026-74516: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (bsc#1275797). - CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). - CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). - CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). - CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). - CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). - CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). - CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). - CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). - CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). - CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). - CVE-2026-74577: net: mpls: initialize rtm_tos in mpls_getroute() (bsc#1275572). - CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). - CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). - CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). - CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). - CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). - CVE-2026-74692: net/smc: fix TOCTOU race between smc_listen_out() and listener close (bsc#1276927). - CVE-2026-74694: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (bsc#1277625). - CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). - CVE-2026-74712: vdpa/mlx5: Fix buffer length in create_direct_keys() (bsc#1276577). - CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). - CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). - CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). - CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). - CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). - CVE-2026-80654: soc: xilinx: Shutdown and free rx mailbox channel (bsc#1277516). The following non security issues were fixed: - accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). - accessibility: speakup: unregister tty ldisc on later init failures (git-fixes). - ACPI: APEI: Fix ERST timeout unit conversion (git-fixes). - ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). - ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git-fixes). - ACPI: pfr_update: fix stack buffer overflow in query_capability() (git-fixes). - ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). - ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). - ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). - ACPI: video: Release PCI device reference after lookup (git-fixes). - add my missing Reviewed-by: tag. - ALSA: 6fire: bound the MIDI event length from the device (git-fixes). - ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). - ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). - ALSA: control: Don't add invalid kcontrols to LED layer (git-fixes). - ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). - ALSA: dummy: Check card index validity at probe (stable-fixes). - ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). - ALSA: hda: Fix connection list comparison in proc output (git-fixes). - ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). - ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). - ALSA: scarlett2: Use a private URB for the notification endpoint (git-fixes). - ALSA: seq: Don't leak the extension cell pointer in the bounce payload (git-fixes). - ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). - ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). - ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). - ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). - ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). - ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). - ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). - ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git-fixes). - apparmor: advertise the tcp fast open fix is applied (git-fixes). - arm64: Exclude nohz_full CPUs from 32bits el0 support (bsc#1269313). - ASoC: adau1761: sort the register default table (git-fixes). - ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). - ASoC: apple: mca: increase SERDES reset delay (git-fixes). - ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). - ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). - ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). - ASoC: cs35l41: sort the register default table (git-fixes). - ASoC: cs35l45: sort the register default table (git-fixes). - ASoC: cs4265: sort the register default table (git-fixes). - ASoC: cx2072x: sort the register default table (git-fixes). - ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). - ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git-fixes). - ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git-fixes). - ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). - ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). - ASoC: fsl_easrc: sort the register default table (git-fixes). - ASoC: hdac_hda: Fix hlink refcount leak on component registration failure (git-fixes). - AsoC: intel: sst: fix PCI device reference leak on probe failure (git-fixes). - ASoC: max9860: sort the register default table (git-fixes). - ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). - ASoC: ml26124: sort the register default table (git-fixes). - ASoC: pcm512x: sort the register default table (git-fixes). - ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). - ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git-fixes). - ASoC: rt274: sort the register default table (git-fixes). - ASoC: rt286: sort the register default table (git-fixes). - ASoC: rt298: sort the register default table (git-fixes). - ASoC: rt700-sdw: always drain jack work on remove (git-fixes). - ASoC: rt700: drop duplicate reg_default entry (git-fixes). - ASoC: rt700: sort the register default table (git-fixes). - ASoC: rt711-sdca: sort the register default tables (git-fixes). - ASoC: rt711: sort the register default table (git-fixes). - ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). - ASoC: rt712-sdca-sdw: sort the register default table (git-fixes). - ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). - ASoC: rt715-sdca: sort the register default tables (git-fixes). - ASoC: rt715: sort the register default table (git-fixes). - ASoC: rt1017-sdca-sdw: sort the register default table (git-fixes). - ASoC: rt1316-sdw: sort the register default table (git-fixes). - ASoC: rt1318-sdw: sort the register default table (git-fixes). - ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). - ASoC: sgtl5000: sort the register default table (git-fixes). - ASoC: SOF: pcm: Move period/buffer configuration print after platform open (stable-fixes). - ASoC: sof: pcm: use snd_pcm_direction_name() (stable-fixes). - ASoC: SOF: Relocate and rework functionality for PCM stream freeing (stable-fixes). - ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git-fixes). - ASoC: SOF: validate topology volume range before allocation (git-fixes). - ASoC: sti-sas: sort the register default table (git-fixes). - ASoC: tas2552: sort the register default table (git-fixes). - ASoC: tas2764: sort the register default table (git-fixes). - ASoC: tas2780: sort the register default table (git-fixes). - ASoC: tegra210_i2s: sort the register default table (git-fixes). - ASoC: tegra210_mixer: sort the register default table (git-fixes). - ASoC: tegra: Fix the MIXER enable default value (git-fixes). - ASoC: tegra: Sort MBDRC register defaults (git-fixes). - ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). - ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). - batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). - batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). - batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). - batman-adv: fix stale receive device on merged fragments (git-fixes). - Bluetooth: btintel: Fix diagnostics event detection (git-fixes). - Bluetooth: btmtk: Do not discard the subsystem reset timeout (git-fixes). - Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() (stable-fixes). - Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). - Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git-fixes). - Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git-fixes). - Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git-fixes). - Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). - Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). - Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378 (git-fixes). - Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_conn: fix the SCO setup context lifetime (git-fixes). - Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). - Bluetooth: hci_conn: re-enable advertising only for peripheral role (git-fixes). - Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb (git-fixes). - Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git-fixes). - Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). - Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). - Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request (git-fixes). - Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). - Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). - Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git-fixes). - Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). - Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). - Bluetooth: MSFT: validate evt_prefix_len against the response length (git-fixes). - Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). - Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git-fixes). - Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). - Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). - bnxt_en: Adjust TX rings if reservation is less than requested (jsc#PED-16798). - bnxt_en: Delay for 5 seconds after AER DPC for all chips (jsc#PED-16798). - bnxt_en: Don't assume XDP is never enabled in bnxt_init_dflt_ring_mode() (jsc#PED-16798). - bnxt_en: Drop pci_save_state() after pci_restore_state() (jsc#PED-16798). - bnxt_en: Implement XDP RSS hash metadata extraction (jsc#PED-16798). - bnxt_en: Implement XDP RSS hash metadata extraction for V3_CMP (jsc#PED-16798). - bnxt_en: Move bnxt_rss_ext_op into header (jsc#PED-16798). - bnxt_en: Refactor some basic ring setup and adjustment logic (jsc#PED-16798). - bnxt_en: Restore default stat ctxs for ULP when resource is available (jsc#PED-16798). - bnxt_en: Set bp->max_tpa according to what the FW supports (jsc#PED-16798). - bnxt_en: Use absolute target ns from ptp_clock_request (jsc#PED-16798). - bnxt_en: use bnxt_xdp_buff for xdp context (jsc#PED-16798). - bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). - bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). - bus: ti-sysc: Fix /chosen node reference leak (git-fixes). - cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). - can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). - cpufreq: intel_pstate: Use correct scaling factor on Raptor Lake-E (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Use CPPC to get scaling factors (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Use HYBRID_SCALING_FACTOR_ADL for Bartlett Lake (bsc#1240957 bsc#1249104 bsc#1265220). - crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). - crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git-fixes). - crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). - crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). - crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). - crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). - crypto: doc - Remove extra parenthesis (git-fixes). - crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). - crypto: keembay - Initialize completion before requesting IRQ (git-fixes). - crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). - crypto: mxs-dcp - fix source scatterlist length access (git-fixes). - crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). - crypto: qat - clear AES key schedule from stack (git-fixes). - crypto: qce - fix CCM AAD buffer underallocation (git-fixes). - crypto: qce - fix error path in devm_qce_register_algs (git-fixes). - crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). - crypto: sa2ul - stop probe if context pool creation fails (git-fixes). - crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git-fixes). - device property: fix infinite loop in fwnode_for_each_child_node() (git-fixes). - dmaengine: dw-edma: Clear stale requests on termination (git-fixes). - dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). - dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). - dmaengine: dw-edma: Serialize abort state updates (git-fixes). - dmaengine: dw-edma: Serialize channel state checks (git-fixes). - dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). - dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). - dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). - dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). - dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). - driver core: soc: Unregister bus on early device registration failure (git-fixes). - drm/amd/display: Add AV mute wait frames to dce110_set_avmute (stable-fixes). - drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). - drm/amd/display: Check for tg ops in dce110_set_avmute (git-fixes). - drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix (git-fixes). - drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE (git-fixes). - drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank() (git-fixes). - drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames (stable-fixes). - drm/amd/display: Remove unused-but-set variable hubp from (git-fixes). - drm/amd/display: validate plane degamma LUT size for private color prop (git-fixes). - drm/amd/pm: adjust the visibility of pp_table sysfs node (stable-fixes). - drm/amd/pm: Use same metric table for APU (stable-fixes). - drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git-fixes). - drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). - drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). - drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). - drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git-fixes). - drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git-fixes). - drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git-fixes). - drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). - drm/amdgpu: check ASPM on the dGPU host link (git-fixes). - drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). - drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). - drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). - drm/amdgpu: fix nbif 6.3.1 l1 low power not functional (git-fixes). - drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). - drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). - drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). - drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). - drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). - drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini (git-fixes). - drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 (git-fixes). - drm/amdgpu: reject oversized IBs with per-ring packet limits (stable-fixes). - drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). - drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable-fixes). - drm/amdgpu: remove unused function parameter (stable-fixes). - drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). - drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). - drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). - drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). - drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore (git-fixes). - drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). - drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). - drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). - drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). - drm/bridge: tc358767: clamp the reported AUX read size to the request (git-fixes). - drm/connector/hdmi: Fix out of bounds memory read (git-fixes). - drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). - drm/hibmc: Fix list of formats on the primary plane (git-fixes). - drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). - drm/i915/fbc: Extract intel_fbc_has_fences() (stable-fixes). - drm/i915/hdcp: check streams bounds before overflow (git-fixes). - drm/i915/hdcp: Move to using intel_display in intel_hdcp (stable-fixes). - drm/i915/hdcp: require monotonically increasing seq_num_v (git-fixes). - drm/i915/hdcp: Skip inactive MST connectors when building stream list (stable-fixes). - drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() (stable-fixes). - drm/i915/vrr: require valid min/max vfreq for VRR (git-fixes). - drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). - drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg (git-fixes). - drm/msm/a6xx: Fix stale rpmh votes after suspend (git-fixes). - drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). - drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). - drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git-fixes). - drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). - drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). - drm/panthor: fix firmware control interface bounds checks (git-fixes). - drm/panthor: return PTR_ERR() from devm_drm_dev_alloc() (git-fixes). - drm/panthor: skip zero-sized firmware sections (git-fixes). - drm/radeon: fix autosuspend cleanup during teardown (git-fixes). - drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). - drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). - drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). - drm/ssd130x: fix column and row end address in partial updates in ssd133x (git-fixes). - drm/sun4i: crtc: Propagate layer initialization error (git-fixes). - drm/sun4i: Drop node references while building component list (git-fixes). - drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). - drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). - drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). - drm/sun4i: hdmi: Don't leak sync polarity bits into packet control (git-fixes). - drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). - drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). - drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). - drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). - drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). - drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info (git-fixes). - drm/tve200: add OF module alias for autoloading (git-fixes). - drm/xe/oa: Check managed mutex initialization errors (git-fixes). - drm/xe/oa: Fix sync entry leak on OA config emit failure (git-fixes). - drm/xe: Introduce xe_gt_dbg_printer() (stable-fixes). - drm/xe: Order ring writes before ring tail updates (git-fixes). - drm/xe: Stub out new pagefault layer (stable-fixes). - drm/xe: tests: fix error message in xe_migrate_sanity_test() (git-fixes). - drm: fix race between partial drm_dev_register() failure and ioctl (git-fixes). - drm: lcdif: Wait for vblank before disabling DMA (git-fixes). - drm: Remove unused header in drm_dumb_buffers.c (git-fixes). - ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). - fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). - fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). - fbdev: kyro: Validate overlay viewport coordinates (git-fixes). - fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). - fbdev: ssd1307fb: defer I2C transfers from damage callbacks (git-fixes). - fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). - fbdev: uvesafb: unregister connector callback on init failure (git-fixes). - firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). - firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). - firmware: arm_scmi: Fix requested device removal race (git-fixes). - firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). - firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). - firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). - firmware: arm_scmi: Unregister device notifier before IDR teardown (git-fixes). - firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). - firmware_loader: do not queue completed sysfs fallback requests (git-fixes). - fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git-fixes). - fpga: dfl: fme: add error handling (git-fixes). - fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git-fixes). - gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). - gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). - HID: core: fix number/pointer type confusion on long items (git-fixes). - HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). - HID: hyperv: validate initial device info bounds (git-fixes). - HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). - HID: lg4ff: validate report length before fixed offsets (git-fixes). - HID: logitech-dj: Fix maxfield check in DJ short report validation (git-fixes). - HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git-fixes). - HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). - HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable-fixes). - HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). - HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git-fixes). - HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). - HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). - HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git-fixes). - HID: picolcd: clamp eeprom debugfs read to bytes actually received (git-fixes). - HID: roccat: bound device-supplied profile index (git-fixes). - HID: roccat: free buffered reports when destroying device (git-fixes). - HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git-fixes). - HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). - HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). - HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). - hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). - hwmon: (lm25066) Use i2c_get_match_data() (stable-fixes). - hwmon: (max6621) fix negative temperature offset and crit readings (git-fixes). - hwmon: (max6621) fix temperature clamp range (git-fixes). - hwmon: (nzxt-smart2) Check return value of init_device() in probe (git-fixes). - hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). - hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). - hwrng: omap - Fix probe error path cleanup (git-fixes). - hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git-fixes). - i2c: bcm-iproc: remove printout on handled timeouts (stable-fixes). - i2c: core: fix debugfs UAF on adapter removal (git-fixes). - i2c: iproc: reset bus after timeout if START_BUSY is stuck (git-fixes). - i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). - i2c: mux: Fix channel node leak on adapter add failure (git-fixes). - i2c: ocores: Disable clock on failed resume (git-fixes). - i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). - i3c: master: Fix device_register() error path (git-fixes). - i3c: master: Fix info leak and UAF in device unregister path (git-fixes). - i3c: master: Fix potential UAF in i3c_device_uevent() (git-fixes). - i3c: master: svc: bound IBI payload to the requested max_payload_len (git-fixes). - ibmvnic: Only record tx completed bytes once per handler (bsc#1274620). - iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). - iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). - iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). - iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). - iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). - iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). - iio: light: cm32181: return zero after writing calibscale (git-fixes). - iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). - iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). - iio: light: isl29028: return zero in write_raw() on success (git-fixes). - iio: light: tsl2583: return zero in write_raw() on success (git-fixes). - iio: light: tsl2772: fix ALS calibscale readback (git-fixes). - iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). - iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git-fixes). - iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). - iio: srf04: fix pm_runtime handling on probe error path (git-fixes). - iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). - Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). - Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). - Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). - Input: evdev - sanitize event type index when fetching event masks (stable-fixes). - Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). - Input: focaltech - use signed coordinates to prevent underflow (git-fixes). - Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). - Input: iforce - validate input packet lengths (stable-fixes). - Input: iqs5xx - validate firmware record destination span (git-fixes). - Input: mms114 - fix Y-resolution configuration (git-fixes). - Input: psxpad-spi - set driver data before use (git-fixes). - Input: sur40 - fix input device registration ordering (stable-fixes). - Input: sur40 - fix V4L error path cleanup (stable-fixes). - Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). - Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). - Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git-fixes). - Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git-fixes). - Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). - Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). - interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). - ipmi: ipmb: validate write message length (git-fixes). - ipmi: si: Fix NULL pointer dereference after failed registration (git-fixes). - kthread: Default affine kthread to its preferred NUMA node (bsc#1269313). - kthread: Make sure kthread hasn't started while binding it (bsc#1269313). - KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes). - KVM: PPC: Book3S HV: Add support for compat CPU capabilities for KVM on PowerNV (bsc#1263864 ltc#217835). - KVM: PPC: Book3S HV: Implement compat CPU capability retrieval for KVM on PowerVM (bsc#1263864 ltc#217835). - KVM: PPC: Book3S HV: Validate arch_compat against host compatibility mode (bsc#1263864 ltc#217835). - KVM: PPC: Document KVM_PPC_GET_COMPAT_CAPS ioctl (bsc#1263864 ltc#217835). - KVM: PPC: Introduce KVM_CAP_PPC_COMPAT_CAPS and wire up ioctl (bsc#1263864 ltc#217835). - KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). - leds: pca9532: Fix inverted GPIO output polarity (git-fixes). - leds: pca9532: Fix phantom device registration on missing hardware (git-fixes). - lib/string: fix memchr_inv() for large ranges (git-fixes). - lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). - mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git-fixes). - mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). - maple_tree: fix argument name in header (git-fixes). - md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). - media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). - media: amphion: Remove obsolete frame_count check in venc_start_session (git-fixes). - media: cec-pin: Fix event FIFO ordering (git-fixes). - media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). - media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). - media: cec: Serialize exclusive follower delivery (git-fixes). - media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). - media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). - media: cobalt: Avoid freeing ALSA private data twice (git-fixes). - media: cx231xx: reject geometry changes while the VBI queue is busy (git-fixes). - media: cx23885: cancel NetUP CI work before teardown (git-fixes). - media: em28xx: defer audio-only extension registration (git-fixes). - media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git-fixes). - media: go7007: defer the ALSA v4l2 put until card release (git-fixes). - media: i2c: imx219: Rename VTS to FRM_LENGTH (stable-fixes). - media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). - media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). - media: i2c: rdacm21: Fix missing media_entity_cleanup() (git-fixes). - media: imx219: Fix maximum frame length in lines (git-fixes). - media: intel/ipu6: fix async notifier cleanup leak on parse error (git-fixes). - media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git-fixes). - media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). - media: mc-entity: Add missing kerneldoc (git-fixes). - media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git-fixes). - media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). - media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). - media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). - media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). - media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). - media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). - media: s2255: bound JPEG frame size before copying into the buffer (git-fixes). - media: s2255: check firmware size before reading trailing marker (git-fixes). - media: saa7164: fix cleanup on resource allocation failure (git-fixes). - media: tda18250: fix possible integer overflow (git-fixes). - media: usbtv: keep device alive while ALSA card exists (git-fixes). - media: v4l2-async: avoid deleting unlinked ASC entry on link error (git-fixes). - media: v4l2-async: Unregister sub-device if asc_list is empty (git-fixes). - media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git-fixes). - media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). - media: venus: fix payload size calculation in parse_raw_formats() (git-fixes). - media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). - media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). - media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). - media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). - media: zoran: Avoid freeing a registered video_device twice (git-fixes). - mei: pull kvfree out of spinlock (git-fixes). - mfd: iqs62x: Reject zero-length firmware records (git-fixes). - mfd: rave-sp: validate received frame payload lengths (git-fixes). - misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). - misc: fastrpc: fix channel ctx ref leak when session alloc fails (git-fixes). - misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). - misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). - misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git-fixes). - misc: rtsx: add missing write register handling (git-fixes). - misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git-fixes). - mkspec-dtb: Move DTS prefix into package list. - mkspec-dtb: Move provides-obsoletes to package list. - mkspec-dtb: Put per-architecture package lists into a hash. - mkspec-dtb: re-indent. - mm: Create/affine kcompactd to its preferred node (bsc#1269313). - mm: Create/affine kswapd to its preferred node (bsc#1269313). - mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git-fixes). - mmc: sdhci: unmap the bounce buffer before device release (git-fixes). - mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). - mtd: afs: validate v2 image info bounds (git-fixes). - mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). - mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). - mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). - mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). - net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). - net: mana: Add handler for sriov configure (bsc#1272756). - net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). - net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). - net: mana: Fall back to scattered pages for GDMA queues (git-fixes). - net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). - net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). - net: mana: Route ring-buffer access through offset-based helpers (git-fixes). - net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). - net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git-fixes). - net: thunderbolt: Mark the connection down when bringing it up fails (git-fixes). - net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git-fixes). - net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). - net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). - net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). - nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). - nfc: digital: Do not dump a NULL response in command completion (git-fixes). - nfc: fdp: bound the device-reported read length and fix an skb leak (git-fixes). - nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). - nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git-fixes). - nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). - nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). - nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git-fixes). - nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). - nfc: microread: validate target discovery payload lengths (git-fixes). - nfc: nci: fix double completion race in nci_data_exchange_complete (git-fixes). - nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git-fixes). - nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git-fixes). - nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git-fixes). - nfc: nci: free destination parameters when closing a connection (git-fixes). - nfc: pn533: hold a reference to the request skb during send_frame (git-fixes). - nfc: pn533: purge fragmented skbs during cleanup (git-fixes). - nfc: st21nfca: validate ATR_REQ length against the received frame (git-fixes). - nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git-fixes). - of: fix out-of-bounds read in of_alias_scan() stem parser (git-fixes). - PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). - PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk (git-fixes). - PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git-fixes). - PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). - PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). - phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs (git-fixes). - phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (git-fixes). - phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table (git-fixes). - phy: sunplus: fix error handling in sp_uphy_init() (git-fixes). - pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). - pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). - pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). - pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). - pinctrl: rockchip: Reset the pin count when recalculating SoC data (git-fixes). - platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). - platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). - platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git-fixes). - platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). - platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git-fixes). - platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). - platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git-fixes). - platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). - platform/x86/amd/hsmp: Reject negative power cap writes in hwmon (git-fixes). - platform/x86: dell-privacy: Fix race condition (git-fixes). - platform/x86: dell-wmi-base: Fix resource leak on module load failure (git-fixes). - platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). - platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). - platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS (git-fixes). - platform/x86: hp-bioscfg: advance elem past consumed array elements (git-fixes). - platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() (git-fixes). - platform/x86: hp-bioscfg: fix heap OOB read on empty password write (git-fixes). - platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password (git-fixes). - platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() (git-fixes). - platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed (git-fixes). - platform/x86: hp-bioscfg: fix password encoding bounds check (git-fixes). - platform/x86: hp-bioscfg: warn on element type mismatch instead of failing (git-fixes). - platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). - platform/x86: ISST: Add a NULL check for sst_inst (git-fixes). - platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). - platform/x86: ISST: Return error during profile addition (git-fixes). - platform/x86: ISST: Use PP level enable mask (git-fixes). - platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). - platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). - platform/x86: ISST: Validate parameter for core power state (git-fixes). - platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). - PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). - power: supply: bd99954: Drop bad register fields (git-fixes). - power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git-fixes). - power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git-fixes). - power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). - power: supply: bq256xx: drain usb_work before freeing the charger (git-fixes). - power: supply: bq24257: fix use-after-free on remove (git-fixes). - power: supply: bq25890: Fix power_supply reference leak (git-fixes). - power: supply: cros_usbpd-charger: bound the EC-reported port count (git-fixes). - power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git-fixes). - power: supply: isp1704_charger: cancel work on remove (git-fixes). - power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git-fixes). - power: supply: max17040: drop incorrect I2C functionality check (git-fixes). - power: supply: max17040: synchronize work cancellation on suspend (git-fixes). - power: supply: qcom_battmgr: terminate the strings from firmware (git-fixes). - power: supply: rt9455: quiesce delayed work before teardown (git-fixes). - power: supply: sbs-battery: Use a per-device serial number buffer (git-fixes). - power: supply: twl4030_charger: cancel workers via devm (git-fixes). - power: supply: ucs1002: fix use-after-free on remove (git-fixes). - powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). - powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors (bsc#1263864 ltc#217835). - powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). - powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). - powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). - powerpc: Replace __ASSEMBLY__ with __ASSEMBLER__ in non-uapi headers (bsc#1263864 ltc#217835). - powerpc: Replace __ASSEMBLY__ with __ASSEMBLER__ in uapi headers (bsc#1263864 ltc#217835). - ppdev: prevent overflow when setting port timeout (git-fixes). - qede: fix out-of-bounds check for cqe->len_list (git-fixes). - rapidio: clear mport->net when rio_add_net() fails (git-fixes). - rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). - RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). - RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). - RDMA/mana_ib: unify QP lookup table (git-fixes). - RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). - regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). - regulator: core: use system_freezable_wq for init complete work (git-fixes). - regulator: devres: add API for reference voltage supplies (stable-fixes). - regulator: devres: fix devm_regulator_get_enable_read_voltage() return (git-fixes). - regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). - regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). - remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). - remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). - remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). - Revert 'drm/amdgpu: fix aperture mapping leak' (git-fixes). - Revert 'media: v4l2-dev: fix error handling in __video_register_device()' (git-fixes). - Revert 'thermal/drivers/hwmon: Cleanup coding style a bit' (stable-fixes). - rpmsg: core: Fix incorrect return value documentation (git-fixes). - rpmsg: glink: smem: order FIFO read after availability check (git-fixes). - rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). - rtc: pcf8563: fix clock provider leak on unbind (git-fixes). - rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). - rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). - rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git-fixes). - rtc: zynqmp: Return optional clock lookup errors (git-fixes). - sched,arm64: Handle CPU isolation on last resort fallback rq (bsc#1269313). - scsi: fnic: Abort timed-out NVMe LS requests (bsc#1236344). - scsi: fnic: Add FDLS role handling for NVMe initiators (bsc#1236344). - scsi: fnic: Add the NVMe/FC transport path (bsc#1236344). - scsi: fnic: Advertise NVMe initiator service parameters (bsc#1236344). - scsi: fnic: Bump up version number (bsc#1236344). - scsi: fnic: Decode firmware role configuration (bsc#1236344). - scsi: fnic: Do not use GFP_ZERO for mempools (bsc#1236344). - scsi: fnic: Expose NVMe transport state in debugfs (bsc#1236344). - scsi: fnic: Handle NVMe LS frames in FDLS (bsc#1236344). - scsi: fnic: Make debug logging protocol independent (bsc#1236344). - scsi: fnic: Make fnic_queuecommand() easier to analyze (bsc#1236344). - scsi: fnic: Refactor in_remove flag and call to fnic_fcpio_reset() (bsc#1236344). - scsi: fnic: Remove a useless struct mempool forward declaration (bsc#1236344). - scsi: fnic: Rename fnic_scsi_fcpio_reset() (bsc#1236344). - scsi: fnic: Route completions and resets by initiator role (bsc#1236344). - scsi: fnic: Self-assignment of intr_time_type has no effect (bsc#1236344). - scsi: fnic: Send NVMe LS requests through FDLS (bsc#1236344). - scsi: fnic: Switch to use %ptSp (bsc#1236344). - scsi: fnic: Track NVMe transport statistics (bsc#1236344). - scsi: fnic: Use fnic_num for non-SCSI identifiers (bsc#1236344). - scsi: fnic: Use mempool for receive frames (bsc#1236344). - scsi: qla2xxx: Declare qla2xxx_mqueuecommand() static (bsc#1275737). - scsi: qla2xxx: Use nr_cpu_ids instead of NR_CPUS for qp_cpu_map allocation (bsc#1275737). - scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). - sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). - serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). - serial: amba-pl011: unprepare console clock on unregister (git-fixes). - serial: core: clear freed pointers on uart_register_driver() failure (git-fixes). - serial: qcom-geni: fix TX DMA buffer flush (git-fixes). - serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants (stable-fixes). - smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). - smb: client: reject overlapping data areas in SMB2 responses (git-fixes). - smb: client: require net admin for CIFS SWN netlink (bsc#1273966). - smb: client: resolve SWN tcon from live registrations (bsc#1273872). - soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git-fixes). - soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). - soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). - software node: Fix software_node_get_reference_args() with index -1 (git-fixes). - soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git-fixes). - speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git-fixes). - spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). - spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). - spi: sprd-adi: Fix probe succeeding without registering the controller (git-fixes). - staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). - staging: media: tegra-video: fix of_node_put() on VIP parse errors (git-fixes). - staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). - staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git-fixes). - staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). - staging: rtl8723bs: fix missing shared-key auth challenge length check (git-fixes). - staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). - staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). - staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). - staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). - staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). - thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). - thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). - thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). - thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). - thunderbolt: Fix bandwidth group reservation indexing (git-fixes). - thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). - tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). - tpm: st33zp24: Return zero on status read failure (git-fixes). - tpm: st33zp24: Validate locality read result (git-fixes). - tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). - tty: clear cdev pointer after cdev_add() failure (git-fixes). - tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). - tty: skip cdev_del() when no cdev is registered (git-fixes). - uaccess: add copy_struct_to_user helper (bsc#1263864 ltc#217835). - uaccess: fix ignored_trailing logic in copy_struct_to_user() (bsc#1263864 ltc#217835). - uio: Fix stale info pointer in failed registration path (git-fixes). - usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). - usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). - USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). - usb: cdnsp: fix incorrect endian conversions for APB timeout register (git-fixes). - usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). - usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). - usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). - usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). - usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). - usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). - usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git-fixes). - usb: gadget: pch_udc: remove excess kernel-doc member for registered (git-fixes). - usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). - usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). - usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git-fixes). - usb: gadget: uac: validate rate list length before storing (git-fixes). - usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). - usb: mtu3: allow system suspend during active gadget connection (git-fixes). - usb: musb: omap2430: clean up probe error handling (stable-fixes). - USB: phy: fsl-usb: fix missing static keywords (git-fixes). - usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). - USB: serial: digi_acceleport: fix port registration order (git-fixes). - USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). - USB: serial: option: add TDTECH MT5710-CN (stable-fixes). - USB: serial: option: fix slab OOB read in interrupt URB callback (git-fixes). - USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). - USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). - usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive() (git-fixes). - usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). - usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git-fixes). - usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). - vt: add permission check for KDSKBMETA ioctl (stable-fixes). - vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable-fixes). - w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). - w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). - wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). - wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). - wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). - wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). - wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git-fixes). - wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). - wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). - wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). - wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). - wifi: brcmfmac: fix P2P action frame handling without device vif (git-fixes). - wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). - wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). - wifi: iwlwifi: mei: check SAP message length before reading it (git-fixes). - wifi: iwlwifi: mei: pass correct argument to function (git-fixes). - wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). - wifi: mac80211: disconnect on CSA to channel 0 (git-fixes). - wifi: mac80211: fix multi-link element inheritance (git-fixes). - wifi: mac80211: fix per-STA profile length in cross-link CSA parsing (git-fixes). - wifi: mac80211: send TWT teardown to peer after setup TX failure (git-fixes). - wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). - wifi: mac80211: skip unused probe response countdown offsets (git-fixes). - wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). - wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). - wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). - wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git-fixes). - wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). - wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git-fixes). - wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git-fixes). - wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). - wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git-fixes). - wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git-fixes). - wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). - wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). - wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git-fixes). - wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). - wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git-fixes). - wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). - wifi: mt76: mt7921: validate CLC firmware records (git-fixes). - wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git-fixes). - wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git-fixes). - wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git-fixes). - wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). - wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU (git-fixes). - wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). - wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git-fixes). - wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). - wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git-fixes). - wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). - wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). - wifi: rtl818x: initialize eeprom_93cx6 struct to zero (git-fixes). - wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). - wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). - wifi: rtw89: fix HE extended capability length check (git-fixes). - wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git-fixes). - x86/bugs: Clarify that syscall hardening isn't a BHI mitigation (git-fixes). - x86/cpu: Add CPU model number for Bartlett Lake CPUs with Raptor Cove cores (bsc#1240957 bsc#1249104 bsc#1265220). - xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). - xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4263-1 Released: Fri Sep 18 13:40:22 2026 Summary: Recommended update for suse-module-tools Type: recommended Severity: moderate References: 1257055,1262432 This update for suse-module-tools fixes the following issues: - Update to version 15.7.11: * weak-modules2: don't remove symlinks in the rpm --reinstall case (bsc#1257055, bsc#1262432) The following package changes have been done: - glibc-2.38-150600.14.58.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - glibc-locale-base-2.38-150600.14.58.1 updated - kernel-macros-6.4.0-150700.53.81.1 updated - glibc-locale-2.38-150600.14.58.1 updated - kernel-devel-6.4.0-150700.53.81.1 updated - suse-module-tools-15.7.11-150700.3.14.1 updated - glibc-devel-2.38-150600.14.58.1 updated - kernel-default-devel-6.4.0-150700.53.81.1 updated - kernel-syms-6.4.0-150700.53.81.1 updated - container:registry.suse.com-bci-bci-base-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated From sle-container-updates at lists.suse.com Wed Sep 23 08:12:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 10:12:43 +0200 (CEST) Subject: SUSE-IU-2026:7295-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260923081243.2DBD2FF1E@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7295-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.81 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.81 Severity : important Type : security References : 1236344 1240890 1240957 1249104 1255225 1255531 1256629 1256671 1258278 1260501 1260577 1262073 1262756 1263004 1263864 1263865 1264267 1264335 1264444 1264541 1264587 1264619 1264807 1264851 1265036 1265068 1265121 1265132 1265141 1265220 1266710 1266860 1266874 1266897 1266928 1267023 1267238 1267373 1267501 1267586 1267612 1267882 1267985 1268972 1268979 1269000 1269004 1269010 1269013 1269108 1269113 1269114 1269126 1269134 1269140 1269162 1269167 1269238 1269242 1269256 1269301 1269306 1269380 1269381 1269388 1269402 1269412 1269417 1269528 1269530 1269579 1269590 1269633 1269635 1269655 1269665 1269685 1269686 1269695 1269697 1269774 1269783 1269792 1269815 1269816 1269888 1269965 1269969 1269985 1269999 1270090 1270108 1270111 1270139 1270251 1270266 1270267 1271050 1271256 1271365 1271825 1272148 1272149 1272175 1272182 1272199 1272200 1272210 1272213 1272230 1272260 1272261 1272262 1272284 1272287 1272297 1272346 1272366 1272385 1272390 1272423 1272426 1272429 1272484 1272486 1272497 1272501 1272502 1272513 1272516 1272568 1272569 1272584 1272641 1272643 1272673 1272756 1272786 1272788 1272791 1272798 1272799 1272804 1272855 1272865 1272868 1272869 1272877 1272891 1272893 1272894 1272904 1272905 1272918 1272963 1272969 1272971 1272983 1272985 1273008 1273019 1273027 1273030 1273032 1273033 1273036 1273037 1273038 1273060 1273105 1273107 1273119 1273134 1273231 1273249 1273251 1273260 1273271 1273273 1273274 1273276 1273277 1273280 1273281 1273283 1273284 1273285 1273286 1273288 1273289 1273291 1273294 1273302 1273303 1273305 1273309 1273310 1273311 1273312 1273314 1273316 1273317 1273318 1273319 1273323 1273325 1273327 1273331 1273334 1273335 1273336 1273337 1273338 1273339 1273340 1273341 1273346 1273420 1273422 1273426 1273443 1273460 1273461 1273463 1273465 1273468 1273469 1273471 1273479 1273480 1273482 1273484 1273486 1273488 1273490 1273495 1273501 1273503 1273504 1273506 1273507 1273509 1273511 1273520 1273523 1273524 1273525 1273533 1273536 1273538 1273542 1273550 1273555 1273557 1273567 1273578 1273579 1273581 1273582 1273596 1273597 1273598 1273600 1273601 1273602 1273603 1273679 1273681 1273682 1273734 1273737 1273738 1273739 1273740 1273741 1273742 1273743 1273744 1273745 1273746 1273748 1273749 1273755 1273759 1273762 1273765 1273766 1273769 1273770 1273774 1273776 1273778 1273780 1273782 1273788 1273790 1273796 1273797 1273801 1273803 1273804 1273809 1273810 1273811 1273812 1273813 1273817 1273822 1273824 1273831 1273834 1273838 1273839 1273842 1273844 1273848 1273849 1273852 1273855 1273859 1273860 1273862 1273864 1273866 1273867 1273868 1273869 1273870 1273872 1273876 1273877 1273880 1273882 1273890 1273891 1273892 1273895 1273896 1273898 1273899 1273903 1273904 1273905 1273930 1273933 1273934 1273935 1273936 1273939 1273940 1273941 1273942 1273944 1273945 1273946 1273947 1273949 1273953 1273954 1273956 1273957 1273958 1273959 1273963 1273966 1273967 1273968 1273972 1273974 1273975 1273977 1273988 1273990 1273991 1273995 1273997 1273999 1274001 1274003 1274006 1274008 1274009 1274010 1274011 1274012 1274014 1274017 1274019 1274020 1274026 1274028 1274030 1274031 1274035 1274036 1274040 1274041 1274052 1274055 1274057 1274058 1274060 1274063 1274065 1274067 1274071 1274075 1274076 1274077 1274078 1274208 1274226 1274239 1274243 1274252 1274253 1274258 1274264 1274265 1274267 1274274 1274277 1274278 1274281 1274283 1274286 1274290 1274292 1274294 1274295 1274296 1274314 1274321 1274491 1274492 1274494 1274497 1274539 1274541 1274543 1274545 1274547 1274550 1274556 1274573 1274578 1274580 1274581 1274622 1274624 1274628 1274632 1274636 1274637 1274639 1274640 1274642 1274644 1274645 1274646 1274650 1274651 1274652 1274656 1274657 1274659 1274662 1274665 1274667 1274669 1274670 1274671 1274675 1274677 1274678 1274679 1274681 1274682 1274690 1274694 1274696 1274698 1274699 1274700 1274702 1274703 1274705 1274706 1274707 1274709 1274710 1274713 1274716 1274721 1274725 1274727 1274730 1274737 1274738 1274749 1274750 1274751 1274752 1274753 1274754 1274755 1274756 1274764 1274768 1274770 1274771 1274773 1274782 1274783 1274787 1274800 1274801 1274802 1274803 1274804 1274805 1274807 1274808 1274811 1274813 1274814 1274831 1274834 1274835 1274838 1274847 1274849 1274853 1274868 1274869 1274872 1274873 1274874 1274876 1274877 1274879 1274881 1274883 1274886 1274887 1274888 1274891 1274892 1274893 1274894 1274895 1274896 1274897 1274898 1274899 1274900 1274901 1274902 1274904 1274905 1274906 1274907 1274908 1274913 1274914 1274921 1274924 1274925 1274927 1274929 1274930 1274933 1274934 1274935 1274938 1274939 1274940 1274941 1274945 1274947 1274951 1274952 1274953 1274955 1274957 1274958 1274965 1274968 1274978 1274981 1275040 1275045 1275069 1275071 1275072 1275073 1275076 1275080 1275081 1275083 1275088 1275091 1275092 1275094 1275125 1275126 1275129 1275131 1275132 1275139 1275141 1275146 1275148 1275149 1275150 1275152 1275154 1275155 1275156 1275157 1275158 1275160 1275161 1275163 1275164 1275169 1275173 1275176 1275185 1275190 1275192 1275229 1275236 1275237 1275238 1275239 1275294 1275300 1275301 1275303 1275304 1275305 1275306 1275307 1275470 1275474 1275479 1275481 1275483 1275486 1275487 1275496 1275506 1275509 1275511 1275514 1275517 1275519 1275528 1275535 1275540 1275553 1275555 1275557 1275561 1275566 1275569 1275572 1275574 1275578 1275582 1275583 1275584 1275587 1275588 1275591 1275595 1275596 1275633 1275636 1275650 1275655 1275656 1275659 1275665 1275669 1275672 1275679 1275685 1275687 1275688 1275690 1275695 1275696 1275704 1275737 1275782 1275784 1275787 1275788 1275789 1275790 1275798 1275799 1275801 1275802 1275804 1275805 1275812 1275817 1275818 1275819 1275820 1275821 1275822 1275823 1275827 1275864 1275866 1275867 1275869 1275870 1275871 1275872 1275886 1275905 1275923 1275925 1275928 1275950 1275954 1275956 1275970 1275973 1275975 1275976 1275985 1276006 1276029 1276257 1276258 1276263 1276265 1276267 1276270 1276273 1276277 1276333 1276335 1276339 1276341 1276346 1276354 1276355 1276381 1276395 1276446 1276452 1276468 1276471 1276473 1276500 1276507 1276512 1276528 1276542 1276546 1276547 1276551 1276552 1276553 1276561 1276562 1276566 1276569 1276572 1276577 1276586 1276665 1276766 1276767 1276771 1276785 1276793 1276801 1276803 1276814 1276818 1276821 1276831 1276840 1276864 1276865 1276866 1276870 1276876 1276880 1276905 1276913 1276922 1276931 1276937 1276941 1276955 1276957 1276961 1277022 1277023 1277033 1277034 1277037 1277047 1277054 1277057 1277059 1277062 1277066 1277069 1277070 1277077 1277078 1277092 1277095 1277108 1277114 1277115 1277118 1277120 1277155 1277159 1277160 1277202 1277204 1277227 1277229 1277230 1277231 1277233 1277249 1277254 1277265 1277268 1277275 1277285 1277308 1277311 1277315 1277321 1277328 1277335 1277349 1277350 1277391 1277407 1277408 1277485 1277505 1277513 1277551 1277553 1277561 1277574 1277636 1277641 1277649 1277655 1277656 1277660 1277668 1277680 1277688 1277726 1277728 1277738 1277748 1277761 1277764 1277773 1277775 1277776 1277782 1277783 1277813 1277818 1277822 1277845 1277862 1277874 1277876 1277898 1277901 1277908 1277918 1278039 1278070 1278088 1278094 1278098 1278113 1278155 1278180 1278233 1278236 1278240 1278253 1278293 1278324 1278331 1278334 1278395 1278416 1278703 1278716 1278733 1279487 1279537 1279580 1279813 1279842 1279847 1279887 1280139 CVE-2025-68214 CVE-2025-68358 CVE-2025-68780 CVE-2025-71075 CVE-2026-23113 CVE-2026-23306 CVE-2026-23348 CVE-2026-31418 CVE-2026-31530 CVE-2026-31531 CVE-2026-43116 CVE-2026-43125 CVE-2026-43163 CVE-2026-43239 CVE-2026-43271 CVE-2026-43299 CVE-2026-43331 CVE-2026-43355 CVE-2026-43363 CVE-2026-43416 CVE-2026-43439 CVE-2026-43448 CVE-2026-45860 CVE-2026-45897 CVE-2026-45968 CVE-2026-46007 CVE-2026-46070 CVE-2026-46091 CVE-2026-46107 CVE-2026-46115 CVE-2026-46133 CVE-2026-46135 CVE-2026-46195 CVE-2026-46304 CVE-2026-52912 CVE-2026-52920 CVE-2026-52928 CVE-2026-52929 CVE-2026-52935 CVE-2026-52939 CVE-2026-52946 CVE-2026-52977 CVE-2026-52990 CVE-2026-52991 CVE-2026-52994 CVE-2026-53001 CVE-2026-53031 CVE-2026-53033 CVE-2026-53034 CVE-2026-53048 CVE-2026-53059 CVE-2026-53061 CVE-2026-53076 CVE-2026-53077 CVE-2026-53089 CVE-2026-53091 CVE-2026-53092 CVE-2026-53094 CVE-2026-53096 CVE-2026-53109 CVE-2026-53110 CVE-2026-53111 CVE-2026-53114 CVE-2026-53126 CVE-2026-53129 CVE-2026-53142 CVE-2026-53154 CVE-2026-53163 CVE-2026-53180 CVE-2026-53207 CVE-2026-53219 CVE-2026-53220 CVE-2026-53223 CVE-2026-53228 CVE-2026-53238 CVE-2026-53264 CVE-2026-53269 CVE-2026-53284 CVE-2026-53291 CVE-2026-53309 CVE-2026-53330 CVE-2026-53336 CVE-2026-53337 CVE-2026-53341 CVE-2026-53353 CVE-2026-53365 CVE-2026-53388 CVE-2026-63801 CVE-2026-63803 CVE-2026-63804 CVE-2026-63808 CVE-2026-63810 CVE-2026-63823 CVE-2026-63828 CVE-2026-63860 CVE-2026-63865 CVE-2026-63868 CVE-2026-63879 CVE-2026-63887 CVE-2026-63888 CVE-2026-63889 CVE-2026-63890 CVE-2026-63891 CVE-2026-63898 CVE-2026-63901 CVE-2026-63906 CVE-2026-63917 CVE-2026-63918 CVE-2026-63920 CVE-2026-63921 CVE-2026-63922 CVE-2026-63924 CVE-2026-63925 CVE-2026-63926 CVE-2026-63928 CVE-2026-63941 CVE-2026-63969 CVE-2026-63970 CVE-2026-63984 CVE-2026-63985 CVE-2026-63986 CVE-2026-63987 CVE-2026-63990 CVE-2026-63992 CVE-2026-63993 CVE-2026-63995 CVE-2026-63996 CVE-2026-63997 CVE-2026-63998 CVE-2026-63999 CVE-2026-64000 CVE-2026-64001 CVE-2026-64002 CVE-2026-64003 CVE-2026-64004 CVE-2026-64005 CVE-2026-64006 CVE-2026-64007 CVE-2026-64010 CVE-2026-64011 CVE-2026-64014 CVE-2026-64015 CVE-2026-64017 CVE-2026-64024 CVE-2026-64029 CVE-2026-64033 CVE-2026-64039 CVE-2026-64047 CVE-2026-64048 CVE-2026-64051 CVE-2026-64052 CVE-2026-64053 CVE-2026-64054 CVE-2026-64055 CVE-2026-64056 CVE-2026-64071 CVE-2026-64073 CVE-2026-64083 CVE-2026-64084 CVE-2026-64085 CVE-2026-64086 CVE-2026-64087 CVE-2026-64088 CVE-2026-64089 CVE-2026-64093 CVE-2026-64097 CVE-2026-64098 CVE-2026-64099 CVE-2026-64102 CVE-2026-64103 CVE-2026-64104 CVE-2026-64105 CVE-2026-64109 CVE-2026-64111 CVE-2026-64112 CVE-2026-64113 CVE-2026-64114 CVE-2026-64115 CVE-2026-64118 CVE-2026-64119 CVE-2026-64121 CVE-2026-64125 CVE-2026-64126 CVE-2026-64127 CVE-2026-64128 CVE-2026-64131 CVE-2026-64133 CVE-2026-64134 CVE-2026-64135 CVE-2026-64137 CVE-2026-64144 CVE-2026-64146 CVE-2026-64147 CVE-2026-64148 CVE-2026-64155 CVE-2026-64162 CVE-2026-64164 CVE-2026-64166 CVE-2026-64168 CVE-2026-64169 CVE-2026-64170 CVE-2026-64177 CVE-2026-64178 CVE-2026-64179 CVE-2026-64180 CVE-2026-64184 CVE-2026-64185 CVE-2026-64190 CVE-2026-64192 CVE-2026-64210 CVE-2026-64214 CVE-2026-64217 CVE-2026-64219 CVE-2026-64222 CVE-2026-64224 CVE-2026-64225 CVE-2026-64232 CVE-2026-64237 CVE-2026-64239 CVE-2026-64240 CVE-2026-64243 CVE-2026-64244 CVE-2026-64245 CVE-2026-64246 CVE-2026-64247 CVE-2026-64249 CVE-2026-64253 CVE-2026-64256 CVE-2026-64265 CVE-2026-64266 CVE-2026-64268 CVE-2026-64269 CVE-2026-64270 CVE-2026-64271 CVE-2026-64272 CVE-2026-64273 CVE-2026-64274 CVE-2026-64275 CVE-2026-64276 CVE-2026-64277 CVE-2026-64278 CVE-2026-64279 CVE-2026-64283 CVE-2026-64286 CVE-2026-64287 CVE-2026-64294 CVE-2026-64296 CVE-2026-64298 CVE-2026-64300 CVE-2026-64301 CVE-2026-64303 CVE-2026-64304 CVE-2026-64305 CVE-2026-64306 CVE-2026-64307 CVE-2026-64308 CVE-2026-64309 CVE-2026-64310 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64316 CVE-2026-64317 CVE-2026-64319 CVE-2026-64320 CVE-2026-64321 CVE-2026-64322 CVE-2026-64323 CVE-2026-64326 CVE-2026-64327 CVE-2026-64328 CVE-2026-64329 CVE-2026-64331 CVE-2026-64332 CVE-2026-64333 CVE-2026-64334 CVE-2026-64335 CVE-2026-64337 CVE-2026-64338 CVE-2026-64340 CVE-2026-64341 CVE-2026-64342 CVE-2026-64343 CVE-2026-64344 CVE-2026-64346 CVE-2026-64348 CVE-2026-64350 CVE-2026-64351 CVE-2026-64354 CVE-2026-64355 CVE-2026-64358 CVE-2026-64362 CVE-2026-64364 CVE-2026-64365 CVE-2026-64367 CVE-2026-64368 CVE-2026-64373 CVE-2026-64375 CVE-2026-64376 CVE-2026-64378 CVE-2026-64380 CVE-2026-64381 CVE-2026-64382 CVE-2026-64383 CVE-2026-64384 CVE-2026-64385 CVE-2026-64386 CVE-2026-64387 CVE-2026-64401 CVE-2026-64403 CVE-2026-64404 CVE-2026-64406 CVE-2026-64407 CVE-2026-64408 CVE-2026-64409 CVE-2026-64411 CVE-2026-64412 CVE-2026-64415 CVE-2026-64416 CVE-2026-64420 CVE-2026-64421 CVE-2026-64423 CVE-2026-64427 CVE-2026-64429 CVE-2026-64433 CVE-2026-64434 CVE-2026-64436 CVE-2026-64440 CVE-2026-64442 CVE-2026-64443 CVE-2026-64444 CVE-2026-64445 CVE-2026-64446 CVE-2026-64450 CVE-2026-64452 CVE-2026-64454 CVE-2026-64455 CVE-2026-64456 CVE-2026-64458 CVE-2026-64463 CVE-2026-64470 CVE-2026-64471 CVE-2026-64472 CVE-2026-64477 CVE-2026-64478 CVE-2026-64479 CVE-2026-64480 CVE-2026-64481 CVE-2026-64482 CVE-2026-64483 CVE-2026-64484 CVE-2026-64486 CVE-2026-64487 CVE-2026-64489 CVE-2026-64490 CVE-2026-64494 CVE-2026-64495 CVE-2026-64496 CVE-2026-64497 CVE-2026-64499 CVE-2026-64500 CVE-2026-64503 CVE-2026-64504 CVE-2026-64505 CVE-2026-64507 CVE-2026-64511 CVE-2026-64512 CVE-2026-64513 CVE-2026-64515 CVE-2026-64517 CVE-2026-64518 CVE-2026-64519 CVE-2026-64524 CVE-2026-64525 CVE-2026-64526 CVE-2026-64527 CVE-2026-64534 CVE-2026-64535 CVE-2026-64536 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539 CVE-2026-64540 CVE-2026-64541 CVE-2026-64542 CVE-2026-64543 CVE-2026-64544 CVE-2026-64545 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64551 CVE-2026-64552 CVE-2026-64553 CVE-2026-64554 CVE-2026-64555 CVE-2026-64556 CVE-2026-64558 CVE-2026-64559 CVE-2026-64561 CVE-2026-64562 CVE-2026-64563 CVE-2026-64565 CVE-2026-64567 CVE-2026-64568 CVE-2026-64569 CVE-2026-64570 CVE-2026-64571 CVE-2026-64572 CVE-2026-64573 CVE-2026-64574 CVE-2026-64576 CVE-2026-64577 CVE-2026-64579 CVE-2026-64581 CVE-2026-64582 CVE-2026-64583 CVE-2026-64584 CVE-2026-64585 CVE-2026-64586 CVE-2026-64589 CVE-2026-64593 CVE-2026-64599 CVE-2026-64602 CVE-2026-64603 CVE-2026-64604 CVE-2026-68081 CVE-2026-68082 CVE-2026-68085 CVE-2026-68086 CVE-2026-68088 CVE-2026-68091 CVE-2026-68093 CVE-2026-68096 CVE-2026-68102 CVE-2026-68104 CVE-2026-68105 CVE-2026-68106 CVE-2026-68107 CVE-2026-68108 CVE-2026-68110 CVE-2026-68111 CVE-2026-68112 CVE-2026-68113 CVE-2026-68115 CVE-2026-68116 CVE-2026-68117 CVE-2026-68120 CVE-2026-68121 CVE-2026-68123 CVE-2026-68124 CVE-2026-68125 CVE-2026-68126 CVE-2026-68127 CVE-2026-68128 CVE-2026-68129 CVE-2026-68132 CVE-2026-68133 CVE-2026-68135 CVE-2026-68136 CVE-2026-68137 CVE-2026-68138 CVE-2026-68139 CVE-2026-68141 CVE-2026-68142 CVE-2026-68143 CVE-2026-68144 CVE-2026-68145 CVE-2026-68148 CVE-2026-68149 CVE-2026-68152 CVE-2026-68153 CVE-2026-68154 CVE-2026-68155 CVE-2026-68156 CVE-2026-68157 CVE-2026-68158 CVE-2026-68159 CVE-2026-68161 CVE-2026-68164 CVE-2026-68165 CVE-2026-68166 CVE-2026-68169 CVE-2026-68178 CVE-2026-68179 CVE-2026-68180 CVE-2026-68181 CVE-2026-68182 CVE-2026-68183 CVE-2026-68184 CVE-2026-68188 CVE-2026-68189 CVE-2026-68192 CVE-2026-68193 CVE-2026-68194 CVE-2026-68195 CVE-2026-68196 CVE-2026-68197 CVE-2026-68198 CVE-2026-68199 CVE-2026-68200 CVE-2026-68201 CVE-2026-68202 CVE-2026-68203 CVE-2026-68204 CVE-2026-68205 CVE-2026-68206 CVE-2026-68207 CVE-2026-68209 CVE-2026-68210 CVE-2026-68212 CVE-2026-68213 CVE-2026-68214 CVE-2026-68215 CVE-2026-68216 CVE-2026-68217 CVE-2026-68218 CVE-2026-68219 CVE-2026-68220 CVE-2026-68221 CVE-2026-68222 CVE-2026-68223 CVE-2026-68225 CVE-2026-68226 CVE-2026-68227 CVE-2026-68228 CVE-2026-68229 CVE-2026-68231 CVE-2026-68234 CVE-2026-68235 CVE-2026-68236 CVE-2026-68238 CVE-2026-68243 CVE-2026-68244 CVE-2026-68245 CVE-2026-68246 CVE-2026-68247 CVE-2026-68248 CVE-2026-68249 CVE-2026-68250 CVE-2026-68251 CVE-2026-68252 CVE-2026-68253 CVE-2026-68254 CVE-2026-68255 CVE-2026-68256 CVE-2026-68257 CVE-2026-68258 CVE-2026-68259 CVE-2026-68260 CVE-2026-68261 CVE-2026-68262 CVE-2026-68263 CVE-2026-68267 CVE-2026-68269 CVE-2026-68271 CVE-2026-68272 CVE-2026-68273 CVE-2026-68277 CVE-2026-68278 CVE-2026-68279 CVE-2026-68280 CVE-2026-68281 CVE-2026-68284 CVE-2026-68286 CVE-2026-68288 CVE-2026-68289 CVE-2026-68293 CVE-2026-68294 CVE-2026-68296 CVE-2026-68297 CVE-2026-68299 CVE-2026-68300 CVE-2026-68302 CVE-2026-68303 CVE-2026-68304 CVE-2026-68306 CVE-2026-68307 CVE-2026-68308 CVE-2026-68309 CVE-2026-68310 CVE-2026-68311 CVE-2026-68313 CVE-2026-68315 CVE-2026-68319 CVE-2026-68320 CVE-2026-68321 CVE-2026-68322 CVE-2026-68325 CVE-2026-68326 CVE-2026-68327 CVE-2026-68328 CVE-2026-68329 CVE-2026-68331 CVE-2026-68333 CVE-2026-68335 CVE-2026-68336 CVE-2026-68338 CVE-2026-68339 CVE-2026-68340 CVE-2026-68344 CVE-2026-68346 CVE-2026-68348 CVE-2026-68349 CVE-2026-68350 CVE-2026-68351 CVE-2026-68352 CVE-2026-68353 CVE-2026-68354 CVE-2026-68355 CVE-2026-68357 CVE-2026-68358 CVE-2026-68359 CVE-2026-68360 CVE-2026-68361 CVE-2026-68362 CVE-2026-68363 CVE-2026-68365 CVE-2026-68366 CVE-2026-68368 CVE-2026-68369 CVE-2026-68370 CVE-2026-68371 CVE-2026-68372 CVE-2026-68373 CVE-2026-68374 CVE-2026-68375 CVE-2026-68377 CVE-2026-68386 CVE-2026-68389 CVE-2026-68391 CVE-2026-68392 CVE-2026-68393 CVE-2026-68394 CVE-2026-68395 CVE-2026-68397 CVE-2026-68398 CVE-2026-68399 CVE-2026-68402 CVE-2026-68403 CVE-2026-68405 CVE-2026-68406 CVE-2026-68407 CVE-2026-68408 CVE-2026-68410 CVE-2026-68413 CVE-2026-68414 CVE-2026-68416 CVE-2026-68417 CVE-2026-68418 CVE-2026-68419 CVE-2026-68422 CVE-2026-68425 CVE-2026-68426 CVE-2026-68427 CVE-2026-68428 CVE-2026-68429 CVE-2026-68430 CVE-2026-68432 CVE-2026-68433 CVE-2026-68434 CVE-2026-68437 CVE-2026-68439 CVE-2026-68442 CVE-2026-68443 CVE-2026-68444 CVE-2026-68445 CVE-2026-68446 CVE-2026-68448 CVE-2026-68450 CVE-2026-68470 CVE-2026-68480 CVE-2026-72017 CVE-2026-72019 CVE-2026-72020 CVE-2026-72022 CVE-2026-72023 CVE-2026-72032 CVE-2026-72034 CVE-2026-72035 CVE-2026-72036 CVE-2026-72045 CVE-2026-72046 CVE-2026-72051 CVE-2026-72052 CVE-2026-72053 CVE-2026-72054 CVE-2026-72055 CVE-2026-72061 CVE-2026-72069 CVE-2026-72072 CVE-2026-72083 CVE-2026-72084 CVE-2026-72100 CVE-2026-72101 CVE-2026-72103 CVE-2026-72106 CVE-2026-72107 CVE-2026-72108 CVE-2026-72132 CVE-2026-72136 CVE-2026-72137 CVE-2026-72161 CVE-2026-72163 CVE-2026-72164 CVE-2026-72176 CVE-2026-72177 CVE-2026-72217 CVE-2026-72221 CVE-2026-72222 CVE-2026-72234 CVE-2026-72242 CVE-2026-72243 CVE-2026-72251 CVE-2026-72254 CVE-2026-72280 CVE-2026-72282 CVE-2026-72288 CVE-2026-72289 CVE-2026-72296 CVE-2026-72297 CVE-2026-72306 CVE-2026-72307 CVE-2026-72308 CVE-2026-72317 CVE-2026-72323 CVE-2026-72325 CVE-2026-72330 CVE-2026-72337 CVE-2026-72339 CVE-2026-72341 CVE-2026-72342 CVE-2026-72343 CVE-2026-72345 CVE-2026-72347 CVE-2026-72350 CVE-2026-72366 CVE-2026-72379 CVE-2026-72389 CVE-2026-72398 CVE-2026-72399 CVE-2026-72414 CVE-2026-72421 CVE-2026-72425 CVE-2026-72430 CVE-2026-72437 CVE-2026-72438 CVE-2026-72439 CVE-2026-72440 CVE-2026-72448 CVE-2026-72450 CVE-2026-72459 CVE-2026-72460 CVE-2026-72464 CVE-2026-72466 CVE-2026-72467 CVE-2026-72468 CVE-2026-72469 CVE-2026-72473 CVE-2026-72485 CVE-2026-72487 CVE-2026-72488 CVE-2026-72494 CVE-2026-72495 CVE-2026-72497 CVE-2026-72499 CVE-2026-72500 CVE-2026-72501 CVE-2026-72502 CVE-2026-74255 CVE-2026-74261 CVE-2026-74269 CVE-2026-74270 CVE-2026-74282 CVE-2026-74284 CVE-2026-74286 CVE-2026-74296 CVE-2026-74297 CVE-2026-74307 CVE-2026-74308 CVE-2026-74313 CVE-2026-74316 CVE-2026-74317 CVE-2026-74318 CVE-2026-74321 CVE-2026-74334 CVE-2026-74345 CVE-2026-74346 CVE-2026-74349 CVE-2026-74363 CVE-2026-74375 CVE-2026-74377 CVE-2026-74378 CVE-2026-74382 CVE-2026-74388 CVE-2026-74390 CVE-2026-74394 CVE-2026-74395 CVE-2026-74397 CVE-2026-74406 CVE-2026-74464 CVE-2026-74474 CVE-2026-74475 CVE-2026-74476 CVE-2026-74479 CVE-2026-74481 CVE-2026-74482 CVE-2026-74495 CVE-2026-74496 CVE-2026-74510 CVE-2026-74512 CVE-2026-74513 CVE-2026-74517 CVE-2026-74518 CVE-2026-74523 CVE-2026-74527 CVE-2026-74533 CVE-2026-74534 CVE-2026-74535 CVE-2026-74536 CVE-2026-74537 CVE-2026-74545 CVE-2026-74548 CVE-2026-74550 CVE-2026-74555 CVE-2026-74556 CVE-2026-74557 CVE-2026-74563 CVE-2026-74566 CVE-2026-74567 CVE-2026-74571 CVE-2026-74577 CVE-2026-74581 CVE-2026-74582 CVE-2026-74584 CVE-2026-74598 CVE-2026-74610 CVE-2026-74612 CVE-2026-74615 CVE-2026-74616 CVE-2026-74622 CVE-2026-74644 CVE-2026-74665 CVE-2026-74669 CVE-2026-74695 CVE-2026-74705 CVE-2026-74712 CVE-2026-74717 CVE-2026-74719 CVE-2026-74722 CVE-2026-74723 CVE-2026-74730 CVE-2026-74737 CVE-2026-74743 CVE-2026-74744 CVE-2026-80529 CVE-2026-80530 CVE-2026-80531 CVE-2026-80533 CVE-2026-80534 CVE-2026-80535 CVE-2026-80557 CVE-2026-80558 CVE-2026-80561 CVE-2026-80586 CVE-2026-80589 CVE-2026-80590 CVE-2026-80603 CVE-2026-80609 CVE-2026-80629 CVE-2026-80646 CVE-2026-80647 CVE-2026-80667 CVE-2026-80681 CVE-2026-80693 CVE-2026-80714 CVE-2026-80721 CVE-2026-80727 CVE-2026-80731 CVE-2026-80737 CVE-2026-80739 CVE-2026-80805 CVE-2026-80813 CVE-2026-80838 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1738 Released: Tue Sep 22 16:23:31 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1236344,1240890,1240957,1249104,1255225,1255531,1256629,1256671,1258278,1260501,1260577,1262073,1262756,1263004,1263864,1263865,1264267,1264335,1264444,1264541,1264587,1264619,1264807,1264851,1265036,1265068,1265121,1265132,1265141,1265220,1266710,1266860,1266874,1266897,1266928,1267023,1267238,1267373,1267501,1267586,1267612,1267882,1267985,1268972,1268979,1269000,1269004,1269010,1269013,1269108,1269113,1269114,1269126,1269134,1269140,1269162,1269167,1269238,1269242,1269256,1269301,1269306,1269380,1269381,1269388,1269402,1269412,1269417,1269528,1269530,1269579,1269590,1269633,1269635,1269655,1269665,1269685,1269686,1269695,1269697,1269774,1269783,1269792,1269815,1269816,1269888,1269965,1269969,1269985,1269999,1270090,1270108,1270111,1270139,1270251,1270266,1270267,1271050,1271256,1271365,1271825,1272148,1272149,1272175,1272182,1272199,1272200,1272210,1272213,1272230,1272260,1272261,1272262,1272284,1272287,1272297,1272346,1272366,1272385,1272390,1272423,1272426,1272429,1 272484,1272486,1272497,1272501,1272502,1272513,1272516,1272568,1272569,1272584,1272641,1272643,1272673,1272756,1272786,1272788,1272791,1272798,1272799,1272804,1272855,1272865,1272868,1272869,1272877,1272891,1272893,1272894,1272904,1272905,1272918,1272963,1272969,1272971,1272983,1272985,1273008,1273019,1273027,1273030,1273032,1273033,1273036,1273037,1273038,1273060,1273105,1273107,1273119,1273134,1273231,1273249,1273251,1273260,1273271,1273273,1273274,1273276,1273277,1273280,1273281,1273283,1273284,1273285,1273286,1273288,1273289,1273291,1273294,1273302,1273303,1273305,1273309,1273310,1273311,1273312,1273314,1273316,1273317,1273318,1273319,1273323,1273325,1273327,1273331,1273334,1273335,1273336,1273337,1273338,1273339,1273340,1273341,1273346,1273420,1273422,1273426,1273443,1273460,1273461,1273463,1273465,1273468,1273469,1273471,1273479,1273480,1273482,1273484,1273486,1273488,1273490,1273495,1273501,1273503,1273504,1273506,1273507,1273509,1273511,1273520,1273523,1273524,1273525,127353 3,1273536,1273538,1273542,1273550,1273555,1273557,1273567,1273578,1273579,1273581,1273582,1273596,1273597,1273598,1273600,1273601,1273602,1273603,1273679,1273681,1273682,1273734,1273737,1273738,1273739,1273740,1273741,1273742,1273743,1273744,1273745,1273746,1273748,1273749,1273755,1273759,1273762,1273765,1273766,1273769,1273770,1273774,1273776,1273778,1273780,1273782,1273788,1273790,1273796,1273797,1273801,1273803,1273804,1273809,1273810,1273811,1273812,1273813,1273817,1273822,1273824,1273831,1273834,1273838,1273839,1273842,1273844,1273848,1273849,1273852,1273855,1273859,1273860,1273862,1273864,1273866,1273867,1273868,1273869,1273870,1273872,1273876,1273877,1273880,1273882,1273890,1273891,1273892,1273895,1273896,1273898,1273899,1273903,1273904,1273905,1273930,1273933,1273934,1273935,1273936,1273939,1273940,1273941,1273942,1273944,1273945,1273946,1273947,1273949,1273953,1273954,1273956,1273957,1273958,1273959,1273963,1273966,1273967,1273968,1273972,1273974,1273975,1273977,1273988,127 3990,1273991,1273995,1273997,1273999,1274001,1274003,1274006,1274008,1274009,1274010,1274011,1274012,1274014,1274017,1274019,1274020,1274026,1274028,1274030,1274031,1274035,1274036,1274040,1274041,1274052,1274055,1274057,1274058,1274060,1274063,1274065,1274067,1274071,1274075,1274076,1274077,1274078,1274208,1274226,1274239,1274243,1274252,1274253,1274258,1274264,1274265,1274267,1274274,1274277,1274278,1274281,1274283,1274286,1274290,1274292,1274294,1274295,1274296,1274314,1274321,1274491,1274492,1274494,1274497,1274539,1274541,1274543,1274545,1274547,1274550,1274556,1274573,1274578,1274580,1274581,1274622,1274624,1274628,1274632,1274636,1274637,1274639,1274640,1274642,1274644,1274645,1274646,1274650,1274651,1274652,1274656,1274657,1274659,1274662,1274665,1274667,1274669,1274670,1274671,1274675,1274677,1274678,1274679,1274681,1274682,1274690,1274694,1274696,1274698,1274699,1274700,1274702,1274703,1274705,1274706,1274707,1274709,1274710,1274713,1274716,1274721,1274725,1274727,1274730, 1274737,1274738,1274749,1274750,1274751,1274752,1274753,1274754,1274755,1274756,1274764,1274768,1274770,1274771,1274773,1274782,1274783,1274787,1274800,1274801,1274802,1274803,1274804,1274805,1274807,1274808,1274811,1274813,1274814,1274831,1274834,1274835,1274838,1274847,1274849,1274853,1274868,1274869,1274872,1274873,1274874,1274876,1274877,1274879,1274881,1274883,1274886,1274887,1274888,1274891,1274892,1274893,1274894,1274895,1274896,1274897,1274898,1274899,1274900,1274901,1274902,1274904,1274905,1274906,1274907,1274908,1274913,1274914,1274921,1274924,1274925,1274927,1274929,1274930,1274933,1274934,1274935,1274938,1274939,1274940,1274941,1274945,1274947,1274951,1274952,1274953,1274955,1274957,1274958,1274965,1274968,1274978,1274981,1275040,1275045,1275069,1275071,1275072,1275073,1275076,1275080,1275081,1275083,1275088,1275091,1275092,1275094,1275125,1275126,1275129,1275131,1275132,1275139,1275141,1275146,1275148,1275149,1275150,1275152,1275154,1275155,1275156,1275157,1275158,12751 60,1275161,1275163,1275164,1275169,1275173,1275176,1275185,1275190,1275192,1275229,1275236,1275237,1275238,1275239,1275294,1275300,1275301,1275303,1275304,1275305,1275306,1275307,1275470,1275474,1275479,1275481,1275483,1275486,1275487,1275496,1275506,1275509,1275511,1275514,1275517,1275519,1275528,1275535,1275540,1275553,1275555,1275557,1275561,1275566,1275569,1275572,1275574,1275578,1275582,1275583,1275584,1275587,1275588,1275591,1275595,1275596,1275633,1275636,1275650,1275655,1275656,1275659,1275665,1275669,1275672,1275679,1275685,1275687,1275688,1275690,1275695,1275696,1275704,1275737,1275782,1275784,1275787,1275788,1275789,1275790,1275798,1275799,1275801,1275802,1275804,1275805,1275812,1275817,1275818,1275819,1275820,1275821,1275822,1275823,1275827,1275864,1275866,1275867,1275869,1275870,1275871,1275872,1275886,1275905,1275923,1275925,1275928,1275950,1275954,1275956,1275970,1275973,1275975,1275976,1275985,1276006,1276029,1276257,1276258,1276263,1276265,1276267,1276270,1276273,12 76277,1276333,1276335,1276339,1276341,1276346,1276354,1276355,1276381,1276395,1276446,1276452,1276468,1276471,1276473,1276500,1276507,1276512,1276528,1276542,1276546,1276547,1276551,1276552,1276553,1276561,1276562,1276566,1276569,1276572,1276577,1276586,1276665,1276766,1276767,1276771,1276785,1276793,1276801,1276803,1276814,1276818,1276821,1276831,1276840,1276864,1276865,1276866,1276870,1276876,1276880,1276905,1276913,1276922,1276931,1276937,1276941,1276955,1276957,1276961,1277022,1277023,1277033,1277034,1277037,1277047,1277054,1277057,1277059,1277062,1277066,1277069,1277070,1277077,1277078,1277092,1277095,1277108,1277114,1277115,1277118,1277120,1277155,1277159,1277160,1277202,1277204,1277227,1277229,1277230,1277231,1277233,1277249,1277254,1277265,1277268,1277275,1277285,1277308,1277311,1277315,1277321,1277328,1277335,1277349,1277350,1277391,1277407,1277408,1277485,1277505,1277513,1277551,1277553,1277561,1277574,1277636,1277641,1277649,1277655,1277656,1277660,1277668,1277680,1277688 ,1277726,1277728,1277738,1277748,1277761,1277764,1277773,1277775,1277776,1277782,1277783,1277813,1277818,1277822,1277845,1277862,1277874,1277876,1277898,1277901,1277908,1277918,1278039,1278070,1278088,1278094,1278098,1278113,1278155,1278180,1278233,1278236,1278240,1278253,1278293,1278324,1278331,1278334,1278395,1278416,1278703,1278716,1278733,1279487,1279537,1279580,1279813,1279842,1279847,1279887,1280139,CVE-2025-68214,CVE-2025-68358,CVE-2025-68780,CVE-2025-71075,CVE-2026-23113,CVE-2026-23306,CVE-2026-23348,CVE-2026-31418,CVE-2026-31530,CVE-2026-31531,CVE-2026-43116,CVE-2026-43125,CVE-2026-43163,CVE-2026-43239,CVE-2026-43271,CVE-2026-43299,CVE-2026-43331,CVE-2026-43355,CVE-2026-43363,CVE-2026-43416,CVE-2026-43439,CVE-2026-43448,CVE-2026-45860,CVE-2026-45897,CVE-2026-45968,CVE-2026-46007,CVE-2026-46070,CVE-2026-46091,CVE-2026-46107,CVE-2026-46115,CVE-2026-46133,CVE-2026-46135,CVE-2026-46195,CVE-2026-46304,CVE-2026-52912,CVE-2026-52920,CVE-2026-52928,CVE-2026-52929,CVE-2026-52935,CVE -2026-52939,CVE-2026-52946,CVE-2026-52977,CVE-2026-52990,CVE-2026-52991,CVE-2026-52994,CVE-2026-53001,CVE-2026-53031,CVE-2026-53033,CVE-2026-53034,CVE-2026-53048,CVE-2026-53059,CVE-2026-53061,CVE-2026-53076,CVE-2026-53077,CVE-2026-53089,CVE-2026-53091,CVE-2026-53092,CVE-2026-53094,CVE-2026-53096,CVE-2026-53109,CVE-2026-53110,CVE-2026-53111,CVE-2026-53114,CVE-2026-53126,CVE-2026-53129,CVE-2026-53142,CVE-2026-53154,CVE-2026-53163,CVE-2026-53180,CVE-2026-53207,CVE-2026-53219,CVE-2026-53220,CVE-2026-53223,CVE-2026-53228,CVE-2026-53238,CVE-2026-53264,CVE-2026-53269,CVE-2026-53284,CVE-2026-53291,CVE-2026-53309,CVE-2026-53330,CVE-2026-53336,CVE-2026-53337,CVE-2026-53341,CVE-2026-53353,CVE-2026-53365,CVE-2026-53388,CVE-2026-63801,CVE-2026-63803,CVE-2026-63804,CVE-2026-63808,CVE-2026-63810,CVE-2026-63823,CVE-2026-63828,CVE-2026-63860,CVE-2026-63865,CVE-2026-63868,CVE-2026-63879,CVE-2026-63887,CVE-2026-63888,CVE-2026-63889,CVE-2026-63890,CVE-2026-63891,CVE-2026-63898,CVE-2026-63901,CVE-2026-6 3906,CVE-2026-63917,CVE-2026-63918,CVE-2026-63920,CVE-2026-63921,CVE-2026-63922,CVE-2026-63924,CVE-2026-63925,CVE-2026-63926,CVE-2026-63928,CVE-2026-63941,CVE-2026-63969,CVE-2026-63970,CVE-2026-63984,CVE-2026-63985,CVE-2026-63986,CVE-2026-63987,CVE-2026-63990,CVE-2026-63992,CVE-2026-63993,CVE-2026-63995,CVE-2026-63996,CVE-2026-63997,CVE-2026-63998,CVE-2026-63999,CVE-2026-64000,CVE-2026-64001,CVE-2026-64002,CVE-2026-64003,CVE-2026-64004,CVE-2026-64005,CVE-2026-64006,CVE-2026-64007,CVE-2026-64010,CVE-2026-64011,CVE-2026-64014,CVE-2026-64015,CVE-2026-64017,CVE-2026-64024,CVE-2026-64029,CVE-2026-64033,CVE-2026-64039,CVE-2026-64047,CVE-2026-64048,CVE-2026-64051,CVE-2026-64052,CVE-2026-64053,CVE-2026-64054,CVE-2026-64055,CVE-2026-64056,CVE-2026-64071,CVE-2026-64073,CVE-2026-64083,CVE-2026-64084,CVE-2026-64085,CVE-2026-64086,CVE-2026-64087,CVE-2026-64088,CVE-2026-64089,CVE-2026-64093,CVE-2026-64097,CVE-2026-64098,CVE-2026-64099,CVE-2026-64102,CVE-2026-64103,CVE-2026-64104,CVE-2026-64105,CV E-2026-64109,CVE-2026-64111,CVE-2026-64112,CVE-2026-64113,CVE-2026-64114,CVE-2026-64115,CVE-2026-64118,CVE-2026-64119,CVE-2026-64121,CVE-2026-64125,CVE-2026-64126,CVE-2026-64127,CVE-2026-64128,CVE-2026-64131,CVE-2026-64133,CVE-2026-64134,CVE-2026-64135,CVE-2026-64137,CVE-2026-64144,CVE-2026-64146,CVE-2026-64147,CVE-2026-64148,CVE-2026-64155,CVE-2026-64162,CVE-2026-64164,CVE-2026-64166,CVE-2026-64168,CVE-2026-64169,CVE-2026-64170,CVE-2026-64177,CVE-2026-64178,CVE-2026-64179,CVE-2026-64180,CVE-2026-64184,CVE-2026-64185,CVE-2026-64190,CVE-2026-64192,CVE-2026-64210,CVE-2026-64214,CVE-2026-64217,CVE-2026-64219,CVE-2026-64222,CVE-2026-64224,CVE-2026-64225,CVE-2026-64232,CVE-2026-64237,CVE-2026-64239,CVE-2026-64240,CVE-2026-64243,CVE-2026-64244,CVE-2026-64245,CVE-2026-64246,CVE-2026-64247,CVE-2026-64249,CVE-2026-64253,CVE-2026-64256,CVE-2026-64265,CVE-2026-64266,CVE-2026-64268,CVE-2026-64269,CVE-2026-64270,CVE-2026-64271,CVE-2026-64272,CVE-2026-64273,CVE-2026-64274,CVE-2026-64275,CVE-2026- 64276,CVE-2026-64277,CVE-2026-64278,CVE-2026-64279,CVE-2026-64283,CVE-2026-64286,CVE-2026-64287,CVE-2026-64294,CVE-2026-64296,CVE-2026-64298,CVE-2026-64300,CVE-2026-64301,CVE-2026-64303,CVE-2026-64304,CVE-2026-64305,CVE-2026-64306,CVE-2026-64307,CVE-2026-64308,CVE-2026-64309,CVE-2026-64310,CVE-2026-64312,CVE-2026-64313,CVE-2026-64315,CVE-2026-64316,CVE-2026-64317,CVE-2026-64319,CVE-2026-64320,CVE-2026-64321,CVE-2026-64322,CVE-2026-64323,CVE-2026-64326,CVE-2026-64327,CVE-2026-64328,CVE-2026-64329,CVE-2026-64331,CVE-2026-64332,CVE-2026-64333,CVE-2026-64334,CVE-2026-64335,CVE-2026-64337,CVE-2026-64338,CVE-2026-64340,CVE-2026-64341,CVE-2026-64342,CVE-2026-64343,CVE-2026-64344,CVE-2026-64346,CVE-2026-64348,CVE-2026-64350,CVE-2026-64351,CVE-2026-64354,CVE-2026-64355,CVE-2026-64358,CVE-2026-64362,CVE-2026-64364,CVE-2026-64365,CVE-2026-64367,CVE-2026-64368,CVE-2026-64373,CVE-2026-64375,CVE-2026-64376,CVE-2026-64378,CVE-2026-64380,CVE-2026-64381,CVE-2026-64382,CVE-2026-64383,CVE-2026-64384,C VE-2026-64385,CVE-2026-64386,CVE-2026-64387,CVE-2026-64401,CVE-2026-64403,CVE-2026-64404,CVE-2026-64406,CVE-2026-64407,CVE-2026-64408,CVE-2026-64409,CVE-2026-64411,CVE-2026-64412,CVE-2026-64415,CVE-2026-64416,CVE-2026-64420,CVE-2026-64421,CVE-2026-64423,CVE-2026-64427,CVE-2026-64429,CVE-2026-64433,CVE-2026-64434,CVE-2026-64436,CVE-2026-64440,CVE-2026-64442,CVE-2026-64443,CVE-2026-64444,CVE-2026-64445,CVE-2026-64446,CVE-2026-64450,CVE-2026-64452,CVE-2026-64454,CVE-2026-64455,CVE-2026-64456,CVE-2026-64458,CVE-2026-64463,CVE-2026-64470,CVE-2026-64471,CVE-2026-64472,CVE-2026-64477,CVE-2026-64478,CVE-2026-64479,CVE-2026-64480,CVE-2026-64481,CVE-2026-64482,CVE-2026-64483,CVE-2026-64484,CVE-2026-64486,CVE-2026-64487,CVE-2026-64489,CVE-2026-64490,CVE-2026-64494,CVE-2026-64495,CVE-2026-64496,CVE-2026-64497,CVE-2026-64499,CVE-2026-64500,CVE-2026-64503,CVE-2026-64504,CVE-2026-64505,CVE-2026-64507,CVE-2026-64511,CVE-2026-64512,CVE-2026-64513,CVE-2026-64515,CVE-2026-64517,CVE-2026-64518,CVE-2026 -64519,CVE-2026-64524,CVE-2026-64525,CVE-2026-64526,CVE-2026-64527,CVE-2026-64534,CVE-2026-64535,CVE-2026-64536,CVE-2026-64537,CVE-2026-64538,CVE-2026-64539,CVE-2026-64540,CVE-2026-64541,CVE-2026-64542,CVE-2026-64543,CVE-2026-64544,CVE-2026-64545,CVE-2026-64546,CVE-2026-64547,CVE-2026-64548,CVE-2026-64549,CVE-2026-64551,CVE-2026-64552,CVE-2026-64553,CVE-2026-64554,CVE-2026-64555,CVE-2026-64556,CVE-2026-64558,CVE-2026-64559,CVE-2026-64561,CVE-2026-64562,CVE-2026-64563,CVE-2026-64565,CVE-2026-64567,CVE-2026-64568,CVE-2026-64569,CVE-2026-64570,CVE-2026-64571,CVE-2026-64572,CVE-2026-64573,CVE-2026-64574,CVE-2026-64576,CVE-2026-64577,CVE-2026-64579,CVE-2026-64581,CVE-2026-64582,CVE-2026-64583,CVE-2026-64584,CVE-2026-64585,CVE-2026-64586,CVE-2026-64589,CVE-2026-64593,CVE-2026-64599,CVE-2026-64602,CVE-2026-64603,CVE-2026-64604,CVE-2026-68081,CVE-2026-68082,CVE-2026-68085,CVE-2026-68086,CVE-2026-68088,CVE-2026-68091,CVE-2026-68093,CVE-2026-68096,CVE-2026-68102,CVE-2026-68104,CVE-2026-68105, CVE-2026-68106,CVE-2026-68107,CVE-2026-68108,CVE-2026-68110,CVE-2026-68111,CVE-2026-68112,CVE-2026-68113,CVE-2026-68115,CVE-2026-68116,CVE-2026-68117,CVE-2026-68120,CVE-2026-68121,CVE-2026-68123,CVE-2026-68124,CVE-2026-68125,CVE-2026-68126,CVE-2026-68127,CVE-2026-68128,CVE-2026-68129,CVE-2026-68132,CVE-2026-68133,CVE-2026-68135,CVE-2026-68136,CVE-2026-68137,CVE-2026-68138,CVE-2026-68139,CVE-2026-68141,CVE-2026-68142,CVE-2026-68143,CVE-2026-68144,CVE-2026-68145,CVE-2026-68148,CVE-2026-68149,CVE-2026-68152,CVE-2026-68153,CVE-2026-68154,CVE-2026-68155,CVE-2026-68156,CVE-2026-68157,CVE-2026-68158,CVE-2026-68159,CVE-2026-68161,CVE-2026-68164,CVE-2026-68165,CVE-2026-68166,CVE-2026-68169,CVE-2026-68178,CVE-2026-68179,CVE-2026-68180,CVE-2026-68181,CVE-2026-68182,CVE-2026-68183,CVE-2026-68184,CVE-2026-68188,CVE-2026-68189,CVE-2026-68192,CVE-2026-68193,CVE-2026-68194,CVE-2026-68195,CVE-2026-68196,CVE-2026-68197,CVE-2026-68198,CVE-2026-68199,CVE-2026-68200,CVE-2026-68201,CVE-2026-68202,CVE-202 6-68203,CVE-2026-68204,CVE-2026-68205,CVE-2026-68206,CVE-2026-68207,CVE-2026-68209,CVE-2026-68210,CVE-2026-68212,CVE-2026-68213,CVE-2026-68214,CVE-2026-68215,CVE-2026-68216,CVE-2026-68217,CVE-2026-68218,CVE-2026-68219,CVE-2026-68220,CVE-2026-68221,CVE-2026-68222,CVE-2026-68223,CVE-2026-68225,CVE-2026-68226,CVE-2026-68227,CVE-2026-68228,CVE-2026-68229,CVE-2026-68231,CVE-2026-68234,CVE-2026-68235,CVE-2026-68236,CVE-2026-68238,CVE-2026-68243,CVE-2026-68244,CVE-2026-68245,CVE-2026-68246,CVE-2026-68247,CVE-2026-68248,CVE-2026-68249,CVE-2026-68250,CVE-2026-68251,CVE-2026-68252,CVE-2026-68253,CVE-2026-68254,CVE-2026-68255,CVE-2026-68256,CVE-2026-68257,CVE-2026-68258,CVE-2026-68259,CVE-2026-68260,CVE-2026-68261,CVE-2026-68262,CVE-2026-68263,CVE-2026-68267,CVE-2026-68269,CVE-2026-68271,CVE-2026-68272,CVE-2026-68273,CVE-2026-68277,CVE-2026-68278,CVE-2026-68279,CVE-2026-68280,CVE-2026-68281,CVE-2026-68284,CVE-2026-68286,CVE-2026-68288,CVE-2026-68289,CVE-2026-68293,CVE-2026-68294,CVE-2026-68296 ,CVE-2026-68297,CVE-2026-68299,CVE-2026-68300,CVE-2026-68302,CVE-2026-68303,CVE-2026-68304,CVE-2026-68306,CVE-2026-68307,CVE-2026-68308,CVE-2026-68309,CVE-2026-68310,CVE-2026-68311,CVE-2026-68313,CVE-2026-68315,CVE-2026-68319,CVE-2026-68320,CVE-2026-68321,CVE-2026-68322,CVE-2026-68325,CVE-2026-68326,CVE-2026-68327,CVE-2026-68328,CVE-2026-68329,CVE-2026-68331,CVE-2026-68333,CVE-2026-68335,CVE-2026-68336,CVE-2026-68338,CVE-2026-68339,CVE-2026-68340,CVE-2026-68344,CVE-2026-68346,CVE-2026-68348,CVE-2026-68349,CVE-2026-68350,CVE-2026-68351,CVE-2026-68352,CVE-2026-68353,CVE-2026-68354,CVE-2026-68355,CVE-2026-68357,CVE-2026-68358,CVE-2026-68359,CVE-2026-68360,CVE-2026-68361,CVE-2026-68362,CVE-2026-68363,CVE-2026-68365,CVE-2026-68366,CVE-2026-68368,CVE-2026-68369,CVE-2026-68370,CVE-2026-68371,CVE-2026-68372,CVE-2026-68373,CVE-2026-68374,CVE-2026-68375,CVE-2026-68377,CVE-2026-68386,CVE-2026-68389,CVE-2026-68391,CVE-2026-68392,CVE-2026-68393,CVE-2026-68394,CVE-2026-68395,CVE-2026-68397,CVE-20 26-68398,CVE-2026-68399,CVE-2026-68402,CVE-2026-68403,CVE-2026-68405,CVE-2026-68406,CVE-2026-68407,CVE-2026-68408,CVE-2026-68410,CVE-2026-68413,CVE-2026-68414,CVE-2026-68416,CVE-2026-68417,CVE-2026-68418,CVE-2026-68419,CVE-2026-68422,CVE-2026-68425,CVE-2026-68426,CVE-2026-68427,CVE-2026-68428,CVE-2026-68429,CVE-2026-68430,CVE-2026-68432,CVE-2026-68433,CVE-2026-68434,CVE-2026-68437,CVE-2026-68439,CVE-2026-68442,CVE-2026-68443,CVE-2026-68444,CVE-2026-68445,CVE-2026-68446,CVE-2026-68448,CVE-2026-68450,CVE-2026-68470,CVE-2026-68480,CVE-2026-72017,CVE-2026-72019,CVE-2026-72020,CVE-2026-72022,CVE-2026-72023,CVE-2026-72032,CVE-2026-72034,CVE-2026-72035,CVE-2026-72036,CVE-2026-72045,CVE-2026-72046,CVE-2026-72051,CVE-2026-72052,CVE-2026-72053,CVE-2026-72054,CVE-2026-72055,CVE-2026-72061,CVE-2026-72069,CVE-2026-72072,CVE-2026-72083,CVE-2026-72084,CVE-2026-72100,CVE-2026-72101,CVE-2026-72103,CVE-2026-72106,CVE-2026-72107,CVE-2026-72108,CVE-2026-72132,CVE-2026-72136,CVE-2026-72137,CVE-2026-7216 1,CVE-2026-72163,CVE-2026-72164,CVE-2026-72176,CVE-2026-72177,CVE-2026-72217,CVE-2026-72221,CVE-2026-72222,CVE-2026-72234,CVE-2026-72242,CVE-2026-72243,CVE-2026-72251,CVE-2026-72254,CVE-2026-72280,CVE-2026-72282,CVE-2026-72288,CVE-2026-72289,CVE-2026-72296,CVE-2026-72297,CVE-2026-72306,CVE-2026-72307,CVE-2026-72308,CVE-2026-72317,CVE-2026-72323,CVE-2026-72325,CVE-2026-72330,CVE-2026-72337,CVE-2026-72339,CVE-2026-72341,CVE-2026-72342,CVE-2026-72343,CVE-2026-72345,CVE-2026-72347,CVE-2026-72350,CVE-2026-72366,CVE-2026-72379,CVE-2026-72389,CVE-2026-72398,CVE-2026-72399,CVE-2026-72414,CVE-2026-72421,CVE-2026-72425,CVE-2026-72430,CVE-2026-72437,CVE-2026-72438,CVE-2026-72439,CVE-2026-72440,CVE-2026-72448,CVE-2026-72450,CVE-2026-72459,CVE-2026-72460,CVE-2026-72464,CVE-2026-72466,CVE-2026-72467,CVE-2026-72468,CVE-2026-72469,CVE-2026-72473,CVE-2026-72485,CVE-2026-72487,CVE-2026-72488,CVE-2026-72494,CVE-2026-72495,CVE-2026-72497,CVE-2026-72499,CVE-2026-72500,CVE-2026-72501,CVE-2026-72502,CVE-2 026-74255,CVE-2026-74261,CVE-2026-74269,CVE-2026-74270,CVE-2026-74282,CVE-2026-74284,CVE-2026-74286,CVE-2026-74296,CVE-2026-74297,CVE-2026-74307,CVE-2026-74308,CVE-2026-74313,CVE-2026-74316,CVE-2026-74317,CVE-2026-74318,CVE-2026-74321,CVE-2026-74334,CVE-2026-74345,CVE-2026-74346,CVE-2026-74349,CVE-2026-74363,CVE-2026-74375,CVE-2026-74377,CVE-2026-74378,CVE-2026-74382,CVE-2026-74388,CVE-2026-74390,CVE-2026-74394,CVE-2026-74395,CVE-2026-74397,CVE-2026-74406,CVE-2026-74464,CVE-2026-74474,CVE-2026-74475,CVE-2026-74476,CVE-2026-74479,CVE-2026-74481,CVE-2026-74482,CVE-2026-74495,CVE-2026-74496,CVE-2026-74510,CVE-2026-74512,CVE-2026-74513,CVE-2026-74517,CVE-2026-74518,CVE-2026-74523,CVE-2026-74527,CVE-2026-74533,CVE-2026-74534,CVE-2026-74535,CVE-2026-74536,CVE-2026-74537,CVE-2026-74545,CVE-2026-74548,CVE-2026-74550,CVE-2026-74555,CVE-2026-74556,CVE-2026-74557,CVE-2026-74563,CVE-2026-74566,CVE-2026-74567,CVE-2026-74571,CVE-2026-74577,CVE-2026-74581,CVE-2026-74582,CVE-2026-74584,CVE-2026-745 98,CVE-2026-74610,CVE-2026-74612,CVE-2026-74615,CVE-2026-74616,CVE-2026-74622,CVE-2026-74644,CVE-2026-74665,CVE-2026-74669,CVE-2026-74695,CVE-2026-74705,CVE-2026-74712,CVE-2026-74717,CVE-2026-74719,CVE-2026-74722,CVE-2026-74723,CVE-2026-74730,CVE-2026-74737,CVE-2026-74743,CVE-2026-74744,CVE-2026-80529,CVE-2026-80530,CVE-2026-80531,CVE-2026-80533,CVE-2026-80534,CVE-2026-80535,CVE-2026-80557,CVE-2026-80558,CVE-2026-80561,CVE-2026-80586,CVE-2026-80589,CVE-2026-80590,CVE-2026-80603,CVE-2026-80609,CVE-2026-80629,CVE-2026-80646,CVE-2026-80647,CVE-2026-80667,CVE-2026-80681,CVE-2026-80693,CVE-2026-80714,CVE-2026-80721,CVE-2026-80727,CVE-2026-80731,CVE-2026-80737,CVE-2026-80739,CVE-2026-80805,CVE-2026-80813,CVE-2026-80838 The SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). - CVE-2025-68358: btrfs: fix racy bitfield write in btrfs_clear_space_info_full() (bsc#1255531). - CVE-2025-68780: sched/deadline: only set free_cpus for online runqueues (bsc#1256671). - CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). - CVE-2026-23113: io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop (bsc#1258278). - CVE-2026-23306: scsi: pm8001: Fix use-after-free in pm8001_queue_command() (bsc#1260501). - CVE-2026-23348: cxl/mem: Clarify @host for devm_cxl_add_nvdimm() (bsc#1260577). - CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). - CVE-2026-31530: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (bsc#1262756). - CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). - CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). - CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). - CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). - CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). - CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). - CVE-2026-43299: btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure() (bsc#1264851). - CVE-2026-43331: x86/kexec: Disable KCOV instrumentation after load_segments() (bsc#1265132). - CVE-2026-43355: iio: light: bh1780: fix PM runtime leak on error path (bsc#1265036). - CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). - CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). - CVE-2026-43439: cgroup: fix race between task migration and iteration (bsc#1265141). - CVE-2026-43448: nvme-pci: Fix race bug in nvme_poll_irqdisable() (bsc#1264807). - CVE-2026-45860: netfilter: nf_conncount: increase the connection clean up limit to 64 (bsc#1266710). - CVE-2026-45897: netfilter: nft_counter: serialize reset with spinlock (bsc#1266897). - CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). - CVE-2026-46007: hwmon: (powerz) Avoid cacheline sharing for DMA buffer (bsc#1267586). - CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). - CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). - CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). - CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). - CVE-2026-46135: nvmet-tcp: remove redundant calls to nvmet_tcp_fatal_error() (bsc#1267373). - CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). - CVE-2026-46304: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free (bsc#1267985). - CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000). - CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). - CVE-2026-52928: af_unix: Reject SIOCATMARK on non-stream sockets (bsc#1269010). - CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). - CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). - CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). - CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). - CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). - CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). - CVE-2026-52991: sched/psi: fix race between file release and pressure write (bsc#1269134). - CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). - CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). - CVE-2026-53031: bpf: Validate node_id in arena_alloc_pages() (bsc#1269380). - CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). - CVE-2026-53034: bpf, sockmap: Fix af_unix null-ptr-deref in proto update (bsc#1269140). - CVE-2026-53048: gfs2: prevent NULL pointer dereference during unmount (bsc#1269162). - CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). - CVE-2026-53061: dm cache: fix dirty mapping checking in passthrough mode switching (bsc#1269685). - CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). - CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). - CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). - CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). - CVE-2026-53092: bpf: Fix linked reg delta tracking when src_reg == dst_reg (bsc#1269528). - CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). - CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). - CVE-2026-53109: powerpc/pgtable-frag: Fix bad page state in pte_frag_destroy (bsc#1269417). - CVE-2026-53110: s390: always declare expoline thunks (bsc#1269985). - CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). - CVE-2026-53114: perf: Extend the bit width of the arch-specific flag (bsc#1269999). - CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). - CVE-2026-53129: fs/mbcache: cancel shrink work before destroying the cache (bsc#1269633). - CVE-2026-53142: drm/xe/display: fix oops in suspend/shutdown without display (bsc#1269402). - CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). - CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). - CVE-2026-53180: timers/migration: Fix livelock in tmigr_handle_remote_up() (bsc#1269888). - CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). - CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). - CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). - CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). - CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). - CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). - CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). - CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). - CVE-2026-53284: btrfs: only release the dirty pages io tree after successful writes (bsc#1269816). - CVE-2026-53291: ALSA: hda/conexant: Fix missing error check for jack detection (bsc#1269697). - CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). - CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). - CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). - CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). - CVE-2026-53341: fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh() (bsc#1270139). - CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). - CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). - CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). - CVE-2026-63803: hdlc_ppp: sync per-proto timers before freeing hdlc state (bsc#1272284). - CVE-2026-63804: gfs2: fix use-after-free in gfs2_qd_dealloc (bsc#1272287). - CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). - CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). - CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). - CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). - CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). - CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). - CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). - CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). - CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). - CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). - CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). - CVE-2026-63890: scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (bsc#1272426). - CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). - CVE-2026-63901: USB: serial: digi_acceleport: fix memory corruption with small endpoints (bsc#1272501). - CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904). - CVE-2026-63918: l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname (bsc#1272905). - CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). - CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918). - CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: refresh nh after handling HAO option (bsc#1272855). - CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). - CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). - CVE-2026-63941: KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor (bsc#1272869). - CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). - CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). - CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865). - CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). - CVE-2026-63986: ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure (bsc#1272969). - CVE-2026-63987: ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES (bsc#1272971). - CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). - CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). - CVE-2026-63993: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (bsc#1279847). - CVE-2026-63995: ethtool: cmis: validate start_cmd_payload_size from module (bsc#1273033). - CVE-2026-63996: ethtool: cmis: require exact CDB reply length (bsc#1273032). - CVE-2026-63997: ethtool: module: avoid leaking a netdev ref on module flash errors (bsc#1273036). - CVE-2026-63998: ethtool: module: call ethnl_ops_complete() on module flash errors (bsc#1273037). - CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). - CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). - CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). - CVE-2026-64003: scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues (bsc#1273782). - CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). - CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). - CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). - CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). - CVE-2026-64017: blk-mq: pop cached request if it is usable (bsc#1273770). - CVE-2026-64024: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction (bsc#1273107). - CVE-2026-64033: RDMA/rtrs: Fix use-after-free in path file creation cleanup (bsc#1273134). - CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). - CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). - CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). - CVE-2026-64053: block: don't overwrite bip_vcnt in bio_integrity_copy_user() (bsc#1272985). - CVE-2026-64054: net: shaper: reject duplicate leaves in GROUP request (bsc#1272894). - CVE-2026-64055: net: ethernet: cortina: Carry over frag counter (bsc#1272893). - CVE-2026-64056: net: ethernet: cortina: Make RX SKB per-port (bsc#1272502). - CVE-2026-64071: nvme-pci: fix use-after-free in nvme_free_host_mem() (bsc#1273486). - CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). - CVE-2026-64088: batman-adv: tt: fix negative tt_buff_len (bsc#1273463). - CVE-2026-64089: batman-adv: tt: fix negative last_changeset_len (bsc#1272513). - CVE-2026-64093: batman-adv: tp_meter: directly shut down timer on cleanup (bsc#1273461). - CVE-2026-64099: drm/v3d: Fix use-after-free of CPU job query arrays on error path (bsc#1273465). - CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). - CVE-2026-64103: scsi: isci: Fix use-after-free in device removal path (bsc#1273759). - CVE-2026-64109: af_unix: Fix UAF read of tail->len in unix_stream_data_wait() (bsc#1273748). - CVE-2026-64111: lsm: hold cred_guard_mutex for lsm_set_self_attr() (bsc#1273740). - CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). - CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). - CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). - CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). - CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). - CVE-2026-64119: l2tp: use list_del_rcu in l2tp_session_unhash (bsc#1273746). - CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). - CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). - CVE-2026-64131: mm/memory: fix spurious warning when unmapping device-private/exclusive pages (bsc#1274063). - CVE-2026-64146: erofs: fix metabuf leak in inode xattr initialization (bsc#1273681). - CVE-2026-64147: pds_core: fix debugfs_lookup dentry leak and error handling (bsc#1273119). - CVE-2026-64148: pds_core: fix error handling in pdsc_devcmd_wait (bsc#1273956). - CVE-2026-64162: idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() (bsc#1272366). - CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). - CVE-2026-64177: phonet/pep: disable BH around forwarded sk_receive_skb() (bsc#1272148). - CVE-2026-64179: net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (bsc#1272149). - CVE-2026-64180: mm/memory_hotplug: fix memory block reference leak on remove (bsc#1273679). - CVE-2026-64184: mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() (bsc#1272199). - CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). - CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). - CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). - CVE-2026-64210: net/mlx5e: xsk: Fix unlocked writing to ICOSQ (bsc#1273899). - CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). - CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). - CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). - CVE-2026-64224: octeontx2-pf: fix double free in rvu_rep_rsrc_init() (bsc#1272804). - CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). - CVE-2026-64232: block: recompute nr_integrity_segments in blk_insert_cloned_request (bsc#1272791). - CVE-2026-64239: mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() (bsc#1273898). - CVE-2026-64244: drivers/base/memory: set mem->altmap after successful device registration (bsc#1273812). - CVE-2026-64253: kernel/fork: clear PF_BLOCK_TS in copy_process() (bsc#1273904). - CVE-2026-64256: xfs: don't wrap around quota ids in dqiterate (bsc#1273271). - CVE-2026-64265: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req (bsc#1273947). - CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). - CVE-2026-64269: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg (bsc#1273280). - CVE-2026-64283: KVM: guest_memfd: Treat memslot binding offset+size as unsigned values (bsc#1273870). - CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). - CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). - CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). - CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). - CVE-2026-64298: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (bsc#1273550). - CVE-2026-64300: perf/aux: Fix page UAF in map_range() (bsc#1273852). - CVE-2026-64307: crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) (bsc#1273567). - CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). - CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). - CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). - CVE-2026-64319: nvmet-auth: validate reply message payload bounds against transfer length (bsc#1273339). - CVE-2026-64320: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (bsc#1273420). - CVE-2026-64321: nvme: target: rdma: fix ndev refcount leak on queue connect (bsc#1273864). - CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). - CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). - CVE-2026-64326: block: skip sync_blockdev() on surprise removal in bdev_mark_dead() (bsc#1273312). - CVE-2026-64327: usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks (bsc#1273283). - CVE-2026-64354: bpf: Validate BTF repeated field counts before expansion (bsc#1274060). - CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). - CVE-2026-64364: HID: multitouch: fix out-of-bounds bit access on mt_io_flags (bsc#1273495). - CVE-2026-64368: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (bsc#1273997). - CVE-2026-64373: cpufreq: Fix hotplug-suspend race during reboot (bsc#1273776). - CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). - CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). - CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). - CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). - CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). - CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). - CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). - CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). - CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). - CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). - CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). - CVE-2026-64415: mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup (bsc#1273317). - CVE-2026-64416: mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host (bsc#1273286). - CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). - CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). - CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). - CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). - CVE-2026-64452: 6lowpan: fix NHC entry use-after-free on error path (bsc#1273460). - CVE-2026-64458: mm/damon/ops-common: handle extreme intervals in damon_hot_score() (bsc#1273788). - CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). - CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). - CVE-2026-64477: x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled (bsc#1274264). - CVE-2026-64507: bpf: Support for hardening against JIT spraying (bsc#1273999). - CVE-2026-64518: tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key() (bsc#1273524). - CVE-2026-64519: NFSD: Fix infinite loop in layout state revocation (bsc#1274252). - CVE-2026-64526: ethtool: tsconfig: fix missing ethnl_ops_complete() (bsc#1274052). - CVE-2026-64534: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error (bsc#1273803). - CVE-2026-64535: nvmet-tcp: Fix potential UAF when ddgst mismatch (bsc#1273809). - CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). - CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). - CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). - CVE-2026-64542: ipv6: ndisc: fix NULL deref in accept_untracked_na() (bsc#1273309). - CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). - CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). - CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). - CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). - CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). - CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). - CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). - CVE-2026-64555: KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() (bsc#1273331). - CVE-2026-64556: perf/core: Detach event groups during remove_on_exec (bsc#1273251). - CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). - CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). - CVE-2026-64569: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (bsc#1274009). - CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). - CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). - CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). - CVE-2026-64579: xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (bsc#1274036). - CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). - CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). - CVE-2026-64586: wifi: brcmfmac: drain bus_reset work on device removal (bsc#1274492). - CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). - CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). - CVE-2026-68096: audit: fix recursive locking deadlock in audit_dupe_exe() (bsc#1274730). - CVE-2026-68105: drm/amdgpu: Fix kernel panic during driver load failure (bsc#1274849). - CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). - CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). - CVE-2026-68120: rtase: Workaround for TX hang caused by hardware packet parsing (bsc#1274887). - CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). - CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). - CVE-2026-68124: mctp: serial: handle zero-length frames to prevent rx buffer overflow (bsc#1275192). - CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). - CVE-2026-68128: ice: reject out-of-range ptype in ice_parser_profile_init (bsc#1275238). - CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). - CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). - CVE-2026-68133: ice: fix PTP Call Trace during PTP release (bsc#1275555). - CVE-2026-68135: net: hip04: fix RX buffer leak on build_skb failure (bsc#1275557). - CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). - CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). - CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). - CVE-2026-68141: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (bsc#1275094). - CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). - CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). - CVE-2026-68144: phonet: pep: fix use-after-free in pep_get_sb() (bsc#1275481). - CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). - CVE-2026-68148: fscrypt: Add missing superblock check in find_or_insert_direct_key() (bsc#1275588). - CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). - CVE-2026-68152: amt: fix use-after-free in AMT delayed works (bsc#1275300). - CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). - CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). - CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). - CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). - CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). - CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). - CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). - CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). - CVE-2026-68164: mm/damon/core: disallow overlapping input ranges for damon_set_regions() (bsc#1274955). - CVE-2026-68165: mm/damon/core: validate ranges in damon_set_regions() (bsc#1274927). - CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). - CVE-2026-68169: mptcp: pm: userspace: fix use-after-free in get_local_id (bsc#1274952). - CVE-2026-68183: firmware: stratix10-svc: fix memory leaks and list corruption bugs (bsc#1274957). - CVE-2026-68198: wifi: ath6kl: fix use-after-free in aggr_reset_state() (bsc#1274803). - CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). - CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). - CVE-2026-68258: drm/amdkfd: Check bounds on CRIU restore queue type and mqd size (bsc#1275866). - CVE-2026-68267: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (bsc#1275139). - CVE-2026-68273: drm/amdgpu: Fix context pstate override handling (bsc#1275129). - CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). - CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). - CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). - CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). - CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). - CVE-2026-68294: net: qrtr: restrict socket creation to the initial network namespace (bsc#1275092). - CVE-2026-68296: net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM (bsc#1275045). - CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). - CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). - CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). - CVE-2026-68302: amt: re-read skb header pointers after every pull (bsc#1275081). - CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). - CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). - CVE-2026-68319: pds_core: fix deadlock between reset thread and remove (bsc#1274657). - CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). - CVE-2026-68321: net: txgbe: fix FDIR filter leak on remove (bsc#1274652). - CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). - CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). - CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). - CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). - CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). - CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). - CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). - CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). - CVE-2026-68338: net/packet: avoid fanout hook re-registration after unregister (bsc#1274637). - CVE-2026-68375: bnxt_en: Handle partially initialized auxiliary devices (bsc#1274835). - CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). - CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). - CVE-2026-68393: Bluetooth: hci_sync: extend conn_hash lookup critical sections (bsc#1274904). - CVE-2026-68395: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered (bsc#1274900). - CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). - CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). - CVE-2026-68399: bpf: Fix UAF in sock clone early bailouts (bsc#1274897). - CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). - CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). - CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). - CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). - CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). - CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). - CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). - CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). - CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). - CVE-2026-68442: btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps (bsc#1274773). - CVE-2026-68448: ovl: check access to copy_file_range source with src mounter creds (bsc#1274838). - CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). - CVE-2026-68470: wifi: mac80211: validate extension-frame layout before RX (bsc#1276500). - CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). - CVE-2026-72017: net: macb: drop in-flight Tx SKBs on close (bsc#1276840). - CVE-2026-72019: macsec: don't read an unset MAC header in macsec_encrypt() (bsc#1276865). - CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). - CVE-2026-72022: llc: fix SAP refcount leak in llc_ui_autobind() (bsc#1276785). - CVE-2026-72023: octeontx2-pf: fix SQB pointer leak on init failure (bsc#1276793). - CVE-2026-72032: net/mlx5: HWS, fix matcher leak on resize target setup failure (bsc#1276955). - CVE-2026-72034: fhandle: reject detached mounts in capable_wrt_mount() (bsc#1276957). - CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). - CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). - CVE-2026-72045: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (bsc#1277078). - CVE-2026-72046: gve: fix header buffer corruption with header-split and HW-GRO (bsc#1275519). - CVE-2026-72051: net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276801). - CVE-2026-72052: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276803). - CVE-2026-72053: net: ipip: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276814). - CVE-2026-72054: net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276818). - CVE-2026-72055: net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276821). - CVE-2026-72061: net: sit: require CAP_NET_ADMIN in the device netns for changelink (bsc#1277249). - CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). - CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). - CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). - CVE-2026-72084: scsi: target: core: Generate correct identifiers for PR OUT transport IDs (bsc#1275540). - CVE-2026-72100: dm-integrity: fix a bug if the bio is out of limits (bsc#1277311). - CVE-2026-72101: dm-integrity: fix leaking uninitialized kernel memory (bsc#1276831). - CVE-2026-72103: dm: avoid leaking the caller's thread keyring via the table device file (bsc#1277315). - CVE-2026-72106: dm-ioctl: fix a possible overflow in list_version_get_info (bsc#1277321). - CVE-2026-72107: dm era: fix out-of-bounds memory access for non-zero start sector (bsc#1277349). - CVE-2026-72108: dm thin metadata: fix metadata snapshot consistency on commit failure (bsc#1277350). - CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). - CVE-2026-72136: xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink (bsc#1277574). - CVE-2026-72137: xfrm: nat_keepalive: avoid double free on send error (bsc#1275587). - CVE-2026-72161: ocfs2: add journal NULL check in ocfs2_checkpoint_inode() (bsc#1277233). - CVE-2026-72163: ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits (bsc#1277231). - CVE-2026-72164: ocfs2: avoid moving extents to occupied clusters (bsc#1277553). - CVE-2026-72176: mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error (bsc#1277230). - CVE-2026-72177: mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() (bsc#1277227). - CVE-2026-72217: SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing (bsc#1275655). - CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). - CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). - CVE-2026-72234: batman-adv: access unicast_ttvn skb->data only after skb realloc (bsc#1275672). - CVE-2026-72242: selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() (bsc#1277655). - CVE-2026-72243: selinux: check connect-related permissions on TCP Fast Open (bsc#1277656). - CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). - CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). - CVE-2026-72280: KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 (bsc#1277726). - CVE-2026-72282: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers (bsc#1277728). - CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). - CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). - CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). - CVE-2026-72297: net: atm: reject out-of-range traffic classes in QoS validation (bsc#1277738). - CVE-2026-72306: vduse: Requeue failed read to send_list head (bsc#1277748). - CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). - CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). - CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). - CVE-2026-72323: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (bsc#1275985). - CVE-2026-72325: perf/x86/amd/core: Avoid enabling BRS from the SVM reload path (bsc#1277761). - CVE-2026-72330: net/tls: Consume empty data records in tls_sw_read_sock() (bsc#1277764). - CVE-2026-72337: Bluetooth: 6lowpan: avoid untracked enable work (bsc#1277773). - CVE-2026-72339: qede: fix off-by-one in BD ring consumption on build_skb failure (bsc#1276006). - CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). - CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). - CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). - CVE-2026-72345: net/mlx5: LAG, Fix off-by-one in single-FDB error rollback (bsc#1277782). - CVE-2026-72347: netfilter: xt_connmark: reject invalid shift parameters (bsc#1277783). - CVE-2026-72350: netfilter: xt_u32: reject invalid shift counts (bsc#1277822). - CVE-2026-72366: netfs: Fix netfs_create_write_req() to handle async cache object creation (bsc#1276333). - CVE-2026-72379: fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid (bsc#1277818). - CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). - CVE-2026-72398: sctp: add INIT verification after cookie unpacking (bsc#1276381). - CVE-2026-72399: net: enetc: check the number of BDs needed for xdp_frame (bsc#1276553). - CVE-2026-72414: net: dsa: sja1105: round up PTP perout pin duration (bsc#1278039). - CVE-2026-72421: ipv4: fib: Don't ignore error route in local/main tables (bsc#1277023). - CVE-2026-72425: ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() (bsc#1277120). - CVE-2026-72430: net/sched: act_ct: fix nf_connlabels leak on two error paths (bsc#1277118). - CVE-2026-72437: md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry (bsc#1277874). - CVE-2026-72438: md/raid10: fix writes_pending and barrier reference leaks on discard failures (bsc#1277115). - CVE-2026-72439: md/raid10: fix writes_pending leak on write request failures (bsc#1277876). - CVE-2026-72440: md/raid1: fix writes_pending and barrier reference leaks on write failures (bsc#1277114). - CVE-2026-72448: octeontx2-pf: Fix leak of SQ timestamp buffer on teardown (bsc#1277108). - CVE-2026-72450: xfrm: validate selector family and prefixlen during match (bsc#1278113). - CVE-2026-72459: apparmor: aa_label_alloc use aa_label_free on alloc failure (bsc#1277092). - CVE-2026-72460: apparmor: check label build before no_new_privs test (bsc#1277229). - CVE-2026-72464: xprtrdma: Post receive buffers after RPC completion (bsc#1277069). - CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). - CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). - CVE-2026-72468: xprtrdma: Initialize re_id before removal registration (bsc#1277062). - CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). - CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). - CVE-2026-72485: coresight: platform: defer connection counter increment until alloc succeeds (bsc#1276771). - CVE-2026-72487: PCI: Introduce named defines for PCI ROM (bsc#1276767). - CVE-2026-72488: soundwire: fix bug in sdw_add_element_group_count found by syzkaller (bsc#1276766). - CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). - CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). - CVE-2026-72497: RDMA/bnxt_re: Add a max slot check for SQ (bsc#1276913). - CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). - CVE-2026-72500: RDMA/bnxt_re: Free SRQ toggle page after firmware teardown (bsc#1276552). - CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). - CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). - CVE-2026-74255: tipc: fix UAF in tipc_l2_send_msg() (bsc#1276547). - CVE-2026-74261: ALSA: seq: avoid stale FIFO cells during resize (bsc#1276528). - CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). - CVE-2026-74270: handshake: Require admin permission for DONE command (bsc#1276512). - CVE-2026-74282: tipc: prevent snt_unacked underflow on CONN_ACK (bsc#1276473). - CVE-2026-74284: net/sched: sch_hfsc: Don't make class passive twice (bsc#1276468). - CVE-2026-74286: net: pfcp: allocate per-cpu tstats for PFCP netdevs (bsc#1276471). - CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). - CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). - CVE-2026-74307: ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT (bsc#1276905). - CVE-2026-74308: ext4: fix kernel BUG in ext4_write_inline_data_end (bsc#1276880). - CVE-2026-74313: vduse: hold vduse_lock across IDR lookup in open path (bsc#1276876). - CVE-2026-74316: NFSD: Handle layout stid in nfsd4_drop_revoked_stid() (bsc#1276870). - CVE-2026-74317: ixgbe: do not configure xps for XDP queues (bsc#1276866). - CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). - CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). - CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). - CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). - CVE-2026-74346: RDMA/irdma: Fix OOB read during CQ MR registration (bsc#1278155). - CVE-2026-74349: ocfs2: reject FITRIM ranges shorter than a cluster (bsc#1278180). - CVE-2026-74363: bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs (bsc#1278070). - CVE-2026-74375: md: replace wait loop with wait_event() in md_handle_request() (bsc#1277649). - CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236). - CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233). - CVE-2026-74382: net/sched: cls_bpf: prevent unbounded recursion in offload rollback (bsc#1278240). - CVE-2026-74388: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data (bsc#1278253). - CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (bsc#1278088). - CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). - CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). - CVE-2026-74397: IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier (bsc#1278098). - CVE-2026-74406: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() (bsc#1276395). - CVE-2026-74464: net: openvswitch: fix skb leak on flow key update failure during ct (bsc#1277070). - CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). - CVE-2026-74475: vxlan: unclone skb head before modifying eth header in route_shortcircuit() (bsc#1276339). - CVE-2026-74476: veth: convert frag_list skbs before running XDP (bsc#1276341). - CVE-2026-74479: net: pktgen: fix proc entry use-after-free (bsc#1276354). - CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). - CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (bsc#1276346). - CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). - CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). - CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). - CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). - CVE-2026-74513: dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister (bsc#1275956). - CVE-2026-74517: KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs (bsc#1276258). - CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). - CVE-2026-74523: qede: sync udp_tunnel ports outside qede_lock in the recovery path (bsc#1275802). - CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). - CVE-2026-74533: Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero (bsc#1275804). - CVE-2026-74534: Bluetooth: ISO: Fix data-race on iso_pi(sk) in socket and HCI event paths (bsc#1275801). - CVE-2026-74535: Bluetooth: ISO: avoid deadlocks in iso_sock_timeout (bsc#1275812). - CVE-2026-74536: Bluetooth: ISO: fix leaking sk after socket release (bsc#1275799). - CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). - CVE-2026-74545: rtase: fix double free of multi-frag skb on DMA map failure (bsc#1275679). - CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). - CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). - CVE-2026-74555: scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race (bsc#1275690). - CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). - CVE-2026-74557: scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (bsc#1275685). - CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). - CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). - CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). - CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). - CVE-2026-74577: net: mpls: initialize rtm_tos in mpls_getroute() (bsc#1275572). - CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). - CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). - CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). - CVE-2026-74598: ipv6: fix Route Information option length validation (bsc#1277918). - CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). - CVE-2026-74612: veth: fix skb length accounting after XDP frag adjustment (bsc#1277505). - CVE-2026-74615: vxlan: do not arm the ageing timer on a device that is down (bsc#1277901). - CVE-2026-74616: xdp: reject clones that overrun skb_shared_info tailroom (bsc#1277813). - CVE-2026-74622: net: atlantic: free RX pages of consumed but not refilled buffers (bsc#1277862). - CVE-2026-74644: mm/damon/ops-common: putback folios on invalid migrate nid (bsc#1277033). - CVE-2026-74665: net: fix skb length accounting after generic XDP frag adjustment (bsc#1277407). - CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). - CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). - CVE-2026-74705: udp: fix potential use-after-free in tunnel segmentation (bsc#1276922). - CVE-2026-74712: vdpa/mlx5: Fix buffer length in create_direct_keys() (bsc#1276577). - CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). - CVE-2026-74719: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() (bsc#1276572). - CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). - CVE-2026-74723: btrfs: lzo: reject inline extents without valid headers (bsc#1276562). - CVE-2026-74730: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (bsc#1276566). - CVE-2026-74737: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG (bsc#1277898). - CVE-2026-74743: macvlan: inherit needed_headroom and needed_tailroom from lowerdev (bsc#1277908). - CVE-2026-74744: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev (bsc#1278094). - CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). - CVE-2026-80530: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN (bsc#1277668). - CVE-2026-80531: xfs: avoid UAF on sc->tempip in xrep_tempfile_create (bsc#1277680). - CVE-2026-80533: xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair (bsc#1277636). - CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). - CVE-2026-80535: xfs: don't double-lock when deleting a self-referential directory (bsc#1277641). - CVE-2026-80557: libceph: fix OOB read in decode_watchers() via missing bounds check (bsc#1277268). - CVE-2026-80558: libceph: Avoid using invalid osd indices from primary_temp (bsc#1277485). - CVE-2026-80561: libceph: fix multiple unsafe decodes in decode_locker() (bsc#1277265). - CVE-2026-80586: mptcp: options: reset DSS fields in case of unexpected size (bsc#1277328). - CVE-2026-80589: block: stop the timeout timer when releasing a never added disk (bsc#1277335). - CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). - CVE-2026-80603: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read (bsc#1278293). - CVE-2026-80609: qede: fix out-of-bounds check for cqe->len_list (bsc#1278334). - CVE-2026-80629: octeontx2-af: npc: Fix size of entry2cntr_map (bsc#1277308). - CVE-2026-80646: ipv6: guard against possible NULL deref in __in6_dev_stats_get() (bsc#1277513). - CVE-2026-80647: RDMA/hns: Fix warning in poll cq direct mode (bsc#1278331). - CVE-2026-80667: net/mlx5: LAG, MPESW, Fix missing complete() on devcom error (bsc#1278324). - CVE-2026-80681: vxlan: re-fetch eth header after route_shortcircuit() (bsc#1278416). - CVE-2026-80693: idpf: bound interrupt-vector register fill to the allocated array (bsc#1278395). - CVE-2026-80714: ipvs: do not propagate one-packet flag to synced conns (bsc#1277561). - CVE-2026-80721: Bluetooth: ISO: ensure no dangling hcon references in iso_conn (bsc#1277845). - CVE-2026-80727: x86/mce: Set up the polling timer before CMCI discovery (bsc#1278703). - CVE-2026-80731: net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (bsc#1278716). - CVE-2026-80737: serial: amba-pl011: synchronize DMA teardown (bsc#1279487). - CVE-2026-80739: net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock (bsc#1278733). - CVE-2026-80805: xfs: validate attr entry pointer before field access (bsc#1279580). - CVE-2026-80813: nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist() (bsc#1279537). - CVE-2026-80838: vxlan: keep the last remote linked during FDB flush (bsc#1279842). The following non security issues were fixed: - accel/ivpu: Limit firmware log name prints to field size (git-fixes). - accel/ivpu: Validate firmware log buffer metadata (git-fixes). - accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr (git-fixes). - accel/qaic: Address potential out-of-bounds read in resp_worker() (git-fixes). - accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). - accessibility: speakup: unregister tty ldisc on later init failures (git-fixes). - ACPI: APEI: Fix ERST timeout unit conversion (git-fixes). - ACPI: battery: Adjust charging status validation check (git-fixes). - ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). - ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git-fixes). - ACPI: pfr_update: fix stack buffer overflow in query_capability() (git-fixes). - ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). - ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). - ACPI: processor_idle: Mark LPI enter functions as __cpuidle (git-fixes). - ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). - ACPI: video: Release PCI device reference after lookup (git-fixes). - ALSA: 6fire: bound the MIDI event length from the device (git-fixes). - ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). - ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). - ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev (git-fixes). - ALSA: caiaq: Fix potential double-free at error path (git-fixes). - ALSA: control: Don't add invalid kcontrols to LED layer (git-fixes). - ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). - ALSA: ctxfi: Fix CA20K2 S/PDIF passthrough (git-fixes). - ALSA: dummy: Check card index validity at probe (stable-fixes). - ALSA: dummy: Report a change when one capture switch channel moves (git-fixes). - ALSA: harmony: initialize locks before requesting IRQ (git-fixes). - ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). - ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r (stable-fixes). - ALSA: hda: Fix connection list comparison in proc output (git-fixes). - ALSA: hda: Report a change when only the channel status bytes move (git-fixes). - ALSA: hda: restore MFG widget enumeration after core split (git-fixes). - ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). - ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF (git-fixes). - ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). - ALSA: rawmidi: Return the error from snd_rawmidi_input_params() (git-fixes). - ALSA: scarlett2: Use a private URB for the notification endpoint (git-fixes). - ALSA: seq: Don't leak the extension cell pointer in the bounce payload (git-fixes). - ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). - ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). - ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). - ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). - ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() (git-fixes). - ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). - ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). - ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf (git-fixes). - ALSA: usbusx2y: validate URB actual_length in interrupt callback (git-fixes). - ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). - ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git-fixes). - apparmor: advertise the tcp fast open fix is applied (git-fixes). - ASoC: ab8500: Correct digital interface format setup (git-fixes). - ASoC: ab8500: Repair the DAPM capture graph (git-fixes). - ASoC: ab8500: Reset the audio block before configuring it (git-fixes). - ASoC: ab8500: Validate and program TDM slots correctly (git-fixes). - ASoC: adau1761: sort the register default table (git-fixes). - ASoC: amd: renoir: fix disable_pdm_interrupts() to clear mask bits (git-fixes). - ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). - ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() (git-fixes). - ASoC: apple: mca: increase SERDES reset delay (git-fixes). - ASoC: bcm: bcm63xx: Publish the OF module aliases (git-fixes). - ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). - ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). - ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). - ASoC: cs35l41: sort the register default table (git-fixes). - ASoC: cs35l45: sort the register default table (git-fixes). - ASoC: cs4265: sort the register default table (git-fixes). - ASoC: cx2072x: sort the register default table (git-fixes). - ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). - ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git-fixes). - ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git-fixes). - ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). - ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). - ASoC: fsl_easrc: sort the register default table (git-fixes). - ASoC: hdac_hda: Fix hlink refcount leak on component registration failure (git-fixes). - ASoC: Intel: avs: Clean up streams if their initialization fails (git-fixes). - ASoC: Intel: avs: Clean up the bus when fetching ML caps fails (git-fixes). - ASoC: Intel: avs: Do not ignore -ENOENT when loading a topology (git-fixes). - ASoC: Intel: avs: Fix unbalanced module reference count (git-fixes). - AsoC: intel: sst: fix PCI device reference leak on probe failure (git-fixes). - ASoC: Intel: SST: Publish the PCI module aliases (git-fixes). - ASoC: loongson: Fix error handling in ACPI property parsing (git-fixes). - ASoC: max9860: sort the register default table (git-fixes). - ASoC: mediatek: mt8183-afe-pcm: Shorten memif_data table using macros (stable-fixes). - ASoC: mediatek: mt8183-afe-pcm: Support >32 bit DMA addresses (git-fixes). - ASoC: mediatek: mt8183-afe-pcm: use local `dev` pointer in driver callbacks (stable-fixes). - ASoC: mediatek: mt8183: Check runtime resume during probe (git-fixes). - ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (stable-fixes). - ASoC: mediatek: mt8192: Check runtime resume during probe (git-fixes). - ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). - ASoC: ml26124: sort the register default table (git-fixes). - ASoC: mt6351: Publish the OF module alias (git-fixes). - ASoC: pcm512x: sort the register default table (git-fixes). - ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). - ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git-fixes). - ASoC: rt274: sort the register default table (git-fixes). - ASoC: rt286: sort the register default table (git-fixes). - ASoC: rt298: sort the register default table (git-fixes). - ASoC: rt700-sdw: always drain jack work on remove (git-fixes). - ASoC: rt700: drop duplicate reg_default entry (git-fixes). - ASoC: rt700: sort the register default table (git-fixes). - ASoC: rt711-sdca: sort the register default tables (git-fixes). - ASoC: rt711: sort the register default table (git-fixes). - ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). - ASoC: rt712-sdca-sdw: sort the register default table (git-fixes). - ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). - ASoC: rt715-sdca: sort the register default tables (git-fixes). - ASoC: rt715: sort the register default table (git-fixes). - ASoC: rt1017-sdca-sdw: sort the register default table (git-fixes). - ASoC: rt1316-sdw: sort the register default table (git-fixes). - ASoC: rt1318-sdw: sort the register default table (git-fixes). - ASoC: rt1318: sort the register default table (git-fixes). - ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). - ASoC: sgtl5000: sort the register default table (git-fixes). - ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git-fixes). - ASoC: SOF: validate topology volume range before allocation (git-fixes). - ASoC: sprd: validate compress buffer sizes against fixed allocations (git-fixes). - ASoC: sti-sas: sort the register default table (git-fixes). - ASoC: sti: initialize IRQ lock before requesting IRQ (git-fixes). - ASoC: tas2552: sort the register default table (git-fixes). - ASoC: tas2764: sort the register default table (git-fixes). - ASoC: tas2780: sort the register default table (git-fixes). - ASoC: tegra210_i2s: sort the register default table (git-fixes). - ASoC: tegra210_mixer: sort the register default table (git-fixes). - ASoC: tegra: Fix the MIXER enable default value (git-fixes). - ASoC: tegra: Sort MBDRC register defaults (git-fixes). - ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). - ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). - ata: ahci: work around lost interrupts on Marvell 88SE61xx (git-fixes). - batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). - batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). - batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). - batman-adv: fix stale receive device on merged fragments (git-fixes). - batman-adv: mcast: ensure unshared skb for multicast packets (git-fixes). - batman-adv: mcast: linearize skbuff for packet generation (git-fixes). - batman-adv: reject unrepresentable multicast TVLV offsets (git-fixes). - blk-mq: reinsert cached request to the list (bsc#1273770). - Bluetooth: btintel: bound firmware ID by TLV length (git-fixes). - Bluetooth: btintel: Fix diagnostics event detection (git-fixes). - Bluetooth: btintel: validate version TLV value lengths (git-fixes). - Bluetooth: btintel_pcie: Clear automask on spurious interrupts (git-fixes). - Bluetooth: btintel_pcie: fix tx_handle bounds off-by-one (git-fixes). - Bluetooth: btintel_pcie: validate packet_len before skb_put_data (git-fixes). - Bluetooth: btmtk: Declare MT7920 (MT7961 1a) Bluetooth firmware (git-fixes). - Bluetooth: btmtk: Do not discard the subsystem reset timeout (git-fixes). - Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() (stable-fixes). - Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). - Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git-fixes). - Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git-fixes). - Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev (git-fixes). - Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 (git-fixes). - Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git-fixes). - Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() (stable-fixes). - Bluetooth: btusb: Fix UAF of btusb_data by rx_work (git-fixes). - Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). - Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). - Bluetooth: hci_aml: validate firmware segment lengths (git-fixes). - Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378 (git-fixes). - Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_conn: fix the SCO setup context lifetime (git-fixes). - Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). - Bluetooth: hci_conn: re-enable advertising only for peripheral role (git-fixes). - Bluetooth: hci_core: Fix race condition during device registration (git-fixes). - Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb (git-fixes). - Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git-fixes). - Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). - Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). - Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_mrvl: Fix wrong return value check of wait_on_bit_timeout() (git-fixes). - Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request (git-fixes). - Bluetooth: hci_sync: Fix accept list UAF during suspend (git-fixes). - Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). - Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). - Bluetooth: hci_sync: Use bt_dev_err() to log error message in hci_update_event_filter_sync() (stable-fixes). - Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del() (git-fixes). - Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git-fixes). - Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync (git-fixes). - Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). - Bluetooth: L2CAP: clear FLAG_DEFER_SETUP only for same PID/PSM (git-fixes). - Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan (git-fixes). - Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect (git-fixes). - Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync (git-fixes). - Bluetooth: MGMT: free the HCI command when it is cancelled (git-fixes). - Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). - Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 (git-fixes). - Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update (git-fixes). - Bluetooth: MSFT: validate evt_prefix_len against the response length (git-fixes). - Bluetooth: qca: fix NVM tag length underflow in TLV parser (git-fixes). - Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). - Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git-fixes). - Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). - Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). - bnxt_en: Check return value of bnxt_hwrm_vnic_cfg (jsc#PED-16798). - bnxt_en: Delay for 5 seconds after AER DPC for all chips (jsc#PED-16798). - bnxt_en: Don't assume XDP is never enabled in bnxt_init_dflt_ring_mode() (jsc#PED-16798). - bnxt_en: Drop pci_save_state() after pci_restore_state() (jsc#PED-16798). - bnxt_en: Implement XDP RSS hash metadata extraction (jsc#PED-16798). - bnxt_en: Implement XDP RSS hash metadata extraction for V3_CMP (jsc#PED-16798). - bnxt_en: Move bnxt_rss_ext_op into header (jsc#PED-16798). - bnxt_en: Refactor some basic ring setup and adjustment logic (jsc#PED-16798). - bnxt_en: Restore default stat ctxs for ULP when resource is available (jsc#PED-16798). - bnxt_en: Set bp->max_tpa according to what the FW supports (jsc#PED-16798). - bnxt_en: Use absolute target ns from ptp_clock_request (jsc#PED-16798). - bnxt_en: use bnxt_xdp_buff for xdp context (jsc#PED-16798). - bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). - bus: mhi: host: Fix controller cleanup on EDL sysfs failure (git-fixes). - bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). - bus: ti-sysc: Fix /chosen node reference leak (git-fixes). - cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). - can: j1939: add missing calls in NETDEV_UNREGISTER notification handler (git-fixes). - can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). - char: xilinx_hwicap: unregister class on init errors (git-fixes). - cleanup: add a scoped version of CLASS() (stable-fixes). - cleanup: fix scoped_class() (git-fixes). - compiler_types: Introduce __flex_counter() and family (bsc#1280139). - cpufreq: intel_pstate: Add and use hybrid_get_cpu_type() (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Avoid SMP calls to get cpu-type (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Fix hwp_get_cpu_scaling() (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Use correct scaling factor on Raptor Lake-E (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Use CPPC to get scaling factors (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Use HYBRID_SCALING_FACTOR_ADL for Bartlett Lake (bsc#1240957 bsc#1249104 bsc#1265220). - crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). - crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git-fixes). - crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). - crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). - crypto: ccp - Abort doing SEV INIT if SNP INIT fails (stable-fixes). - crypto: ccp - Add new SEV/SNP platform shutdown API (stable-fixes). - crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() (git-fixes). - crypto: ccp - Fix __sev_snp_shutdown_locked (git-fixes). - crypto: ccp - Fix dereferencing uninitialized error pointer (git-fixes). - crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). - crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). - crypto: ccp - Fix SNP panic notifier unregistration (git-fixes). - crypto: ccp - Move dev_info/err messages for SEV/SNP init and shutdown (stable-fixes). - crypto: ccp - Move SEV/SNP Platform initialization to KVM (stable-fixes). - crypto: ccp - Register SNP panic notifier only if SNP is enabled (stable-fixes). - crypto: ccp - Reset TMR size at SNP Shutdown (stable-fixes). - crypto: doc - Remove extra parenthesis (git-fixes). - crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). - crypto: keembay - Fix AEAD unregister count in error path (git-fixes). - crypto: keembay - Initialize completion before requesting IRQ (git-fixes). - crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). - crypto: lskcipher - propagate errors from unaligned crypt (git-fixes). - crypto: mxs-dcp - fix source scatterlist length access (git-fixes). - crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). - crypto: qat - clear AES key schedule from stack (git-fixes). - crypto: qce - fix CCM AAD buffer underallocation (git-fixes). - crypto: qce - fix error path in devm_qce_register_algs (git-fixes). - crypto: qcom-rng - Allow zero as a random number (git-fixes). - crypto: qcom-rng - Enable clock in hwrng case (git-fixes). - crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). - crypto: sa2ul - stop probe if context pool creation fails (git-fixes). - crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git-fixes). - crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin (stable-fixes). - crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() (git-fixes). - cxl/acpi: Fix CXL_ACPI and CXL_PMEM Kconfig tristate mismatch (git-fixes). - cxl: Adjust the startup priority of cxl_pmem to be higher (git-fixes). - default_gfp(): avoid using the 'newfangled' __VA_OPT__ trick (bsc#1280139). - device property: fix infinite loop in fwnode_for_each_child_node() (git-fixes). - dm/amdgpu: fix malformed link_settings debugfs output (git-fixes). - dma-mapping: add __dma_from_device_group_begin()/end() (bsc#1267586). - dmaengine: dw-edma: Clear stale requests on termination (git-fixes). - dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). - dmaengine: dw-edma: Fix HDMA channel status register access (git-fixes). - dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). - dmaengine: dw-edma: Serialize abort state updates (git-fixes). - dmaengine: dw-edma: Serialize channel state checks (git-fixes). - dmaengine: dw-edma: Terminate all descriptors without callbacks (git-fixes). - dmaengine: fsl-edma: tracing: no ptr dereference during log output (git-fixes). - dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). - dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). - dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). - dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). - dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). - dmaengine: zynqmp_dma: fix kernel doc for zynqmp_dma_remove() (git-fixes). - driver core: soc: Unregister bus on early device registration failure (git-fixes). - drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook() (git-fixes). - Drivers: hv: Use meaningful errnos for hypercall status codes (git-fixes). - drm/amd/display: Add AV mute wait frames to dce110_set_avmute (stable-fixes). - drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). - drm/amd/display: Check for tg ops in dce110_set_avmute (git-fixes). - drm/amd/display: dce100: skip non-DP stream encoders for DP MST (stable-fixes). - drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix (git-fixes). - drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE (git-fixes). - drm/amd/display: fix division by zero in get_estimated_bw() (git-fixes). - drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank() (git-fixes). - drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames (stable-fixes). - drm/amd/display: Remove unused-but-set variable hubp from (git-fixes). - drm/amd/display: validate plane degamma LUT size for private color prop (git-fixes). - drm/amd/pm: adjust the visibility of pp_table sysfs node (stable-fixes). - drm/amd/pm: fix gpu metrics energy accumulator for smu 13.0.0/13.0.7 (git-fixes). - drm/amd/pm: fix smu14 power limit range calculation (stable-fixes). - drm/amd/pm: make pp_features read-only when scpm is enabled (stable-fixes). - drm/amd/pm: Use same metric table for APU (stable-fixes). - drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git-fixes). - drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). - drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). - drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). - drm/amdgpu/gfx8: drop unecessary BUG_ON() (stable-fixes). - drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git-fixes). - drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git-fixes). - drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) (stable-fixes). - drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older (stable-fixes). - drm/amdgpu/vce: fix integer overflow in image size (stable-fixes). - drm/amdgpu/vcn4: avoid rereading IB param length (stable-fixes). - drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git-fixes). - drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). - drm/amdgpu: check ASPM on the dGPU host link (git-fixes). - drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). - drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). - drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). - drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved (stable-fixes). - drm/amdgpu: fix division by zero with invalid uvd dimensions (stable-fixes). - drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() (stable-fixes). - drm/amdgpu: fix nbif 6.3.1 l1 low power not functional (git-fixes). - drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). - drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). - drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). - drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). - drm/amdgpu: Fix VFCT bus number matching with soft filter (stable-fixes). - drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). - drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (stable-fixes). - drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini (git-fixes). - drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 (git-fixes). - drm/amdgpu: reject oversized IBs with per-ring packet limits (stable-fixes). - drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). - drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable-fixes). - drm/amdgpu: remove unused function parameter (stable-fixes). - drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). - drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). - drm/amdkfd: Check bounds in allocate_event_notification_slot (stable-fixes). - drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (stable-fixes). - drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). - drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). - drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore (git-fixes). - drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). - drm/amdkfd: Use kvcalloc to allocate arrays (stable-fixes). - drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). - drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). - drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). - drm/bridge: tc358767: clamp the reported AUX read size to the request (git-fixes). - drm/connector/hdmi: Fix out of bounds memory read (git-fixes). - drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). - drm/drm_exec: fix up contended obj when num_objects is 0 (git-fixes). - drm/gud: NUL-terminate TV mode names read from the device (git-fixes). - drm/gud: validate TV mode names before creating enum property (git-fixes). - drm/hibmc: Fix list of formats on the primary plane (git-fixes). - drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). - drm/i915/hdcp: check streams bounds before overflow (git-fixes). - drm/i915/hdcp: Move to using intel_display in intel_hdcp (stable-fixes). - drm/i915/hdcp: require monotonically increasing seq_num_v (git-fixes). - drm/i915/hdcp: Skip inactive MST connectors when building stream list (stable-fixes). - drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() (stable-fixes). - drm/i915/vrr: require valid min/max vfreq for VRR (git-fixes). - drm/i915: Fix memory leak in query_perf_config_list() (git-fixes). - drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). - drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg (git-fixes). - drm/msm/a6xx: Fix stale rpmh votes after suspend (git-fixes). - drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). - drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). - drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git-fixes). - drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE (git-fixes). - drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op (git-fixes). - drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE (git-fixes). - drm/nouveau: unsubscribe the channel-kill event before the fence context (git-fixes). - drm/nouveau: Use write-combined maps for coherent (git-fixes). - drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). - drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). - drm/panthor: fix firmware control interface bounds checks (git-fixes). - drm/panthor: return PTR_ERR() from devm_drm_dev_alloc() (git-fixes). - drm/panthor: skip zero-sized firmware sections (git-fixes). - drm/radeon: fix autosuspend cleanup during teardown (git-fixes). - drm/radeon: fix r100_copy_blit for large BOs (stable-fixes). - drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). - drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). - drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). - drm/ssd130x: fix column and row end address in partial updates in ssd133x (git-fixes). - drm/sun4i: crtc: Propagate layer initialization error (git-fixes). - drm/sun4i: Drop node references while building component list (git-fixes). - drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). - drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). - drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). - drm/sun4i: hdmi: Don't leak sync polarity bits into packet control (git-fixes). - drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). - drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). - drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). - drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). - drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). - drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info (git-fixes). - drm/tve200: add OF module alias for autoloading (git-fixes). - drm/virtio: Fix a NULL vs ERR_PTR() bug in virtio_gpu_user_framebuffer_create() (git-fixes). - drm/xe/oa: Check managed mutex initialization errors (git-fixes). - drm/xe/oa: Fix sync entry leak on OA config emit failure (git-fixes). - drm/xe/oa: Remove sysfs entry on idr_alloc failure in xe_oa_add_config_ioctl() (git-fixes). - drm/xe: Introduce xe_gt_dbg_printer() (stable-fixes). - drm/xe: Order ring writes before ring tail updates (git-fixes). - drm/xe: Stub out new pagefault layer (stable-fixes). - drm/xe: tests: fix error message in xe_migrate_sanity_test() (git-fixes). - drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used (git-fixes). - drm: fix race between partial drm_dev_register() failure and ioctl (git-fixes). - drm: lcdif: Wait for vblank before disabling DMA (git-fixes). - drm: Remove unused header in drm_dumb_buffers.c (git-fixes). - efi: fix stale reference to efi_recover_from_page_fault() (git-fixes). - erspan: Initialize options_len before referencing options (bsc#1274727). - ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). - fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). - fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). - fbdev: kyro: Validate overlay viewport coordinates (git-fixes). - fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). - fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). - fbdev: uvesafb: unregister connector callback on init failure (git-fixes). - fbdev: vfb: defer cleanup until the last reference (git-fixes). - firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). - firmware: arm_scmi: Clean up channels on setup failure (git-fixes). - firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). - firmware: arm_scmi: Fix requested device removal race (git-fixes). - firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). - firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). - firmware: arm_scmi: Publish channel state before callbacks (git-fixes). - firmware: arm_scmi: Quiesce notifications before teardown (git-fixes). - firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (git-fixes). - firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). - firmware: arm_scmi: Roll back partial protocol table registration (git-fixes). - firmware: arm_scmi: Unregister device notifier before IDR teardown (git-fixes). - firmware: arm_scmi: Unrequest devices if driver registration fails (git-fixes). - firmware: arm_scmi: Unwind P2A receiver mailbox setup failure (git-fixes). - firmware: arm_scmi: Unwind TX receiver mailbox setup failure (git-fixes). - firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). - firmware_loader: do not queue completed sysfs fallback requests (git-fixes). - fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git-fixes). - fpga: dfl: fme: add error handling (git-fixes). - fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git-fixes). - fuse: fix race between interrupt and resend (git-fixes). - gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind (git-fixes). - gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). - gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). - gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings (stable-fixes). - HID: asus: fix missing hid_is_usb() check (git-fixes). - HID: asus: simplify RGB init sequence (stable-fixes). - HID: bpf: serialize device reference release in struct_ops destroy path (git-fixes). - HID: core: fix number/pointer type confusion on long items (git-fixes). - HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). - HID: ft260: fix stack-use-after-return write in I2C read race (git-fixes). - HID: ft260: validate i2c input report length (stable-fixes). - HID: hyperv: validate initial device info bounds (git-fixes). - HID: i2c-hid: Fix '(null)' output when reading report descriptor fails (git-fixes). - HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). - HID: lg4ff: validate report length before fixed offsets (git-fixes). - HID: logitech-dj: Fix maxfield check in DJ short report validation (git-fixes). - HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git-fixes). - HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). - HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable-fixes). - HID: magicmouse: do not keep a stale msc->input if no input is claimed (git-fixes). - HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C (git-fixes). - HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). - HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git-fixes). - HID: magicmouse: re-enable multitouch after reset-resume (git-fixes). - HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). - HID: multitouch: reclassify HTIX5288 to WIN_8_FORCE_MULTI_INPUT_NSMU (git-fixes). - HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). - HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git-fixes). - HID: nintendo: register input device after capabilities are set (git-fixes). - HID: nintendo: stop device IO before hid_hw_stop on probe failure (git-fixes). - HID: picolcd: clamp eeprom debugfs read to bytes actually received (git-fixes). - HID: pidff: Rework pidff_set_time() to fix warnings (stable-fixes). - HID: pidff: Use ARRAY_SIZE macro instead of sizeof (stable-fixes). - HID: rmi: fix OOB access with undersized RMI reports (git-fixes). - HID: roccat: bound device-supplied profile index (git-fixes). - HID: roccat: free buffered reports when destroying device (git-fixes). - HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git-fixes). - HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). - HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). - HID: synchronize input before cleaning up a failed probe (git-fixes). - HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). - HID: wacom: validate report length in wacom_intuos_pro2_bt_irq (git-fixes). - hwmon: (ads7828) Fix external VREF regulator handling (git-fixes). - hwmon: (applesmc) fix key backlight workqueue leak on register failure (git-fixes). - hwmon: (aspeed-pwm-tacho) Propagate reset deassert errors (git-fixes). - hwmon: (chipcap2) fix channels in humidity alarm notifications (git-fixes). - hwmon: (coretemp) Fix core_data leak on CPUs without PTS (git-fixes). - hwmon: (corsair-cpro) Create debugfs entries after hwmon registration (git-fixes). - hwmon: (corsair-cpro) Remove debugfs entries when probe fails (git-fixes). - hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). - hwmon: (gpio-fan) Fix use-after-free in alarm work (git-fixes). - hwmon: (gpio-fan) take fan_data->lock in gpio_fan_shutdown() (git-fixes). - hwmon: (ina2xx) Add support for has_alerts configuration flag (stable-fixes). - hwmon: (ina2xx) Add support for INA234 (stable-fixes). - hwmon: (ina2xx) Add support for INA260 (stable-fixes). - hwmon: (ina2xx) Fix various overflow issues (git-fixes). - hwmon: (ina2xx) Make it easier to add more devices (stable-fixes). - hwmon: (ina2xx) Shift INA234 shunt and current registers (stable-fixes). - hwmon: (ina226) Add support for SY24655 (stable-fixes). - hwmon: (ltc4282) Avoid overflow in maximum power calculation (git-fixes). - hwmon: (ltc4282) Clamp negative current limits (git-fixes). - hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt (git-fixes). - hwmon: (ltc4282) Make sure clk_init_data is fully initialized (git-fixes). - hwmon: (max6621) fix negative temperature offset and crit readings (git-fixes). - hwmon: (max6621) fix temperature clamp range (git-fixes). - hwmon: (nzxt-smart2) Check return value of init_device() in probe (git-fixes). - hwmon: (pmbus) Clear generic status alarms with CLEAR_FAULTS (git-fixes). - hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). - hwmon: Switch back to struct platform_driver::remove() (stable-fixes). - hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). - hwrng: omap - Fix probe error path cleanup (git-fixes). - hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git-fixes). - i2c: core: fix debugfs UAF on adapter removal (git-fixes). - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (git-fixes). - i2c: imx: separate atomic, dma and non-dma use case (stable-fixes). - i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). - i2c: mux: Fix channel node leak on adapter add failure (git-fixes). - i2c: ocores: Disable clock on failed resume (git-fixes). - i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). - i3c: dw: rename 'pclk' to 'apb' to match dt-binding (git-fixes). - i3c: master: Fix device_register() error path (git-fixes). - i3c: master: Fix info leak and UAF in device unregister path (git-fixes). - i3c: master: Fix potential UAF in i3c_device_uevent() (git-fixes). - i3c: master: svc: bound IBI payload to the requested max_payload_len (git-fixes). - ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink (git-fixes). - ieee802154: cc2520: fix FIFOP work use-after-free (git-fixes). - ieee802154: hwsim: serialize pib updates to fix double-free (git-fixes). - iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). - iio: adc: max34408: add missing 'select REGMAP_I2C' to Kconfig (git-fixes). - iio: adc: pac1921: fix wrong channel used in trigger handler read (git-fixes). - iio: buffer: Fix potential use-after-free in anonymous buffer release (git-fixes). - iio: buffer: Make IIO DMA fence release RCU-safe (git-fixes). - iio: buffer: Tie IIO dma fence lock lifetime to the fence (git-fixes). - iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). - iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). - iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). - iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). - iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). - iio: light: cm32181: return zero after writing calibscale (git-fixes). - iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). - iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). - iio: light: isl29028: return zero in write_raw() on success (git-fixes). - iio: light: ltrf216a: fix runtime PM reference leak in error path (git-fixes). - iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem() (git-fixes). - iio: light: opt4001: Fix power down clearing bits of the wrong register (git-fixes). - iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask (git-fixes). - iio: light: opt4001: Reject integration times with a non-zero seconds part (git-fixes). - iio: light: tsl2583: return zero in write_raw() on success (git-fixes). - iio: light: tsl2772: fix ALS calibscale readback (git-fixes). - iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). - iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git-fixes). - iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). - iio: srf04: fix pm_runtime handling on probe error path (git-fixes). - iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). - Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). - Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). - Input: cs40l50-vibra - validate custom data from user space (git-fixes). - Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). - Input: evdev - sanitize event type index when fetching event masks (stable-fixes). - Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). - Input: focaltech - use signed coordinates to prevent underflow (git-fixes). - Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). - Input: iforce - validate input packet lengths (stable-fixes). - Input: iqs5xx - validate firmware record destination span (git-fixes). - Input: mms114 - fix Y-resolution configuration (git-fixes). - Input: psxpad-spi - set driver data before use (git-fixes). - Input: reject inhibit and uninhibit requests on unregistering devices (git-fixes). - Input: sur40 - fix input device registration ordering (stable-fixes). - Input: sur40 - fix V4L error path cleanup (stable-fixes). - Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). - Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). - Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git-fixes). - Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git-fixes). - Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). - Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). - interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). - io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item (git-fixes). - io_uring/net: Avoid msghdr on op_connect/op_bind async data (git-fixes). - iommu/arm-smmu-v3: Manage teardown with devm (stable-fixes). - ip_tunnel: Use ip_tunnel_info() helper instead of 'info + 1' (bsc#1274727). - ipmi: ipmb: validate write message length (git-fixes). - ipmi: si: Fix NULL pointer dereference after failed registration (git-fixes). - KVM: arm64: Ensure FFA ranges are page aligned (git-fixes). - KVM: arm64: Fix bounds checking in do_ffa_mem_reclaim() (git-fixes). - KVM: arm64: Fix sign-extension of MMIO loads (git-fixes). - KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure (git-fixes). - KVM: arm64: Zero out the stack initialized data in the FFA handler (git-fixes). - KVM: nSVM: Always inject a #GP if mapping VMCB12 fails on nested VMRUN (git-fixes). - KVM: nSVM: Remove a user-triggerable WARN on nested_svm_load_cr3() succeeding (git-fixes). - KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit (git-fixes). - KVM: nVMX: Service local TLB flushes on failed nested VM-Enter (git-fixes). - KVM: PPC: Book3S HV: Add support for compat CPU capabilities for KVM on PowerNV (bsc#1263864 ltc#217835). - KVM: PPC: Book3S HV: Implement compat CPU capability retrieval for KVM on PowerVM (bsc#1263864 ltc#217835). - KVM: PPC: Book3S HV: Validate arch_compat against host compatibility mode (bsc#1263864 ltc#217835). - KVM: PPC: Document KVM_PPC_GET_COMPAT_CAPS ioctl (bsc#1263864 ltc#217835). - KVM: PPC: Introduce KVM_CAP_PPC_COMPAT_CAPS and wire up ioctl (bsc#1263864 ltc#217835). - KVM: SEV: Use to_kvm_sev_info() for fetching kvm_sev_info struct (git-fixes). - KVM: SVM: Add support to initialize SEV/SNP functionality in KVM (bsc#1279887). - KVM: SVM: Explicitly mark vmcb01 dirty after modifying VMCB intercepts (git-fixes). - KVM: SVM: Serialize accesses to the owner and mirror list with separate lock (git-fixes). - KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (git-fixes). - KVM: TDX: Account all non-transient page allocations for per-TD structures (git-fixes). - KVM: TDX: Fix x2APIC MSR handling in tdx_has_emulated_msr() (git-fixes). - KVM: VMX: Don't register posted interrupt wakeup handler if alloc_kvm_area() fails (git-fixes). - KVM: x86/hyperv: Check for NULL vCPU Hyper-V object in kvm_hv_get_tlb_flush_fifo() (git-fixes). - KVM: x86/hyperv: Ensure vCPU's Hyper-V object is initialized on cross-vCPU accesses (git-fixes). - KVM: x86/hyperv: Get target FIFO in hv_tlb_flush_enqueue(), not caller (git-fixes). - KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). - KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). - KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). - KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). - KVM: x86: Don't WARN if IRQ disappears because it was cleared from the PIC (git-fixes). - KVM: x86: Don't WARN if IRQ disappears when Xen emulation is enabled (git-fixes). - KVM: x86: Fix array_index_nospec() protection in kvm_vcpu_ioctl_x86_set_mce() (git-fixes). - KVM: x86: Fix emulated CPUID features being applied to wrong sub-leaf (git-fixes). - KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock (git-fixes). - leds: pca9532: Fix inverted GPIO output polarity (git-fixes). - leds: pca9532: Fix phantom device registration on missing hardware (git-fixes). - lib/string: fix memchr_inv() for large ranges (git-fixes). - lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). - mac802154: fix data race and NULL deref on local->assoc_dev (git-fixes). - mac802154: fix netdev use-after-free in beacon worker (git-fixes). - mac802154: fix use-after-free of sdata via queued RX frames (git-fixes). - mailbox: pcc: Fix command timeout due to missed interrupt (git-fixes). - mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler (git-fixes). - mailbox: qcom-cpucp: handle NULL data in send_data callback (git-fixes). - mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git-fixes). - mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). - maple_tree: fix argument name in header (git-fixes). - md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). - media: airspy: Return queued buffers on start_streaming() failure (git-fixes). - media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). - media: amphion: Remove obsolete frame_count check in venc_start_session (git-fixes). - media: bcm2835-unicam: Fix asc leaked in error/remove path (git-fixes). - media: cec-pin: Fix event FIFO ordering (git-fixes). - media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). - media: cec: extron-da-hd-4k-plus: add sanity check (git-fixes). - media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). - media: cec: Serialize exclusive follower delivery (git-fixes). - media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). - media: cedrus: clean up media device on probe failure (git-fixes). - media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). - media: chips-media: wave5: Guard bit depth check with initial_info_obtained (git-fixes). - media: chips-media: wave5: Move src_buf Removal to finish_encode (git-fixes). - media: cobalt: Avoid freeing ALSA private data twice (git-fixes). - media: cx231xx: fix devres lifetime (git-fixes). - media: cx231xx: reject geometry changes while the VBI queue is busy (git-fixes). - media: cx23885: add ioremap return check and cleanup (git-fixes). - media: cx23885: cancel NetUP CI work before teardown (git-fixes). - media: em28xx: defer audio-only extension registration (git-fixes). - media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git-fixes). - media: go7007: defer the ALSA v4l2 put until card release (git-fixes). - media: hevc: add bounded tile-count helpers (git-fixes). - media: i2c: alvium: fix critical pointer access in alvium_ctrl_init (git-fixes). - media: i2c: alvium: Fix: Correct name of register in alvium_set_ctrl_auto_exposure (git-fixes). - media: i2c: imx219: Rename VTS to FRM_LENGTH (stable-fixes). - media: i2c: imx415: Return test pattern write errors (git-fixes). - media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). - media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). - media: i2c: rdacm21: Fix missing media_entity_cleanup() (git-fixes). - media: imx219: Fix maximum frame length in lines (git-fixes). - media: intel/ipu6: fix async notifier cleanup leak on parse error (git-fixes). - media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges (git-fixes). - media: ipu6: Do not free aux device pdata after init (git-fixes). - media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git-fixes). - media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). - media: mc-entity: Add missing kerneldoc (git-fixes). - media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity (git-fixes). - media: meson: vdec: Fix memory leak in error path of vdec_open (git-fixes). - media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git-fixes). - media: msi2500: Return queued buffers on start_streaming() failure (git-fixes). - media: nuvoton: npcm-video: fix error handling in npcm_video_init() (git-fixes). - media: nuvoton: npcm-video: fix memory leaks in probe and remove (git-fixes). - media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe (git-fixes). - media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure (git-fixes). - media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). - media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path (git-fixes). - media: nxp: imx8-isi: Fix potential out-of-bounds issues (git-fixes). - media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding (git-fixes). - media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). - media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). - media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode() (stable-fixes). - media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup (git-fixes). - media: platform: mtk-mdp3: Fix SCP device refcounting (git-fixes). - media: pwc: Drain fill_buf on start_streaming() failure (git-fixes). - media: pwc: Return queued buffers on start_streaming() failure (git-fixes). - media: qcom: camss: Fix RDI streaming for CSID GEN2 (git-fixes). - media: radio-si476x: Unregister v4l2_device on probe failure (git-fixes). - media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). - media: rtl2832: fix use-after-free in rtl2832_remove() (git-fixes). - media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). - media: rtl2832_sdr: Return queued buffers on start_streaming() failure (git-fixes). - media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). - media: s2255: bound JPEG frame size before copying into the buffer (git-fixes). - media: s2255: check firmware size before reading trailing marker (git-fixes). - media: saa7134: Fix a possible memory leak in saa7134_video_init1 (git-fixes). - media: saa7164: fix cleanup on resource allocation failure (git-fixes). - media: stm32: dcmi: unregister notifier on probe failure (git-fixes). - media: sun4i-csi: Return queued buffers on start_streaming() failure (git-fixes). - media: tda18250: fix possible integer overflow (git-fixes). - media: tegra-video: vi: fix invalid u32 return value in format lookup (git-fixes). - media: usbtv: keep device alive while ALSA card exists (git-fixes). - media: v4l2-async: avoid deleting unlinked ASC entry on link error (git-fixes). - media: v4l2-async: Unregister sub-device if asc_list is empty (git-fixes). - media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (git-fixes). - media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git-fixes). - media: v4l2-ctrls: validate AV1 tile counts (git-fixes). - media: v4l2-ctrls: validate HEVC tile counts (git-fixes). - media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). - media: v4l2-h264: Fix memcmp() size in B1 reference list comparison (git-fixes). - media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely (git-fixes). - media: venus: fix payload size calculation in parse_raw_formats() (git-fixes). - media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). - media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity (git-fixes). - media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer (git-fixes). - media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity (git-fixes). - media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). - media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). - media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). - media: vivid: add vivid_update_reduced_fps() (git-fixes). - media: vivid: check for vb2_is_busy() when toggling caps (git-fixes). - media: vivid: fix cleanup bugs in vivid_init() (git-fixes). - media: zoran: Avoid freeing a registered video_device twice (git-fixes). - mei: pull kvfree out of spinlock (git-fixes). - mfd: iqs62x: Reject zero-length firmware records (git-fixes). - mfd: rave-sp: validate received frame payload lengths (git-fixes). - mfd: sm501: Fix potential memory leaks during remove (git-fixes). - misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). - misc: fastrpc: fix channel ctx ref leak when session alloc fails (git-fixes). - misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). - misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). - misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git-fixes). - misc: nsm: bound the device-reported response length (git-fixes). - misc: rtsx: add missing write register handling (git-fixes). - misc: sgi-gru: remove interrupt-context page-table walks (git-fixes). - misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git-fixes). - mkspec-dtb: Move DTS prefix into package list. - mkspec-dtb: Move provides-obsoletes to package list. - mkspec-dtb: Put per-architecture package lists into a hash. - mkspec-dtb: re-indent. - mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition (git-fixes). - mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git-fixes). - mmc: sdhci: unmap the bounce buffer before device release (git-fixes). - mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). - mtd: afs: validate v2 image info bounds (git-fixes). - mtd: fix double free and WARN_ON in add_mtd_device() error paths (git-fixes). - mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). - mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). - mtd: mtdswap: remove debugfs stats file on teardown (git-fixes). - mtd: nand: mtk-ecc: stop on ECC idle timeouts (git-fixes). - mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). - mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). - mtd: spinand: fix direct mapping creation sizes (stable-fixes). - mtd: spinand: repeat reading in regular mode if continuous reading fails (stable-fixes). - mtd: spinand: try a regular dirmap if creating a dirmap for continuous reading fails (stable-fixes). - mtd: ubi: Release device reference on busy detach (git-fixes). - mtd: ubi: skip programming unused bits in ubi headers (stable-fixes). - net: Add options as a flexible array to struct ip_tunnel_info (bsc#1274727). - net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). - net: mana: Add handler for sriov configure (bsc#1272756). - net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). - net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). - net: mana: Fall back to scattered pages for GDMA queues (git-fixes). - net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). - net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). - net: mana: Route ring-buffer access through offset-based helpers (git-fixes). - net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). - net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git-fixes). - net: thunderbolt: Mark the connection down when bringing it up fails (git-fixes). - net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git-fixes). - net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). - net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). - net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow (git-fixes). - net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). - net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition (git-fixes). - nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). - nfc: digital: Do not dump a NULL response in command completion (git-fixes). - nfc: fdp: bound the device-reported read length and fix an skb leak (git-fixes). - nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). - nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git-fixes). - nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). - nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). - nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git-fixes). - nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). - nfc: microread: validate target discovery payload lengths (git-fixes). - nfc: nci: fix double completion race in nci_data_exchange_complete (git-fixes). - nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git-fixes). - nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git-fixes). - nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git-fixes). - nfc: nci: free destination parameters when closing a connection (git-fixes). - nfc: pn533: hold a reference to the request skb during send_frame (git-fixes). - nfc: pn533: purge fragmented skbs during cleanup (git-fixes). - nfc: st21nfca: validate ATR_REQ length against the received frame (git-fixes). - nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git-fixes). - nvme-tcp: fix usage of page_frag_cache (bsc#1267882). - nvmet-rdma: fix queue leak when connect backlog is exceeded (git-fixes). - of: fix out-of-bounds read in of_alias_scan() stem parser (git-fixes). - PCI/ASPM: Use pcie_capability_clear_and_set_word() for ASPM disable/restore (git-fixes). - PCI/proc: Avoid spurious runtime PM wakeup on config space accesses (git-fixes). - PCI/proc: Use file_ns_capable() when checking config space read access (git-fixes). - PCI/proc: Warn on writes to kernel-exclusive config space regions (git-fixes). - PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses (git-fixes). - PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). - PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git-fixes). - PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). - PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). - PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() (git-fixes). - PCI: plda: Fix use-after-free of event IRQs during teardown (git-fixes). - perf: Reject exited events as group leaders (git-fixes). - pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). - pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). - pinctrl: rockchip: Reset the pin count when recalculating SoC data (git-fixes). - platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). - platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). - platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git-fixes). - platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). - platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git-fixes). - platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). - platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git-fixes). - platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). - platform/x86/amd/hsmp: Reject negative power cap writes in hwmon (git-fixes). - platform/x86: asus-wmi: fix resource leaks on probe failure (git-fixes). - platform/x86: dell-privacy: Fix race condition (git-fixes). - platform/x86: dell-wmi-base: Fix resource leak on module load failure (git-fixes). - platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). - platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). - platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS (git-fixes). - platform/x86: hp-bioscfg: advance elem past consumed array elements (git-fixes). - platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() (git-fixes). - platform/x86: hp-bioscfg: fix heap OOB read on empty password write (git-fixes). - platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password (git-fixes). - platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() (git-fixes). - platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed (git-fixes). - platform/x86: hp-bioscfg: fix password encoding bounds check (git-fixes). - platform/x86: hp-bioscfg: warn on element type mismatch instead of failing (git-fixes). - platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). - platform/x86: ISST: Add a NULL check for sst_inst (git-fixes). - platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). - platform/x86: ISST: Return error during profile addition (git-fixes). - platform/x86: ISST: Use PP level enable mask (git-fixes). - platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). - platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). - platform/x86: ISST: Validate parameter for core power state (git-fixes). - platform/x86: ISST: Validate parameter for frequency and priority (git-fixes). - platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). - PM: hibernate: Fix memory leak in snapshot_write_next() error path (git-fixes). - PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). - power: supply: bd99954: Drop bad register fields (git-fixes). - power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git-fixes). - power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git-fixes). - power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). - power: supply: bq256xx: drain usb_work before freeing the charger (git-fixes). - power: supply: bq24257: fix use-after-free on remove (git-fixes). - power: supply: bq25890: Fix power_supply reference leak (git-fixes). - power: supply: charger-manager: register regulators before exposing sysfs (git-fixes). - power: supply: cros_usbpd-charger: bound the EC-reported port count (git-fixes). - power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git-fixes). - power: supply: isp1704_charger: cancel work on remove (git-fixes). - power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git-fixes). - power: supply: lp8788-charger: fix use-after-free on remove (git-fixes). - power: supply: max17040: drop incorrect I2C functionality check (git-fixes). - power: supply: max17040: propagate register read errors (git-fixes). - power: supply: max17040: synchronize work cancellation on suspend (git-fixes). - power: supply: qcom_battmgr: terminate the strings from firmware (git-fixes). - power: supply: rt9455: quiesce delayed work before teardown (git-fixes). - power: supply: sbs-battery: Use a per-device serial number buffer (git-fixes). - power: supply: sc2731_charger: cancel work on remove (git-fixes). - power: supply: twl4030_charger: cancel workers via devm (git-fixes). - power: supply: ucs1002: fix use-after-free on remove (git-fixes). - powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). - powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors (bsc#1263864 ltc#217835). - powerpc/kexec_file: Use inclusive range checks in add_usable_mem() (git-fixes). - powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). - powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). - powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak (bsc#1274751 ltc#221105 bsc#1274750 ltc#221106). - powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). - powerpc/rtas_pci: No hotplug on permanently removed device on pSeries (git-fixes). - powerpc: Replace __ASSEMBLY__ with __ASSEMBLER__ in non-uapi headers (bsc#1263864 ltc#217835). - powerpc: Replace __ASSEMBLY__ with __ASSEMBLER__ in uapi headers (bsc#1263864 ltc#217835). - ppdev: prevent overflow when setting port timeout (git-fixes). - rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() (git-fixes). - rapidio: clear mport->net when rio_add_net() fails (git-fixes). - rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). - RDMA/bnxt_re: Avoid displaying the kernel pointer (git-fixes). - RDMA/bnxt_re: Proper rollback if the ioremap fails (git-fixes). - RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). - RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). - RDMA/mana_ib: unify QP lookup table (git-fixes). - RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). - regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). - regulator: core: use system_freezable_wq for init complete work (git-fixes). - regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). - regulator: qcom-refgen: correct the regulator type to CURRENT (git-fixes). - regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). - remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). - remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). - remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). - Revert 'drm/amdgpu: fix aperture mapping leak' (git-fixes). - Revert 'media: v4l2-dev: fix error handling in __video_register_device()' (git-fixes). - Revert 'net: thunderbolt: Enable end-to-end flow control also in transmit' (git-fixes). - Revert 'thermal/drivers/hwmon: Cleanup coding style a bit' (stable-fixes). - Revert 'wifi: mt76: Disable napi when removing device' (git-fixes). - rpmsg: core: Fix incorrect return value documentation (git-fixes). - rpmsg: glink: smem: order FIFO read after availability check (git-fixes). - rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). - rtc: pcf8563: fix clock provider leak on unbind (git-fixes). - rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). - rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). - rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git-fixes). - rtc: zynqmp: Return optional clock lookup errors (git-fixes). - s390/pkey: Check length in pkey_pckmo handler implementation (bsc#1270266). - s390/pkey: Check length in PKEY_VERIFYPROTK ioctl (bsc#1270267). - sched/psi: Create the psimon kthread outside of cgroup_mutex (bsc#1269134). - scsi: fnic: Abort timed-out NVMe LS requests (bsc#1236344). - scsi: fnic: Add and improve logs in FDMI and FDMI ABTS paths (bsc#1236344). - scsi: fnic: Add FDLS role handling for NVMe initiators (bsc#1236344). - scsi: fnic: Add the NVMe/FC transport path (bsc#1236344). - scsi: fnic: Advertise NVMe initiator service parameters (bsc#1236344). - scsi: fnic: Bump up version number (bsc#1236344). - scsi: fnic: Decode firmware role configuration (bsc#1236344). - scsi: fnic: Do not use GFP_ZERO for mempools (bsc#1236344). - scsi: fnic: Expose NVMe transport state in debugfs (bsc#1236344). - scsi: fnic: Handle NVMe LS frames in FDLS (bsc#1236344). - scsi: fnic: Make debug logging protocol independent (bsc#1236344). - scsi: fnic: Make fnic_queuecommand() easier to analyze (bsc#1236344). - scsi: fnic: Refactor in_remove flag and call to fnic_fcpio_reset() (bsc#1236344). - scsi: fnic: Remove a useless struct mempool forward declaration (bsc#1236344). - scsi: fnic: Rename fnic_scsi_fcpio_reset() (bsc#1236344). - scsi: fnic: Route completions and resets by initiator role (bsc#1236344). - scsi: fnic: Self-assignment of intr_time_type has no effect (bsc#1236344). - scsi: fnic: Send NVMe LS requests through FDLS (bsc#1236344). - scsi: fnic: Switch to use %ptSp (bsc#1236344). - scsi: fnic: Track NVMe transport statistics (bsc#1236344). - scsi: fnic: Use fnic_num for non-SCSI identifiers (bsc#1236344). - scsi: fnic: Use mempool for receive frames (bsc#1236344). - scsi: qla2xxx: Add support to report MPI FW state (bsc#1275737). - scsi: qla2xxx: Declare qla2xxx_mqueuecommand() static (bsc#1275737). - scsi: qla2xxx: Use nr_cpu_ids instead of NR_CPUS for qp_cpu_map allocation (bsc#1275737). - scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). - sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). - selftests/alsa: Fix the step check for INTEGER controls (git-fixes). - serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). - serial: amba-pl011: unprepare console clock on unregister (git-fixes). - serial: core: clear freed pointers on uart_register_driver() failure (git-fixes). - serial: imx: serialize imx_uart_ports lifetime (git-fixes). - serial: ma35d1: Fix OF node reference leaks in console init (git-fixes). - serial: qcom-geni: do not advance stale DMA completions (git-fixes). - serial: qcom-geni: fix TX DMA buffer flush (git-fixes). - serial: sc16is7xx: enable THRI before filling TX FIFO (git-fixes). - serial: sc16is7xx: rename EFR mutex with generic name (stable-fixes). - serial: sc16is7xx: use guards for simple mutex locks (stable-fixes). - slab.h: disable completely broken overflow handling in flex allocations (bsc#1280139). - slab: Introduce kmalloc_flex() and family (bsc#1280139). - slab: Introduce kmalloc_obj() and family (bsc#1280139). - slab: recognize @GFP parameter as optional in kernel-doc (bsc#1280139). - smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). - smb: client: harden POSIX SID length parsing (bsc#1273557). - smb: client: require net admin for CIFS SWN netlink (bsc#1273966). - smb: client: resolve SWN tcon from live registrations (bsc#1273872). - soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git-fixes). - soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). - soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). - software node: Fix software_node_get_reference_args() with index -1 (git-fixes). - soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git-fixes). - speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git-fixes). - spi: bcm63xx-hsspi: disable clocks on resume failure (git-fixes). - spi: bcm63xx: disable clock on resume failure (git-fixes). - spi: bcmbca-hsspi: disable clocks on resume failure (git-fixes). - spi: davinci: switch to managed controller allocation (git-fixes). - spi: Fix DMA mapping ownership on partial map failure (git-fixes). - spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). - spi: oc-tiny: switch to managed controller allocation (git-fixes). - spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX (git-fixes). - spi: spi-cadence: Move TX FIFO full busy-wait into FIFO (git-fixes). - spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 (stable-fixes). - spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). - spi: sprd-adi: Fix probe succeeding without registering the controller (git-fixes). - staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). - staging: media: tegra-video: fix of_node_put() on VIP parse errors (git-fixes). - staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). - staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git-fixes). - staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). - staging: rtl8723bs: fix missing shared-key auth challenge length check (git-fixes). - staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() (git-fixes). - staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() (git-fixes). - staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). - staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). - staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() (git-fixes). - staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). - staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). - staging: sm750fb: Add missing Kconfig dependency (git-fixes). - staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). - thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). - thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). - thermal/drivers/rcar: Fix error checking in probe() (git-fixes). - thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). - thermal: sysfs: switch to use scnprintf() to suppress truncation warning (git-fixes). - thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). - thunderbolt: Fix bandwidth group reservation indexing (git-fixes). - thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). - tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). - tpm: st33zp24: Return zero on status read failure (git-fixes). - tpm: st33zp24: Validate locality read result (git-fixes). - tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). - tty: clear cdev pointer after cdev_add() failure (git-fixes). - tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). - tty: skip cdev_del() when no cdev is registered (git-fixes). - uio: Fix stale info pointer in failed registration path (git-fixes). - usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). - usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (git-fixes). - usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). - USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). - usb: cdnsp: fix incorrect endian conversions for APB timeout register (git-fixes). - usb: core: Add lock to usb_wakeup_notification() (git-fixes). - usb: core: Add lock to usb_wakeup_notification() (stable-fixes). - usb: core: Strengthen error handling in hub_hub_status() (git-fixes). - usb: core: Strengthen error handling in hub_hub_status() (stable-fixes). - usb: core: sysfs: add lock to bos_descriptors_read() (stable-fixes). - usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). - usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). - usb: dwc3: clear forceRM when issuing EndTransfer (git-fixes). - usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition (git-fixes). - usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns() (git-fixes). - usb: fix UAF when probe runs concurrent to dyn ID removal (git-fixes). - usb: gadget: aspeed_udc: check endpoint DMA allocation (git-fixes). - usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed (git-fixes). - usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). - usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths (git-fixes). - usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). - usb: gadget: f_midi: initialize work in f_midi_alloc() (git-fixes). - usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). - usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). - usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git-fixes). - usb: gadget: fix null pointer dereference in usb_put_function_instance() (git-fixes). - USB: gadget: fsl-udc: fix dev_printk() device (git-fixes). - usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs (git-fixes). - usb: gadget: midi2: remove default configfs groups on teardown (git-fixes). - usb: gadget: pch_udc: remove excess kernel-doc member for registered (git-fixes). - usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). - usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). - usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git-fixes). - usb: gadget: uac: validate rate list length before storing (git-fixes). - USB: gadget: Use str_enable_disable-like helpers (stable-fixes). - usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). - usb: ljca: bound bank_num in ljca_enumerate_gpio() (git-fixes). - usb: mtu3: allow system suspend during active gadget connection (git-fixes). - usb: musb: omap2430: clean up probe error handling (stable-fixes). - usb: musb: omap2430: Do not put borrowed of_node in probe (git-fixes). - usb: musb: omap2430: Fix use-after-free in omap2430_probe() (git-fixes). - USB: phy: fsl-usb: fix missing static keywords (git-fixes). - usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). - USB: serial: digi_acceleport: fix port registration order (git-fixes). - USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). - USB: serial: option: add TDTECH MT5710-CN (stable-fixes). - USB: serial: option: fix slab OOB read in interrupt URB callback (git-fixes). - USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). - USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). - usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop (git-fixes). - usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails (git-fixes). - usb: typec: qcom-pmic: cancel reset_work on stop (git-fixes). - usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive() (git-fixes). - usb: typec: thunderbolt: Disable work before freeing tbt on remove (git-fixes). - usb: typec: ucsi: displayport: Fix OOB altmode array index (git-fixes). - usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). - usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion (git-fixes). - usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git-fixes). - usb: usbtest: disable dynamic ID support (stable-fixes). - usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). - vfs: Add a sysctl for automated deletion of dentry (bsc#1240890 bsc#1276586). - vt: add permission check for KDSKBMETA ioctl (stable-fixes). - vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable-fixes). - w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). - w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). - watchdog: bd96801_wdt: Fix timeout for enabled WDG (git-fixes). - watchdog: fix hrtimer start when pretimeout is zero (git-fixes). - watchdog: msc313e: Avoid division by zero (git-fixes). - watchdog: msc313e: Enable clock before accessing hardware registers (git-fixes). - watchdog: msc313e: Fix clock leak and spurious timer in settimeout() (git-fixes). - watchdog: msc313e: Fix NULL pointer dereference in PM callbacks (git-fixes). - watchdog: msc313e: Fix spurious reset on suspend (git-fixes). - watchdog: msc313e: Fix undefined behavior (git-fixes). - watchdog: msc313e: Sync timeout value if WDT was running at boot (git-fixes). - watchdog: sunxi_wdt: preserve boot-enabled watchdog (git-fixes). - wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). - wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). - wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). - wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). - wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git-fixes). - wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). - wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() (git-fixes). - wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). - wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). - wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). - wifi: brcmfmac: fix P2P action frame handling without device vif (git-fixes). - wifi: brcmfmac: initialize SDIO data work before cleanup (git-fixes). - wifi: cfg80211: bound element ID read when checking non-inheritance (git-fixes). - wifi: cfg80211: cancel sched scan results work on unregister (git-fixes). - wifi: cfg80211: derive S1G beacon TSF from S1G fields (git-fixes). - wifi: cfg80211: reject unsupported PMSR FTM location requests (git-fixes). - wifi: cfg80211: validate PMSR FTM preamble range (git-fixes). - wifi: cfg80211: validate PMSR measurement type data (git-fixes). - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (git-fixes). - wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). - wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). - wifi: iwlwifi: mei: check SAP message length before reading it (git-fixes). - wifi: iwlwifi: mei: pass correct argument to function (git-fixes). - wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). - wifi: libertas: fix memory leak in helper_firmware_cb() (git-fixes). - wifi: mac80211: disconnect on CSA to channel 0 (git-fixes). - wifi: mac80211: fix fils_discovery double free on alloc failure (git-fixes). - wifi: mac80211: fix per-STA profile length in cross-link CSA parsing (git-fixes). - wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure (git-fixes). - wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (git-fixes). - wifi: mac80211: send TWT teardown to peer after setup TX failure (git-fixes). - wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). - wifi: mac80211: skip unused probe response countdown offsets (git-fixes). - wifi: mt76: check txfree done event on the WED hw path (git-fixes). - wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). - wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). - wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). - wifi: mt76: fix non-AQL packet accounting for MLO stations (git-fixes). - wifi: mt76: fix stranded frames in mt76_txq_schedule_pending (git-fixes). - wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git-fixes). - wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). - wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete (git-fixes). - wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git-fixes). - wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git-fixes). - wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear (git-fixes). - wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). - wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git-fixes). - wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git-fixes). - wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). - wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). - wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git-fixes). - wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). - wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git-fixes). - wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). - wifi: mt76: mt7921: skip unknown CLC firmware records (git-fixes). - wifi: mt76: mt7921: validate CLC firmware records (git-fixes). - wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git-fixes). - wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git-fixes). - wifi: mt76: mt7925: update clc before setting sar power table (git-fixes). - wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git-fixes). - wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). - wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU (git-fixes). - wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). - wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git-fixes). - wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). - wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git-fixes). - wifi: mt76: only consume the WO drop bit on WED v2 devices (git-fixes). - wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). - wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). - wifi: nl80211: free RNR data on MBSSID mismatch (git-fixes). - wifi: nl80211: validate nested MBSSID IE blobs (git-fixes). - wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (git-fixes). - wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop (git-fixes). - wifi: rtl818x: initialize eeprom_93cx6 struct to zero (git-fixes). - wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). - wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids (git-fixes). - wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() (git-fixes). - wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). - wifi: rtw88: pci: fix resource leak on failed NAPI setup (git-fixes). - wifi: rtw89: fix HE extended capability length check (git-fixes). - wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git-fixes). - x86/virt/tdx: Print TDX module version during init (git-fixes). - x86/virt/tdx: Retrieve TDX module version (git-fixes). - xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). - xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). - xhci: fix lost bounce buffers on TDs spanning several ring segments (git-fixes). The following package changes have been done: - kernel-default-6.12.0-160000.38.1 updated From sle-container-updates at lists.suse.com Wed Sep 23 08:21:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 10:21:39 +0200 (CEST) Subject: SUSE-IU-2026:7300-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260923082139.0BABDFF17@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7300-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.136 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.136 Severity : important Type : security References : 1236344 1240890 1240957 1249104 1255225 1255531 1256629 1256671 1258278 1260501 1260577 1261606 1262073 1262756 1263004 1263864 1263865 1264267 1264335 1264444 1264541 1264587 1264619 1264807 1264851 1265036 1265068 1265121 1265132 1265141 1265220 1266710 1266860 1266874 1266897 1266928 1267023 1267238 1267373 1267501 1267586 1267612 1267882 1267985 1268886 1268972 1268979 1269000 1269004 1269010 1269013 1269108 1269113 1269114 1269126 1269134 1269140 1269162 1269167 1269238 1269242 1269256 1269301 1269306 1269380 1269381 1269388 1269402 1269412 1269417 1269528 1269530 1269579 1269583 1269590 1269633 1269635 1269655 1269665 1269685 1269686 1269695 1269697 1269774 1269783 1269792 1269815 1269816 1269888 1269965 1269969 1269985 1269999 1270090 1270108 1270111 1270139 1270219 1270251 1270266 1270267 1271050 1271256 1271365 1271825 1272148 1272149 1272175 1272182 1272199 1272200 1272210 1272213 1272230 1272260 1272261 1272262 1272284 1272287 1272297 1272346 1272366 1272385 1272390 1272423 1272426 1272429 1272484 1272486 1272497 1272501 1272502 1272513 1272516 1272568 1272569 1272584 1272641 1272643 1272673 1272756 1272786 1272788 1272791 1272798 1272799 1272804 1272855 1272865 1272868 1272869 1272877 1272891 1272893 1272894 1272904 1272905 1272918 1272963 1272969 1272971 1272983 1272985 1273008 1273019 1273027 1273030 1273032 1273033 1273036 1273037 1273038 1273060 1273105 1273107 1273119 1273134 1273231 1273249 1273251 1273260 1273271 1273273 1273274 1273276 1273277 1273280 1273281 1273283 1273284 1273285 1273286 1273288 1273289 1273291 1273294 1273302 1273303 1273305 1273309 1273310 1273311 1273312 1273314 1273316 1273317 1273318 1273319 1273323 1273325 1273327 1273331 1273334 1273335 1273336 1273337 1273338 1273339 1273340 1273341 1273346 1273420 1273422 1273426 1273443 1273460 1273461 1273463 1273465 1273468 1273469 1273471 1273479 1273480 1273482 1273484 1273486 1273488 1273490 1273495 1273501 1273503 1273504 1273506 1273507 1273509 1273511 1273520 1273523 1273524 1273525 1273533 1273536 1273538 1273542 1273550 1273555 1273557 1273567 1273578 1273579 1273581 1273582 1273596 1273597 1273598 1273600 1273601 1273602 1273603 1273679 1273681 1273682 1273734 1273737 1273738 1273739 1273740 1273741 1273742 1273743 1273744 1273745 1273746 1273748 1273749 1273755 1273759 1273762 1273765 1273766 1273769 1273770 1273774 1273776 1273778 1273780 1273782 1273788 1273790 1273796 1273797 1273801 1273803 1273804 1273809 1273810 1273811 1273812 1273813 1273817 1273822 1273824 1273831 1273834 1273838 1273839 1273842 1273844 1273848 1273849 1273852 1273855 1273859 1273860 1273862 1273864 1273866 1273867 1273868 1273869 1273870 1273872 1273876 1273877 1273880 1273882 1273890 1273891 1273892 1273895 1273896 1273898 1273899 1273903 1273904 1273905 1273930 1273933 1273934 1273935 1273936 1273939 1273940 1273941 1273942 1273944 1273945 1273946 1273947 1273949 1273953 1273954 1273956 1273957 1273958 1273959 1273963 1273966 1273967 1273968 1273972 1273974 1273975 1273977 1273988 1273990 1273991 1273995 1273997 1273999 1274001 1274003 1274006 1274008 1274009 1274010 1274011 1274012 1274014 1274017 1274019 1274020 1274026 1274028 1274030 1274031 1274035 1274036 1274040 1274041 1274052 1274055 1274057 1274058 1274060 1274063 1274065 1274067 1274071 1274075 1274076 1274077 1274078 1274208 1274226 1274239 1274243 1274252 1274253 1274258 1274264 1274265 1274267 1274274 1274277 1274278 1274281 1274283 1274286 1274290 1274292 1274294 1274295 1274296 1274314 1274321 1274491 1274492 1274494 1274497 1274539 1274541 1274543 1274545 1274547 1274550 1274556 1274573 1274578 1274580 1274581 1274622 1274624 1274628 1274632 1274636 1274637 1274639 1274640 1274642 1274644 1274645 1274646 1274650 1274651 1274652 1274656 1274657 1274659 1274662 1274665 1274667 1274669 1274670 1274671 1274675 1274677 1274678 1274679 1274681 1274682 1274690 1274694 1274696 1274698 1274699 1274700 1274702 1274703 1274705 1274706 1274707 1274709 1274710 1274713 1274716 1274721 1274725 1274727 1274730 1274737 1274738 1274749 1274750 1274751 1274752 1274753 1274754 1274755 1274756 1274764 1274768 1274770 1274771 1274773 1274782 1274783 1274787 1274800 1274801 1274802 1274803 1274804 1274805 1274807 1274808 1274811 1274813 1274814 1274831 1274834 1274835 1274838 1274847 1274849 1274853 1274868 1274869 1274872 1274873 1274874 1274876 1274877 1274879 1274881 1274883 1274886 1274887 1274888 1274891 1274892 1274893 1274894 1274895 1274896 1274897 1274898 1274899 1274900 1274901 1274902 1274904 1274905 1274906 1274907 1274908 1274913 1274914 1274921 1274924 1274925 1274927 1274929 1274930 1274933 1274934 1274935 1274938 1274939 1274940 1274941 1274945 1274947 1274951 1274952 1274953 1274955 1274957 1274958 1274965 1274968 1274978 1274981 1275040 1275045 1275069 1275071 1275072 1275073 1275076 1275080 1275081 1275083 1275088 1275091 1275092 1275094 1275125 1275126 1275129 1275131 1275132 1275139 1275141 1275146 1275148 1275149 1275150 1275152 1275154 1275155 1275156 1275157 1275158 1275160 1275161 1275163 1275164 1275169 1275173 1275176 1275185 1275190 1275192 1275229 1275236 1275237 1275238 1275239 1275294 1275300 1275301 1275303 1275304 1275305 1275306 1275307 1275441 1275470 1275474 1275479 1275481 1275483 1275486 1275487 1275496 1275506 1275509 1275511 1275514 1275517 1275519 1275528 1275535 1275540 1275553 1275555 1275557 1275561 1275566 1275569 1275572 1275574 1275578 1275582 1275583 1275584 1275587 1275588 1275591 1275595 1275596 1275633 1275636 1275650 1275655 1275656 1275659 1275665 1275669 1275672 1275679 1275685 1275687 1275688 1275690 1275695 1275696 1275704 1275737 1275782 1275784 1275787 1275788 1275789 1275790 1275798 1275799 1275801 1275802 1275804 1275805 1275812 1275817 1275818 1275819 1275820 1275821 1275822 1275823 1275827 1275864 1275866 1275867 1275869 1275870 1275871 1275872 1275886 1275905 1275923 1275925 1275928 1275950 1275954 1275956 1275970 1275973 1275975 1275976 1275985 1276006 1276029 1276257 1276258 1276263 1276265 1276267 1276270 1276273 1276277 1276333 1276335 1276339 1276341 1276346 1276354 1276355 1276381 1276395 1276446 1276452 1276468 1276471 1276473 1276500 1276507 1276512 1276528 1276542 1276546 1276547 1276551 1276552 1276553 1276561 1276562 1276566 1276569 1276572 1276577 1276586 1276665 1276766 1276767 1276771 1276785 1276793 1276801 1276803 1276814 1276818 1276821 1276831 1276840 1276864 1276865 1276866 1276870 1276876 1276880 1276905 1276913 1276922 1276931 1276937 1276941 1276955 1276957 1276961 1277022 1277023 1277033 1277034 1277037 1277047 1277054 1277057 1277059 1277062 1277066 1277069 1277070 1277077 1277078 1277092 1277095 1277108 1277114 1277115 1277118 1277120 1277155 1277159 1277160 1277202 1277204 1277227 1277229 1277230 1277231 1277233 1277249 1277254 1277265 1277268 1277275 1277285 1277308 1277311 1277315 1277321 1277328 1277335 1277349 1277350 1277391 1277407 1277408 1277485 1277505 1277513 1277551 1277553 1277561 1277574 1277636 1277641 1277649 1277655 1277656 1277660 1277668 1277680 1277688 1277726 1277728 1277738 1277748 1277761 1277764 1277773 1277775 1277776 1277782 1277783 1277813 1277818 1277822 1277845 1277862 1277874 1277876 1277898 1277901 1277908 1277918 1278039 1278070 1278088 1278094 1278098 1278113 1278155 1278180 1278233 1278236 1278240 1278253 1278293 1278324 1278331 1278334 1278347 1278348 1278349 1278395 1278416 1278703 1278716 1278733 1279487 1279537 1279580 1279813 1279842 1279847 1279887 1280139 CVE-2025-68214 CVE-2025-68358 CVE-2025-68780 CVE-2025-71075 CVE-2026-13595 CVE-2026-23113 CVE-2026-23306 CVE-2026-23348 CVE-2026-27456 CVE-2026-31418 CVE-2026-31530 CVE-2026-31531 CVE-2026-43116 CVE-2026-43125 CVE-2026-43163 CVE-2026-43239 CVE-2026-43271 CVE-2026-43299 CVE-2026-43331 CVE-2026-43355 CVE-2026-43363 CVE-2026-43416 CVE-2026-43439 CVE-2026-43448 CVE-2026-45860 CVE-2026-45897 CVE-2026-45968 CVE-2026-46007 CVE-2026-46070 CVE-2026-46091 CVE-2026-46107 CVE-2026-46115 CVE-2026-46133 CVE-2026-46135 CVE-2026-46195 CVE-2026-46304 CVE-2026-52912 CVE-2026-52920 CVE-2026-52928 CVE-2026-52929 CVE-2026-52935 CVE-2026-52939 CVE-2026-52946 CVE-2026-52977 CVE-2026-52990 CVE-2026-52991 CVE-2026-52994 CVE-2026-53001 CVE-2026-53031 CVE-2026-53033 CVE-2026-53034 CVE-2026-53048 CVE-2026-53059 CVE-2026-53061 CVE-2026-53076 CVE-2026-53077 CVE-2026-53089 CVE-2026-53091 CVE-2026-53092 CVE-2026-53094 CVE-2026-53096 CVE-2026-53109 CVE-2026-53110 CVE-2026-53111 CVE-2026-53114 CVE-2026-53126 CVE-2026-53129 CVE-2026-53142 CVE-2026-53154 CVE-2026-53163 CVE-2026-53180 CVE-2026-53207 CVE-2026-53219 CVE-2026-53220 CVE-2026-53223 CVE-2026-53228 CVE-2026-53238 CVE-2026-53264 CVE-2026-53269 CVE-2026-53284 CVE-2026-53291 CVE-2026-53309 CVE-2026-53330 CVE-2026-53336 CVE-2026-53337 CVE-2026-53341 CVE-2026-53353 CVE-2026-53365 CVE-2026-53388 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-63801 CVE-2026-63803 CVE-2026-63804 CVE-2026-63808 CVE-2026-63810 CVE-2026-63823 CVE-2026-63828 CVE-2026-63860 CVE-2026-63865 CVE-2026-63868 CVE-2026-63879 CVE-2026-63887 CVE-2026-63888 CVE-2026-63889 CVE-2026-63890 CVE-2026-63891 CVE-2026-63898 CVE-2026-63901 CVE-2026-63906 CVE-2026-63917 CVE-2026-63918 CVE-2026-63920 CVE-2026-63921 CVE-2026-63922 CVE-2026-63924 CVE-2026-63925 CVE-2026-63926 CVE-2026-63928 CVE-2026-63941 CVE-2026-63969 CVE-2026-63970 CVE-2026-63984 CVE-2026-63985 CVE-2026-63986 CVE-2026-63987 CVE-2026-63990 CVE-2026-63992 CVE-2026-63993 CVE-2026-63995 CVE-2026-63996 CVE-2026-63997 CVE-2026-63998 CVE-2026-63999 CVE-2026-64000 CVE-2026-64001 CVE-2026-64002 CVE-2026-64003 CVE-2026-64004 CVE-2026-64005 CVE-2026-64006 CVE-2026-64007 CVE-2026-64010 CVE-2026-64011 CVE-2026-64014 CVE-2026-64015 CVE-2026-64017 CVE-2026-64024 CVE-2026-64029 CVE-2026-64033 CVE-2026-64039 CVE-2026-64047 CVE-2026-64048 CVE-2026-64051 CVE-2026-64052 CVE-2026-64053 CVE-2026-64054 CVE-2026-64055 CVE-2026-64056 CVE-2026-64071 CVE-2026-64073 CVE-2026-64083 CVE-2026-64084 CVE-2026-64085 CVE-2026-64086 CVE-2026-64087 CVE-2026-64088 CVE-2026-64089 CVE-2026-64093 CVE-2026-64097 CVE-2026-64098 CVE-2026-64099 CVE-2026-64102 CVE-2026-64103 CVE-2026-64104 CVE-2026-64105 CVE-2026-64109 CVE-2026-64111 CVE-2026-64112 CVE-2026-64113 CVE-2026-64114 CVE-2026-64115 CVE-2026-64118 CVE-2026-64119 CVE-2026-64121 CVE-2026-64125 CVE-2026-64126 CVE-2026-64127 CVE-2026-64128 CVE-2026-64131 CVE-2026-64133 CVE-2026-64134 CVE-2026-64135 CVE-2026-64137 CVE-2026-64144 CVE-2026-64146 CVE-2026-64147 CVE-2026-64148 CVE-2026-64155 CVE-2026-64162 CVE-2026-64164 CVE-2026-64166 CVE-2026-64168 CVE-2026-64169 CVE-2026-64170 CVE-2026-64177 CVE-2026-64178 CVE-2026-64179 CVE-2026-64180 CVE-2026-64184 CVE-2026-64185 CVE-2026-64190 CVE-2026-64192 CVE-2026-64210 CVE-2026-64214 CVE-2026-64217 CVE-2026-64219 CVE-2026-64222 CVE-2026-64224 CVE-2026-64225 CVE-2026-64232 CVE-2026-64237 CVE-2026-64239 CVE-2026-64240 CVE-2026-64243 CVE-2026-64244 CVE-2026-64245 CVE-2026-64246 CVE-2026-64247 CVE-2026-64249 CVE-2026-64253 CVE-2026-64256 CVE-2026-64265 CVE-2026-64266 CVE-2026-64268 CVE-2026-64269 CVE-2026-64270 CVE-2026-64271 CVE-2026-64272 CVE-2026-64273 CVE-2026-64274 CVE-2026-64275 CVE-2026-64276 CVE-2026-64277 CVE-2026-64278 CVE-2026-64279 CVE-2026-64283 CVE-2026-64286 CVE-2026-64287 CVE-2026-64294 CVE-2026-64296 CVE-2026-64298 CVE-2026-64300 CVE-2026-64301 CVE-2026-64303 CVE-2026-64304 CVE-2026-64305 CVE-2026-64306 CVE-2026-64307 CVE-2026-64308 CVE-2026-64309 CVE-2026-64310 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64316 CVE-2026-64317 CVE-2026-64319 CVE-2026-64320 CVE-2026-64321 CVE-2026-64322 CVE-2026-64323 CVE-2026-64326 CVE-2026-64327 CVE-2026-64328 CVE-2026-64329 CVE-2026-64331 CVE-2026-64332 CVE-2026-64333 CVE-2026-64334 CVE-2026-64335 CVE-2026-64337 CVE-2026-64338 CVE-2026-64340 CVE-2026-64341 CVE-2026-64342 CVE-2026-64343 CVE-2026-64344 CVE-2026-64346 CVE-2026-64348 CVE-2026-64350 CVE-2026-64351 CVE-2026-64354 CVE-2026-64355 CVE-2026-64358 CVE-2026-64362 CVE-2026-64364 CVE-2026-64365 CVE-2026-64367 CVE-2026-64368 CVE-2026-64373 CVE-2026-64375 CVE-2026-64376 CVE-2026-64378 CVE-2026-64380 CVE-2026-64381 CVE-2026-64382 CVE-2026-64383 CVE-2026-64384 CVE-2026-64385 CVE-2026-64386 CVE-2026-64387 CVE-2026-64401 CVE-2026-64403 CVE-2026-64404 CVE-2026-64406 CVE-2026-64407 CVE-2026-64408 CVE-2026-64409 CVE-2026-64411 CVE-2026-64412 CVE-2026-64415 CVE-2026-64416 CVE-2026-64420 CVE-2026-64421 CVE-2026-64423 CVE-2026-64427 CVE-2026-64429 CVE-2026-64433 CVE-2026-64434 CVE-2026-64436 CVE-2026-64440 CVE-2026-64442 CVE-2026-64443 CVE-2026-64444 CVE-2026-64445 CVE-2026-64446 CVE-2026-64450 CVE-2026-64452 CVE-2026-64454 CVE-2026-64455 CVE-2026-64456 CVE-2026-64458 CVE-2026-64463 CVE-2026-64470 CVE-2026-64471 CVE-2026-64472 CVE-2026-64477 CVE-2026-64478 CVE-2026-64479 CVE-2026-64480 CVE-2026-64481 CVE-2026-64482 CVE-2026-64483 CVE-2026-64484 CVE-2026-64486 CVE-2026-64487 CVE-2026-64489 CVE-2026-64490 CVE-2026-64494 CVE-2026-64495 CVE-2026-64496 CVE-2026-64497 CVE-2026-64499 CVE-2026-64500 CVE-2026-64503 CVE-2026-64504 CVE-2026-64505 CVE-2026-64507 CVE-2026-64511 CVE-2026-64512 CVE-2026-64513 CVE-2026-64515 CVE-2026-64517 CVE-2026-64518 CVE-2026-64519 CVE-2026-64524 CVE-2026-64525 CVE-2026-64526 CVE-2026-64527 CVE-2026-64534 CVE-2026-64535 CVE-2026-64536 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539 CVE-2026-64540 CVE-2026-64541 CVE-2026-64542 CVE-2026-64543 CVE-2026-64544 CVE-2026-64545 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64551 CVE-2026-64552 CVE-2026-64553 CVE-2026-64554 CVE-2026-64555 CVE-2026-64556 CVE-2026-64558 CVE-2026-64559 CVE-2026-64561 CVE-2026-64562 CVE-2026-64563 CVE-2026-64565 CVE-2026-64567 CVE-2026-64568 CVE-2026-64569 CVE-2026-64570 CVE-2026-64571 CVE-2026-64572 CVE-2026-64573 CVE-2026-64574 CVE-2026-64576 CVE-2026-64577 CVE-2026-64579 CVE-2026-64581 CVE-2026-64582 CVE-2026-64583 CVE-2026-64584 CVE-2026-64585 CVE-2026-64586 CVE-2026-64589 CVE-2026-64593 CVE-2026-64599 CVE-2026-64602 CVE-2026-64603 CVE-2026-64604 CVE-2026-68081 CVE-2026-68082 CVE-2026-68085 CVE-2026-68086 CVE-2026-68088 CVE-2026-68091 CVE-2026-68093 CVE-2026-68096 CVE-2026-68102 CVE-2026-68104 CVE-2026-68105 CVE-2026-68106 CVE-2026-68107 CVE-2026-68108 CVE-2026-68110 CVE-2026-68111 CVE-2026-68112 CVE-2026-68113 CVE-2026-68115 CVE-2026-68116 CVE-2026-68117 CVE-2026-68120 CVE-2026-68121 CVE-2026-68123 CVE-2026-68124 CVE-2026-68125 CVE-2026-68126 CVE-2026-68127 CVE-2026-68128 CVE-2026-68129 CVE-2026-68132 CVE-2026-68133 CVE-2026-68135 CVE-2026-68136 CVE-2026-68137 CVE-2026-68138 CVE-2026-68139 CVE-2026-68141 CVE-2026-68142 CVE-2026-68143 CVE-2026-68144 CVE-2026-68145 CVE-2026-68148 CVE-2026-68149 CVE-2026-68152 CVE-2026-68153 CVE-2026-68154 CVE-2026-68155 CVE-2026-68156 CVE-2026-68157 CVE-2026-68158 CVE-2026-68159 CVE-2026-68161 CVE-2026-68164 CVE-2026-68165 CVE-2026-68166 CVE-2026-68169 CVE-2026-68178 CVE-2026-68179 CVE-2026-68180 CVE-2026-68181 CVE-2026-68182 CVE-2026-68183 CVE-2026-68184 CVE-2026-68188 CVE-2026-68189 CVE-2026-68192 CVE-2026-68193 CVE-2026-68194 CVE-2026-68195 CVE-2026-68196 CVE-2026-68197 CVE-2026-68198 CVE-2026-68199 CVE-2026-68200 CVE-2026-68201 CVE-2026-68202 CVE-2026-68203 CVE-2026-68204 CVE-2026-68205 CVE-2026-68206 CVE-2026-68207 CVE-2026-68209 CVE-2026-68210 CVE-2026-68212 CVE-2026-68213 CVE-2026-68214 CVE-2026-68215 CVE-2026-68216 CVE-2026-68217 CVE-2026-68218 CVE-2026-68219 CVE-2026-68220 CVE-2026-68221 CVE-2026-68222 CVE-2026-68223 CVE-2026-68225 CVE-2026-68226 CVE-2026-68227 CVE-2026-68228 CVE-2026-68229 CVE-2026-68231 CVE-2026-68234 CVE-2026-68235 CVE-2026-68236 CVE-2026-68238 CVE-2026-68243 CVE-2026-68244 CVE-2026-68245 CVE-2026-68246 CVE-2026-68247 CVE-2026-68248 CVE-2026-68249 CVE-2026-68250 CVE-2026-68251 CVE-2026-68252 CVE-2026-68253 CVE-2026-68254 CVE-2026-68255 CVE-2026-68256 CVE-2026-68257 CVE-2026-68258 CVE-2026-68259 CVE-2026-68260 CVE-2026-68261 CVE-2026-68262 CVE-2026-68263 CVE-2026-68267 CVE-2026-68269 CVE-2026-68271 CVE-2026-68272 CVE-2026-68273 CVE-2026-68277 CVE-2026-68278 CVE-2026-68279 CVE-2026-68280 CVE-2026-68281 CVE-2026-68284 CVE-2026-68286 CVE-2026-68288 CVE-2026-68289 CVE-2026-68293 CVE-2026-68294 CVE-2026-68296 CVE-2026-68297 CVE-2026-68299 CVE-2026-68300 CVE-2026-68302 CVE-2026-68303 CVE-2026-68304 CVE-2026-68306 CVE-2026-68307 CVE-2026-68308 CVE-2026-68309 CVE-2026-68310 CVE-2026-68311 CVE-2026-68313 CVE-2026-68315 CVE-2026-68319 CVE-2026-68320 CVE-2026-68321 CVE-2026-68322 CVE-2026-68325 CVE-2026-68326 CVE-2026-68327 CVE-2026-68328 CVE-2026-68329 CVE-2026-68331 CVE-2026-68333 CVE-2026-68335 CVE-2026-68336 CVE-2026-68338 CVE-2026-68339 CVE-2026-68340 CVE-2026-68344 CVE-2026-68346 CVE-2026-68348 CVE-2026-68349 CVE-2026-68350 CVE-2026-68351 CVE-2026-68352 CVE-2026-68353 CVE-2026-68354 CVE-2026-68355 CVE-2026-68357 CVE-2026-68358 CVE-2026-68359 CVE-2026-68360 CVE-2026-68361 CVE-2026-68362 CVE-2026-68363 CVE-2026-68365 CVE-2026-68366 CVE-2026-68368 CVE-2026-68369 CVE-2026-68370 CVE-2026-68371 CVE-2026-68372 CVE-2026-68373 CVE-2026-68374 CVE-2026-68375 CVE-2026-68377 CVE-2026-68386 CVE-2026-68389 CVE-2026-68391 CVE-2026-68392 CVE-2026-68393 CVE-2026-68394 CVE-2026-68395 CVE-2026-68397 CVE-2026-68398 CVE-2026-68399 CVE-2026-68402 CVE-2026-68403 CVE-2026-68405 CVE-2026-68406 CVE-2026-68407 CVE-2026-68408 CVE-2026-68410 CVE-2026-68413 CVE-2026-68414 CVE-2026-68416 CVE-2026-68417 CVE-2026-68418 CVE-2026-68419 CVE-2026-68422 CVE-2026-68425 CVE-2026-68426 CVE-2026-68427 CVE-2026-68428 CVE-2026-68429 CVE-2026-68430 CVE-2026-68432 CVE-2026-68433 CVE-2026-68434 CVE-2026-68437 CVE-2026-68439 CVE-2026-68442 CVE-2026-68443 CVE-2026-68444 CVE-2026-68445 CVE-2026-68446 CVE-2026-68448 CVE-2026-68450 CVE-2026-68470 CVE-2026-68480 CVE-2026-72017 CVE-2026-72019 CVE-2026-72020 CVE-2026-72022 CVE-2026-72023 CVE-2026-72032 CVE-2026-72034 CVE-2026-72035 CVE-2026-72036 CVE-2026-72045 CVE-2026-72046 CVE-2026-72051 CVE-2026-72052 CVE-2026-72053 CVE-2026-72054 CVE-2026-72055 CVE-2026-72061 CVE-2026-72069 CVE-2026-72072 CVE-2026-72083 CVE-2026-72084 CVE-2026-72100 CVE-2026-72101 CVE-2026-72103 CVE-2026-72106 CVE-2026-72107 CVE-2026-72108 CVE-2026-72132 CVE-2026-72136 CVE-2026-72137 CVE-2026-72161 CVE-2026-72163 CVE-2026-72164 CVE-2026-72176 CVE-2026-72177 CVE-2026-72217 CVE-2026-72221 CVE-2026-72222 CVE-2026-72234 CVE-2026-72242 CVE-2026-72243 CVE-2026-72251 CVE-2026-72254 CVE-2026-72280 CVE-2026-72282 CVE-2026-72288 CVE-2026-72289 CVE-2026-72296 CVE-2026-72297 CVE-2026-72306 CVE-2026-72307 CVE-2026-72308 CVE-2026-72317 CVE-2026-72323 CVE-2026-72325 CVE-2026-72330 CVE-2026-72337 CVE-2026-72339 CVE-2026-72341 CVE-2026-72342 CVE-2026-72343 CVE-2026-72345 CVE-2026-72347 CVE-2026-72350 CVE-2026-72366 CVE-2026-72379 CVE-2026-72389 CVE-2026-72398 CVE-2026-72399 CVE-2026-72414 CVE-2026-72421 CVE-2026-72425 CVE-2026-72430 CVE-2026-72437 CVE-2026-72438 CVE-2026-72439 CVE-2026-72440 CVE-2026-72448 CVE-2026-72450 CVE-2026-72459 CVE-2026-72460 CVE-2026-72464 CVE-2026-72466 CVE-2026-72467 CVE-2026-72468 CVE-2026-72469 CVE-2026-72473 CVE-2026-72485 CVE-2026-72487 CVE-2026-72488 CVE-2026-72494 CVE-2026-72495 CVE-2026-72497 CVE-2026-72499 CVE-2026-72500 CVE-2026-72501 CVE-2026-72502 CVE-2026-74255 CVE-2026-74261 CVE-2026-74269 CVE-2026-74270 CVE-2026-74282 CVE-2026-74284 CVE-2026-74286 CVE-2026-74296 CVE-2026-74297 CVE-2026-74307 CVE-2026-74308 CVE-2026-74313 CVE-2026-74316 CVE-2026-74317 CVE-2026-74318 CVE-2026-74321 CVE-2026-74334 CVE-2026-74345 CVE-2026-74346 CVE-2026-74349 CVE-2026-74363 CVE-2026-74375 CVE-2026-74377 CVE-2026-74378 CVE-2026-74382 CVE-2026-74388 CVE-2026-74390 CVE-2026-74394 CVE-2026-74395 CVE-2026-74397 CVE-2026-74406 CVE-2026-74464 CVE-2026-74474 CVE-2026-74475 CVE-2026-74476 CVE-2026-74479 CVE-2026-74481 CVE-2026-74482 CVE-2026-74495 CVE-2026-74496 CVE-2026-74510 CVE-2026-74512 CVE-2026-74513 CVE-2026-74517 CVE-2026-74518 CVE-2026-74523 CVE-2026-74527 CVE-2026-74533 CVE-2026-74534 CVE-2026-74535 CVE-2026-74536 CVE-2026-74537 CVE-2026-74545 CVE-2026-74548 CVE-2026-74550 CVE-2026-74555 CVE-2026-74556 CVE-2026-74557 CVE-2026-74563 CVE-2026-74566 CVE-2026-74567 CVE-2026-74571 CVE-2026-74577 CVE-2026-74581 CVE-2026-74582 CVE-2026-74584 CVE-2026-74598 CVE-2026-74610 CVE-2026-74612 CVE-2026-74615 CVE-2026-74616 CVE-2026-74622 CVE-2026-74644 CVE-2026-74665 CVE-2026-74669 CVE-2026-74695 CVE-2026-74705 CVE-2026-74712 CVE-2026-74717 CVE-2026-74719 CVE-2026-74722 CVE-2026-74723 CVE-2026-74730 CVE-2026-74737 CVE-2026-74743 CVE-2026-74744 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 CVE-2026-80529 CVE-2026-80530 CVE-2026-80531 CVE-2026-80533 CVE-2026-80534 CVE-2026-80535 CVE-2026-80557 CVE-2026-80558 CVE-2026-80561 CVE-2026-80586 CVE-2026-80589 CVE-2026-80590 CVE-2026-80603 CVE-2026-80609 CVE-2026-80629 CVE-2026-80646 CVE-2026-80647 CVE-2026-80667 CVE-2026-80681 CVE-2026-80693 CVE-2026-80714 CVE-2026-80721 CVE-2026-80727 CVE-2026-80731 CVE-2026-80737 CVE-2026-80739 CVE-2026-80805 CVE-2026-80813 CVE-2026-80838 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). ----------------------------------------------------------------- Advisory ID: 1738 Released: Tue Sep 22 16:23:31 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1236344,1240890,1240957,1249104,1255225,1255531,1256629,1256671,1258278,1260501,1260577,1262073,1262756,1263004,1263864,1263865,1264267,1264335,1264444,1264541,1264587,1264619,1264807,1264851,1265036,1265068,1265121,1265132,1265141,1265220,1266710,1266860,1266874,1266897,1266928,1267023,1267238,1267373,1267501,1267586,1267612,1267882,1267985,1268972,1268979,1269000,1269004,1269010,1269013,1269108,1269113,1269114,1269126,1269134,1269140,1269162,1269167,1269238,1269242,1269256,1269301,1269306,1269380,1269381,1269388,1269402,1269412,1269417,1269528,1269530,1269579,1269590,1269633,1269635,1269655,1269665,1269685,1269686,1269695,1269697,1269774,1269783,1269792,1269815,1269816,1269888,1269965,1269969,1269985,1269999,1270090,1270108,1270111,1270139,1270251,1270266,1270267,1271050,1271256,1271365,1271825,1272148,1272149,1272175,1272182,1272199,1272200,1272210,1272213,1272230,1272260,1272261,1272262,1272284,1272287,1272297,1272346,1272366,1272385,1272390,1272423,1272426,1272429,1 272484,1272486,1272497,1272501,1272502,1272513,1272516,1272568,1272569,1272584,1272641,1272643,1272673,1272756,1272786,1272788,1272791,1272798,1272799,1272804,1272855,1272865,1272868,1272869,1272877,1272891,1272893,1272894,1272904,1272905,1272918,1272963,1272969,1272971,1272983,1272985,1273008,1273019,1273027,1273030,1273032,1273033,1273036,1273037,1273038,1273060,1273105,1273107,1273119,1273134,1273231,1273249,1273251,1273260,1273271,1273273,1273274,1273276,1273277,1273280,1273281,1273283,1273284,1273285,1273286,1273288,1273289,1273291,1273294,1273302,1273303,1273305,1273309,1273310,1273311,1273312,1273314,1273316,1273317,1273318,1273319,1273323,1273325,1273327,1273331,1273334,1273335,1273336,1273337,1273338,1273339,1273340,1273341,1273346,1273420,1273422,1273426,1273443,1273460,1273461,1273463,1273465,1273468,1273469,1273471,1273479,1273480,1273482,1273484,1273486,1273488,1273490,1273495,1273501,1273503,1273504,1273506,1273507,1273509,1273511,1273520,1273523,1273524,1273525,127353 3,1273536,1273538,1273542,1273550,1273555,1273557,1273567,1273578,1273579,1273581,1273582,1273596,1273597,1273598,1273600,1273601,1273602,1273603,1273679,1273681,1273682,1273734,1273737,1273738,1273739,1273740,1273741,1273742,1273743,1273744,1273745,1273746,1273748,1273749,1273755,1273759,1273762,1273765,1273766,1273769,1273770,1273774,1273776,1273778,1273780,1273782,1273788,1273790,1273796,1273797,1273801,1273803,1273804,1273809,1273810,1273811,1273812,1273813,1273817,1273822,1273824,1273831,1273834,1273838,1273839,1273842,1273844,1273848,1273849,1273852,1273855,1273859,1273860,1273862,1273864,1273866,1273867,1273868,1273869,1273870,1273872,1273876,1273877,1273880,1273882,1273890,1273891,1273892,1273895,1273896,1273898,1273899,1273903,1273904,1273905,1273930,1273933,1273934,1273935,1273936,1273939,1273940,1273941,1273942,1273944,1273945,1273946,1273947,1273949,1273953,1273954,1273956,1273957,1273958,1273959,1273963,1273966,1273967,1273968,1273972,1273974,1273975,1273977,1273988,127 3990,1273991,1273995,1273997,1273999,1274001,1274003,1274006,1274008,1274009,1274010,1274011,1274012,1274014,1274017,1274019,1274020,1274026,1274028,1274030,1274031,1274035,1274036,1274040,1274041,1274052,1274055,1274057,1274058,1274060,1274063,1274065,1274067,1274071,1274075,1274076,1274077,1274078,1274208,1274226,1274239,1274243,1274252,1274253,1274258,1274264,1274265,1274267,1274274,1274277,1274278,1274281,1274283,1274286,1274290,1274292,1274294,1274295,1274296,1274314,1274321,1274491,1274492,1274494,1274497,1274539,1274541,1274543,1274545,1274547,1274550,1274556,1274573,1274578,1274580,1274581,1274622,1274624,1274628,1274632,1274636,1274637,1274639,1274640,1274642,1274644,1274645,1274646,1274650,1274651,1274652,1274656,1274657,1274659,1274662,1274665,1274667,1274669,1274670,1274671,1274675,1274677,1274678,1274679,1274681,1274682,1274690,1274694,1274696,1274698,1274699,1274700,1274702,1274703,1274705,1274706,1274707,1274709,1274710,1274713,1274716,1274721,1274725,1274727,1274730, 1274737,1274738,1274749,1274750,1274751,1274752,1274753,1274754,1274755,1274756,1274764,1274768,1274770,1274771,1274773,1274782,1274783,1274787,1274800,1274801,1274802,1274803,1274804,1274805,1274807,1274808,1274811,1274813,1274814,1274831,1274834,1274835,1274838,1274847,1274849,1274853,1274868,1274869,1274872,1274873,1274874,1274876,1274877,1274879,1274881,1274883,1274886,1274887,1274888,1274891,1274892,1274893,1274894,1274895,1274896,1274897,1274898,1274899,1274900,1274901,1274902,1274904,1274905,1274906,1274907,1274908,1274913,1274914,1274921,1274924,1274925,1274927,1274929,1274930,1274933,1274934,1274935,1274938,1274939,1274940,1274941,1274945,1274947,1274951,1274952,1274953,1274955,1274957,1274958,1274965,1274968,1274978,1274981,1275040,1275045,1275069,1275071,1275072,1275073,1275076,1275080,1275081,1275083,1275088,1275091,1275092,1275094,1275125,1275126,1275129,1275131,1275132,1275139,1275141,1275146,1275148,1275149,1275150,1275152,1275154,1275155,1275156,1275157,1275158,12751 60,1275161,1275163,1275164,1275169,1275173,1275176,1275185,1275190,1275192,1275229,1275236,1275237,1275238,1275239,1275294,1275300,1275301,1275303,1275304,1275305,1275306,1275307,1275470,1275474,1275479,1275481,1275483,1275486,1275487,1275496,1275506,1275509,1275511,1275514,1275517,1275519,1275528,1275535,1275540,1275553,1275555,1275557,1275561,1275566,1275569,1275572,1275574,1275578,1275582,1275583,1275584,1275587,1275588,1275591,1275595,1275596,1275633,1275636,1275650,1275655,1275656,1275659,1275665,1275669,1275672,1275679,1275685,1275687,1275688,1275690,1275695,1275696,1275704,1275737,1275782,1275784,1275787,1275788,1275789,1275790,1275798,1275799,1275801,1275802,1275804,1275805,1275812,1275817,1275818,1275819,1275820,1275821,1275822,1275823,1275827,1275864,1275866,1275867,1275869,1275870,1275871,1275872,1275886,1275905,1275923,1275925,1275928,1275950,1275954,1275956,1275970,1275973,1275975,1275976,1275985,1276006,1276029,1276257,1276258,1276263,1276265,1276267,1276270,1276273,12 76277,1276333,1276335,1276339,1276341,1276346,1276354,1276355,1276381,1276395,1276446,1276452,1276468,1276471,1276473,1276500,1276507,1276512,1276528,1276542,1276546,1276547,1276551,1276552,1276553,1276561,1276562,1276566,1276569,1276572,1276577,1276586,1276665,1276766,1276767,1276771,1276785,1276793,1276801,1276803,1276814,1276818,1276821,1276831,1276840,1276864,1276865,1276866,1276870,1276876,1276880,1276905,1276913,1276922,1276931,1276937,1276941,1276955,1276957,1276961,1277022,1277023,1277033,1277034,1277037,1277047,1277054,1277057,1277059,1277062,1277066,1277069,1277070,1277077,1277078,1277092,1277095,1277108,1277114,1277115,1277118,1277120,1277155,1277159,1277160,1277202,1277204,1277227,1277229,1277230,1277231,1277233,1277249,1277254,1277265,1277268,1277275,1277285,1277308,1277311,1277315,1277321,1277328,1277335,1277349,1277350,1277391,1277407,1277408,1277485,1277505,1277513,1277551,1277553,1277561,1277574,1277636,1277641,1277649,1277655,1277656,1277660,1277668,1277680,1277688 ,1277726,1277728,1277738,1277748,1277761,1277764,1277773,1277775,1277776,1277782,1277783,1277813,1277818,1277822,1277845,1277862,1277874,1277876,1277898,1277901,1277908,1277918,1278039,1278070,1278088,1278094,1278098,1278113,1278155,1278180,1278233,1278236,1278240,1278253,1278293,1278324,1278331,1278334,1278395,1278416,1278703,1278716,1278733,1279487,1279537,1279580,1279813,1279842,1279847,1279887,1280139,CVE-2025-68214,CVE-2025-68358,CVE-2025-68780,CVE-2025-71075,CVE-2026-23113,CVE-2026-23306,CVE-2026-23348,CVE-2026-31418,CVE-2026-31530,CVE-2026-31531,CVE-2026-43116,CVE-2026-43125,CVE-2026-43163,CVE-2026-43239,CVE-2026-43271,CVE-2026-43299,CVE-2026-43331,CVE-2026-43355,CVE-2026-43363,CVE-2026-43416,CVE-2026-43439,CVE-2026-43448,CVE-2026-45860,CVE-2026-45897,CVE-2026-45968,CVE-2026-46007,CVE-2026-46070,CVE-2026-46091,CVE-2026-46107,CVE-2026-46115,CVE-2026-46133,CVE-2026-46135,CVE-2026-46195,CVE-2026-46304,CVE-2026-52912,CVE-2026-52920,CVE-2026-52928,CVE-2026-52929,CVE-2026-52935,CVE -2026-52939,CVE-2026-52946,CVE-2026-52977,CVE-2026-52990,CVE-2026-52991,CVE-2026-52994,CVE-2026-53001,CVE-2026-53031,CVE-2026-53033,CVE-2026-53034,CVE-2026-53048,CVE-2026-53059,CVE-2026-53061,CVE-2026-53076,CVE-2026-53077,CVE-2026-53089,CVE-2026-53091,CVE-2026-53092,CVE-2026-53094,CVE-2026-53096,CVE-2026-53109,CVE-2026-53110,CVE-2026-53111,CVE-2026-53114,CVE-2026-53126,CVE-2026-53129,CVE-2026-53142,CVE-2026-53154,CVE-2026-53163,CVE-2026-53180,CVE-2026-53207,CVE-2026-53219,CVE-2026-53220,CVE-2026-53223,CVE-2026-53228,CVE-2026-53238,CVE-2026-53264,CVE-2026-53269,CVE-2026-53284,CVE-2026-53291,CVE-2026-53309,CVE-2026-53330,CVE-2026-53336,CVE-2026-53337,CVE-2026-53341,CVE-2026-53353,CVE-2026-53365,CVE-2026-53388,CVE-2026-63801,CVE-2026-63803,CVE-2026-63804,CVE-2026-63808,CVE-2026-63810,CVE-2026-63823,CVE-2026-63828,CVE-2026-63860,CVE-2026-63865,CVE-2026-63868,CVE-2026-63879,CVE-2026-63887,CVE-2026-63888,CVE-2026-63889,CVE-2026-63890,CVE-2026-63891,CVE-2026-63898,CVE-2026-63901,CVE-2026-6 3906,CVE-2026-63917,CVE-2026-63918,CVE-2026-63920,CVE-2026-63921,CVE-2026-63922,CVE-2026-63924,CVE-2026-63925,CVE-2026-63926,CVE-2026-63928,CVE-2026-63941,CVE-2026-63969,CVE-2026-63970,CVE-2026-63984,CVE-2026-63985,CVE-2026-63986,CVE-2026-63987,CVE-2026-63990,CVE-2026-63992,CVE-2026-63993,CVE-2026-63995,CVE-2026-63996,CVE-2026-63997,CVE-2026-63998,CVE-2026-63999,CVE-2026-64000,CVE-2026-64001,CVE-2026-64002,CVE-2026-64003,CVE-2026-64004,CVE-2026-64005,CVE-2026-64006,CVE-2026-64007,CVE-2026-64010,CVE-2026-64011,CVE-2026-64014,CVE-2026-64015,CVE-2026-64017,CVE-2026-64024,CVE-2026-64029,CVE-2026-64033,CVE-2026-64039,CVE-2026-64047,CVE-2026-64048,CVE-2026-64051,CVE-2026-64052,CVE-2026-64053,CVE-2026-64054,CVE-2026-64055,CVE-2026-64056,CVE-2026-64071,CVE-2026-64073,CVE-2026-64083,CVE-2026-64084,CVE-2026-64085,CVE-2026-64086,CVE-2026-64087,CVE-2026-64088,CVE-2026-64089,CVE-2026-64093,CVE-2026-64097,CVE-2026-64098,CVE-2026-64099,CVE-2026-64102,CVE-2026-64103,CVE-2026-64104,CVE-2026-64105,CV E-2026-64109,CVE-2026-64111,CVE-2026-64112,CVE-2026-64113,CVE-2026-64114,CVE-2026-64115,CVE-2026-64118,CVE-2026-64119,CVE-2026-64121,CVE-2026-64125,CVE-2026-64126,CVE-2026-64127,CVE-2026-64128,CVE-2026-64131,CVE-2026-64133,CVE-2026-64134,CVE-2026-64135,CVE-2026-64137,CVE-2026-64144,CVE-2026-64146,CVE-2026-64147,CVE-2026-64148,CVE-2026-64155,CVE-2026-64162,CVE-2026-64164,CVE-2026-64166,CVE-2026-64168,CVE-2026-64169,CVE-2026-64170,CVE-2026-64177,CVE-2026-64178,CVE-2026-64179,CVE-2026-64180,CVE-2026-64184,CVE-2026-64185,CVE-2026-64190,CVE-2026-64192,CVE-2026-64210,CVE-2026-64214,CVE-2026-64217,CVE-2026-64219,CVE-2026-64222,CVE-2026-64224,CVE-2026-64225,CVE-2026-64232,CVE-2026-64237,CVE-2026-64239,CVE-2026-64240,CVE-2026-64243,CVE-2026-64244,CVE-2026-64245,CVE-2026-64246,CVE-2026-64247,CVE-2026-64249,CVE-2026-64253,CVE-2026-64256,CVE-2026-64265,CVE-2026-64266,CVE-2026-64268,CVE-2026-64269,CVE-2026-64270,CVE-2026-64271,CVE-2026-64272,CVE-2026-64273,CVE-2026-64274,CVE-2026-64275,CVE-2026- 64276,CVE-2026-64277,CVE-2026-64278,CVE-2026-64279,CVE-2026-64283,CVE-2026-64286,CVE-2026-64287,CVE-2026-64294,CVE-2026-64296,CVE-2026-64298,CVE-2026-64300,CVE-2026-64301,CVE-2026-64303,CVE-2026-64304,CVE-2026-64305,CVE-2026-64306,CVE-2026-64307,CVE-2026-64308,CVE-2026-64309,CVE-2026-64310,CVE-2026-64312,CVE-2026-64313,CVE-2026-64315,CVE-2026-64316,CVE-2026-64317,CVE-2026-64319,CVE-2026-64320,CVE-2026-64321,CVE-2026-64322,CVE-2026-64323,CVE-2026-64326,CVE-2026-64327,CVE-2026-64328,CVE-2026-64329,CVE-2026-64331,CVE-2026-64332,CVE-2026-64333,CVE-2026-64334,CVE-2026-64335,CVE-2026-64337,CVE-2026-64338,CVE-2026-64340,CVE-2026-64341,CVE-2026-64342,CVE-2026-64343,CVE-2026-64344,CVE-2026-64346,CVE-2026-64348,CVE-2026-64350,CVE-2026-64351,CVE-2026-64354,CVE-2026-64355,CVE-2026-64358,CVE-2026-64362,CVE-2026-64364,CVE-2026-64365,CVE-2026-64367,CVE-2026-64368,CVE-2026-64373,CVE-2026-64375,CVE-2026-64376,CVE-2026-64378,CVE-2026-64380,CVE-2026-64381,CVE-2026-64382,CVE-2026-64383,CVE-2026-64384,C VE-2026-64385,CVE-2026-64386,CVE-2026-64387,CVE-2026-64401,CVE-2026-64403,CVE-2026-64404,CVE-2026-64406,CVE-2026-64407,CVE-2026-64408,CVE-2026-64409,CVE-2026-64411,CVE-2026-64412,CVE-2026-64415,CVE-2026-64416,CVE-2026-64420,CVE-2026-64421,CVE-2026-64423,CVE-2026-64427,CVE-2026-64429,CVE-2026-64433,CVE-2026-64434,CVE-2026-64436,CVE-2026-64440,CVE-2026-64442,CVE-2026-64443,CVE-2026-64444,CVE-2026-64445,CVE-2026-64446,CVE-2026-64450,CVE-2026-64452,CVE-2026-64454,CVE-2026-64455,CVE-2026-64456,CVE-2026-64458,CVE-2026-64463,CVE-2026-64470,CVE-2026-64471,CVE-2026-64472,CVE-2026-64477,CVE-2026-64478,CVE-2026-64479,CVE-2026-64480,CVE-2026-64481,CVE-2026-64482,CVE-2026-64483,CVE-2026-64484,CVE-2026-64486,CVE-2026-64487,CVE-2026-64489,CVE-2026-64490,CVE-2026-64494,CVE-2026-64495,CVE-2026-64496,CVE-2026-64497,CVE-2026-64499,CVE-2026-64500,CVE-2026-64503,CVE-2026-64504,CVE-2026-64505,CVE-2026-64507,CVE-2026-64511,CVE-2026-64512,CVE-2026-64513,CVE-2026-64515,CVE-2026-64517,CVE-2026-64518,CVE-2026 -64519,CVE-2026-64524,CVE-2026-64525,CVE-2026-64526,CVE-2026-64527,CVE-2026-64534,CVE-2026-64535,CVE-2026-64536,CVE-2026-64537,CVE-2026-64538,CVE-2026-64539,CVE-2026-64540,CVE-2026-64541,CVE-2026-64542,CVE-2026-64543,CVE-2026-64544,CVE-2026-64545,CVE-2026-64546,CVE-2026-64547,CVE-2026-64548,CVE-2026-64549,CVE-2026-64551,CVE-2026-64552,CVE-2026-64553,CVE-2026-64554,CVE-2026-64555,CVE-2026-64556,CVE-2026-64558,CVE-2026-64559,CVE-2026-64561,CVE-2026-64562,CVE-2026-64563,CVE-2026-64565,CVE-2026-64567,CVE-2026-64568,CVE-2026-64569,CVE-2026-64570,CVE-2026-64571,CVE-2026-64572,CVE-2026-64573,CVE-2026-64574,CVE-2026-64576,CVE-2026-64577,CVE-2026-64579,CVE-2026-64581,CVE-2026-64582,CVE-2026-64583,CVE-2026-64584,CVE-2026-64585,CVE-2026-64586,CVE-2026-64589,CVE-2026-64593,CVE-2026-64599,CVE-2026-64602,CVE-2026-64603,CVE-2026-64604,CVE-2026-68081,CVE-2026-68082,CVE-2026-68085,CVE-2026-68086,CVE-2026-68088,CVE-2026-68091,CVE-2026-68093,CVE-2026-68096,CVE-2026-68102,CVE-2026-68104,CVE-2026-68105, CVE-2026-68106,CVE-2026-68107,CVE-2026-68108,CVE-2026-68110,CVE-2026-68111,CVE-2026-68112,CVE-2026-68113,CVE-2026-68115,CVE-2026-68116,CVE-2026-68117,CVE-2026-68120,CVE-2026-68121,CVE-2026-68123,CVE-2026-68124,CVE-2026-68125,CVE-2026-68126,CVE-2026-68127,CVE-2026-68128,CVE-2026-68129,CVE-2026-68132,CVE-2026-68133,CVE-2026-68135,CVE-2026-68136,CVE-2026-68137,CVE-2026-68138,CVE-2026-68139,CVE-2026-68141,CVE-2026-68142,CVE-2026-68143,CVE-2026-68144,CVE-2026-68145,CVE-2026-68148,CVE-2026-68149,CVE-2026-68152,CVE-2026-68153,CVE-2026-68154,CVE-2026-68155,CVE-2026-68156,CVE-2026-68157,CVE-2026-68158,CVE-2026-68159,CVE-2026-68161,CVE-2026-68164,CVE-2026-68165,CVE-2026-68166,CVE-2026-68169,CVE-2026-68178,CVE-2026-68179,CVE-2026-68180,CVE-2026-68181,CVE-2026-68182,CVE-2026-68183,CVE-2026-68184,CVE-2026-68188,CVE-2026-68189,CVE-2026-68192,CVE-2026-68193,CVE-2026-68194,CVE-2026-68195,CVE-2026-68196,CVE-2026-68197,CVE-2026-68198,CVE-2026-68199,CVE-2026-68200,CVE-2026-68201,CVE-2026-68202,CVE-202 6-68203,CVE-2026-68204,CVE-2026-68205,CVE-2026-68206,CVE-2026-68207,CVE-2026-68209,CVE-2026-68210,CVE-2026-68212,CVE-2026-68213,CVE-2026-68214,CVE-2026-68215,CVE-2026-68216,CVE-2026-68217,CVE-2026-68218,CVE-2026-68219,CVE-2026-68220,CVE-2026-68221,CVE-2026-68222,CVE-2026-68223,CVE-2026-68225,CVE-2026-68226,CVE-2026-68227,CVE-2026-68228,CVE-2026-68229,CVE-2026-68231,CVE-2026-68234,CVE-2026-68235,CVE-2026-68236,CVE-2026-68238,CVE-2026-68243,CVE-2026-68244,CVE-2026-68245,CVE-2026-68246,CVE-2026-68247,CVE-2026-68248,CVE-2026-68249,CVE-2026-68250,CVE-2026-68251,CVE-2026-68252,CVE-2026-68253,CVE-2026-68254,CVE-2026-68255,CVE-2026-68256,CVE-2026-68257,CVE-2026-68258,CVE-2026-68259,CVE-2026-68260,CVE-2026-68261,CVE-2026-68262,CVE-2026-68263,CVE-2026-68267,CVE-2026-68269,CVE-2026-68271,CVE-2026-68272,CVE-2026-68273,CVE-2026-68277,CVE-2026-68278,CVE-2026-68279,CVE-2026-68280,CVE-2026-68281,CVE-2026-68284,CVE-2026-68286,CVE-2026-68288,CVE-2026-68289,CVE-2026-68293,CVE-2026-68294,CVE-2026-68296 ,CVE-2026-68297,CVE-2026-68299,CVE-2026-68300,CVE-2026-68302,CVE-2026-68303,CVE-2026-68304,CVE-2026-68306,CVE-2026-68307,CVE-2026-68308,CVE-2026-68309,CVE-2026-68310,CVE-2026-68311,CVE-2026-68313,CVE-2026-68315,CVE-2026-68319,CVE-2026-68320,CVE-2026-68321,CVE-2026-68322,CVE-2026-68325,CVE-2026-68326,CVE-2026-68327,CVE-2026-68328,CVE-2026-68329,CVE-2026-68331,CVE-2026-68333,CVE-2026-68335,CVE-2026-68336,CVE-2026-68338,CVE-2026-68339,CVE-2026-68340,CVE-2026-68344,CVE-2026-68346,CVE-2026-68348,CVE-2026-68349,CVE-2026-68350,CVE-2026-68351,CVE-2026-68352,CVE-2026-68353,CVE-2026-68354,CVE-2026-68355,CVE-2026-68357,CVE-2026-68358,CVE-2026-68359,CVE-2026-68360,CVE-2026-68361,CVE-2026-68362,CVE-2026-68363,CVE-2026-68365,CVE-2026-68366,CVE-2026-68368,CVE-2026-68369,CVE-2026-68370,CVE-2026-68371,CVE-2026-68372,CVE-2026-68373,CVE-2026-68374,CVE-2026-68375,CVE-2026-68377,CVE-2026-68386,CVE-2026-68389,CVE-2026-68391,CVE-2026-68392,CVE-2026-68393,CVE-2026-68394,CVE-2026-68395,CVE-2026-68397,CVE-20 26-68398,CVE-2026-68399,CVE-2026-68402,CVE-2026-68403,CVE-2026-68405,CVE-2026-68406,CVE-2026-68407,CVE-2026-68408,CVE-2026-68410,CVE-2026-68413,CVE-2026-68414,CVE-2026-68416,CVE-2026-68417,CVE-2026-68418,CVE-2026-68419,CVE-2026-68422,CVE-2026-68425,CVE-2026-68426,CVE-2026-68427,CVE-2026-68428,CVE-2026-68429,CVE-2026-68430,CVE-2026-68432,CVE-2026-68433,CVE-2026-68434,CVE-2026-68437,CVE-2026-68439,CVE-2026-68442,CVE-2026-68443,CVE-2026-68444,CVE-2026-68445,CVE-2026-68446,CVE-2026-68448,CVE-2026-68450,CVE-2026-68470,CVE-2026-68480,CVE-2026-72017,CVE-2026-72019,CVE-2026-72020,CVE-2026-72022,CVE-2026-72023,CVE-2026-72032,CVE-2026-72034,CVE-2026-72035,CVE-2026-72036,CVE-2026-72045,CVE-2026-72046,CVE-2026-72051,CVE-2026-72052,CVE-2026-72053,CVE-2026-72054,CVE-2026-72055,CVE-2026-72061,CVE-2026-72069,CVE-2026-72072,CVE-2026-72083,CVE-2026-72084,CVE-2026-72100,CVE-2026-72101,CVE-2026-72103,CVE-2026-72106,CVE-2026-72107,CVE-2026-72108,CVE-2026-72132,CVE-2026-72136,CVE-2026-72137,CVE-2026-7216 1,CVE-2026-72163,CVE-2026-72164,CVE-2026-72176,CVE-2026-72177,CVE-2026-72217,CVE-2026-72221,CVE-2026-72222,CVE-2026-72234,CVE-2026-72242,CVE-2026-72243,CVE-2026-72251,CVE-2026-72254,CVE-2026-72280,CVE-2026-72282,CVE-2026-72288,CVE-2026-72289,CVE-2026-72296,CVE-2026-72297,CVE-2026-72306,CVE-2026-72307,CVE-2026-72308,CVE-2026-72317,CVE-2026-72323,CVE-2026-72325,CVE-2026-72330,CVE-2026-72337,CVE-2026-72339,CVE-2026-72341,CVE-2026-72342,CVE-2026-72343,CVE-2026-72345,CVE-2026-72347,CVE-2026-72350,CVE-2026-72366,CVE-2026-72379,CVE-2026-72389,CVE-2026-72398,CVE-2026-72399,CVE-2026-72414,CVE-2026-72421,CVE-2026-72425,CVE-2026-72430,CVE-2026-72437,CVE-2026-72438,CVE-2026-72439,CVE-2026-72440,CVE-2026-72448,CVE-2026-72450,CVE-2026-72459,CVE-2026-72460,CVE-2026-72464,CVE-2026-72466,CVE-2026-72467,CVE-2026-72468,CVE-2026-72469,CVE-2026-72473,CVE-2026-72485,CVE-2026-72487,CVE-2026-72488,CVE-2026-72494,CVE-2026-72495,CVE-2026-72497,CVE-2026-72499,CVE-2026-72500,CVE-2026-72501,CVE-2026-72502,CVE-2 026-74255,CVE-2026-74261,CVE-2026-74269,CVE-2026-74270,CVE-2026-74282,CVE-2026-74284,CVE-2026-74286,CVE-2026-74296,CVE-2026-74297,CVE-2026-74307,CVE-2026-74308,CVE-2026-74313,CVE-2026-74316,CVE-2026-74317,CVE-2026-74318,CVE-2026-74321,CVE-2026-74334,CVE-2026-74345,CVE-2026-74346,CVE-2026-74349,CVE-2026-74363,CVE-2026-74375,CVE-2026-74377,CVE-2026-74378,CVE-2026-74382,CVE-2026-74388,CVE-2026-74390,CVE-2026-74394,CVE-2026-74395,CVE-2026-74397,CVE-2026-74406,CVE-2026-74464,CVE-2026-74474,CVE-2026-74475,CVE-2026-74476,CVE-2026-74479,CVE-2026-74481,CVE-2026-74482,CVE-2026-74495,CVE-2026-74496,CVE-2026-74510,CVE-2026-74512,CVE-2026-74513,CVE-2026-74517,CVE-2026-74518,CVE-2026-74523,CVE-2026-74527,CVE-2026-74533,CVE-2026-74534,CVE-2026-74535,CVE-2026-74536,CVE-2026-74537,CVE-2026-74545,CVE-2026-74548,CVE-2026-74550,CVE-2026-74555,CVE-2026-74556,CVE-2026-74557,CVE-2026-74563,CVE-2026-74566,CVE-2026-74567,CVE-2026-74571,CVE-2026-74577,CVE-2026-74581,CVE-2026-74582,CVE-2026-74584,CVE-2026-745 98,CVE-2026-74610,CVE-2026-74612,CVE-2026-74615,CVE-2026-74616,CVE-2026-74622,CVE-2026-74644,CVE-2026-74665,CVE-2026-74669,CVE-2026-74695,CVE-2026-74705,CVE-2026-74712,CVE-2026-74717,CVE-2026-74719,CVE-2026-74722,CVE-2026-74723,CVE-2026-74730,CVE-2026-74737,CVE-2026-74743,CVE-2026-74744,CVE-2026-80529,CVE-2026-80530,CVE-2026-80531,CVE-2026-80533,CVE-2026-80534,CVE-2026-80535,CVE-2026-80557,CVE-2026-80558,CVE-2026-80561,CVE-2026-80586,CVE-2026-80589,CVE-2026-80590,CVE-2026-80603,CVE-2026-80609,CVE-2026-80629,CVE-2026-80646,CVE-2026-80647,CVE-2026-80667,CVE-2026-80681,CVE-2026-80693,CVE-2026-80714,CVE-2026-80721,CVE-2026-80727,CVE-2026-80731,CVE-2026-80737,CVE-2026-80739,CVE-2026-80805,CVE-2026-80813,CVE-2026-80838 The SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). - CVE-2025-68358: btrfs: fix racy bitfield write in btrfs_clear_space_info_full() (bsc#1255531). - CVE-2025-68780: sched/deadline: only set free_cpus for online runqueues (bsc#1256671). - CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). - CVE-2026-23113: io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop (bsc#1258278). - CVE-2026-23306: scsi: pm8001: Fix use-after-free in pm8001_queue_command() (bsc#1260501). - CVE-2026-23348: cxl/mem: Clarify @host for devm_cxl_add_nvdimm() (bsc#1260577). - CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). - CVE-2026-31530: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (bsc#1262756). - CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). - CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). - CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). - CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). - CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). - CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). - CVE-2026-43299: btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure() (bsc#1264851). - CVE-2026-43331: x86/kexec: Disable KCOV instrumentation after load_segments() (bsc#1265132). - CVE-2026-43355: iio: light: bh1780: fix PM runtime leak on error path (bsc#1265036). - CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). - CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). - CVE-2026-43439: cgroup: fix race between task migration and iteration (bsc#1265141). - CVE-2026-43448: nvme-pci: Fix race bug in nvme_poll_irqdisable() (bsc#1264807). - CVE-2026-45860: netfilter: nf_conncount: increase the connection clean up limit to 64 (bsc#1266710). - CVE-2026-45897: netfilter: nft_counter: serialize reset with spinlock (bsc#1266897). - CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). - CVE-2026-46007: hwmon: (powerz) Avoid cacheline sharing for DMA buffer (bsc#1267586). - CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). - CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). - CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). - CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). - CVE-2026-46135: nvmet-tcp: remove redundant calls to nvmet_tcp_fatal_error() (bsc#1267373). - CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). - CVE-2026-46304: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free (bsc#1267985). - CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000). - CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). - CVE-2026-52928: af_unix: Reject SIOCATMARK on non-stream sockets (bsc#1269010). - CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). - CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). - CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). - CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). - CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). - CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). - CVE-2026-52991: sched/psi: fix race between file release and pressure write (bsc#1269134). - CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). - CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). - CVE-2026-53031: bpf: Validate node_id in arena_alloc_pages() (bsc#1269380). - CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). - CVE-2026-53034: bpf, sockmap: Fix af_unix null-ptr-deref in proto update (bsc#1269140). - CVE-2026-53048: gfs2: prevent NULL pointer dereference during unmount (bsc#1269162). - CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). - CVE-2026-53061: dm cache: fix dirty mapping checking in passthrough mode switching (bsc#1269685). - CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). - CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). - CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). - CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). - CVE-2026-53092: bpf: Fix linked reg delta tracking when src_reg == dst_reg (bsc#1269528). - CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). - CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). - CVE-2026-53109: powerpc/pgtable-frag: Fix bad page state in pte_frag_destroy (bsc#1269417). - CVE-2026-53110: s390: always declare expoline thunks (bsc#1269985). - CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). - CVE-2026-53114: perf: Extend the bit width of the arch-specific flag (bsc#1269999). - CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). - CVE-2026-53129: fs/mbcache: cancel shrink work before destroying the cache (bsc#1269633). - CVE-2026-53142: drm/xe/display: fix oops in suspend/shutdown without display (bsc#1269402). - CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). - CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). - CVE-2026-53180: timers/migration: Fix livelock in tmigr_handle_remote_up() (bsc#1269888). - CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). - CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). - CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). - CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). - CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). - CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). - CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). - CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). - CVE-2026-53284: btrfs: only release the dirty pages io tree after successful writes (bsc#1269816). - CVE-2026-53291: ALSA: hda/conexant: Fix missing error check for jack detection (bsc#1269697). - CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). - CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). - CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). - CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). - CVE-2026-53341: fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh() (bsc#1270139). - CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). - CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). - CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). - CVE-2026-63803: hdlc_ppp: sync per-proto timers before freeing hdlc state (bsc#1272284). - CVE-2026-63804: gfs2: fix use-after-free in gfs2_qd_dealloc (bsc#1272287). - CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). - CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). - CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). - CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). - CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). - CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). - CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). - CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). - CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). - CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). - CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). - CVE-2026-63890: scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (bsc#1272426). - CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). - CVE-2026-63901: USB: serial: digi_acceleport: fix memory corruption with small endpoints (bsc#1272501). - CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904). - CVE-2026-63918: l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname (bsc#1272905). - CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). - CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918). - CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: refresh nh after handling HAO option (bsc#1272855). - CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). - CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). - CVE-2026-63941: KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor (bsc#1272869). - CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). - CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). - CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865). - CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). - CVE-2026-63986: ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure (bsc#1272969). - CVE-2026-63987: ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES (bsc#1272971). - CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). - CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). - CVE-2026-63993: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (bsc#1279847). - CVE-2026-63995: ethtool: cmis: validate start_cmd_payload_size from module (bsc#1273033). - CVE-2026-63996: ethtool: cmis: require exact CDB reply length (bsc#1273032). - CVE-2026-63997: ethtool: module: avoid leaking a netdev ref on module flash errors (bsc#1273036). - CVE-2026-63998: ethtool: module: call ethnl_ops_complete() on module flash errors (bsc#1273037). - CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). - CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). - CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). - CVE-2026-64003: scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues (bsc#1273782). - CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). - CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). - CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). - CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). - CVE-2026-64017: blk-mq: pop cached request if it is usable (bsc#1273770). - CVE-2026-64024: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction (bsc#1273107). - CVE-2026-64033: RDMA/rtrs: Fix use-after-free in path file creation cleanup (bsc#1273134). - CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). - CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). - CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). - CVE-2026-64053: block: don't overwrite bip_vcnt in bio_integrity_copy_user() (bsc#1272985). - CVE-2026-64054: net: shaper: reject duplicate leaves in GROUP request (bsc#1272894). - CVE-2026-64055: net: ethernet: cortina: Carry over frag counter (bsc#1272893). - CVE-2026-64056: net: ethernet: cortina: Make RX SKB per-port (bsc#1272502). - CVE-2026-64071: nvme-pci: fix use-after-free in nvme_free_host_mem() (bsc#1273486). - CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). - CVE-2026-64088: batman-adv: tt: fix negative tt_buff_len (bsc#1273463). - CVE-2026-64089: batman-adv: tt: fix negative last_changeset_len (bsc#1272513). - CVE-2026-64093: batman-adv: tp_meter: directly shut down timer on cleanup (bsc#1273461). - CVE-2026-64099: drm/v3d: Fix use-after-free of CPU job query arrays on error path (bsc#1273465). - CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). - CVE-2026-64103: scsi: isci: Fix use-after-free in device removal path (bsc#1273759). - CVE-2026-64109: af_unix: Fix UAF read of tail->len in unix_stream_data_wait() (bsc#1273748). - CVE-2026-64111: lsm: hold cred_guard_mutex for lsm_set_self_attr() (bsc#1273740). - CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). - CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). - CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). - CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). - CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). - CVE-2026-64119: l2tp: use list_del_rcu in l2tp_session_unhash (bsc#1273746). - CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). - CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). - CVE-2026-64131: mm/memory: fix spurious warning when unmapping device-private/exclusive pages (bsc#1274063). - CVE-2026-64146: erofs: fix metabuf leak in inode xattr initialization (bsc#1273681). - CVE-2026-64147: pds_core: fix debugfs_lookup dentry leak and error handling (bsc#1273119). - CVE-2026-64148: pds_core: fix error handling in pdsc_devcmd_wait (bsc#1273956). - CVE-2026-64162: idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() (bsc#1272366). - CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). - CVE-2026-64177: phonet/pep: disable BH around forwarded sk_receive_skb() (bsc#1272148). - CVE-2026-64179: net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (bsc#1272149). - CVE-2026-64180: mm/memory_hotplug: fix memory block reference leak on remove (bsc#1273679). - CVE-2026-64184: mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() (bsc#1272199). - CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). - CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). - CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). - CVE-2026-64210: net/mlx5e: xsk: Fix unlocked writing to ICOSQ (bsc#1273899). - CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). - CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). - CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). - CVE-2026-64224: octeontx2-pf: fix double free in rvu_rep_rsrc_init() (bsc#1272804). - CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). - CVE-2026-64232: block: recompute nr_integrity_segments in blk_insert_cloned_request (bsc#1272791). - CVE-2026-64239: mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() (bsc#1273898). - CVE-2026-64244: drivers/base/memory: set mem->altmap after successful device registration (bsc#1273812). - CVE-2026-64253: kernel/fork: clear PF_BLOCK_TS in copy_process() (bsc#1273904). - CVE-2026-64256: xfs: don't wrap around quota ids in dqiterate (bsc#1273271). - CVE-2026-64265: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req (bsc#1273947). - CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). - CVE-2026-64269: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg (bsc#1273280). - CVE-2026-64283: KVM: guest_memfd: Treat memslot binding offset+size as unsigned values (bsc#1273870). - CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). - CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). - CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). - CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). - CVE-2026-64298: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (bsc#1273550). - CVE-2026-64300: perf/aux: Fix page UAF in map_range() (bsc#1273852). - CVE-2026-64307: crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) (bsc#1273567). - CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). - CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). - CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). - CVE-2026-64319: nvmet-auth: validate reply message payload bounds against transfer length (bsc#1273339). - CVE-2026-64320: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (bsc#1273420). - CVE-2026-64321: nvme: target: rdma: fix ndev refcount leak on queue connect (bsc#1273864). - CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). - CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). - CVE-2026-64326: block: skip sync_blockdev() on surprise removal in bdev_mark_dead() (bsc#1273312). - CVE-2026-64327: usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks (bsc#1273283). - CVE-2026-64354: bpf: Validate BTF repeated field counts before expansion (bsc#1274060). - CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). - CVE-2026-64364: HID: multitouch: fix out-of-bounds bit access on mt_io_flags (bsc#1273495). - CVE-2026-64368: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (bsc#1273997). - CVE-2026-64373: cpufreq: Fix hotplug-suspend race during reboot (bsc#1273776). - CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). - CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). - CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). - CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). - CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). - CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). - CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). - CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). - CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). - CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). - CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). - CVE-2026-64415: mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup (bsc#1273317). - CVE-2026-64416: mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host (bsc#1273286). - CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). - CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). - CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). - CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). - CVE-2026-64452: 6lowpan: fix NHC entry use-after-free on error path (bsc#1273460). - CVE-2026-64458: mm/damon/ops-common: handle extreme intervals in damon_hot_score() (bsc#1273788). - CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). - CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). - CVE-2026-64477: x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled (bsc#1274264). - CVE-2026-64507: bpf: Support for hardening against JIT spraying (bsc#1273999). - CVE-2026-64518: tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key() (bsc#1273524). - CVE-2026-64519: NFSD: Fix infinite loop in layout state revocation (bsc#1274252). - CVE-2026-64526: ethtool: tsconfig: fix missing ethnl_ops_complete() (bsc#1274052). - CVE-2026-64534: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error (bsc#1273803). - CVE-2026-64535: nvmet-tcp: Fix potential UAF when ddgst mismatch (bsc#1273809). - CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). - CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). - CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). - CVE-2026-64542: ipv6: ndisc: fix NULL deref in accept_untracked_na() (bsc#1273309). - CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). - CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). - CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). - CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). - CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). - CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). - CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). - CVE-2026-64555: KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() (bsc#1273331). - CVE-2026-64556: perf/core: Detach event groups during remove_on_exec (bsc#1273251). - CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). - CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). - CVE-2026-64569: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (bsc#1274009). - CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). - CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). - CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). - CVE-2026-64579: xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (bsc#1274036). - CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). - CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). - CVE-2026-64586: wifi: brcmfmac: drain bus_reset work on device removal (bsc#1274492). - CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). - CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). - CVE-2026-68096: audit: fix recursive locking deadlock in audit_dupe_exe() (bsc#1274730). - CVE-2026-68105: drm/amdgpu: Fix kernel panic during driver load failure (bsc#1274849). - CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). - CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). - CVE-2026-68120: rtase: Workaround for TX hang caused by hardware packet parsing (bsc#1274887). - CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). - CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). - CVE-2026-68124: mctp: serial: handle zero-length frames to prevent rx buffer overflow (bsc#1275192). - CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). - CVE-2026-68128: ice: reject out-of-range ptype in ice_parser_profile_init (bsc#1275238). - CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). - CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). - CVE-2026-68133: ice: fix PTP Call Trace during PTP release (bsc#1275555). - CVE-2026-68135: net: hip04: fix RX buffer leak on build_skb failure (bsc#1275557). - CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). - CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). - CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). - CVE-2026-68141: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (bsc#1275094). - CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). - CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). - CVE-2026-68144: phonet: pep: fix use-after-free in pep_get_sb() (bsc#1275481). - CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). - CVE-2026-68148: fscrypt: Add missing superblock check in find_or_insert_direct_key() (bsc#1275588). - CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). - CVE-2026-68152: amt: fix use-after-free in AMT delayed works (bsc#1275300). - CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). - CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). - CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). - CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). - CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). - CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). - CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). - CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). - CVE-2026-68164: mm/damon/core: disallow overlapping input ranges for damon_set_regions() (bsc#1274955). - CVE-2026-68165: mm/damon/core: validate ranges in damon_set_regions() (bsc#1274927). - CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). - CVE-2026-68169: mptcp: pm: userspace: fix use-after-free in get_local_id (bsc#1274952). - CVE-2026-68183: firmware: stratix10-svc: fix memory leaks and list corruption bugs (bsc#1274957). - CVE-2026-68198: wifi: ath6kl: fix use-after-free in aggr_reset_state() (bsc#1274803). - CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). - CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). - CVE-2026-68258: drm/amdkfd: Check bounds on CRIU restore queue type and mqd size (bsc#1275866). - CVE-2026-68267: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (bsc#1275139). - CVE-2026-68273: drm/amdgpu: Fix context pstate override handling (bsc#1275129). - CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). - CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). - CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). - CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). - CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). - CVE-2026-68294: net: qrtr: restrict socket creation to the initial network namespace (bsc#1275092). - CVE-2026-68296: net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM (bsc#1275045). - CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). - CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). - CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). - CVE-2026-68302: amt: re-read skb header pointers after every pull (bsc#1275081). - CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). - CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). - CVE-2026-68319: pds_core: fix deadlock between reset thread and remove (bsc#1274657). - CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). - CVE-2026-68321: net: txgbe: fix FDIR filter leak on remove (bsc#1274652). - CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). - CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). - CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). - CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). - CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). - CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). - CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). - CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). - CVE-2026-68338: net/packet: avoid fanout hook re-registration after unregister (bsc#1274637). - CVE-2026-68375: bnxt_en: Handle partially initialized auxiliary devices (bsc#1274835). - CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). - CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). - CVE-2026-68393: Bluetooth: hci_sync: extend conn_hash lookup critical sections (bsc#1274904). - CVE-2026-68395: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered (bsc#1274900). - CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). - CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). - CVE-2026-68399: bpf: Fix UAF in sock clone early bailouts (bsc#1274897). - CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). - CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). - CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). - CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). - CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). - CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). - CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). - CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). - CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). - CVE-2026-68442: btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps (bsc#1274773). - CVE-2026-68448: ovl: check access to copy_file_range source with src mounter creds (bsc#1274838). - CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). - CVE-2026-68470: wifi: mac80211: validate extension-frame layout before RX (bsc#1276500). - CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). - CVE-2026-72017: net: macb: drop in-flight Tx SKBs on close (bsc#1276840). - CVE-2026-72019: macsec: don't read an unset MAC header in macsec_encrypt() (bsc#1276865). - CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). - CVE-2026-72022: llc: fix SAP refcount leak in llc_ui_autobind() (bsc#1276785). - CVE-2026-72023: octeontx2-pf: fix SQB pointer leak on init failure (bsc#1276793). - CVE-2026-72032: net/mlx5: HWS, fix matcher leak on resize target setup failure (bsc#1276955). - CVE-2026-72034: fhandle: reject detached mounts in capable_wrt_mount() (bsc#1276957). - CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). - CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). - CVE-2026-72045: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (bsc#1277078). - CVE-2026-72046: gve: fix header buffer corruption with header-split and HW-GRO (bsc#1275519). - CVE-2026-72051: net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276801). - CVE-2026-72052: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276803). - CVE-2026-72053: net: ipip: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276814). - CVE-2026-72054: net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276818). - CVE-2026-72055: net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276821). - CVE-2026-72061: net: sit: require CAP_NET_ADMIN in the device netns for changelink (bsc#1277249). - CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). - CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). - CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). - CVE-2026-72084: scsi: target: core: Generate correct identifiers for PR OUT transport IDs (bsc#1275540). - CVE-2026-72100: dm-integrity: fix a bug if the bio is out of limits (bsc#1277311). - CVE-2026-72101: dm-integrity: fix leaking uninitialized kernel memory (bsc#1276831). - CVE-2026-72103: dm: avoid leaking the caller's thread keyring via the table device file (bsc#1277315). - CVE-2026-72106: dm-ioctl: fix a possible overflow in list_version_get_info (bsc#1277321). - CVE-2026-72107: dm era: fix out-of-bounds memory access for non-zero start sector (bsc#1277349). - CVE-2026-72108: dm thin metadata: fix metadata snapshot consistency on commit failure (bsc#1277350). - CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). - CVE-2026-72136: xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink (bsc#1277574). - CVE-2026-72137: xfrm: nat_keepalive: avoid double free on send error (bsc#1275587). - CVE-2026-72161: ocfs2: add journal NULL check in ocfs2_checkpoint_inode() (bsc#1277233). - CVE-2026-72163: ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits (bsc#1277231). - CVE-2026-72164: ocfs2: avoid moving extents to occupied clusters (bsc#1277553). - CVE-2026-72176: mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error (bsc#1277230). - CVE-2026-72177: mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() (bsc#1277227). - CVE-2026-72217: SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing (bsc#1275655). - CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). - CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). - CVE-2026-72234: batman-adv: access unicast_ttvn skb->data only after skb realloc (bsc#1275672). - CVE-2026-72242: selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() (bsc#1277655). - CVE-2026-72243: selinux: check connect-related permissions on TCP Fast Open (bsc#1277656). - CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). - CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). - CVE-2026-72280: KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 (bsc#1277726). - CVE-2026-72282: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers (bsc#1277728). - CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). - CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). - CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). - CVE-2026-72297: net: atm: reject out-of-range traffic classes in QoS validation (bsc#1277738). - CVE-2026-72306: vduse: Requeue failed read to send_list head (bsc#1277748). - CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). - CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). - CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). - CVE-2026-72323: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (bsc#1275985). - CVE-2026-72325: perf/x86/amd/core: Avoid enabling BRS from the SVM reload path (bsc#1277761). - CVE-2026-72330: net/tls: Consume empty data records in tls_sw_read_sock() (bsc#1277764). - CVE-2026-72337: Bluetooth: 6lowpan: avoid untracked enable work (bsc#1277773). - CVE-2026-72339: qede: fix off-by-one in BD ring consumption on build_skb failure (bsc#1276006). - CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). - CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). - CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). - CVE-2026-72345: net/mlx5: LAG, Fix off-by-one in single-FDB error rollback (bsc#1277782). - CVE-2026-72347: netfilter: xt_connmark: reject invalid shift parameters (bsc#1277783). - CVE-2026-72350: netfilter: xt_u32: reject invalid shift counts (bsc#1277822). - CVE-2026-72366: netfs: Fix netfs_create_write_req() to handle async cache object creation (bsc#1276333). - CVE-2026-72379: fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid (bsc#1277818). - CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). - CVE-2026-72398: sctp: add INIT verification after cookie unpacking (bsc#1276381). - CVE-2026-72399: net: enetc: check the number of BDs needed for xdp_frame (bsc#1276553). - CVE-2026-72414: net: dsa: sja1105: round up PTP perout pin duration (bsc#1278039). - CVE-2026-72421: ipv4: fib: Don't ignore error route in local/main tables (bsc#1277023). - CVE-2026-72425: ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() (bsc#1277120). - CVE-2026-72430: net/sched: act_ct: fix nf_connlabels leak on two error paths (bsc#1277118). - CVE-2026-72437: md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry (bsc#1277874). - CVE-2026-72438: md/raid10: fix writes_pending and barrier reference leaks on discard failures (bsc#1277115). - CVE-2026-72439: md/raid10: fix writes_pending leak on write request failures (bsc#1277876). - CVE-2026-72440: md/raid1: fix writes_pending and barrier reference leaks on write failures (bsc#1277114). - CVE-2026-72448: octeontx2-pf: Fix leak of SQ timestamp buffer on teardown (bsc#1277108). - CVE-2026-72450: xfrm: validate selector family and prefixlen during match (bsc#1278113). - CVE-2026-72459: apparmor: aa_label_alloc use aa_label_free on alloc failure (bsc#1277092). - CVE-2026-72460: apparmor: check label build before no_new_privs test (bsc#1277229). - CVE-2026-72464: xprtrdma: Post receive buffers after RPC completion (bsc#1277069). - CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). - CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). - CVE-2026-72468: xprtrdma: Initialize re_id before removal registration (bsc#1277062). - CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). - CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). - CVE-2026-72485: coresight: platform: defer connection counter increment until alloc succeeds (bsc#1276771). - CVE-2026-72487: PCI: Introduce named defines for PCI ROM (bsc#1276767). - CVE-2026-72488: soundwire: fix bug in sdw_add_element_group_count found by syzkaller (bsc#1276766). - CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). - CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). - CVE-2026-72497: RDMA/bnxt_re: Add a max slot check for SQ (bsc#1276913). - CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). - CVE-2026-72500: RDMA/bnxt_re: Free SRQ toggle page after firmware teardown (bsc#1276552). - CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). - CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). - CVE-2026-74255: tipc: fix UAF in tipc_l2_send_msg() (bsc#1276547). - CVE-2026-74261: ALSA: seq: avoid stale FIFO cells during resize (bsc#1276528). - CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). - CVE-2026-74270: handshake: Require admin permission for DONE command (bsc#1276512). - CVE-2026-74282: tipc: prevent snt_unacked underflow on CONN_ACK (bsc#1276473). - CVE-2026-74284: net/sched: sch_hfsc: Don't make class passive twice (bsc#1276468). - CVE-2026-74286: net: pfcp: allocate per-cpu tstats for PFCP netdevs (bsc#1276471). - CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). - CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). - CVE-2026-74307: ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT (bsc#1276905). - CVE-2026-74308: ext4: fix kernel BUG in ext4_write_inline_data_end (bsc#1276880). - CVE-2026-74313: vduse: hold vduse_lock across IDR lookup in open path (bsc#1276876). - CVE-2026-74316: NFSD: Handle layout stid in nfsd4_drop_revoked_stid() (bsc#1276870). - CVE-2026-74317: ixgbe: do not configure xps for XDP queues (bsc#1276866). - CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). - CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). - CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). - CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). - CVE-2026-74346: RDMA/irdma: Fix OOB read during CQ MR registration (bsc#1278155). - CVE-2026-74349: ocfs2: reject FITRIM ranges shorter than a cluster (bsc#1278180). - CVE-2026-74363: bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs (bsc#1278070). - CVE-2026-74375: md: replace wait loop with wait_event() in md_handle_request() (bsc#1277649). - CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236). - CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233). - CVE-2026-74382: net/sched: cls_bpf: prevent unbounded recursion in offload rollback (bsc#1278240). - CVE-2026-74388: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data (bsc#1278253). - CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (bsc#1278088). - CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). - CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). - CVE-2026-74397: IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier (bsc#1278098). - CVE-2026-74406: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() (bsc#1276395). - CVE-2026-74464: net: openvswitch: fix skb leak on flow key update failure during ct (bsc#1277070). - CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). - CVE-2026-74475: vxlan: unclone skb head before modifying eth header in route_shortcircuit() (bsc#1276339). - CVE-2026-74476: veth: convert frag_list skbs before running XDP (bsc#1276341). - CVE-2026-74479: net: pktgen: fix proc entry use-after-free (bsc#1276354). - CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). - CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (bsc#1276346). - CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). - CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). - CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). - CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). - CVE-2026-74513: dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister (bsc#1275956). - CVE-2026-74517: KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs (bsc#1276258). - CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). - CVE-2026-74523: qede: sync udp_tunnel ports outside qede_lock in the recovery path (bsc#1275802). - CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). - CVE-2026-74533: Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero (bsc#1275804). - CVE-2026-74534: Bluetooth: ISO: Fix data-race on iso_pi(sk) in socket and HCI event paths (bsc#1275801). - CVE-2026-74535: Bluetooth: ISO: avoid deadlocks in iso_sock_timeout (bsc#1275812). - CVE-2026-74536: Bluetooth: ISO: fix leaking sk after socket release (bsc#1275799). - CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). - CVE-2026-74545: rtase: fix double free of multi-frag skb on DMA map failure (bsc#1275679). - CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). - CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). - CVE-2026-74555: scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race (bsc#1275690). - CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). - CVE-2026-74557: scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (bsc#1275685). - CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). - CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). - CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). - CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). - CVE-2026-74577: net: mpls: initialize rtm_tos in mpls_getroute() (bsc#1275572). - CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). - CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). - CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). - CVE-2026-74598: ipv6: fix Route Information option length validation (bsc#1277918). - CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). - CVE-2026-74612: veth: fix skb length accounting after XDP frag adjustment (bsc#1277505). - CVE-2026-74615: vxlan: do not arm the ageing timer on a device that is down (bsc#1277901). - CVE-2026-74616: xdp: reject clones that overrun skb_shared_info tailroom (bsc#1277813). - CVE-2026-74622: net: atlantic: free RX pages of consumed but not refilled buffers (bsc#1277862). - CVE-2026-74644: mm/damon/ops-common: putback folios on invalid migrate nid (bsc#1277033). - CVE-2026-74665: net: fix skb length accounting after generic XDP frag adjustment (bsc#1277407). - CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). - CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). - CVE-2026-74705: udp: fix potential use-after-free in tunnel segmentation (bsc#1276922). - CVE-2026-74712: vdpa/mlx5: Fix buffer length in create_direct_keys() (bsc#1276577). - CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). - CVE-2026-74719: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() (bsc#1276572). - CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). - CVE-2026-74723: btrfs: lzo: reject inline extents without valid headers (bsc#1276562). - CVE-2026-74730: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (bsc#1276566). - CVE-2026-74737: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG (bsc#1277898). - CVE-2026-74743: macvlan: inherit needed_headroom and needed_tailroom from lowerdev (bsc#1277908). - CVE-2026-74744: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev (bsc#1278094). - CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). - CVE-2026-80530: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN (bsc#1277668). - CVE-2026-80531: xfs: avoid UAF on sc->tempip in xrep_tempfile_create (bsc#1277680). - CVE-2026-80533: xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair (bsc#1277636). - CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). - CVE-2026-80535: xfs: don't double-lock when deleting a self-referential directory (bsc#1277641). - CVE-2026-80557: libceph: fix OOB read in decode_watchers() via missing bounds check (bsc#1277268). - CVE-2026-80558: libceph: Avoid using invalid osd indices from primary_temp (bsc#1277485). - CVE-2026-80561: libceph: fix multiple unsafe decodes in decode_locker() (bsc#1277265). - CVE-2026-80586: mptcp: options: reset DSS fields in case of unexpected size (bsc#1277328). - CVE-2026-80589: block: stop the timeout timer when releasing a never added disk (bsc#1277335). - CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). - CVE-2026-80603: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read (bsc#1278293). - CVE-2026-80609: qede: fix out-of-bounds check for cqe->len_list (bsc#1278334). - CVE-2026-80629: octeontx2-af: npc: Fix size of entry2cntr_map (bsc#1277308). - CVE-2026-80646: ipv6: guard against possible NULL deref in __in6_dev_stats_get() (bsc#1277513). - CVE-2026-80647: RDMA/hns: Fix warning in poll cq direct mode (bsc#1278331). - CVE-2026-80667: net/mlx5: LAG, MPESW, Fix missing complete() on devcom error (bsc#1278324). - CVE-2026-80681: vxlan: re-fetch eth header after route_shortcircuit() (bsc#1278416). - CVE-2026-80693: idpf: bound interrupt-vector register fill to the allocated array (bsc#1278395). - CVE-2026-80714: ipvs: do not propagate one-packet flag to synced conns (bsc#1277561). - CVE-2026-80721: Bluetooth: ISO: ensure no dangling hcon references in iso_conn (bsc#1277845). - CVE-2026-80727: x86/mce: Set up the polling timer before CMCI discovery (bsc#1278703). - CVE-2026-80731: net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (bsc#1278716). - CVE-2026-80737: serial: amba-pl011: synchronize DMA teardown (bsc#1279487). - CVE-2026-80739: net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock (bsc#1278733). - CVE-2026-80805: xfs: validate attr entry pointer before field access (bsc#1279580). - CVE-2026-80813: nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist() (bsc#1279537). - CVE-2026-80838: vxlan: keep the last remote linked during FDB flush (bsc#1279842). The following non security issues were fixed: - accel/ivpu: Limit firmware log name prints to field size (git-fixes). - accel/ivpu: Validate firmware log buffer metadata (git-fixes). - accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr (git-fixes). - accel/qaic: Address potential out-of-bounds read in resp_worker() (git-fixes). - accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). - accessibility: speakup: unregister tty ldisc on later init failures (git-fixes). - ACPI: APEI: Fix ERST timeout unit conversion (git-fixes). - ACPI: battery: Adjust charging status validation check (git-fixes). - ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). - ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git-fixes). - ACPI: pfr_update: fix stack buffer overflow in query_capability() (git-fixes). - ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). - ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). - ACPI: processor_idle: Mark LPI enter functions as __cpuidle (git-fixes). - ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). - ACPI: video: Release PCI device reference after lookup (git-fixes). - ALSA: 6fire: bound the MIDI event length from the device (git-fixes). - ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). - ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). - ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev (git-fixes). - ALSA: caiaq: Fix potential double-free at error path (git-fixes). - ALSA: control: Don't add invalid kcontrols to LED layer (git-fixes). - ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). - ALSA: ctxfi: Fix CA20K2 S/PDIF passthrough (git-fixes). - ALSA: dummy: Check card index validity at probe (stable-fixes). - ALSA: dummy: Report a change when one capture switch channel moves (git-fixes). - ALSA: harmony: initialize locks before requesting IRQ (git-fixes). - ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). - ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r (stable-fixes). - ALSA: hda: Fix connection list comparison in proc output (git-fixes). - ALSA: hda: Report a change when only the channel status bytes move (git-fixes). - ALSA: hda: restore MFG widget enumeration after core split (git-fixes). - ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). - ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF (git-fixes). - ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). - ALSA: rawmidi: Return the error from snd_rawmidi_input_params() (git-fixes). - ALSA: scarlett2: Use a private URB for the notification endpoint (git-fixes). - ALSA: seq: Don't leak the extension cell pointer in the bounce payload (git-fixes). - ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). - ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). - ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). - ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). - ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() (git-fixes). - ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). - ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). - ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf (git-fixes). - ALSA: usbusx2y: validate URB actual_length in interrupt callback (git-fixes). - ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). - ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git-fixes). - apparmor: advertise the tcp fast open fix is applied (git-fixes). - ASoC: ab8500: Correct digital interface format setup (git-fixes). - ASoC: ab8500: Repair the DAPM capture graph (git-fixes). - ASoC: ab8500: Reset the audio block before configuring it (git-fixes). - ASoC: ab8500: Validate and program TDM slots correctly (git-fixes). - ASoC: adau1761: sort the register default table (git-fixes). - ASoC: amd: renoir: fix disable_pdm_interrupts() to clear mask bits (git-fixes). - ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). - ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() (git-fixes). - ASoC: apple: mca: increase SERDES reset delay (git-fixes). - ASoC: bcm: bcm63xx: Publish the OF module aliases (git-fixes). - ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). - ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). - ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). - ASoC: cs35l41: sort the register default table (git-fixes). - ASoC: cs35l45: sort the register default table (git-fixes). - ASoC: cs4265: sort the register default table (git-fixes). - ASoC: cx2072x: sort the register default table (git-fixes). - ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). - ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git-fixes). - ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git-fixes). - ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). - ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). - ASoC: fsl_easrc: sort the register default table (git-fixes). - ASoC: hdac_hda: Fix hlink refcount leak on component registration failure (git-fixes). - ASoC: Intel: avs: Clean up streams if their initialization fails (git-fixes). - ASoC: Intel: avs: Clean up the bus when fetching ML caps fails (git-fixes). - ASoC: Intel: avs: Do not ignore -ENOENT when loading a topology (git-fixes). - ASoC: Intel: avs: Fix unbalanced module reference count (git-fixes). - AsoC: intel: sst: fix PCI device reference leak on probe failure (git-fixes). - ASoC: Intel: SST: Publish the PCI module aliases (git-fixes). - ASoC: loongson: Fix error handling in ACPI property parsing (git-fixes). - ASoC: max9860: sort the register default table (git-fixes). - ASoC: mediatek: mt8183-afe-pcm: Shorten memif_data table using macros (stable-fixes). - ASoC: mediatek: mt8183-afe-pcm: Support >32 bit DMA addresses (git-fixes). - ASoC: mediatek: mt8183-afe-pcm: use local `dev` pointer in driver callbacks (stable-fixes). - ASoC: mediatek: mt8183: Check runtime resume during probe (git-fixes). - ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (stable-fixes). - ASoC: mediatek: mt8192: Check runtime resume during probe (git-fixes). - ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). - ASoC: ml26124: sort the register default table (git-fixes). - ASoC: mt6351: Publish the OF module alias (git-fixes). - ASoC: pcm512x: sort the register default table (git-fixes). - ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). - ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git-fixes). - ASoC: rt274: sort the register default table (git-fixes). - ASoC: rt286: sort the register default table (git-fixes). - ASoC: rt298: sort the register default table (git-fixes). - ASoC: rt700-sdw: always drain jack work on remove (git-fixes). - ASoC: rt700: drop duplicate reg_default entry (git-fixes). - ASoC: rt700: sort the register default table (git-fixes). - ASoC: rt711-sdca: sort the register default tables (git-fixes). - ASoC: rt711: sort the register default table (git-fixes). - ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). - ASoC: rt712-sdca-sdw: sort the register default table (git-fixes). - ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). - ASoC: rt715-sdca: sort the register default tables (git-fixes). - ASoC: rt715: sort the register default table (git-fixes). - ASoC: rt1017-sdca-sdw: sort the register default table (git-fixes). - ASoC: rt1316-sdw: sort the register default table (git-fixes). - ASoC: rt1318-sdw: sort the register default table (git-fixes). - ASoC: rt1318: sort the register default table (git-fixes). - ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). - ASoC: sgtl5000: sort the register default table (git-fixes). - ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git-fixes). - ASoC: SOF: validate topology volume range before allocation (git-fixes). - ASoC: sprd: validate compress buffer sizes against fixed allocations (git-fixes). - ASoC: sti-sas: sort the register default table (git-fixes). - ASoC: sti: initialize IRQ lock before requesting IRQ (git-fixes). - ASoC: tas2552: sort the register default table (git-fixes). - ASoC: tas2764: sort the register default table (git-fixes). - ASoC: tas2780: sort the register default table (git-fixes). - ASoC: tegra210_i2s: sort the register default table (git-fixes). - ASoC: tegra210_mixer: sort the register default table (git-fixes). - ASoC: tegra: Fix the MIXER enable default value (git-fixes). - ASoC: tegra: Sort MBDRC register defaults (git-fixes). - ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). - ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). - ata: ahci: work around lost interrupts on Marvell 88SE61xx (git-fixes). - batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). - batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). - batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). - batman-adv: fix stale receive device on merged fragments (git-fixes). - batman-adv: mcast: ensure unshared skb for multicast packets (git-fixes). - batman-adv: mcast: linearize skbuff for packet generation (git-fixes). - batman-adv: reject unrepresentable multicast TVLV offsets (git-fixes). - blk-mq: reinsert cached request to the list (bsc#1273770). - Bluetooth: btintel: bound firmware ID by TLV length (git-fixes). - Bluetooth: btintel: Fix diagnostics event detection (git-fixes). - Bluetooth: btintel: validate version TLV value lengths (git-fixes). - Bluetooth: btintel_pcie: Clear automask on spurious interrupts (git-fixes). - Bluetooth: btintel_pcie: fix tx_handle bounds off-by-one (git-fixes). - Bluetooth: btintel_pcie: validate packet_len before skb_put_data (git-fixes). - Bluetooth: btmtk: Declare MT7920 (MT7961 1a) Bluetooth firmware (git-fixes). - Bluetooth: btmtk: Do not discard the subsystem reset timeout (git-fixes). - Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() (stable-fixes). - Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). - Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git-fixes). - Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git-fixes). - Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev (git-fixes). - Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 (git-fixes). - Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git-fixes). - Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() (stable-fixes). - Bluetooth: btusb: Fix UAF of btusb_data by rx_work (git-fixes). - Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). - Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). - Bluetooth: hci_aml: validate firmware segment lengths (git-fixes). - Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378 (git-fixes). - Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_conn: fix the SCO setup context lifetime (git-fixes). - Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). - Bluetooth: hci_conn: re-enable advertising only for peripheral role (git-fixes). - Bluetooth: hci_core: Fix race condition during device registration (git-fixes). - Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb (git-fixes). - Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git-fixes). - Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). - Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). - Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_mrvl: Fix wrong return value check of wait_on_bit_timeout() (git-fixes). - Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request (git-fixes). - Bluetooth: hci_sync: Fix accept list UAF during suspend (git-fixes). - Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). - Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). - Bluetooth: hci_sync: Use bt_dev_err() to log error message in hci_update_event_filter_sync() (stable-fixes). - Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del() (git-fixes). - Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git-fixes). - Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync (git-fixes). - Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). - Bluetooth: L2CAP: clear FLAG_DEFER_SETUP only for same PID/PSM (git-fixes). - Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan (git-fixes). - Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect (git-fixes). - Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync (git-fixes). - Bluetooth: MGMT: free the HCI command when it is cancelled (git-fixes). - Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). - Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 (git-fixes). - Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update (git-fixes). - Bluetooth: MSFT: validate evt_prefix_len against the response length (git-fixes). - Bluetooth: qca: fix NVM tag length underflow in TLV parser (git-fixes). - Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). - Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git-fixes). - Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). - Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). - bnxt_en: Check return value of bnxt_hwrm_vnic_cfg (jsc#PED-16798). - bnxt_en: Delay for 5 seconds after AER DPC for all chips (jsc#PED-16798). - bnxt_en: Don't assume XDP is never enabled in bnxt_init_dflt_ring_mode() (jsc#PED-16798). - bnxt_en: Drop pci_save_state() after pci_restore_state() (jsc#PED-16798). - bnxt_en: Implement XDP RSS hash metadata extraction (jsc#PED-16798). - bnxt_en: Implement XDP RSS hash metadata extraction for V3_CMP (jsc#PED-16798). - bnxt_en: Move bnxt_rss_ext_op into header (jsc#PED-16798). - bnxt_en: Refactor some basic ring setup and adjustment logic (jsc#PED-16798). - bnxt_en: Restore default stat ctxs for ULP when resource is available (jsc#PED-16798). - bnxt_en: Set bp->max_tpa according to what the FW supports (jsc#PED-16798). - bnxt_en: Use absolute target ns from ptp_clock_request (jsc#PED-16798). - bnxt_en: use bnxt_xdp_buff for xdp context (jsc#PED-16798). - bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). - bus: mhi: host: Fix controller cleanup on EDL sysfs failure (git-fixes). - bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). - bus: ti-sysc: Fix /chosen node reference leak (git-fixes). - cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). - can: j1939: add missing calls in NETDEV_UNREGISTER notification handler (git-fixes). - can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). - char: xilinx_hwicap: unregister class on init errors (git-fixes). - cleanup: add a scoped version of CLASS() (stable-fixes). - cleanup: fix scoped_class() (git-fixes). - compiler_types: Introduce __flex_counter() and family (bsc#1280139). - cpufreq: intel_pstate: Add and use hybrid_get_cpu_type() (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Avoid SMP calls to get cpu-type (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Fix hwp_get_cpu_scaling() (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Use correct scaling factor on Raptor Lake-E (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Use CPPC to get scaling factors (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Use HYBRID_SCALING_FACTOR_ADL for Bartlett Lake (bsc#1240957 bsc#1249104 bsc#1265220). - crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). - crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git-fixes). - crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). - crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). - crypto: ccp - Abort doing SEV INIT if SNP INIT fails (stable-fixes). - crypto: ccp - Add new SEV/SNP platform shutdown API (stable-fixes). - crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() (git-fixes). - crypto: ccp - Fix __sev_snp_shutdown_locked (git-fixes). - crypto: ccp - Fix dereferencing uninitialized error pointer (git-fixes). - crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). - crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). - crypto: ccp - Fix SNP panic notifier unregistration (git-fixes). - crypto: ccp - Move dev_info/err messages for SEV/SNP init and shutdown (stable-fixes). - crypto: ccp - Move SEV/SNP Platform initialization to KVM (stable-fixes). - crypto: ccp - Register SNP panic notifier only if SNP is enabled (stable-fixes). - crypto: ccp - Reset TMR size at SNP Shutdown (stable-fixes). - crypto: doc - Remove extra parenthesis (git-fixes). - crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). - crypto: keembay - Fix AEAD unregister count in error path (git-fixes). - crypto: keembay - Initialize completion before requesting IRQ (git-fixes). - crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). - crypto: lskcipher - propagate errors from unaligned crypt (git-fixes). - crypto: mxs-dcp - fix source scatterlist length access (git-fixes). - crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). - crypto: qat - clear AES key schedule from stack (git-fixes). - crypto: qce - fix CCM AAD buffer underallocation (git-fixes). - crypto: qce - fix error path in devm_qce_register_algs (git-fixes). - crypto: qcom-rng - Allow zero as a random number (git-fixes). - crypto: qcom-rng - Enable clock in hwrng case (git-fixes). - crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). - crypto: sa2ul - stop probe if context pool creation fails (git-fixes). - crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git-fixes). - crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin (stable-fixes). - crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() (git-fixes). - cxl/acpi: Fix CXL_ACPI and CXL_PMEM Kconfig tristate mismatch (git-fixes). - cxl: Adjust the startup priority of cxl_pmem to be higher (git-fixes). - default_gfp(): avoid using the 'newfangled' __VA_OPT__ trick (bsc#1280139). - device property: fix infinite loop in fwnode_for_each_child_node() (git-fixes). - dm/amdgpu: fix malformed link_settings debugfs output (git-fixes). - dma-mapping: add __dma_from_device_group_begin()/end() (bsc#1267586). - dmaengine: dw-edma: Clear stale requests on termination (git-fixes). - dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). - dmaengine: dw-edma: Fix HDMA channel status register access (git-fixes). - dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). - dmaengine: dw-edma: Serialize abort state updates (git-fixes). - dmaengine: dw-edma: Serialize channel state checks (git-fixes). - dmaengine: dw-edma: Terminate all descriptors without callbacks (git-fixes). - dmaengine: fsl-edma: tracing: no ptr dereference during log output (git-fixes). - dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). - dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). - dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). - dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). - dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). - dmaengine: zynqmp_dma: fix kernel doc for zynqmp_dma_remove() (git-fixes). - driver core: soc: Unregister bus on early device registration failure (git-fixes). - drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook() (git-fixes). - Drivers: hv: Use meaningful errnos for hypercall status codes (git-fixes). - drm/amd/display: Add AV mute wait frames to dce110_set_avmute (stable-fixes). - drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). - drm/amd/display: Check for tg ops in dce110_set_avmute (git-fixes). - drm/amd/display: dce100: skip non-DP stream encoders for DP MST (stable-fixes). - drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix (git-fixes). - drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE (git-fixes). - drm/amd/display: fix division by zero in get_estimated_bw() (git-fixes). - drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank() (git-fixes). - drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames (stable-fixes). - drm/amd/display: Remove unused-but-set variable hubp from (git-fixes). - drm/amd/display: validate plane degamma LUT size for private color prop (git-fixes). - drm/amd/pm: adjust the visibility of pp_table sysfs node (stable-fixes). - drm/amd/pm: fix gpu metrics energy accumulator for smu 13.0.0/13.0.7 (git-fixes). - drm/amd/pm: fix smu14 power limit range calculation (stable-fixes). - drm/amd/pm: make pp_features read-only when scpm is enabled (stable-fixes). - drm/amd/pm: Use same metric table for APU (stable-fixes). - drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git-fixes). - drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). - drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). - drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). - drm/amdgpu/gfx8: drop unecessary BUG_ON() (stable-fixes). - drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git-fixes). - drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git-fixes). - drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) (stable-fixes). - drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older (stable-fixes). - drm/amdgpu/vce: fix integer overflow in image size (stable-fixes). - drm/amdgpu/vcn4: avoid rereading IB param length (stable-fixes). - drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git-fixes). - drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). - drm/amdgpu: check ASPM on the dGPU host link (git-fixes). - drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). - drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). - drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). - drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved (stable-fixes). - drm/amdgpu: fix division by zero with invalid uvd dimensions (stable-fixes). - drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() (stable-fixes). - drm/amdgpu: fix nbif 6.3.1 l1 low power not functional (git-fixes). - drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). - drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). - drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). - drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). - drm/amdgpu: Fix VFCT bus number matching with soft filter (stable-fixes). - drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). - drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (stable-fixes). - drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini (git-fixes). - drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 (git-fixes). - drm/amdgpu: reject oversized IBs with per-ring packet limits (stable-fixes). - drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). - drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable-fixes). - drm/amdgpu: remove unused function parameter (stable-fixes). - drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). - drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). - drm/amdkfd: Check bounds in allocate_event_notification_slot (stable-fixes). - drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (stable-fixes). - drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). - drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). - drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore (git-fixes). - drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). - drm/amdkfd: Use kvcalloc to allocate arrays (stable-fixes). - drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). - drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). - drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). - drm/bridge: tc358767: clamp the reported AUX read size to the request (git-fixes). - drm/connector/hdmi: Fix out of bounds memory read (git-fixes). - drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). - drm/drm_exec: fix up contended obj when num_objects is 0 (git-fixes). - drm/gud: NUL-terminate TV mode names read from the device (git-fixes). - drm/gud: validate TV mode names before creating enum property (git-fixes). - drm/hibmc: Fix list of formats on the primary plane (git-fixes). - drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). - drm/i915/hdcp: check streams bounds before overflow (git-fixes). - drm/i915/hdcp: Move to using intel_display in intel_hdcp (stable-fixes). - drm/i915/hdcp: require monotonically increasing seq_num_v (git-fixes). - drm/i915/hdcp: Skip inactive MST connectors when building stream list (stable-fixes). - drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() (stable-fixes). - drm/i915/vrr: require valid min/max vfreq for VRR (git-fixes). - drm/i915: Fix memory leak in query_perf_config_list() (git-fixes). - drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). - drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg (git-fixes). - drm/msm/a6xx: Fix stale rpmh votes after suspend (git-fixes). - drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). - drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). - drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git-fixes). - drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE (git-fixes). - drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op (git-fixes). - drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE (git-fixes). - drm/nouveau: unsubscribe the channel-kill event before the fence context (git-fixes). - drm/nouveau: Use write-combined maps for coherent (git-fixes). - drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). - drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). - drm/panthor: fix firmware control interface bounds checks (git-fixes). - drm/panthor: return PTR_ERR() from devm_drm_dev_alloc() (git-fixes). - drm/panthor: skip zero-sized firmware sections (git-fixes). - drm/radeon: fix autosuspend cleanup during teardown (git-fixes). - drm/radeon: fix r100_copy_blit for large BOs (stable-fixes). - drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). - drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). - drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). - drm/ssd130x: fix column and row end address in partial updates in ssd133x (git-fixes). - drm/sun4i: crtc: Propagate layer initialization error (git-fixes). - drm/sun4i: Drop node references while building component list (git-fixes). - drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). - drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). - drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). - drm/sun4i: hdmi: Don't leak sync polarity bits into packet control (git-fixes). - drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). - drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). - drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). - drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). - drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). - drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info (git-fixes). - drm/tve200: add OF module alias for autoloading (git-fixes). - drm/virtio: Fix a NULL vs ERR_PTR() bug in virtio_gpu_user_framebuffer_create() (git-fixes). - drm/xe/oa: Check managed mutex initialization errors (git-fixes). - drm/xe/oa: Fix sync entry leak on OA config emit failure (git-fixes). - drm/xe/oa: Remove sysfs entry on idr_alloc failure in xe_oa_add_config_ioctl() (git-fixes). - drm/xe: Introduce xe_gt_dbg_printer() (stable-fixes). - drm/xe: Order ring writes before ring tail updates (git-fixes). - drm/xe: Stub out new pagefault layer (stable-fixes). - drm/xe: tests: fix error message in xe_migrate_sanity_test() (git-fixes). - drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used (git-fixes). - drm: fix race between partial drm_dev_register() failure and ioctl (git-fixes). - drm: lcdif: Wait for vblank before disabling DMA (git-fixes). - drm: Remove unused header in drm_dumb_buffers.c (git-fixes). - efi: fix stale reference to efi_recover_from_page_fault() (git-fixes). - erspan: Initialize options_len before referencing options (bsc#1274727). - ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). - fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). - fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). - fbdev: kyro: Validate overlay viewport coordinates (git-fixes). - fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). - fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). - fbdev: uvesafb: unregister connector callback on init failure (git-fixes). - fbdev: vfb: defer cleanup until the last reference (git-fixes). - firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). - firmware: arm_scmi: Clean up channels on setup failure (git-fixes). - firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). - firmware: arm_scmi: Fix requested device removal race (git-fixes). - firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). - firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). - firmware: arm_scmi: Publish channel state before callbacks (git-fixes). - firmware: arm_scmi: Quiesce notifications before teardown (git-fixes). - firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (git-fixes). - firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). - firmware: arm_scmi: Roll back partial protocol table registration (git-fixes). - firmware: arm_scmi: Unregister device notifier before IDR teardown (git-fixes). - firmware: arm_scmi: Unrequest devices if driver registration fails (git-fixes). - firmware: arm_scmi: Unwind P2A receiver mailbox setup failure (git-fixes). - firmware: arm_scmi: Unwind TX receiver mailbox setup failure (git-fixes). - firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). - firmware_loader: do not queue completed sysfs fallback requests (git-fixes). - fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git-fixes). - fpga: dfl: fme: add error handling (git-fixes). - fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git-fixes). - fuse: fix race between interrupt and resend (git-fixes). - gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind (git-fixes). - gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). - gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). - gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings (stable-fixes). - HID: asus: fix missing hid_is_usb() check (git-fixes). - HID: asus: simplify RGB init sequence (stable-fixes). - HID: bpf: serialize device reference release in struct_ops destroy path (git-fixes). - HID: core: fix number/pointer type confusion on long items (git-fixes). - HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). - HID: ft260: fix stack-use-after-return write in I2C read race (git-fixes). - HID: ft260: validate i2c input report length (stable-fixes). - HID: hyperv: validate initial device info bounds (git-fixes). - HID: i2c-hid: Fix '(null)' output when reading report descriptor fails (git-fixes). - HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). - HID: lg4ff: validate report length before fixed offsets (git-fixes). - HID: logitech-dj: Fix maxfield check in DJ short report validation (git-fixes). - HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git-fixes). - HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). - HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable-fixes). - HID: magicmouse: do not keep a stale msc->input if no input is claimed (git-fixes). - HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C (git-fixes). - HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). - HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git-fixes). - HID: magicmouse: re-enable multitouch after reset-resume (git-fixes). - HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). - HID: multitouch: reclassify HTIX5288 to WIN_8_FORCE_MULTI_INPUT_NSMU (git-fixes). - HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). - HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git-fixes). - HID: nintendo: register input device after capabilities are set (git-fixes). - HID: nintendo: stop device IO before hid_hw_stop on probe failure (git-fixes). - HID: picolcd: clamp eeprom debugfs read to bytes actually received (git-fixes). - HID: pidff: Rework pidff_set_time() to fix warnings (stable-fixes). - HID: pidff: Use ARRAY_SIZE macro instead of sizeof (stable-fixes). - HID: rmi: fix OOB access with undersized RMI reports (git-fixes). - HID: roccat: bound device-supplied profile index (git-fixes). - HID: roccat: free buffered reports when destroying device (git-fixes). - HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git-fixes). - HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). - HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). - HID: synchronize input before cleaning up a failed probe (git-fixes). - HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). - HID: wacom: validate report length in wacom_intuos_pro2_bt_irq (git-fixes). - hwmon: (ads7828) Fix external VREF regulator handling (git-fixes). - hwmon: (applesmc) fix key backlight workqueue leak on register failure (git-fixes). - hwmon: (aspeed-pwm-tacho) Propagate reset deassert errors (git-fixes). - hwmon: (chipcap2) fix channels in humidity alarm notifications (git-fixes). - hwmon: (coretemp) Fix core_data leak on CPUs without PTS (git-fixes). - hwmon: (corsair-cpro) Create debugfs entries after hwmon registration (git-fixes). - hwmon: (corsair-cpro) Remove debugfs entries when probe fails (git-fixes). - hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). - hwmon: (gpio-fan) Fix use-after-free in alarm work (git-fixes). - hwmon: (gpio-fan) take fan_data->lock in gpio_fan_shutdown() (git-fixes). - hwmon: (ina2xx) Add support for has_alerts configuration flag (stable-fixes). - hwmon: (ina2xx) Add support for INA234 (stable-fixes). - hwmon: (ina2xx) Add support for INA260 (stable-fixes). - hwmon: (ina2xx) Fix various overflow issues (git-fixes). - hwmon: (ina2xx) Make it easier to add more devices (stable-fixes). - hwmon: (ina2xx) Shift INA234 shunt and current registers (stable-fixes). - hwmon: (ina226) Add support for SY24655 (stable-fixes). - hwmon: (ltc4282) Avoid overflow in maximum power calculation (git-fixes). - hwmon: (ltc4282) Clamp negative current limits (git-fixes). - hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt (git-fixes). - hwmon: (ltc4282) Make sure clk_init_data is fully initialized (git-fixes). - hwmon: (max6621) fix negative temperature offset and crit readings (git-fixes). - hwmon: (max6621) fix temperature clamp range (git-fixes). - hwmon: (nzxt-smart2) Check return value of init_device() in probe (git-fixes). - hwmon: (pmbus) Clear generic status alarms with CLEAR_FAULTS (git-fixes). - hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). - hwmon: Switch back to struct platform_driver::remove() (stable-fixes). - hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). - hwrng: omap - Fix probe error path cleanup (git-fixes). - hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git-fixes). - i2c: core: fix debugfs UAF on adapter removal (git-fixes). - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (git-fixes). - i2c: imx: separate atomic, dma and non-dma use case (stable-fixes). - i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). - i2c: mux: Fix channel node leak on adapter add failure (git-fixes). - i2c: ocores: Disable clock on failed resume (git-fixes). - i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). - i3c: dw: rename 'pclk' to 'apb' to match dt-binding (git-fixes). - i3c: master: Fix device_register() error path (git-fixes). - i3c: master: Fix info leak and UAF in device unregister path (git-fixes). - i3c: master: Fix potential UAF in i3c_device_uevent() (git-fixes). - i3c: master: svc: bound IBI payload to the requested max_payload_len (git-fixes). - ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink (git-fixes). - ieee802154: cc2520: fix FIFOP work use-after-free (git-fixes). - ieee802154: hwsim: serialize pib updates to fix double-free (git-fixes). - iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). - iio: adc: max34408: add missing 'select REGMAP_I2C' to Kconfig (git-fixes). - iio: adc: pac1921: fix wrong channel used in trigger handler read (git-fixes). - iio: buffer: Fix potential use-after-free in anonymous buffer release (git-fixes). - iio: buffer: Make IIO DMA fence release RCU-safe (git-fixes). - iio: buffer: Tie IIO dma fence lock lifetime to the fence (git-fixes). - iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). - iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). - iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). - iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). - iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). - iio: light: cm32181: return zero after writing calibscale (git-fixes). - iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). - iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). - iio: light: isl29028: return zero in write_raw() on success (git-fixes). - iio: light: ltrf216a: fix runtime PM reference leak in error path (git-fixes). - iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem() (git-fixes). - iio: light: opt4001: Fix power down clearing bits of the wrong register (git-fixes). - iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask (git-fixes). - iio: light: opt4001: Reject integration times with a non-zero seconds part (git-fixes). - iio: light: tsl2583: return zero in write_raw() on success (git-fixes). - iio: light: tsl2772: fix ALS calibscale readback (git-fixes). - iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). - iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git-fixes). - iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). - iio: srf04: fix pm_runtime handling on probe error path (git-fixes). - iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). - Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). - Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). - Input: cs40l50-vibra - validate custom data from user space (git-fixes). - Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). - Input: evdev - sanitize event type index when fetching event masks (stable-fixes). - Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). - Input: focaltech - use signed coordinates to prevent underflow (git-fixes). - Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). - Input: iforce - validate input packet lengths (stable-fixes). - Input: iqs5xx - validate firmware record destination span (git-fixes). - Input: mms114 - fix Y-resolution configuration (git-fixes). - Input: psxpad-spi - set driver data before use (git-fixes). - Input: reject inhibit and uninhibit requests on unregistering devices (git-fixes). - Input: sur40 - fix input device registration ordering (stable-fixes). - Input: sur40 - fix V4L error path cleanup (stable-fixes). - Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). - Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). - Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git-fixes). - Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git-fixes). - Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). - Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). - interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). - io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item (git-fixes). - io_uring/net: Avoid msghdr on op_connect/op_bind async data (git-fixes). - iommu/arm-smmu-v3: Manage teardown with devm (stable-fixes). - ip_tunnel: Use ip_tunnel_info() helper instead of 'info + 1' (bsc#1274727). - ipmi: ipmb: validate write message length (git-fixes). - ipmi: si: Fix NULL pointer dereference after failed registration (git-fixes). - KVM: arm64: Ensure FFA ranges are page aligned (git-fixes). - KVM: arm64: Fix bounds checking in do_ffa_mem_reclaim() (git-fixes). - KVM: arm64: Fix sign-extension of MMIO loads (git-fixes). - KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure (git-fixes). - KVM: arm64: Zero out the stack initialized data in the FFA handler (git-fixes). - KVM: nSVM: Always inject a #GP if mapping VMCB12 fails on nested VMRUN (git-fixes). - KVM: nSVM: Remove a user-triggerable WARN on nested_svm_load_cr3() succeeding (git-fixes). - KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit (git-fixes). - KVM: nVMX: Service local TLB flushes on failed nested VM-Enter (git-fixes). - KVM: PPC: Book3S HV: Add support for compat CPU capabilities for KVM on PowerNV (bsc#1263864 ltc#217835). - KVM: PPC: Book3S HV: Implement compat CPU capability retrieval for KVM on PowerVM (bsc#1263864 ltc#217835). - KVM: PPC: Book3S HV: Validate arch_compat against host compatibility mode (bsc#1263864 ltc#217835). - KVM: PPC: Document KVM_PPC_GET_COMPAT_CAPS ioctl (bsc#1263864 ltc#217835). - KVM: PPC: Introduce KVM_CAP_PPC_COMPAT_CAPS and wire up ioctl (bsc#1263864 ltc#217835). - KVM: SEV: Use to_kvm_sev_info() for fetching kvm_sev_info struct (git-fixes). - KVM: SVM: Add support to initialize SEV/SNP functionality in KVM (bsc#1279887). - KVM: SVM: Explicitly mark vmcb01 dirty after modifying VMCB intercepts (git-fixes). - KVM: SVM: Serialize accesses to the owner and mirror list with separate lock (git-fixes). - KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (git-fixes). - KVM: TDX: Account all non-transient page allocations for per-TD structures (git-fixes). - KVM: TDX: Fix x2APIC MSR handling in tdx_has_emulated_msr() (git-fixes). - KVM: VMX: Don't register posted interrupt wakeup handler if alloc_kvm_area() fails (git-fixes). - KVM: x86/hyperv: Check for NULL vCPU Hyper-V object in kvm_hv_get_tlb_flush_fifo() (git-fixes). - KVM: x86/hyperv: Ensure vCPU's Hyper-V object is initialized on cross-vCPU accesses (git-fixes). - KVM: x86/hyperv: Get target FIFO in hv_tlb_flush_enqueue(), not caller (git-fixes). - KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). - KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). - KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). - KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). - KVM: x86: Don't WARN if IRQ disappears because it was cleared from the PIC (git-fixes). - KVM: x86: Don't WARN if IRQ disappears when Xen emulation is enabled (git-fixes). - KVM: x86: Fix array_index_nospec() protection in kvm_vcpu_ioctl_x86_set_mce() (git-fixes). - KVM: x86: Fix emulated CPUID features being applied to wrong sub-leaf (git-fixes). - KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock (git-fixes). - leds: pca9532: Fix inverted GPIO output polarity (git-fixes). - leds: pca9532: Fix phantom device registration on missing hardware (git-fixes). - lib/string: fix memchr_inv() for large ranges (git-fixes). - lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). - mac802154: fix data race and NULL deref on local->assoc_dev (git-fixes). - mac802154: fix netdev use-after-free in beacon worker (git-fixes). - mac802154: fix use-after-free of sdata via queued RX frames (git-fixes). - mailbox: pcc: Fix command timeout due to missed interrupt (git-fixes). - mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler (git-fixes). - mailbox: qcom-cpucp: handle NULL data in send_data callback (git-fixes). - mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git-fixes). - mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). - maple_tree: fix argument name in header (git-fixes). - md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). - media: airspy: Return queued buffers on start_streaming() failure (git-fixes). - media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). - media: amphion: Remove obsolete frame_count check in venc_start_session (git-fixes). - media: bcm2835-unicam: Fix asc leaked in error/remove path (git-fixes). - media: cec-pin: Fix event FIFO ordering (git-fixes). - media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). - media: cec: extron-da-hd-4k-plus: add sanity check (git-fixes). - media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). - media: cec: Serialize exclusive follower delivery (git-fixes). - media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). - media: cedrus: clean up media device on probe failure (git-fixes). - media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). - media: chips-media: wave5: Guard bit depth check with initial_info_obtained (git-fixes). - media: chips-media: wave5: Move src_buf Removal to finish_encode (git-fixes). - media: cobalt: Avoid freeing ALSA private data twice (git-fixes). - media: cx231xx: fix devres lifetime (git-fixes). - media: cx231xx: reject geometry changes while the VBI queue is busy (git-fixes). - media: cx23885: add ioremap return check and cleanup (git-fixes). - media: cx23885: cancel NetUP CI work before teardown (git-fixes). - media: em28xx: defer audio-only extension registration (git-fixes). - media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git-fixes). - media: go7007: defer the ALSA v4l2 put until card release (git-fixes). - media: hevc: add bounded tile-count helpers (git-fixes). - media: i2c: alvium: fix critical pointer access in alvium_ctrl_init (git-fixes). - media: i2c: alvium: Fix: Correct name of register in alvium_set_ctrl_auto_exposure (git-fixes). - media: i2c: imx219: Rename VTS to FRM_LENGTH (stable-fixes). - media: i2c: imx415: Return test pattern write errors (git-fixes). - media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). - media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). - media: i2c: rdacm21: Fix missing media_entity_cleanup() (git-fixes). - media: imx219: Fix maximum frame length in lines (git-fixes). - media: intel/ipu6: fix async notifier cleanup leak on parse error (git-fixes). - media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges (git-fixes). - media: ipu6: Do not free aux device pdata after init (git-fixes). - media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git-fixes). - media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). - media: mc-entity: Add missing kerneldoc (git-fixes). - media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity (git-fixes). - media: meson: vdec: Fix memory leak in error path of vdec_open (git-fixes). - media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git-fixes). - media: msi2500: Return queued buffers on start_streaming() failure (git-fixes). - media: nuvoton: npcm-video: fix error handling in npcm_video_init() (git-fixes). - media: nuvoton: npcm-video: fix memory leaks in probe and remove (git-fixes). - media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe (git-fixes). - media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure (git-fixes). - media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). - media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path (git-fixes). - media: nxp: imx8-isi: Fix potential out-of-bounds issues (git-fixes). - media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding (git-fixes). - media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). - media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). - media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode() (stable-fixes). - media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup (git-fixes). - media: platform: mtk-mdp3: Fix SCP device refcounting (git-fixes). - media: pwc: Drain fill_buf on start_streaming() failure (git-fixes). - media: pwc: Return queued buffers on start_streaming() failure (git-fixes). - media: qcom: camss: Fix RDI streaming for CSID GEN2 (git-fixes). - media: radio-si476x: Unregister v4l2_device on probe failure (git-fixes). - media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). - media: rtl2832: fix use-after-free in rtl2832_remove() (git-fixes). - media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). - media: rtl2832_sdr: Return queued buffers on start_streaming() failure (git-fixes). - media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). - media: s2255: bound JPEG frame size before copying into the buffer (git-fixes). - media: s2255: check firmware size before reading trailing marker (git-fixes). - media: saa7134: Fix a possible memory leak in saa7134_video_init1 (git-fixes). - media: saa7164: fix cleanup on resource allocation failure (git-fixes). - media: stm32: dcmi: unregister notifier on probe failure (git-fixes). - media: sun4i-csi: Return queued buffers on start_streaming() failure (git-fixes). - media: tda18250: fix possible integer overflow (git-fixes). - media: tegra-video: vi: fix invalid u32 return value in format lookup (git-fixes). - media: usbtv: keep device alive while ALSA card exists (git-fixes). - media: v4l2-async: avoid deleting unlinked ASC entry on link error (git-fixes). - media: v4l2-async: Unregister sub-device if asc_list is empty (git-fixes). - media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (git-fixes). - media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git-fixes). - media: v4l2-ctrls: validate AV1 tile counts (git-fixes). - media: v4l2-ctrls: validate HEVC tile counts (git-fixes). - media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). - media: v4l2-h264: Fix memcmp() size in B1 reference list comparison (git-fixes). - media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely (git-fixes). - media: venus: fix payload size calculation in parse_raw_formats() (git-fixes). - media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). - media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity (git-fixes). - media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer (git-fixes). - media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity (git-fixes). - media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). - media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). - media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). - media: vivid: add vivid_update_reduced_fps() (git-fixes). - media: vivid: check for vb2_is_busy() when toggling caps (git-fixes). - media: vivid: fix cleanup bugs in vivid_init() (git-fixes). - media: zoran: Avoid freeing a registered video_device twice (git-fixes). - mei: pull kvfree out of spinlock (git-fixes). - mfd: iqs62x: Reject zero-length firmware records (git-fixes). - mfd: rave-sp: validate received frame payload lengths (git-fixes). - mfd: sm501: Fix potential memory leaks during remove (git-fixes). - misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). - misc: fastrpc: fix channel ctx ref leak when session alloc fails (git-fixes). - misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). - misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). - misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git-fixes). - misc: nsm: bound the device-reported response length (git-fixes). - misc: rtsx: add missing write register handling (git-fixes). - misc: sgi-gru: remove interrupt-context page-table walks (git-fixes). - misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git-fixes). - mkspec-dtb: Move DTS prefix into package list. - mkspec-dtb: Move provides-obsoletes to package list. - mkspec-dtb: Put per-architecture package lists into a hash. - mkspec-dtb: re-indent. - mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition (git-fixes). - mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git-fixes). - mmc: sdhci: unmap the bounce buffer before device release (git-fixes). - mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). - mtd: afs: validate v2 image info bounds (git-fixes). - mtd: fix double free and WARN_ON in add_mtd_device() error paths (git-fixes). - mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). - mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). - mtd: mtdswap: remove debugfs stats file on teardown (git-fixes). - mtd: nand: mtk-ecc: stop on ECC idle timeouts (git-fixes). - mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). - mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). - mtd: spinand: fix direct mapping creation sizes (stable-fixes). - mtd: spinand: repeat reading in regular mode if continuous reading fails (stable-fixes). - mtd: spinand: try a regular dirmap if creating a dirmap for continuous reading fails (stable-fixes). - mtd: ubi: Release device reference on busy detach (git-fixes). - mtd: ubi: skip programming unused bits in ubi headers (stable-fixes). - net: Add options as a flexible array to struct ip_tunnel_info (bsc#1274727). - net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). - net: mana: Add handler for sriov configure (bsc#1272756). - net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). - net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). - net: mana: Fall back to scattered pages for GDMA queues (git-fixes). - net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). - net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). - net: mana: Route ring-buffer access through offset-based helpers (git-fixes). - net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). - net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git-fixes). - net: thunderbolt: Mark the connection down when bringing it up fails (git-fixes). - net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git-fixes). - net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). - net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). - net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow (git-fixes). - net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). - net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition (git-fixes). - nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). - nfc: digital: Do not dump a NULL response in command completion (git-fixes). - nfc: fdp: bound the device-reported read length and fix an skb leak (git-fixes). - nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). - nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git-fixes). - nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). - nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). - nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git-fixes). - nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). - nfc: microread: validate target discovery payload lengths (git-fixes). - nfc: nci: fix double completion race in nci_data_exchange_complete (git-fixes). - nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git-fixes). - nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git-fixes). - nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git-fixes). - nfc: nci: free destination parameters when closing a connection (git-fixes). - nfc: pn533: hold a reference to the request skb during send_frame (git-fixes). - nfc: pn533: purge fragmented skbs during cleanup (git-fixes). - nfc: st21nfca: validate ATR_REQ length against the received frame (git-fixes). - nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git-fixes). - nvme-tcp: fix usage of page_frag_cache (bsc#1267882). - nvmet-rdma: fix queue leak when connect backlog is exceeded (git-fixes). - of: fix out-of-bounds read in of_alias_scan() stem parser (git-fixes). - PCI/ASPM: Use pcie_capability_clear_and_set_word() for ASPM disable/restore (git-fixes). - PCI/proc: Avoid spurious runtime PM wakeup on config space accesses (git-fixes). - PCI/proc: Use file_ns_capable() when checking config space read access (git-fixes). - PCI/proc: Warn on writes to kernel-exclusive config space regions (git-fixes). - PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses (git-fixes). - PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). - PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git-fixes). - PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). - PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). - PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() (git-fixes). - PCI: plda: Fix use-after-free of event IRQs during teardown (git-fixes). - perf: Reject exited events as group leaders (git-fixes). - pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). - pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). - pinctrl: rockchip: Reset the pin count when recalculating SoC data (git-fixes). - platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). - platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). - platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git-fixes). - platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). - platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git-fixes). - platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). - platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git-fixes). - platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). - platform/x86/amd/hsmp: Reject negative power cap writes in hwmon (git-fixes). - platform/x86: asus-wmi: fix resource leaks on probe failure (git-fixes). - platform/x86: dell-privacy: Fix race condition (git-fixes). - platform/x86: dell-wmi-base: Fix resource leak on module load failure (git-fixes). - platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). - platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). - platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS (git-fixes). - platform/x86: hp-bioscfg: advance elem past consumed array elements (git-fixes). - platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() (git-fixes). - platform/x86: hp-bioscfg: fix heap OOB read on empty password write (git-fixes). - platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password (git-fixes). - platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() (git-fixes). - platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed (git-fixes). - platform/x86: hp-bioscfg: fix password encoding bounds check (git-fixes). - platform/x86: hp-bioscfg: warn on element type mismatch instead of failing (git-fixes). - platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). - platform/x86: ISST: Add a NULL check for sst_inst (git-fixes). - platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). - platform/x86: ISST: Return error during profile addition (git-fixes). - platform/x86: ISST: Use PP level enable mask (git-fixes). - platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). - platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). - platform/x86: ISST: Validate parameter for core power state (git-fixes). - platform/x86: ISST: Validate parameter for frequency and priority (git-fixes). - platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). - PM: hibernate: Fix memory leak in snapshot_write_next() error path (git-fixes). - PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). - power: supply: bd99954: Drop bad register fields (git-fixes). - power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git-fixes). - power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git-fixes). - power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). - power: supply: bq256xx: drain usb_work before freeing the charger (git-fixes). - power: supply: bq24257: fix use-after-free on remove (git-fixes). - power: supply: bq25890: Fix power_supply reference leak (git-fixes). - power: supply: charger-manager: register regulators before exposing sysfs (git-fixes). - power: supply: cros_usbpd-charger: bound the EC-reported port count (git-fixes). - power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git-fixes). - power: supply: isp1704_charger: cancel work on remove (git-fixes). - power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git-fixes). - power: supply: lp8788-charger: fix use-after-free on remove (git-fixes). - power: supply: max17040: drop incorrect I2C functionality check (git-fixes). - power: supply: max17040: propagate register read errors (git-fixes). - power: supply: max17040: synchronize work cancellation on suspend (git-fixes). - power: supply: qcom_battmgr: terminate the strings from firmware (git-fixes). - power: supply: rt9455: quiesce delayed work before teardown (git-fixes). - power: supply: sbs-battery: Use a per-device serial number buffer (git-fixes). - power: supply: sc2731_charger: cancel work on remove (git-fixes). - power: supply: twl4030_charger: cancel workers via devm (git-fixes). - power: supply: ucs1002: fix use-after-free on remove (git-fixes). - powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). - powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors (bsc#1263864 ltc#217835). - powerpc/kexec_file: Use inclusive range checks in add_usable_mem() (git-fixes). - powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). - powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). - powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak (bsc#1274751 ltc#221105 bsc#1274750 ltc#221106). - powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). - powerpc/rtas_pci: No hotplug on permanently removed device on pSeries (git-fixes). - powerpc: Replace __ASSEMBLY__ with __ASSEMBLER__ in non-uapi headers (bsc#1263864 ltc#217835). - powerpc: Replace __ASSEMBLY__ with __ASSEMBLER__ in uapi headers (bsc#1263864 ltc#217835). - ppdev: prevent overflow when setting port timeout (git-fixes). - rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() (git-fixes). - rapidio: clear mport->net when rio_add_net() fails (git-fixes). - rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). - RDMA/bnxt_re: Avoid displaying the kernel pointer (git-fixes). - RDMA/bnxt_re: Proper rollback if the ioremap fails (git-fixes). - RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). - RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). - RDMA/mana_ib: unify QP lookup table (git-fixes). - RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). - regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). - regulator: core: use system_freezable_wq for init complete work (git-fixes). - regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). - regulator: qcom-refgen: correct the regulator type to CURRENT (git-fixes). - regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). - remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). - remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). - remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). - Revert 'drm/amdgpu: fix aperture mapping leak' (git-fixes). - Revert 'media: v4l2-dev: fix error handling in __video_register_device()' (git-fixes). - Revert 'net: thunderbolt: Enable end-to-end flow control also in transmit' (git-fixes). - Revert 'thermal/drivers/hwmon: Cleanup coding style a bit' (stable-fixes). - Revert 'wifi: mt76: Disable napi when removing device' (git-fixes). - rpmsg: core: Fix incorrect return value documentation (git-fixes). - rpmsg: glink: smem: order FIFO read after availability check (git-fixes). - rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). - rtc: pcf8563: fix clock provider leak on unbind (git-fixes). - rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). - rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). - rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git-fixes). - rtc: zynqmp: Return optional clock lookup errors (git-fixes). - s390/pkey: Check length in pkey_pckmo handler implementation (bsc#1270266). - s390/pkey: Check length in PKEY_VERIFYPROTK ioctl (bsc#1270267). - sched/psi: Create the psimon kthread outside of cgroup_mutex (bsc#1269134). - scsi: fnic: Abort timed-out NVMe LS requests (bsc#1236344). - scsi: fnic: Add and improve logs in FDMI and FDMI ABTS paths (bsc#1236344). - scsi: fnic: Add FDLS role handling for NVMe initiators (bsc#1236344). - scsi: fnic: Add the NVMe/FC transport path (bsc#1236344). - scsi: fnic: Advertise NVMe initiator service parameters (bsc#1236344). - scsi: fnic: Bump up version number (bsc#1236344). - scsi: fnic: Decode firmware role configuration (bsc#1236344). - scsi: fnic: Do not use GFP_ZERO for mempools (bsc#1236344). - scsi: fnic: Expose NVMe transport state in debugfs (bsc#1236344). - scsi: fnic: Handle NVMe LS frames in FDLS (bsc#1236344). - scsi: fnic: Make debug logging protocol independent (bsc#1236344). - scsi: fnic: Make fnic_queuecommand() easier to analyze (bsc#1236344). - scsi: fnic: Refactor in_remove flag and call to fnic_fcpio_reset() (bsc#1236344). - scsi: fnic: Remove a useless struct mempool forward declaration (bsc#1236344). - scsi: fnic: Rename fnic_scsi_fcpio_reset() (bsc#1236344). - scsi: fnic: Route completions and resets by initiator role (bsc#1236344). - scsi: fnic: Self-assignment of intr_time_type has no effect (bsc#1236344). - scsi: fnic: Send NVMe LS requests through FDLS (bsc#1236344). - scsi: fnic: Switch to use %ptSp (bsc#1236344). - scsi: fnic: Track NVMe transport statistics (bsc#1236344). - scsi: fnic: Use fnic_num for non-SCSI identifiers (bsc#1236344). - scsi: fnic: Use mempool for receive frames (bsc#1236344). - scsi: qla2xxx: Add support to report MPI FW state (bsc#1275737). - scsi: qla2xxx: Declare qla2xxx_mqueuecommand() static (bsc#1275737). - scsi: qla2xxx: Use nr_cpu_ids instead of NR_CPUS for qp_cpu_map allocation (bsc#1275737). - scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). - sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). - selftests/alsa: Fix the step check for INTEGER controls (git-fixes). - serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). - serial: amba-pl011: unprepare console clock on unregister (git-fixes). - serial: core: clear freed pointers on uart_register_driver() failure (git-fixes). - serial: imx: serialize imx_uart_ports lifetime (git-fixes). - serial: ma35d1: Fix OF node reference leaks in console init (git-fixes). - serial: qcom-geni: do not advance stale DMA completions (git-fixes). - serial: qcom-geni: fix TX DMA buffer flush (git-fixes). - serial: sc16is7xx: enable THRI before filling TX FIFO (git-fixes). - serial: sc16is7xx: rename EFR mutex with generic name (stable-fixes). - serial: sc16is7xx: use guards for simple mutex locks (stable-fixes). - slab.h: disable completely broken overflow handling in flex allocations (bsc#1280139). - slab: Introduce kmalloc_flex() and family (bsc#1280139). - slab: Introduce kmalloc_obj() and family (bsc#1280139). - slab: recognize @GFP parameter as optional in kernel-doc (bsc#1280139). - smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). - smb: client: harden POSIX SID length parsing (bsc#1273557). - smb: client: require net admin for CIFS SWN netlink (bsc#1273966). - smb: client: resolve SWN tcon from live registrations (bsc#1273872). - soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git-fixes). - soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). - soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). - software node: Fix software_node_get_reference_args() with index -1 (git-fixes). - soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git-fixes). - speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git-fixes). - spi: bcm63xx-hsspi: disable clocks on resume failure (git-fixes). - spi: bcm63xx: disable clock on resume failure (git-fixes). - spi: bcmbca-hsspi: disable clocks on resume failure (git-fixes). - spi: davinci: switch to managed controller allocation (git-fixes). - spi: Fix DMA mapping ownership on partial map failure (git-fixes). - spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). - spi: oc-tiny: switch to managed controller allocation (git-fixes). - spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX (git-fixes). - spi: spi-cadence: Move TX FIFO full busy-wait into FIFO (git-fixes). - spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 (stable-fixes). - spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). - spi: sprd-adi: Fix probe succeeding without registering the controller (git-fixes). - staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). - staging: media: tegra-video: fix of_node_put() on VIP parse errors (git-fixes). - staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). - staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git-fixes). - staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). - staging: rtl8723bs: fix missing shared-key auth challenge length check (git-fixes). - staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() (git-fixes). - staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() (git-fixes). - staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). - staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). - staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() (git-fixes). - staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). - staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). - staging: sm750fb: Add missing Kconfig dependency (git-fixes). - staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). - thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). - thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). - thermal/drivers/rcar: Fix error checking in probe() (git-fixes). - thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). - thermal: sysfs: switch to use scnprintf() to suppress truncation warning (git-fixes). - thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). - thunderbolt: Fix bandwidth group reservation indexing (git-fixes). - thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). - tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). - tpm: st33zp24: Return zero on status read failure (git-fixes). - tpm: st33zp24: Validate locality read result (git-fixes). - tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). - tty: clear cdev pointer after cdev_add() failure (git-fixes). - tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). - tty: skip cdev_del() when no cdev is registered (git-fixes). - uio: Fix stale info pointer in failed registration path (git-fixes). - usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). - usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (git-fixes). - usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). - USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). - usb: cdnsp: fix incorrect endian conversions for APB timeout register (git-fixes). - usb: core: Add lock to usb_wakeup_notification() (git-fixes). - usb: core: Add lock to usb_wakeup_notification() (stable-fixes). - usb: core: Strengthen error handling in hub_hub_status() (git-fixes). - usb: core: Strengthen error handling in hub_hub_status() (stable-fixes). - usb: core: sysfs: add lock to bos_descriptors_read() (stable-fixes). - usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). - usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). - usb: dwc3: clear forceRM when issuing EndTransfer (git-fixes). - usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition (git-fixes). - usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns() (git-fixes). - usb: fix UAF when probe runs concurrent to dyn ID removal (git-fixes). - usb: gadget: aspeed_udc: check endpoint DMA allocation (git-fixes). - usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed (git-fixes). - usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). - usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths (git-fixes). - usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). - usb: gadget: f_midi: initialize work in f_midi_alloc() (git-fixes). - usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). - usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). - usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git-fixes). - usb: gadget: fix null pointer dereference in usb_put_function_instance() (git-fixes). - USB: gadget: fsl-udc: fix dev_printk() device (git-fixes). - usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs (git-fixes). - usb: gadget: midi2: remove default configfs groups on teardown (git-fixes). - usb: gadget: pch_udc: remove excess kernel-doc member for registered (git-fixes). - usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). - usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). - usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git-fixes). - usb: gadget: uac: validate rate list length before storing (git-fixes). - USB: gadget: Use str_enable_disable-like helpers (stable-fixes). - usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). - usb: ljca: bound bank_num in ljca_enumerate_gpio() (git-fixes). - usb: mtu3: allow system suspend during active gadget connection (git-fixes). - usb: musb: omap2430: clean up probe error handling (stable-fixes). - usb: musb: omap2430: Do not put borrowed of_node in probe (git-fixes). - usb: musb: omap2430: Fix use-after-free in omap2430_probe() (git-fixes). - USB: phy: fsl-usb: fix missing static keywords (git-fixes). - usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). - USB: serial: digi_acceleport: fix port registration order (git-fixes). - USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). - USB: serial: option: add TDTECH MT5710-CN (stable-fixes). - USB: serial: option: fix slab OOB read in interrupt URB callback (git-fixes). - USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). - USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). - usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop (git-fixes). - usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails (git-fixes). - usb: typec: qcom-pmic: cancel reset_work on stop (git-fixes). - usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive() (git-fixes). - usb: typec: thunderbolt: Disable work before freeing tbt on remove (git-fixes). - usb: typec: ucsi: displayport: Fix OOB altmode array index (git-fixes). - usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). - usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion (git-fixes). - usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git-fixes). - usb: usbtest: disable dynamic ID support (stable-fixes). - usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). - vfs: Add a sysctl for automated deletion of dentry (bsc#1240890 bsc#1276586). - vt: add permission check for KDSKBMETA ioctl (stable-fixes). - vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable-fixes). - w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). - w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). - watchdog: bd96801_wdt: Fix timeout for enabled WDG (git-fixes). - watchdog: fix hrtimer start when pretimeout is zero (git-fixes). - watchdog: msc313e: Avoid division by zero (git-fixes). - watchdog: msc313e: Enable clock before accessing hardware registers (git-fixes). - watchdog: msc313e: Fix clock leak and spurious timer in settimeout() (git-fixes). - watchdog: msc313e: Fix NULL pointer dereference in PM callbacks (git-fixes). - watchdog: msc313e: Fix spurious reset on suspend (git-fixes). - watchdog: msc313e: Fix undefined behavior (git-fixes). - watchdog: msc313e: Sync timeout value if WDT was running at boot (git-fixes). - watchdog: sunxi_wdt: preserve boot-enabled watchdog (git-fixes). - wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). - wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). - wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). - wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). - wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git-fixes). - wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). - wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() (git-fixes). - wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). - wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). - wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). - wifi: brcmfmac: fix P2P action frame handling without device vif (git-fixes). - wifi: brcmfmac: initialize SDIO data work before cleanup (git-fixes). - wifi: cfg80211: bound element ID read when checking non-inheritance (git-fixes). - wifi: cfg80211: cancel sched scan results work on unregister (git-fixes). - wifi: cfg80211: derive S1G beacon TSF from S1G fields (git-fixes). - wifi: cfg80211: reject unsupported PMSR FTM location requests (git-fixes). - wifi: cfg80211: validate PMSR FTM preamble range (git-fixes). - wifi: cfg80211: validate PMSR measurement type data (git-fixes). - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (git-fixes). - wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). - wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). - wifi: iwlwifi: mei: check SAP message length before reading it (git-fixes). - wifi: iwlwifi: mei: pass correct argument to function (git-fixes). - wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). - wifi: libertas: fix memory leak in helper_firmware_cb() (git-fixes). - wifi: mac80211: disconnect on CSA to channel 0 (git-fixes). - wifi: mac80211: fix fils_discovery double free on alloc failure (git-fixes). - wifi: mac80211: fix per-STA profile length in cross-link CSA parsing (git-fixes). - wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure (git-fixes). - wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (git-fixes). - wifi: mac80211: send TWT teardown to peer after setup TX failure (git-fixes). - wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). - wifi: mac80211: skip unused probe response countdown offsets (git-fixes). - wifi: mt76: check txfree done event on the WED hw path (git-fixes). - wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). - wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). - wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). - wifi: mt76: fix non-AQL packet accounting for MLO stations (git-fixes). - wifi: mt76: fix stranded frames in mt76_txq_schedule_pending (git-fixes). - wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git-fixes). - wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). - wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete (git-fixes). - wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git-fixes). - wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git-fixes). - wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear (git-fixes). - wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). - wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git-fixes). - wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git-fixes). - wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). - wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). - wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git-fixes). - wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). - wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git-fixes). - wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). - wifi: mt76: mt7921: skip unknown CLC firmware records (git-fixes). - wifi: mt76: mt7921: validate CLC firmware records (git-fixes). - wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git-fixes). - wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git-fixes). - wifi: mt76: mt7925: update clc before setting sar power table (git-fixes). - wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git-fixes). - wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). - wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU (git-fixes). - wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). - wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git-fixes). - wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). - wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git-fixes). - wifi: mt76: only consume the WO drop bit on WED v2 devices (git-fixes). - wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). - wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). - wifi: nl80211: free RNR data on MBSSID mismatch (git-fixes). - wifi: nl80211: validate nested MBSSID IE blobs (git-fixes). - wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (git-fixes). - wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop (git-fixes). - wifi: rtl818x: initialize eeprom_93cx6 struct to zero (git-fixes). - wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). - wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids (git-fixes). - wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() (git-fixes). - wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). - wifi: rtw88: pci: fix resource leak on failed NAPI setup (git-fixes). - wifi: rtw89: fix HE extended capability length check (git-fixes). - wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git-fixes). - x86/virt/tdx: Print TDX module version during init (git-fixes). - x86/virt/tdx: Retrieve TDX module version (git-fixes). - xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). - xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). - xhci: fix lost bounce buffers on TDs spanning several ring segments (git-fixes). The following package changes have been done: - libuuid1-2.41.1-160000.5.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - liblastlog2-2-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - util-linux-systemd-2.41.1-160000.5.1 updated - kernel-default-base-6.12.0-160000.38.1.160000.2.24 updated - container:suse-sl-micro-6.2-base-os-container-latest-b418d673df310746ae418b83e1018dbff86b101a3ce3219953a070a6b628fe18-0 updated From sle-container-updates at lists.suse.com Wed Sep 23 08:30:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 23 Sep 2026 10:30:42 +0200 (CEST) Subject: SUSE-IU-2026:7308-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260923083042.778F3FF19@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7308-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.175 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.175 Severity : important Type : security References : 1236344 1240890 1240957 1249104 1255225 1255531 1256629 1256671 1258278 1260501 1260577 1261606 1262073 1262756 1263004 1263864 1263865 1264267 1264335 1264444 1264541 1264587 1264619 1264807 1264851 1265036 1265068 1265121 1265132 1265141 1265220 1266710 1266860 1266874 1266897 1266928 1267023 1267238 1267373 1267501 1267586 1267612 1267882 1267985 1268886 1268972 1268979 1269000 1269004 1269010 1269013 1269108 1269113 1269114 1269126 1269134 1269140 1269162 1269167 1269238 1269242 1269256 1269301 1269306 1269380 1269381 1269388 1269402 1269412 1269417 1269528 1269530 1269579 1269583 1269590 1269633 1269635 1269655 1269665 1269685 1269686 1269695 1269697 1269774 1269783 1269792 1269815 1269816 1269888 1269965 1269969 1269985 1269999 1270090 1270108 1270111 1270139 1270219 1270251 1270266 1270267 1271050 1271256 1271365 1271825 1272148 1272149 1272175 1272182 1272199 1272200 1272210 1272213 1272230 1272260 1272261 1272262 1272284 1272287 1272297 1272346 1272366 1272385 1272390 1272423 1272426 1272429 1272484 1272486 1272497 1272501 1272502 1272513 1272516 1272568 1272569 1272584 1272641 1272643 1272673 1272756 1272786 1272788 1272791 1272798 1272799 1272804 1272855 1272865 1272868 1272869 1272877 1272891 1272893 1272894 1272904 1272905 1272918 1272963 1272969 1272971 1272983 1272985 1273008 1273019 1273027 1273030 1273032 1273033 1273036 1273037 1273038 1273060 1273105 1273107 1273119 1273134 1273231 1273249 1273251 1273260 1273271 1273273 1273274 1273276 1273277 1273280 1273281 1273283 1273284 1273285 1273286 1273288 1273289 1273291 1273294 1273302 1273303 1273305 1273309 1273310 1273311 1273312 1273314 1273316 1273317 1273318 1273319 1273323 1273325 1273327 1273331 1273334 1273335 1273336 1273337 1273338 1273339 1273340 1273341 1273346 1273420 1273422 1273426 1273443 1273460 1273461 1273463 1273465 1273468 1273469 1273471 1273479 1273480 1273482 1273484 1273486 1273488 1273490 1273495 1273501 1273503 1273504 1273506 1273507 1273509 1273511 1273520 1273523 1273524 1273525 1273533 1273536 1273538 1273542 1273550 1273555 1273557 1273567 1273578 1273579 1273581 1273582 1273596 1273597 1273598 1273600 1273601 1273602 1273603 1273679 1273681 1273682 1273734 1273737 1273738 1273739 1273740 1273741 1273742 1273743 1273744 1273745 1273746 1273748 1273749 1273755 1273759 1273762 1273765 1273766 1273769 1273770 1273774 1273776 1273778 1273780 1273782 1273788 1273790 1273796 1273797 1273801 1273803 1273804 1273809 1273810 1273811 1273812 1273813 1273817 1273822 1273824 1273831 1273834 1273838 1273839 1273842 1273844 1273848 1273849 1273852 1273855 1273859 1273860 1273862 1273864 1273866 1273867 1273868 1273869 1273870 1273872 1273876 1273877 1273880 1273882 1273890 1273891 1273892 1273895 1273896 1273898 1273899 1273903 1273904 1273905 1273930 1273933 1273934 1273935 1273936 1273939 1273940 1273941 1273942 1273944 1273945 1273946 1273947 1273949 1273953 1273954 1273956 1273957 1273958 1273959 1273963 1273966 1273967 1273968 1273972 1273974 1273975 1273977 1273988 1273990 1273991 1273995 1273997 1273999 1274001 1274003 1274006 1274008 1274009 1274010 1274011 1274012 1274014 1274017 1274019 1274020 1274026 1274028 1274030 1274031 1274035 1274036 1274040 1274041 1274052 1274055 1274057 1274058 1274060 1274063 1274065 1274067 1274071 1274075 1274076 1274077 1274078 1274208 1274226 1274239 1274243 1274252 1274253 1274258 1274264 1274265 1274267 1274274 1274277 1274278 1274281 1274283 1274286 1274290 1274292 1274294 1274295 1274296 1274314 1274321 1274491 1274492 1274494 1274497 1274539 1274541 1274543 1274545 1274547 1274550 1274556 1274573 1274578 1274580 1274581 1274622 1274624 1274628 1274632 1274636 1274637 1274639 1274640 1274642 1274644 1274645 1274646 1274650 1274651 1274652 1274656 1274657 1274659 1274662 1274665 1274667 1274669 1274670 1274671 1274675 1274677 1274678 1274679 1274681 1274682 1274690 1274694 1274696 1274698 1274699 1274700 1274702 1274703 1274705 1274706 1274707 1274709 1274710 1274713 1274716 1274721 1274725 1274727 1274730 1274737 1274738 1274749 1274750 1274751 1274752 1274753 1274754 1274755 1274756 1274764 1274768 1274770 1274771 1274773 1274782 1274783 1274787 1274800 1274801 1274802 1274803 1274804 1274805 1274807 1274808 1274811 1274813 1274814 1274831 1274834 1274835 1274838 1274847 1274849 1274853 1274868 1274869 1274872 1274873 1274874 1274876 1274877 1274879 1274881 1274883 1274886 1274887 1274888 1274891 1274892 1274893 1274894 1274895 1274896 1274897 1274898 1274899 1274900 1274901 1274902 1274904 1274905 1274906 1274907 1274908 1274913 1274914 1274921 1274924 1274925 1274927 1274929 1274930 1274933 1274934 1274935 1274938 1274939 1274940 1274941 1274945 1274947 1274951 1274952 1274953 1274955 1274957 1274958 1274965 1274968 1274978 1274981 1275040 1275045 1275069 1275071 1275072 1275073 1275076 1275080 1275081 1275083 1275088 1275091 1275092 1275094 1275125 1275126 1275129 1275131 1275132 1275139 1275141 1275146 1275148 1275149 1275150 1275152 1275154 1275155 1275156 1275157 1275158 1275160 1275161 1275163 1275164 1275169 1275173 1275176 1275185 1275190 1275192 1275229 1275236 1275237 1275238 1275239 1275294 1275300 1275301 1275303 1275304 1275305 1275306 1275307 1275441 1275470 1275474 1275479 1275481 1275483 1275486 1275487 1275496 1275506 1275509 1275511 1275514 1275517 1275519 1275528 1275535 1275540 1275553 1275555 1275557 1275561 1275566 1275569 1275572 1275574 1275578 1275582 1275583 1275584 1275587 1275588 1275591 1275595 1275596 1275633 1275636 1275650 1275655 1275656 1275659 1275665 1275669 1275672 1275679 1275685 1275687 1275688 1275690 1275695 1275696 1275704 1275737 1275782 1275784 1275787 1275788 1275789 1275790 1275798 1275799 1275801 1275802 1275804 1275805 1275812 1275817 1275818 1275819 1275820 1275821 1275822 1275823 1275827 1275864 1275866 1275867 1275869 1275870 1275871 1275872 1275886 1275905 1275923 1275925 1275928 1275950 1275954 1275956 1275970 1275973 1275975 1275976 1275985 1276006 1276029 1276257 1276258 1276263 1276265 1276267 1276270 1276273 1276277 1276333 1276335 1276339 1276341 1276346 1276354 1276355 1276381 1276395 1276446 1276452 1276468 1276471 1276473 1276500 1276507 1276512 1276528 1276542 1276546 1276547 1276551 1276552 1276553 1276561 1276562 1276566 1276569 1276572 1276577 1276586 1276665 1276766 1276767 1276771 1276785 1276793 1276801 1276803 1276814 1276818 1276821 1276831 1276840 1276864 1276865 1276866 1276870 1276876 1276880 1276905 1276913 1276922 1276931 1276937 1276941 1276955 1276957 1276961 1277022 1277023 1277033 1277034 1277037 1277047 1277054 1277057 1277059 1277062 1277066 1277069 1277070 1277077 1277078 1277092 1277095 1277108 1277114 1277115 1277118 1277120 1277155 1277159 1277160 1277202 1277204 1277227 1277229 1277230 1277231 1277233 1277249 1277254 1277265 1277268 1277275 1277285 1277308 1277311 1277315 1277321 1277328 1277335 1277349 1277350 1277391 1277407 1277408 1277485 1277505 1277513 1277551 1277553 1277561 1277574 1277636 1277641 1277649 1277655 1277656 1277660 1277668 1277680 1277688 1277726 1277728 1277738 1277748 1277761 1277764 1277773 1277775 1277776 1277782 1277783 1277813 1277818 1277822 1277845 1277862 1277874 1277876 1277898 1277901 1277908 1277918 1278039 1278070 1278088 1278094 1278098 1278113 1278155 1278180 1278233 1278236 1278240 1278253 1278293 1278324 1278331 1278334 1278347 1278348 1278349 1278395 1278416 1278703 1278716 1278733 1279487 1279537 1279580 1279813 1279842 1279847 1279887 1280139 CVE-2025-68214 CVE-2025-68358 CVE-2025-68780 CVE-2025-71075 CVE-2026-13595 CVE-2026-23113 CVE-2026-23306 CVE-2026-23348 CVE-2026-27456 CVE-2026-31418 CVE-2026-31530 CVE-2026-31531 CVE-2026-43116 CVE-2026-43125 CVE-2026-43163 CVE-2026-43239 CVE-2026-43271 CVE-2026-43299 CVE-2026-43331 CVE-2026-43355 CVE-2026-43363 CVE-2026-43416 CVE-2026-43439 CVE-2026-43448 CVE-2026-45860 CVE-2026-45897 CVE-2026-45968 CVE-2026-46007 CVE-2026-46070 CVE-2026-46091 CVE-2026-46107 CVE-2026-46115 CVE-2026-46133 CVE-2026-46135 CVE-2026-46195 CVE-2026-46304 CVE-2026-52912 CVE-2026-52920 CVE-2026-52928 CVE-2026-52929 CVE-2026-52935 CVE-2026-52939 CVE-2026-52946 CVE-2026-52977 CVE-2026-52990 CVE-2026-52991 CVE-2026-52994 CVE-2026-53001 CVE-2026-53031 CVE-2026-53033 CVE-2026-53034 CVE-2026-53048 CVE-2026-53059 CVE-2026-53061 CVE-2026-53076 CVE-2026-53077 CVE-2026-53089 CVE-2026-53091 CVE-2026-53092 CVE-2026-53094 CVE-2026-53096 CVE-2026-53109 CVE-2026-53110 CVE-2026-53111 CVE-2026-53114 CVE-2026-53126 CVE-2026-53129 CVE-2026-53142 CVE-2026-53154 CVE-2026-53163 CVE-2026-53180 CVE-2026-53207 CVE-2026-53219 CVE-2026-53220 CVE-2026-53223 CVE-2026-53228 CVE-2026-53238 CVE-2026-53264 CVE-2026-53269 CVE-2026-53284 CVE-2026-53291 CVE-2026-53309 CVE-2026-53330 CVE-2026-53336 CVE-2026-53337 CVE-2026-53341 CVE-2026-53353 CVE-2026-53365 CVE-2026-53388 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-63801 CVE-2026-63803 CVE-2026-63804 CVE-2026-63808 CVE-2026-63810 CVE-2026-63823 CVE-2026-63828 CVE-2026-63860 CVE-2026-63865 CVE-2026-63868 CVE-2026-63879 CVE-2026-63887 CVE-2026-63888 CVE-2026-63889 CVE-2026-63890 CVE-2026-63891 CVE-2026-63898 CVE-2026-63901 CVE-2026-63906 CVE-2026-63917 CVE-2026-63918 CVE-2026-63920 CVE-2026-63921 CVE-2026-63922 CVE-2026-63924 CVE-2026-63925 CVE-2026-63926 CVE-2026-63928 CVE-2026-63941 CVE-2026-63969 CVE-2026-63970 CVE-2026-63984 CVE-2026-63985 CVE-2026-63986 CVE-2026-63987 CVE-2026-63990 CVE-2026-63992 CVE-2026-63993 CVE-2026-63995 CVE-2026-63996 CVE-2026-63997 CVE-2026-63998 CVE-2026-63999 CVE-2026-64000 CVE-2026-64001 CVE-2026-64002 CVE-2026-64003 CVE-2026-64004 CVE-2026-64005 CVE-2026-64006 CVE-2026-64007 CVE-2026-64010 CVE-2026-64011 CVE-2026-64014 CVE-2026-64015 CVE-2026-64017 CVE-2026-64024 CVE-2026-64029 CVE-2026-64033 CVE-2026-64039 CVE-2026-64047 CVE-2026-64048 CVE-2026-64051 CVE-2026-64052 CVE-2026-64053 CVE-2026-64054 CVE-2026-64055 CVE-2026-64056 CVE-2026-64071 CVE-2026-64073 CVE-2026-64083 CVE-2026-64084 CVE-2026-64085 CVE-2026-64086 CVE-2026-64087 CVE-2026-64088 CVE-2026-64089 CVE-2026-64093 CVE-2026-64097 CVE-2026-64098 CVE-2026-64099 CVE-2026-64102 CVE-2026-64103 CVE-2026-64104 CVE-2026-64105 CVE-2026-64109 CVE-2026-64111 CVE-2026-64112 CVE-2026-64113 CVE-2026-64114 CVE-2026-64115 CVE-2026-64118 CVE-2026-64119 CVE-2026-64121 CVE-2026-64125 CVE-2026-64126 CVE-2026-64127 CVE-2026-64128 CVE-2026-64131 CVE-2026-64133 CVE-2026-64134 CVE-2026-64135 CVE-2026-64137 CVE-2026-64144 CVE-2026-64146 CVE-2026-64147 CVE-2026-64148 CVE-2026-64155 CVE-2026-64162 CVE-2026-64164 CVE-2026-64166 CVE-2026-64168 CVE-2026-64169 CVE-2026-64170 CVE-2026-64177 CVE-2026-64178 CVE-2026-64179 CVE-2026-64180 CVE-2026-64184 CVE-2026-64185 CVE-2026-64190 CVE-2026-64192 CVE-2026-64210 CVE-2026-64214 CVE-2026-64217 CVE-2026-64219 CVE-2026-64222 CVE-2026-64224 CVE-2026-64225 CVE-2026-64232 CVE-2026-64237 CVE-2026-64239 CVE-2026-64240 CVE-2026-64243 CVE-2026-64244 CVE-2026-64245 CVE-2026-64246 CVE-2026-64247 CVE-2026-64249 CVE-2026-64253 CVE-2026-64256 CVE-2026-64265 CVE-2026-64266 CVE-2026-64268 CVE-2026-64269 CVE-2026-64270 CVE-2026-64271 CVE-2026-64272 CVE-2026-64273 CVE-2026-64274 CVE-2026-64275 CVE-2026-64276 CVE-2026-64277 CVE-2026-64278 CVE-2026-64279 CVE-2026-64283 CVE-2026-64286 CVE-2026-64287 CVE-2026-64294 CVE-2026-64296 CVE-2026-64298 CVE-2026-64300 CVE-2026-64301 CVE-2026-64303 CVE-2026-64304 CVE-2026-64305 CVE-2026-64306 CVE-2026-64307 CVE-2026-64308 CVE-2026-64309 CVE-2026-64310 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64316 CVE-2026-64317 CVE-2026-64319 CVE-2026-64320 CVE-2026-64321 CVE-2026-64322 CVE-2026-64323 CVE-2026-64326 CVE-2026-64327 CVE-2026-64328 CVE-2026-64329 CVE-2026-64331 CVE-2026-64332 CVE-2026-64333 CVE-2026-64334 CVE-2026-64335 CVE-2026-64337 CVE-2026-64338 CVE-2026-64340 CVE-2026-64341 CVE-2026-64342 CVE-2026-64343 CVE-2026-64344 CVE-2026-64346 CVE-2026-64348 CVE-2026-64350 CVE-2026-64351 CVE-2026-64354 CVE-2026-64355 CVE-2026-64358 CVE-2026-64362 CVE-2026-64364 CVE-2026-64365 CVE-2026-64367 CVE-2026-64368 CVE-2026-64373 CVE-2026-64375 CVE-2026-64376 CVE-2026-64378 CVE-2026-64380 CVE-2026-64381 CVE-2026-64382 CVE-2026-64383 CVE-2026-64384 CVE-2026-64385 CVE-2026-64386 CVE-2026-64387 CVE-2026-64401 CVE-2026-64403 CVE-2026-64404 CVE-2026-64406 CVE-2026-64407 CVE-2026-64408 CVE-2026-64409 CVE-2026-64411 CVE-2026-64412 CVE-2026-64415 CVE-2026-64416 CVE-2026-64420 CVE-2026-64421 CVE-2026-64423 CVE-2026-64427 CVE-2026-64429 CVE-2026-64433 CVE-2026-64434 CVE-2026-64436 CVE-2026-64440 CVE-2026-64442 CVE-2026-64443 CVE-2026-64444 CVE-2026-64445 CVE-2026-64446 CVE-2026-64450 CVE-2026-64452 CVE-2026-64454 CVE-2026-64455 CVE-2026-64456 CVE-2026-64458 CVE-2026-64463 CVE-2026-64470 CVE-2026-64471 CVE-2026-64472 CVE-2026-64477 CVE-2026-64478 CVE-2026-64479 CVE-2026-64480 CVE-2026-64481 CVE-2026-64482 CVE-2026-64483 CVE-2026-64484 CVE-2026-64486 CVE-2026-64487 CVE-2026-64489 CVE-2026-64490 CVE-2026-64494 CVE-2026-64495 CVE-2026-64496 CVE-2026-64497 CVE-2026-64499 CVE-2026-64500 CVE-2026-64503 CVE-2026-64504 CVE-2026-64505 CVE-2026-64507 CVE-2026-64511 CVE-2026-64512 CVE-2026-64513 CVE-2026-64515 CVE-2026-64517 CVE-2026-64518 CVE-2026-64519 CVE-2026-64524 CVE-2026-64525 CVE-2026-64526 CVE-2026-64527 CVE-2026-64534 CVE-2026-64535 CVE-2026-64536 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539 CVE-2026-64540 CVE-2026-64541 CVE-2026-64542 CVE-2026-64543 CVE-2026-64544 CVE-2026-64545 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64551 CVE-2026-64552 CVE-2026-64553 CVE-2026-64554 CVE-2026-64555 CVE-2026-64556 CVE-2026-64558 CVE-2026-64559 CVE-2026-64561 CVE-2026-64562 CVE-2026-64563 CVE-2026-64565 CVE-2026-64567 CVE-2026-64568 CVE-2026-64569 CVE-2026-64570 CVE-2026-64571 CVE-2026-64572 CVE-2026-64573 CVE-2026-64574 CVE-2026-64576 CVE-2026-64577 CVE-2026-64579 CVE-2026-64581 CVE-2026-64582 CVE-2026-64583 CVE-2026-64584 CVE-2026-64585 CVE-2026-64586 CVE-2026-64589 CVE-2026-64593 CVE-2026-64599 CVE-2026-64602 CVE-2026-64603 CVE-2026-64604 CVE-2026-68081 CVE-2026-68082 CVE-2026-68085 CVE-2026-68086 CVE-2026-68088 CVE-2026-68091 CVE-2026-68093 CVE-2026-68096 CVE-2026-68102 CVE-2026-68104 CVE-2026-68105 CVE-2026-68106 CVE-2026-68107 CVE-2026-68108 CVE-2026-68110 CVE-2026-68111 CVE-2026-68112 CVE-2026-68113 CVE-2026-68115 CVE-2026-68116 CVE-2026-68117 CVE-2026-68120 CVE-2026-68121 CVE-2026-68123 CVE-2026-68124 CVE-2026-68125 CVE-2026-68126 CVE-2026-68127 CVE-2026-68128 CVE-2026-68129 CVE-2026-68132 CVE-2026-68133 CVE-2026-68135 CVE-2026-68136 CVE-2026-68137 CVE-2026-68138 CVE-2026-68139 CVE-2026-68141 CVE-2026-68142 CVE-2026-68143 CVE-2026-68144 CVE-2026-68145 CVE-2026-68148 CVE-2026-68149 CVE-2026-68152 CVE-2026-68153 CVE-2026-68154 CVE-2026-68155 CVE-2026-68156 CVE-2026-68157 CVE-2026-68158 CVE-2026-68159 CVE-2026-68161 CVE-2026-68164 CVE-2026-68165 CVE-2026-68166 CVE-2026-68169 CVE-2026-68178 CVE-2026-68179 CVE-2026-68180 CVE-2026-68181 CVE-2026-68182 CVE-2026-68183 CVE-2026-68184 CVE-2026-68188 CVE-2026-68189 CVE-2026-68192 CVE-2026-68193 CVE-2026-68194 CVE-2026-68195 CVE-2026-68196 CVE-2026-68197 CVE-2026-68198 CVE-2026-68199 CVE-2026-68200 CVE-2026-68201 CVE-2026-68202 CVE-2026-68203 CVE-2026-68204 CVE-2026-68205 CVE-2026-68206 CVE-2026-68207 CVE-2026-68209 CVE-2026-68210 CVE-2026-68212 CVE-2026-68213 CVE-2026-68214 CVE-2026-68215 CVE-2026-68216 CVE-2026-68217 CVE-2026-68218 CVE-2026-68219 CVE-2026-68220 CVE-2026-68221 CVE-2026-68222 CVE-2026-68223 CVE-2026-68225 CVE-2026-68226 CVE-2026-68227 CVE-2026-68228 CVE-2026-68229 CVE-2026-68231 CVE-2026-68234 CVE-2026-68235 CVE-2026-68236 CVE-2026-68238 CVE-2026-68243 CVE-2026-68244 CVE-2026-68245 CVE-2026-68246 CVE-2026-68247 CVE-2026-68248 CVE-2026-68249 CVE-2026-68250 CVE-2026-68251 CVE-2026-68252 CVE-2026-68253 CVE-2026-68254 CVE-2026-68255 CVE-2026-68256 CVE-2026-68257 CVE-2026-68258 CVE-2026-68259 CVE-2026-68260 CVE-2026-68261 CVE-2026-68262 CVE-2026-68263 CVE-2026-68267 CVE-2026-68269 CVE-2026-68271 CVE-2026-68272 CVE-2026-68273 CVE-2026-68277 CVE-2026-68278 CVE-2026-68279 CVE-2026-68280 CVE-2026-68281 CVE-2026-68284 CVE-2026-68286 CVE-2026-68288 CVE-2026-68289 CVE-2026-68293 CVE-2026-68294 CVE-2026-68296 CVE-2026-68297 CVE-2026-68299 CVE-2026-68300 CVE-2026-68302 CVE-2026-68303 CVE-2026-68304 CVE-2026-68306 CVE-2026-68307 CVE-2026-68308 CVE-2026-68309 CVE-2026-68310 CVE-2026-68311 CVE-2026-68313 CVE-2026-68315 CVE-2026-68319 CVE-2026-68320 CVE-2026-68321 CVE-2026-68322 CVE-2026-68325 CVE-2026-68326 CVE-2026-68327 CVE-2026-68328 CVE-2026-68329 CVE-2026-68331 CVE-2026-68333 CVE-2026-68335 CVE-2026-68336 CVE-2026-68338 CVE-2026-68339 CVE-2026-68340 CVE-2026-68344 CVE-2026-68346 CVE-2026-68348 CVE-2026-68349 CVE-2026-68350 CVE-2026-68351 CVE-2026-68352 CVE-2026-68353 CVE-2026-68354 CVE-2026-68355 CVE-2026-68357 CVE-2026-68358 CVE-2026-68359 CVE-2026-68360 CVE-2026-68361 CVE-2026-68362 CVE-2026-68363 CVE-2026-68365 CVE-2026-68366 CVE-2026-68368 CVE-2026-68369 CVE-2026-68370 CVE-2026-68371 CVE-2026-68372 CVE-2026-68373 CVE-2026-68374 CVE-2026-68375 CVE-2026-68377 CVE-2026-68386 CVE-2026-68389 CVE-2026-68391 CVE-2026-68392 CVE-2026-68393 CVE-2026-68394 CVE-2026-68395 CVE-2026-68397 CVE-2026-68398 CVE-2026-68399 CVE-2026-68402 CVE-2026-68403 CVE-2026-68405 CVE-2026-68406 CVE-2026-68407 CVE-2026-68408 CVE-2026-68410 CVE-2026-68413 CVE-2026-68414 CVE-2026-68416 CVE-2026-68417 CVE-2026-68418 CVE-2026-68419 CVE-2026-68422 CVE-2026-68425 CVE-2026-68426 CVE-2026-68427 CVE-2026-68428 CVE-2026-68429 CVE-2026-68430 CVE-2026-68432 CVE-2026-68433 CVE-2026-68434 CVE-2026-68437 CVE-2026-68439 CVE-2026-68442 CVE-2026-68443 CVE-2026-68444 CVE-2026-68445 CVE-2026-68446 CVE-2026-68448 CVE-2026-68450 CVE-2026-68470 CVE-2026-68480 CVE-2026-72017 CVE-2026-72019 CVE-2026-72020 CVE-2026-72022 CVE-2026-72023 CVE-2026-72032 CVE-2026-72034 CVE-2026-72035 CVE-2026-72036 CVE-2026-72045 CVE-2026-72046 CVE-2026-72051 CVE-2026-72052 CVE-2026-72053 CVE-2026-72054 CVE-2026-72055 CVE-2026-72061 CVE-2026-72069 CVE-2026-72072 CVE-2026-72083 CVE-2026-72084 CVE-2026-72100 CVE-2026-72101 CVE-2026-72103 CVE-2026-72106 CVE-2026-72107 CVE-2026-72108 CVE-2026-72132 CVE-2026-72136 CVE-2026-72137 CVE-2026-72161 CVE-2026-72163 CVE-2026-72164 CVE-2026-72176 CVE-2026-72177 CVE-2026-72217 CVE-2026-72221 CVE-2026-72222 CVE-2026-72234 CVE-2026-72242 CVE-2026-72243 CVE-2026-72251 CVE-2026-72254 CVE-2026-72280 CVE-2026-72282 CVE-2026-72288 CVE-2026-72289 CVE-2026-72296 CVE-2026-72297 CVE-2026-72306 CVE-2026-72307 CVE-2026-72308 CVE-2026-72317 CVE-2026-72323 CVE-2026-72325 CVE-2026-72330 CVE-2026-72337 CVE-2026-72339 CVE-2026-72341 CVE-2026-72342 CVE-2026-72343 CVE-2026-72345 CVE-2026-72347 CVE-2026-72350 CVE-2026-72366 CVE-2026-72379 CVE-2026-72389 CVE-2026-72398 CVE-2026-72399 CVE-2026-72414 CVE-2026-72421 CVE-2026-72425 CVE-2026-72430 CVE-2026-72437 CVE-2026-72438 CVE-2026-72439 CVE-2026-72440 CVE-2026-72448 CVE-2026-72450 CVE-2026-72459 CVE-2026-72460 CVE-2026-72464 CVE-2026-72466 CVE-2026-72467 CVE-2026-72468 CVE-2026-72469 CVE-2026-72473 CVE-2026-72485 CVE-2026-72487 CVE-2026-72488 CVE-2026-72494 CVE-2026-72495 CVE-2026-72497 CVE-2026-72499 CVE-2026-72500 CVE-2026-72501 CVE-2026-72502 CVE-2026-74255 CVE-2026-74261 CVE-2026-74269 CVE-2026-74270 CVE-2026-74282 CVE-2026-74284 CVE-2026-74286 CVE-2026-74296 CVE-2026-74297 CVE-2026-74307 CVE-2026-74308 CVE-2026-74313 CVE-2026-74316 CVE-2026-74317 CVE-2026-74318 CVE-2026-74321 CVE-2026-74334 CVE-2026-74345 CVE-2026-74346 CVE-2026-74349 CVE-2026-74363 CVE-2026-74375 CVE-2026-74377 CVE-2026-74378 CVE-2026-74382 CVE-2026-74388 CVE-2026-74390 CVE-2026-74394 CVE-2026-74395 CVE-2026-74397 CVE-2026-74406 CVE-2026-74464 CVE-2026-74474 CVE-2026-74475 CVE-2026-74476 CVE-2026-74479 CVE-2026-74481 CVE-2026-74482 CVE-2026-74495 CVE-2026-74496 CVE-2026-74510 CVE-2026-74512 CVE-2026-74513 CVE-2026-74517 CVE-2026-74518 CVE-2026-74523 CVE-2026-74527 CVE-2026-74533 CVE-2026-74534 CVE-2026-74535 CVE-2026-74536 CVE-2026-74537 CVE-2026-74545 CVE-2026-74548 CVE-2026-74550 CVE-2026-74555 CVE-2026-74556 CVE-2026-74557 CVE-2026-74563 CVE-2026-74566 CVE-2026-74567 CVE-2026-74571 CVE-2026-74577 CVE-2026-74581 CVE-2026-74582 CVE-2026-74584 CVE-2026-74598 CVE-2026-74610 CVE-2026-74612 CVE-2026-74615 CVE-2026-74616 CVE-2026-74622 CVE-2026-74644 CVE-2026-74665 CVE-2026-74669 CVE-2026-74695 CVE-2026-74705 CVE-2026-74712 CVE-2026-74717 CVE-2026-74719 CVE-2026-74722 CVE-2026-74723 CVE-2026-74730 CVE-2026-74737 CVE-2026-74743 CVE-2026-74744 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 CVE-2026-80529 CVE-2026-80530 CVE-2026-80531 CVE-2026-80533 CVE-2026-80534 CVE-2026-80535 CVE-2026-80557 CVE-2026-80558 CVE-2026-80561 CVE-2026-80586 CVE-2026-80589 CVE-2026-80590 CVE-2026-80603 CVE-2026-80609 CVE-2026-80629 CVE-2026-80646 CVE-2026-80647 CVE-2026-80667 CVE-2026-80681 CVE-2026-80693 CVE-2026-80714 CVE-2026-80721 CVE-2026-80727 CVE-2026-80731 CVE-2026-80737 CVE-2026-80739 CVE-2026-80805 CVE-2026-80813 CVE-2026-80838 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). ----------------------------------------------------------------- Advisory ID: 1738 Released: Tue Sep 22 16:23:31 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1236344,1240890,1240957,1249104,1255225,1255531,1256629,1256671,1258278,1260501,1260577,1262073,1262756,1263004,1263864,1263865,1264267,1264335,1264444,1264541,1264587,1264619,1264807,1264851,1265036,1265068,1265121,1265132,1265141,1265220,1266710,1266860,1266874,1266897,1266928,1267023,1267238,1267373,1267501,1267586,1267612,1267882,1267985,1268972,1268979,1269000,1269004,1269010,1269013,1269108,1269113,1269114,1269126,1269134,1269140,1269162,1269167,1269238,1269242,1269256,1269301,1269306,1269380,1269381,1269388,1269402,1269412,1269417,1269528,1269530,1269579,1269590,1269633,1269635,1269655,1269665,1269685,1269686,1269695,1269697,1269774,1269783,1269792,1269815,1269816,1269888,1269965,1269969,1269985,1269999,1270090,1270108,1270111,1270139,1270251,1270266,1270267,1271050,1271256,1271365,1271825,1272148,1272149,1272175,1272182,1272199,1272200,1272210,1272213,1272230,1272260,1272261,1272262,1272284,1272287,1272297,1272346,1272366,1272385,1272390,1272423,1272426,1272429,1 272484,1272486,1272497,1272501,1272502,1272513,1272516,1272568,1272569,1272584,1272641,1272643,1272673,1272756,1272786,1272788,1272791,1272798,1272799,1272804,1272855,1272865,1272868,1272869,1272877,1272891,1272893,1272894,1272904,1272905,1272918,1272963,1272969,1272971,1272983,1272985,1273008,1273019,1273027,1273030,1273032,1273033,1273036,1273037,1273038,1273060,1273105,1273107,1273119,1273134,1273231,1273249,1273251,1273260,1273271,1273273,1273274,1273276,1273277,1273280,1273281,1273283,1273284,1273285,1273286,1273288,1273289,1273291,1273294,1273302,1273303,1273305,1273309,1273310,1273311,1273312,1273314,1273316,1273317,1273318,1273319,1273323,1273325,1273327,1273331,1273334,1273335,1273336,1273337,1273338,1273339,1273340,1273341,1273346,1273420,1273422,1273426,1273443,1273460,1273461,1273463,1273465,1273468,1273469,1273471,1273479,1273480,1273482,1273484,1273486,1273488,1273490,1273495,1273501,1273503,1273504,1273506,1273507,1273509,1273511,1273520,1273523,1273524,1273525,127353 3,1273536,1273538,1273542,1273550,1273555,1273557,1273567,1273578,1273579,1273581,1273582,1273596,1273597,1273598,1273600,1273601,1273602,1273603,1273679,1273681,1273682,1273734,1273737,1273738,1273739,1273740,1273741,1273742,1273743,1273744,1273745,1273746,1273748,1273749,1273755,1273759,1273762,1273765,1273766,1273769,1273770,1273774,1273776,1273778,1273780,1273782,1273788,1273790,1273796,1273797,1273801,1273803,1273804,1273809,1273810,1273811,1273812,1273813,1273817,1273822,1273824,1273831,1273834,1273838,1273839,1273842,1273844,1273848,1273849,1273852,1273855,1273859,1273860,1273862,1273864,1273866,1273867,1273868,1273869,1273870,1273872,1273876,1273877,1273880,1273882,1273890,1273891,1273892,1273895,1273896,1273898,1273899,1273903,1273904,1273905,1273930,1273933,1273934,1273935,1273936,1273939,1273940,1273941,1273942,1273944,1273945,1273946,1273947,1273949,1273953,1273954,1273956,1273957,1273958,1273959,1273963,1273966,1273967,1273968,1273972,1273974,1273975,1273977,1273988,127 3990,1273991,1273995,1273997,1273999,1274001,1274003,1274006,1274008,1274009,1274010,1274011,1274012,1274014,1274017,1274019,1274020,1274026,1274028,1274030,1274031,1274035,1274036,1274040,1274041,1274052,1274055,1274057,1274058,1274060,1274063,1274065,1274067,1274071,1274075,1274076,1274077,1274078,1274208,1274226,1274239,1274243,1274252,1274253,1274258,1274264,1274265,1274267,1274274,1274277,1274278,1274281,1274283,1274286,1274290,1274292,1274294,1274295,1274296,1274314,1274321,1274491,1274492,1274494,1274497,1274539,1274541,1274543,1274545,1274547,1274550,1274556,1274573,1274578,1274580,1274581,1274622,1274624,1274628,1274632,1274636,1274637,1274639,1274640,1274642,1274644,1274645,1274646,1274650,1274651,1274652,1274656,1274657,1274659,1274662,1274665,1274667,1274669,1274670,1274671,1274675,1274677,1274678,1274679,1274681,1274682,1274690,1274694,1274696,1274698,1274699,1274700,1274702,1274703,1274705,1274706,1274707,1274709,1274710,1274713,1274716,1274721,1274725,1274727,1274730, 1274737,1274738,1274749,1274750,1274751,1274752,1274753,1274754,1274755,1274756,1274764,1274768,1274770,1274771,1274773,1274782,1274783,1274787,1274800,1274801,1274802,1274803,1274804,1274805,1274807,1274808,1274811,1274813,1274814,1274831,1274834,1274835,1274838,1274847,1274849,1274853,1274868,1274869,1274872,1274873,1274874,1274876,1274877,1274879,1274881,1274883,1274886,1274887,1274888,1274891,1274892,1274893,1274894,1274895,1274896,1274897,1274898,1274899,1274900,1274901,1274902,1274904,1274905,1274906,1274907,1274908,1274913,1274914,1274921,1274924,1274925,1274927,1274929,1274930,1274933,1274934,1274935,1274938,1274939,1274940,1274941,1274945,1274947,1274951,1274952,1274953,1274955,1274957,1274958,1274965,1274968,1274978,1274981,1275040,1275045,1275069,1275071,1275072,1275073,1275076,1275080,1275081,1275083,1275088,1275091,1275092,1275094,1275125,1275126,1275129,1275131,1275132,1275139,1275141,1275146,1275148,1275149,1275150,1275152,1275154,1275155,1275156,1275157,1275158,12751 60,1275161,1275163,1275164,1275169,1275173,1275176,1275185,1275190,1275192,1275229,1275236,1275237,1275238,1275239,1275294,1275300,1275301,1275303,1275304,1275305,1275306,1275307,1275470,1275474,1275479,1275481,1275483,1275486,1275487,1275496,1275506,1275509,1275511,1275514,1275517,1275519,1275528,1275535,1275540,1275553,1275555,1275557,1275561,1275566,1275569,1275572,1275574,1275578,1275582,1275583,1275584,1275587,1275588,1275591,1275595,1275596,1275633,1275636,1275650,1275655,1275656,1275659,1275665,1275669,1275672,1275679,1275685,1275687,1275688,1275690,1275695,1275696,1275704,1275737,1275782,1275784,1275787,1275788,1275789,1275790,1275798,1275799,1275801,1275802,1275804,1275805,1275812,1275817,1275818,1275819,1275820,1275821,1275822,1275823,1275827,1275864,1275866,1275867,1275869,1275870,1275871,1275872,1275886,1275905,1275923,1275925,1275928,1275950,1275954,1275956,1275970,1275973,1275975,1275976,1275985,1276006,1276029,1276257,1276258,1276263,1276265,1276267,1276270,1276273,12 76277,1276333,1276335,1276339,1276341,1276346,1276354,1276355,1276381,1276395,1276446,1276452,1276468,1276471,1276473,1276500,1276507,1276512,1276528,1276542,1276546,1276547,1276551,1276552,1276553,1276561,1276562,1276566,1276569,1276572,1276577,1276586,1276665,1276766,1276767,1276771,1276785,1276793,1276801,1276803,1276814,1276818,1276821,1276831,1276840,1276864,1276865,1276866,1276870,1276876,1276880,1276905,1276913,1276922,1276931,1276937,1276941,1276955,1276957,1276961,1277022,1277023,1277033,1277034,1277037,1277047,1277054,1277057,1277059,1277062,1277066,1277069,1277070,1277077,1277078,1277092,1277095,1277108,1277114,1277115,1277118,1277120,1277155,1277159,1277160,1277202,1277204,1277227,1277229,1277230,1277231,1277233,1277249,1277254,1277265,1277268,1277275,1277285,1277308,1277311,1277315,1277321,1277328,1277335,1277349,1277350,1277391,1277407,1277408,1277485,1277505,1277513,1277551,1277553,1277561,1277574,1277636,1277641,1277649,1277655,1277656,1277660,1277668,1277680,1277688 ,1277726,1277728,1277738,1277748,1277761,1277764,1277773,1277775,1277776,1277782,1277783,1277813,1277818,1277822,1277845,1277862,1277874,1277876,1277898,1277901,1277908,1277918,1278039,1278070,1278088,1278094,1278098,1278113,1278155,1278180,1278233,1278236,1278240,1278253,1278293,1278324,1278331,1278334,1278395,1278416,1278703,1278716,1278733,1279487,1279537,1279580,1279813,1279842,1279847,1279887,1280139,CVE-2025-68214,CVE-2025-68358,CVE-2025-68780,CVE-2025-71075,CVE-2026-23113,CVE-2026-23306,CVE-2026-23348,CVE-2026-31418,CVE-2026-31530,CVE-2026-31531,CVE-2026-43116,CVE-2026-43125,CVE-2026-43163,CVE-2026-43239,CVE-2026-43271,CVE-2026-43299,CVE-2026-43331,CVE-2026-43355,CVE-2026-43363,CVE-2026-43416,CVE-2026-43439,CVE-2026-43448,CVE-2026-45860,CVE-2026-45897,CVE-2026-45968,CVE-2026-46007,CVE-2026-46070,CVE-2026-46091,CVE-2026-46107,CVE-2026-46115,CVE-2026-46133,CVE-2026-46135,CVE-2026-46195,CVE-2026-46304,CVE-2026-52912,CVE-2026-52920,CVE-2026-52928,CVE-2026-52929,CVE-2026-52935,CVE -2026-52939,CVE-2026-52946,CVE-2026-52977,CVE-2026-52990,CVE-2026-52991,CVE-2026-52994,CVE-2026-53001,CVE-2026-53031,CVE-2026-53033,CVE-2026-53034,CVE-2026-53048,CVE-2026-53059,CVE-2026-53061,CVE-2026-53076,CVE-2026-53077,CVE-2026-53089,CVE-2026-53091,CVE-2026-53092,CVE-2026-53094,CVE-2026-53096,CVE-2026-53109,CVE-2026-53110,CVE-2026-53111,CVE-2026-53114,CVE-2026-53126,CVE-2026-53129,CVE-2026-53142,CVE-2026-53154,CVE-2026-53163,CVE-2026-53180,CVE-2026-53207,CVE-2026-53219,CVE-2026-53220,CVE-2026-53223,CVE-2026-53228,CVE-2026-53238,CVE-2026-53264,CVE-2026-53269,CVE-2026-53284,CVE-2026-53291,CVE-2026-53309,CVE-2026-53330,CVE-2026-53336,CVE-2026-53337,CVE-2026-53341,CVE-2026-53353,CVE-2026-53365,CVE-2026-53388,CVE-2026-63801,CVE-2026-63803,CVE-2026-63804,CVE-2026-63808,CVE-2026-63810,CVE-2026-63823,CVE-2026-63828,CVE-2026-63860,CVE-2026-63865,CVE-2026-63868,CVE-2026-63879,CVE-2026-63887,CVE-2026-63888,CVE-2026-63889,CVE-2026-63890,CVE-2026-63891,CVE-2026-63898,CVE-2026-63901,CVE-2026-6 3906,CVE-2026-63917,CVE-2026-63918,CVE-2026-63920,CVE-2026-63921,CVE-2026-63922,CVE-2026-63924,CVE-2026-63925,CVE-2026-63926,CVE-2026-63928,CVE-2026-63941,CVE-2026-63969,CVE-2026-63970,CVE-2026-63984,CVE-2026-63985,CVE-2026-63986,CVE-2026-63987,CVE-2026-63990,CVE-2026-63992,CVE-2026-63993,CVE-2026-63995,CVE-2026-63996,CVE-2026-63997,CVE-2026-63998,CVE-2026-63999,CVE-2026-64000,CVE-2026-64001,CVE-2026-64002,CVE-2026-64003,CVE-2026-64004,CVE-2026-64005,CVE-2026-64006,CVE-2026-64007,CVE-2026-64010,CVE-2026-64011,CVE-2026-64014,CVE-2026-64015,CVE-2026-64017,CVE-2026-64024,CVE-2026-64029,CVE-2026-64033,CVE-2026-64039,CVE-2026-64047,CVE-2026-64048,CVE-2026-64051,CVE-2026-64052,CVE-2026-64053,CVE-2026-64054,CVE-2026-64055,CVE-2026-64056,CVE-2026-64071,CVE-2026-64073,CVE-2026-64083,CVE-2026-64084,CVE-2026-64085,CVE-2026-64086,CVE-2026-64087,CVE-2026-64088,CVE-2026-64089,CVE-2026-64093,CVE-2026-64097,CVE-2026-64098,CVE-2026-64099,CVE-2026-64102,CVE-2026-64103,CVE-2026-64104,CVE-2026-64105,CV E-2026-64109,CVE-2026-64111,CVE-2026-64112,CVE-2026-64113,CVE-2026-64114,CVE-2026-64115,CVE-2026-64118,CVE-2026-64119,CVE-2026-64121,CVE-2026-64125,CVE-2026-64126,CVE-2026-64127,CVE-2026-64128,CVE-2026-64131,CVE-2026-64133,CVE-2026-64134,CVE-2026-64135,CVE-2026-64137,CVE-2026-64144,CVE-2026-64146,CVE-2026-64147,CVE-2026-64148,CVE-2026-64155,CVE-2026-64162,CVE-2026-64164,CVE-2026-64166,CVE-2026-64168,CVE-2026-64169,CVE-2026-64170,CVE-2026-64177,CVE-2026-64178,CVE-2026-64179,CVE-2026-64180,CVE-2026-64184,CVE-2026-64185,CVE-2026-64190,CVE-2026-64192,CVE-2026-64210,CVE-2026-64214,CVE-2026-64217,CVE-2026-64219,CVE-2026-64222,CVE-2026-64224,CVE-2026-64225,CVE-2026-64232,CVE-2026-64237,CVE-2026-64239,CVE-2026-64240,CVE-2026-64243,CVE-2026-64244,CVE-2026-64245,CVE-2026-64246,CVE-2026-64247,CVE-2026-64249,CVE-2026-64253,CVE-2026-64256,CVE-2026-64265,CVE-2026-64266,CVE-2026-64268,CVE-2026-64269,CVE-2026-64270,CVE-2026-64271,CVE-2026-64272,CVE-2026-64273,CVE-2026-64274,CVE-2026-64275,CVE-2026- 64276,CVE-2026-64277,CVE-2026-64278,CVE-2026-64279,CVE-2026-64283,CVE-2026-64286,CVE-2026-64287,CVE-2026-64294,CVE-2026-64296,CVE-2026-64298,CVE-2026-64300,CVE-2026-64301,CVE-2026-64303,CVE-2026-64304,CVE-2026-64305,CVE-2026-64306,CVE-2026-64307,CVE-2026-64308,CVE-2026-64309,CVE-2026-64310,CVE-2026-64312,CVE-2026-64313,CVE-2026-64315,CVE-2026-64316,CVE-2026-64317,CVE-2026-64319,CVE-2026-64320,CVE-2026-64321,CVE-2026-64322,CVE-2026-64323,CVE-2026-64326,CVE-2026-64327,CVE-2026-64328,CVE-2026-64329,CVE-2026-64331,CVE-2026-64332,CVE-2026-64333,CVE-2026-64334,CVE-2026-64335,CVE-2026-64337,CVE-2026-64338,CVE-2026-64340,CVE-2026-64341,CVE-2026-64342,CVE-2026-64343,CVE-2026-64344,CVE-2026-64346,CVE-2026-64348,CVE-2026-64350,CVE-2026-64351,CVE-2026-64354,CVE-2026-64355,CVE-2026-64358,CVE-2026-64362,CVE-2026-64364,CVE-2026-64365,CVE-2026-64367,CVE-2026-64368,CVE-2026-64373,CVE-2026-64375,CVE-2026-64376,CVE-2026-64378,CVE-2026-64380,CVE-2026-64381,CVE-2026-64382,CVE-2026-64383,CVE-2026-64384,C VE-2026-64385,CVE-2026-64386,CVE-2026-64387,CVE-2026-64401,CVE-2026-64403,CVE-2026-64404,CVE-2026-64406,CVE-2026-64407,CVE-2026-64408,CVE-2026-64409,CVE-2026-64411,CVE-2026-64412,CVE-2026-64415,CVE-2026-64416,CVE-2026-64420,CVE-2026-64421,CVE-2026-64423,CVE-2026-64427,CVE-2026-64429,CVE-2026-64433,CVE-2026-64434,CVE-2026-64436,CVE-2026-64440,CVE-2026-64442,CVE-2026-64443,CVE-2026-64444,CVE-2026-64445,CVE-2026-64446,CVE-2026-64450,CVE-2026-64452,CVE-2026-64454,CVE-2026-64455,CVE-2026-64456,CVE-2026-64458,CVE-2026-64463,CVE-2026-64470,CVE-2026-64471,CVE-2026-64472,CVE-2026-64477,CVE-2026-64478,CVE-2026-64479,CVE-2026-64480,CVE-2026-64481,CVE-2026-64482,CVE-2026-64483,CVE-2026-64484,CVE-2026-64486,CVE-2026-64487,CVE-2026-64489,CVE-2026-64490,CVE-2026-64494,CVE-2026-64495,CVE-2026-64496,CVE-2026-64497,CVE-2026-64499,CVE-2026-64500,CVE-2026-64503,CVE-2026-64504,CVE-2026-64505,CVE-2026-64507,CVE-2026-64511,CVE-2026-64512,CVE-2026-64513,CVE-2026-64515,CVE-2026-64517,CVE-2026-64518,CVE-2026 -64519,CVE-2026-64524,CVE-2026-64525,CVE-2026-64526,CVE-2026-64527,CVE-2026-64534,CVE-2026-64535,CVE-2026-64536,CVE-2026-64537,CVE-2026-64538,CVE-2026-64539,CVE-2026-64540,CVE-2026-64541,CVE-2026-64542,CVE-2026-64543,CVE-2026-64544,CVE-2026-64545,CVE-2026-64546,CVE-2026-64547,CVE-2026-64548,CVE-2026-64549,CVE-2026-64551,CVE-2026-64552,CVE-2026-64553,CVE-2026-64554,CVE-2026-64555,CVE-2026-64556,CVE-2026-64558,CVE-2026-64559,CVE-2026-64561,CVE-2026-64562,CVE-2026-64563,CVE-2026-64565,CVE-2026-64567,CVE-2026-64568,CVE-2026-64569,CVE-2026-64570,CVE-2026-64571,CVE-2026-64572,CVE-2026-64573,CVE-2026-64574,CVE-2026-64576,CVE-2026-64577,CVE-2026-64579,CVE-2026-64581,CVE-2026-64582,CVE-2026-64583,CVE-2026-64584,CVE-2026-64585,CVE-2026-64586,CVE-2026-64589,CVE-2026-64593,CVE-2026-64599,CVE-2026-64602,CVE-2026-64603,CVE-2026-64604,CVE-2026-68081,CVE-2026-68082,CVE-2026-68085,CVE-2026-68086,CVE-2026-68088,CVE-2026-68091,CVE-2026-68093,CVE-2026-68096,CVE-2026-68102,CVE-2026-68104,CVE-2026-68105, CVE-2026-68106,CVE-2026-68107,CVE-2026-68108,CVE-2026-68110,CVE-2026-68111,CVE-2026-68112,CVE-2026-68113,CVE-2026-68115,CVE-2026-68116,CVE-2026-68117,CVE-2026-68120,CVE-2026-68121,CVE-2026-68123,CVE-2026-68124,CVE-2026-68125,CVE-2026-68126,CVE-2026-68127,CVE-2026-68128,CVE-2026-68129,CVE-2026-68132,CVE-2026-68133,CVE-2026-68135,CVE-2026-68136,CVE-2026-68137,CVE-2026-68138,CVE-2026-68139,CVE-2026-68141,CVE-2026-68142,CVE-2026-68143,CVE-2026-68144,CVE-2026-68145,CVE-2026-68148,CVE-2026-68149,CVE-2026-68152,CVE-2026-68153,CVE-2026-68154,CVE-2026-68155,CVE-2026-68156,CVE-2026-68157,CVE-2026-68158,CVE-2026-68159,CVE-2026-68161,CVE-2026-68164,CVE-2026-68165,CVE-2026-68166,CVE-2026-68169,CVE-2026-68178,CVE-2026-68179,CVE-2026-68180,CVE-2026-68181,CVE-2026-68182,CVE-2026-68183,CVE-2026-68184,CVE-2026-68188,CVE-2026-68189,CVE-2026-68192,CVE-2026-68193,CVE-2026-68194,CVE-2026-68195,CVE-2026-68196,CVE-2026-68197,CVE-2026-68198,CVE-2026-68199,CVE-2026-68200,CVE-2026-68201,CVE-2026-68202,CVE-202 6-68203,CVE-2026-68204,CVE-2026-68205,CVE-2026-68206,CVE-2026-68207,CVE-2026-68209,CVE-2026-68210,CVE-2026-68212,CVE-2026-68213,CVE-2026-68214,CVE-2026-68215,CVE-2026-68216,CVE-2026-68217,CVE-2026-68218,CVE-2026-68219,CVE-2026-68220,CVE-2026-68221,CVE-2026-68222,CVE-2026-68223,CVE-2026-68225,CVE-2026-68226,CVE-2026-68227,CVE-2026-68228,CVE-2026-68229,CVE-2026-68231,CVE-2026-68234,CVE-2026-68235,CVE-2026-68236,CVE-2026-68238,CVE-2026-68243,CVE-2026-68244,CVE-2026-68245,CVE-2026-68246,CVE-2026-68247,CVE-2026-68248,CVE-2026-68249,CVE-2026-68250,CVE-2026-68251,CVE-2026-68252,CVE-2026-68253,CVE-2026-68254,CVE-2026-68255,CVE-2026-68256,CVE-2026-68257,CVE-2026-68258,CVE-2026-68259,CVE-2026-68260,CVE-2026-68261,CVE-2026-68262,CVE-2026-68263,CVE-2026-68267,CVE-2026-68269,CVE-2026-68271,CVE-2026-68272,CVE-2026-68273,CVE-2026-68277,CVE-2026-68278,CVE-2026-68279,CVE-2026-68280,CVE-2026-68281,CVE-2026-68284,CVE-2026-68286,CVE-2026-68288,CVE-2026-68289,CVE-2026-68293,CVE-2026-68294,CVE-2026-68296 ,CVE-2026-68297,CVE-2026-68299,CVE-2026-68300,CVE-2026-68302,CVE-2026-68303,CVE-2026-68304,CVE-2026-68306,CVE-2026-68307,CVE-2026-68308,CVE-2026-68309,CVE-2026-68310,CVE-2026-68311,CVE-2026-68313,CVE-2026-68315,CVE-2026-68319,CVE-2026-68320,CVE-2026-68321,CVE-2026-68322,CVE-2026-68325,CVE-2026-68326,CVE-2026-68327,CVE-2026-68328,CVE-2026-68329,CVE-2026-68331,CVE-2026-68333,CVE-2026-68335,CVE-2026-68336,CVE-2026-68338,CVE-2026-68339,CVE-2026-68340,CVE-2026-68344,CVE-2026-68346,CVE-2026-68348,CVE-2026-68349,CVE-2026-68350,CVE-2026-68351,CVE-2026-68352,CVE-2026-68353,CVE-2026-68354,CVE-2026-68355,CVE-2026-68357,CVE-2026-68358,CVE-2026-68359,CVE-2026-68360,CVE-2026-68361,CVE-2026-68362,CVE-2026-68363,CVE-2026-68365,CVE-2026-68366,CVE-2026-68368,CVE-2026-68369,CVE-2026-68370,CVE-2026-68371,CVE-2026-68372,CVE-2026-68373,CVE-2026-68374,CVE-2026-68375,CVE-2026-68377,CVE-2026-68386,CVE-2026-68389,CVE-2026-68391,CVE-2026-68392,CVE-2026-68393,CVE-2026-68394,CVE-2026-68395,CVE-2026-68397,CVE-20 26-68398,CVE-2026-68399,CVE-2026-68402,CVE-2026-68403,CVE-2026-68405,CVE-2026-68406,CVE-2026-68407,CVE-2026-68408,CVE-2026-68410,CVE-2026-68413,CVE-2026-68414,CVE-2026-68416,CVE-2026-68417,CVE-2026-68418,CVE-2026-68419,CVE-2026-68422,CVE-2026-68425,CVE-2026-68426,CVE-2026-68427,CVE-2026-68428,CVE-2026-68429,CVE-2026-68430,CVE-2026-68432,CVE-2026-68433,CVE-2026-68434,CVE-2026-68437,CVE-2026-68439,CVE-2026-68442,CVE-2026-68443,CVE-2026-68444,CVE-2026-68445,CVE-2026-68446,CVE-2026-68448,CVE-2026-68450,CVE-2026-68470,CVE-2026-68480,CVE-2026-72017,CVE-2026-72019,CVE-2026-72020,CVE-2026-72022,CVE-2026-72023,CVE-2026-72032,CVE-2026-72034,CVE-2026-72035,CVE-2026-72036,CVE-2026-72045,CVE-2026-72046,CVE-2026-72051,CVE-2026-72052,CVE-2026-72053,CVE-2026-72054,CVE-2026-72055,CVE-2026-72061,CVE-2026-72069,CVE-2026-72072,CVE-2026-72083,CVE-2026-72084,CVE-2026-72100,CVE-2026-72101,CVE-2026-72103,CVE-2026-72106,CVE-2026-72107,CVE-2026-72108,CVE-2026-72132,CVE-2026-72136,CVE-2026-72137,CVE-2026-7216 1,CVE-2026-72163,CVE-2026-72164,CVE-2026-72176,CVE-2026-72177,CVE-2026-72217,CVE-2026-72221,CVE-2026-72222,CVE-2026-72234,CVE-2026-72242,CVE-2026-72243,CVE-2026-72251,CVE-2026-72254,CVE-2026-72280,CVE-2026-72282,CVE-2026-72288,CVE-2026-72289,CVE-2026-72296,CVE-2026-72297,CVE-2026-72306,CVE-2026-72307,CVE-2026-72308,CVE-2026-72317,CVE-2026-72323,CVE-2026-72325,CVE-2026-72330,CVE-2026-72337,CVE-2026-72339,CVE-2026-72341,CVE-2026-72342,CVE-2026-72343,CVE-2026-72345,CVE-2026-72347,CVE-2026-72350,CVE-2026-72366,CVE-2026-72379,CVE-2026-72389,CVE-2026-72398,CVE-2026-72399,CVE-2026-72414,CVE-2026-72421,CVE-2026-72425,CVE-2026-72430,CVE-2026-72437,CVE-2026-72438,CVE-2026-72439,CVE-2026-72440,CVE-2026-72448,CVE-2026-72450,CVE-2026-72459,CVE-2026-72460,CVE-2026-72464,CVE-2026-72466,CVE-2026-72467,CVE-2026-72468,CVE-2026-72469,CVE-2026-72473,CVE-2026-72485,CVE-2026-72487,CVE-2026-72488,CVE-2026-72494,CVE-2026-72495,CVE-2026-72497,CVE-2026-72499,CVE-2026-72500,CVE-2026-72501,CVE-2026-72502,CVE-2 026-74255,CVE-2026-74261,CVE-2026-74269,CVE-2026-74270,CVE-2026-74282,CVE-2026-74284,CVE-2026-74286,CVE-2026-74296,CVE-2026-74297,CVE-2026-74307,CVE-2026-74308,CVE-2026-74313,CVE-2026-74316,CVE-2026-74317,CVE-2026-74318,CVE-2026-74321,CVE-2026-74334,CVE-2026-74345,CVE-2026-74346,CVE-2026-74349,CVE-2026-74363,CVE-2026-74375,CVE-2026-74377,CVE-2026-74378,CVE-2026-74382,CVE-2026-74388,CVE-2026-74390,CVE-2026-74394,CVE-2026-74395,CVE-2026-74397,CVE-2026-74406,CVE-2026-74464,CVE-2026-74474,CVE-2026-74475,CVE-2026-74476,CVE-2026-74479,CVE-2026-74481,CVE-2026-74482,CVE-2026-74495,CVE-2026-74496,CVE-2026-74510,CVE-2026-74512,CVE-2026-74513,CVE-2026-74517,CVE-2026-74518,CVE-2026-74523,CVE-2026-74527,CVE-2026-74533,CVE-2026-74534,CVE-2026-74535,CVE-2026-74536,CVE-2026-74537,CVE-2026-74545,CVE-2026-74548,CVE-2026-74550,CVE-2026-74555,CVE-2026-74556,CVE-2026-74557,CVE-2026-74563,CVE-2026-74566,CVE-2026-74567,CVE-2026-74571,CVE-2026-74577,CVE-2026-74581,CVE-2026-74582,CVE-2026-74584,CVE-2026-745 98,CVE-2026-74610,CVE-2026-74612,CVE-2026-74615,CVE-2026-74616,CVE-2026-74622,CVE-2026-74644,CVE-2026-74665,CVE-2026-74669,CVE-2026-74695,CVE-2026-74705,CVE-2026-74712,CVE-2026-74717,CVE-2026-74719,CVE-2026-74722,CVE-2026-74723,CVE-2026-74730,CVE-2026-74737,CVE-2026-74743,CVE-2026-74744,CVE-2026-80529,CVE-2026-80530,CVE-2026-80531,CVE-2026-80533,CVE-2026-80534,CVE-2026-80535,CVE-2026-80557,CVE-2026-80558,CVE-2026-80561,CVE-2026-80586,CVE-2026-80589,CVE-2026-80590,CVE-2026-80603,CVE-2026-80609,CVE-2026-80629,CVE-2026-80646,CVE-2026-80647,CVE-2026-80667,CVE-2026-80681,CVE-2026-80693,CVE-2026-80714,CVE-2026-80721,CVE-2026-80727,CVE-2026-80731,CVE-2026-80737,CVE-2026-80739,CVE-2026-80805,CVE-2026-80813,CVE-2026-80838 The SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). - CVE-2025-68358: btrfs: fix racy bitfield write in btrfs_clear_space_info_full() (bsc#1255531). - CVE-2025-68780: sched/deadline: only set free_cpus for online runqueues (bsc#1256671). - CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). - CVE-2026-23113: io_uring/io-wq: check IO_WQ_BIT_EXIT inside work run loop (bsc#1258278). - CVE-2026-23306: scsi: pm8001: Fix use-after-free in pm8001_queue_command() (bsc#1260501). - CVE-2026-23348: cxl/mem: Clarify @host for devm_cxl_add_nvdimm() (bsc#1260577). - CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). - CVE-2026-31530: cxl/port: Fix use after free of parent_port in cxl_detach_ep() (bsc#1262756). - CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). - CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). - CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). - CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). - CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). - CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). - CVE-2026-43299: btrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure() (bsc#1264851). - CVE-2026-43331: x86/kexec: Disable KCOV instrumentation after load_segments() (bsc#1265132). - CVE-2026-43355: iio: light: bh1780: fix PM runtime leak on error path (bsc#1265036). - CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). - CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). - CVE-2026-43439: cgroup: fix race between task migration and iteration (bsc#1265141). - CVE-2026-43448: nvme-pci: Fix race bug in nvme_poll_irqdisable() (bsc#1264807). - CVE-2026-45860: netfilter: nf_conncount: increase the connection clean up limit to 64 (bsc#1266710). - CVE-2026-45897: netfilter: nft_counter: serialize reset with spinlock (bsc#1266897). - CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). - CVE-2026-46007: hwmon: (powerz) Avoid cacheline sharing for DMA buffer (bsc#1267586). - CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). - CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). - CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). - CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). - CVE-2026-46135: nvmet-tcp: remove redundant calls to nvmet_tcp_fatal_error() (bsc#1267373). - CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). - CVE-2026-46304: nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free (bsc#1267985). - CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000). - CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). - CVE-2026-52928: af_unix: Reject SIOCATMARK on non-stream sockets (bsc#1269010). - CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). - CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). - CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). - CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). - CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). - CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). - CVE-2026-52991: sched/psi: fix race between file release and pressure write (bsc#1269134). - CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). - CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). - CVE-2026-53031: bpf: Validate node_id in arena_alloc_pages() (bsc#1269380). - CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). - CVE-2026-53034: bpf, sockmap: Fix af_unix null-ptr-deref in proto update (bsc#1269140). - CVE-2026-53048: gfs2: prevent NULL pointer dereference during unmount (bsc#1269162). - CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). - CVE-2026-53061: dm cache: fix dirty mapping checking in passthrough mode switching (bsc#1269685). - CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). - CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). - CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). - CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). - CVE-2026-53092: bpf: Fix linked reg delta tracking when src_reg == dst_reg (bsc#1269528). - CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). - CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). - CVE-2026-53109: powerpc/pgtable-frag: Fix bad page state in pte_frag_destroy (bsc#1269417). - CVE-2026-53110: s390: always declare expoline thunks (bsc#1269985). - CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). - CVE-2026-53114: perf: Extend the bit width of the arch-specific flag (bsc#1269999). - CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). - CVE-2026-53129: fs/mbcache: cancel shrink work before destroying the cache (bsc#1269633). - CVE-2026-53142: drm/xe/display: fix oops in suspend/shutdown without display (bsc#1269402). - CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). - CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). - CVE-2026-53180: timers/migration: Fix livelock in tmigr_handle_remote_up() (bsc#1269888). - CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). - CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). - CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). - CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). - CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). - CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). - CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). - CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). - CVE-2026-53284: btrfs: only release the dirty pages io tree after successful writes (bsc#1269816). - CVE-2026-53291: ALSA: hda/conexant: Fix missing error check for jack detection (bsc#1269697). - CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). - CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). - CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). - CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). - CVE-2026-53341: fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh() (bsc#1270139). - CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). - CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). - CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). - CVE-2026-63803: hdlc_ppp: sync per-proto timers before freeing hdlc state (bsc#1272284). - CVE-2026-63804: gfs2: fix use-after-free in gfs2_qd_dealloc (bsc#1272287). - CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). - CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). - CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). - CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). - CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). - CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). - CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). - CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). - CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). - CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). - CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). - CVE-2026-63890: scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (bsc#1272426). - CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). - CVE-2026-63901: USB: serial: digi_acceleport: fix memory corruption with small endpoints (bsc#1272501). - CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904). - CVE-2026-63918: l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname (bsc#1272905). - CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). - CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918). - CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: refresh nh after handling HAO option (bsc#1272855). - CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). - CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). - CVE-2026-63941: KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor (bsc#1272869). - CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). - CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). - CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865). - CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). - CVE-2026-63986: ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure (bsc#1272969). - CVE-2026-63987: ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES (bsc#1272971). - CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). - CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). - CVE-2026-63993: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() (bsc#1279847). - CVE-2026-63995: ethtool: cmis: validate start_cmd_payload_size from module (bsc#1273033). - CVE-2026-63996: ethtool: cmis: require exact CDB reply length (bsc#1273032). - CVE-2026-63997: ethtool: module: avoid leaking a netdev ref on module flash errors (bsc#1273036). - CVE-2026-63998: ethtool: module: call ethnl_ops_complete() on module flash errors (bsc#1273037). - CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). - CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). - CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). - CVE-2026-64003: scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues (bsc#1273782). - CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). - CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). - CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). - CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). - CVE-2026-64017: blk-mq: pop cached request if it is usable (bsc#1273770). - CVE-2026-64024: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction (bsc#1273107). - CVE-2026-64033: RDMA/rtrs: Fix use-after-free in path file creation cleanup (bsc#1273134). - CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). - CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). - CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). - CVE-2026-64053: block: don't overwrite bip_vcnt in bio_integrity_copy_user() (bsc#1272985). - CVE-2026-64054: net: shaper: reject duplicate leaves in GROUP request (bsc#1272894). - CVE-2026-64055: net: ethernet: cortina: Carry over frag counter (bsc#1272893). - CVE-2026-64056: net: ethernet: cortina: Make RX SKB per-port (bsc#1272502). - CVE-2026-64071: nvme-pci: fix use-after-free in nvme_free_host_mem() (bsc#1273486). - CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). - CVE-2026-64088: batman-adv: tt: fix negative tt_buff_len (bsc#1273463). - CVE-2026-64089: batman-adv: tt: fix negative last_changeset_len (bsc#1272513). - CVE-2026-64093: batman-adv: tp_meter: directly shut down timer on cleanup (bsc#1273461). - CVE-2026-64099: drm/v3d: Fix use-after-free of CPU job query arrays on error path (bsc#1273465). - CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). - CVE-2026-64103: scsi: isci: Fix use-after-free in device removal path (bsc#1273759). - CVE-2026-64109: af_unix: Fix UAF read of tail->len in unix_stream_data_wait() (bsc#1273748). - CVE-2026-64111: lsm: hold cred_guard_mutex for lsm_set_self_attr() (bsc#1273740). - CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). - CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). - CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). - CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). - CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). - CVE-2026-64119: l2tp: use list_del_rcu in l2tp_session_unhash (bsc#1273746). - CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). - CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). - CVE-2026-64131: mm/memory: fix spurious warning when unmapping device-private/exclusive pages (bsc#1274063). - CVE-2026-64146: erofs: fix metabuf leak in inode xattr initialization (bsc#1273681). - CVE-2026-64147: pds_core: fix debugfs_lookup dentry leak and error handling (bsc#1273119). - CVE-2026-64148: pds_core: fix error handling in pdsc_devcmd_wait (bsc#1273956). - CVE-2026-64162: idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() (bsc#1272366). - CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). - CVE-2026-64177: phonet/pep: disable BH around forwarded sk_receive_skb() (bsc#1272148). - CVE-2026-64179: net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (bsc#1272149). - CVE-2026-64180: mm/memory_hotplug: fix memory block reference leak on remove (bsc#1273679). - CVE-2026-64184: mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() (bsc#1272199). - CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). - CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). - CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). - CVE-2026-64210: net/mlx5e: xsk: Fix unlocked writing to ICOSQ (bsc#1273899). - CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). - CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). - CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). - CVE-2026-64224: octeontx2-pf: fix double free in rvu_rep_rsrc_init() (bsc#1272804). - CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). - CVE-2026-64232: block: recompute nr_integrity_segments in blk_insert_cloned_request (bsc#1272791). - CVE-2026-64239: mm/damon/sysfs-schemes: delete tried region in regions_rmdirs() (bsc#1273898). - CVE-2026-64244: drivers/base/memory: set mem->altmap after successful device registration (bsc#1273812). - CVE-2026-64253: kernel/fork: clear PF_BLOCK_TS in copy_process() (bsc#1273904). - CVE-2026-64256: xfs: don't wrap around quota ids in dqiterate (bsc#1273271). - CVE-2026-64265: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req (bsc#1273947). - CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). - CVE-2026-64269: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg (bsc#1273280). - CVE-2026-64283: KVM: guest_memfd: Treat memslot binding offset+size as unsigned values (bsc#1273870). - CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). - CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). - CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). - CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). - CVE-2026-64298: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (bsc#1273550). - CVE-2026-64300: perf/aux: Fix page UAF in map_range() (bsc#1273852). - CVE-2026-64307: crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) (bsc#1273567). - CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). - CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). - CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). - CVE-2026-64319: nvmet-auth: validate reply message payload bounds against transfer length (bsc#1273339). - CVE-2026-64320: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page (bsc#1273420). - CVE-2026-64321: nvme: target: rdma: fix ndev refcount leak on queue connect (bsc#1273864). - CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). - CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). - CVE-2026-64326: block: skip sync_blockdev() on surprise removal in bdev_mark_dead() (bsc#1273312). - CVE-2026-64327: usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks (bsc#1273283). - CVE-2026-64354: bpf: Validate BTF repeated field counts before expansion (bsc#1274060). - CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). - CVE-2026-64364: HID: multitouch: fix out-of-bounds bit access on mt_io_flags (bsc#1273495). - CVE-2026-64368: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled (bsc#1273997). - CVE-2026-64373: cpufreq: Fix hotplug-suspend race during reboot (bsc#1273776). - CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). - CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). - CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). - CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). - CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). - CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). - CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). - CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). - CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). - CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). - CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). - CVE-2026-64415: mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup (bsc#1273317). - CVE-2026-64416: mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host (bsc#1273286). - CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). - CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). - CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). - CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). - CVE-2026-64452: 6lowpan: fix NHC entry use-after-free on error path (bsc#1273460). - CVE-2026-64458: mm/damon/ops-common: handle extreme intervals in damon_hot_score() (bsc#1273788). - CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). - CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). - CVE-2026-64477: x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled (bsc#1274264). - CVE-2026-64507: bpf: Support for hardening against JIT spraying (bsc#1273999). - CVE-2026-64518: tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key() (bsc#1273524). - CVE-2026-64519: NFSD: Fix infinite loop in layout state revocation (bsc#1274252). - CVE-2026-64526: ethtool: tsconfig: fix missing ethnl_ops_complete() (bsc#1274052). - CVE-2026-64534: nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error (bsc#1273803). - CVE-2026-64535: nvmet-tcp: Fix potential UAF when ddgst mismatch (bsc#1273809). - CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). - CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). - CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). - CVE-2026-64542: ipv6: ndisc: fix NULL deref in accept_untracked_na() (bsc#1273309). - CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). - CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). - CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). - CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). - CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). - CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). - CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). - CVE-2026-64555: KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() (bsc#1273331). - CVE-2026-64556: perf/core: Detach event groups during remove_on_exec (bsc#1273251). - CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). - CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). - CVE-2026-64569: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (bsc#1274009). - CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). - CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). - CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). - CVE-2026-64579: xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert (bsc#1274036). - CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). - CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). - CVE-2026-64586: wifi: brcmfmac: drain bus_reset work on device removal (bsc#1274492). - CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). - CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). - CVE-2026-68096: audit: fix recursive locking deadlock in audit_dupe_exe() (bsc#1274730). - CVE-2026-68105: drm/amdgpu: Fix kernel panic during driver load failure (bsc#1274849). - CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). - CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). - CVE-2026-68120: rtase: Workaround for TX hang caused by hardware packet parsing (bsc#1274887). - CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). - CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). - CVE-2026-68124: mctp: serial: handle zero-length frames to prevent rx buffer overflow (bsc#1275192). - CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). - CVE-2026-68128: ice: reject out-of-range ptype in ice_parser_profile_init (bsc#1275238). - CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). - CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). - CVE-2026-68133: ice: fix PTP Call Trace during PTP release (bsc#1275555). - CVE-2026-68135: net: hip04: fix RX buffer leak on build_skb failure (bsc#1275557). - CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). - CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). - CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). - CVE-2026-68141: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (bsc#1275094). - CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). - CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). - CVE-2026-68144: phonet: pep: fix use-after-free in pep_get_sb() (bsc#1275481). - CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). - CVE-2026-68148: fscrypt: Add missing superblock check in find_or_insert_direct_key() (bsc#1275588). - CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). - CVE-2026-68152: amt: fix use-after-free in AMT delayed works (bsc#1275300). - CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). - CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). - CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). - CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). - CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). - CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). - CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). - CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). - CVE-2026-68164: mm/damon/core: disallow overlapping input ranges for damon_set_regions() (bsc#1274955). - CVE-2026-68165: mm/damon/core: validate ranges in damon_set_regions() (bsc#1274927). - CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). - CVE-2026-68169: mptcp: pm: userspace: fix use-after-free in get_local_id (bsc#1274952). - CVE-2026-68183: firmware: stratix10-svc: fix memory leaks and list corruption bugs (bsc#1274957). - CVE-2026-68198: wifi: ath6kl: fix use-after-free in aggr_reset_state() (bsc#1274803). - CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). - CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). - CVE-2026-68258: drm/amdkfd: Check bounds on CRIU restore queue type and mqd size (bsc#1275866). - CVE-2026-68267: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (bsc#1275139). - CVE-2026-68273: drm/amdgpu: Fix context pstate override handling (bsc#1275129). - CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). - CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). - CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). - CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). - CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). - CVE-2026-68294: net: qrtr: restrict socket creation to the initial network namespace (bsc#1275092). - CVE-2026-68296: net: gre: fix lltx regression for GRE tunnels with SEQ/CSUM (bsc#1275045). - CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). - CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). - CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). - CVE-2026-68302: amt: re-read skb header pointers after every pull (bsc#1275081). - CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). - CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). - CVE-2026-68319: pds_core: fix deadlock between reset thread and remove (bsc#1274657). - CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). - CVE-2026-68321: net: txgbe: fix FDIR filter leak on remove (bsc#1274652). - CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). - CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). - CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). - CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). - CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). - CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). - CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). - CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). - CVE-2026-68338: net/packet: avoid fanout hook re-registration after unregister (bsc#1274637). - CVE-2026-68375: bnxt_en: Handle partially initialized auxiliary devices (bsc#1274835). - CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). - CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). - CVE-2026-68393: Bluetooth: hci_sync: extend conn_hash lookup critical sections (bsc#1274904). - CVE-2026-68395: ata: sata_dwc_460ex: enable SATA interrupts only after IRQ handler is registered (bsc#1274900). - CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). - CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). - CVE-2026-68399: bpf: Fix UAF in sock clone early bailouts (bsc#1274897). - CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). - CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). - CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). - CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). - CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). - CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). - CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). - CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). - CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). - CVE-2026-68442: btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps (bsc#1274773). - CVE-2026-68448: ovl: check access to copy_file_range source with src mounter creds (bsc#1274838). - CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). - CVE-2026-68470: wifi: mac80211: validate extension-frame layout before RX (bsc#1276500). - CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). - CVE-2026-72017: net: macb: drop in-flight Tx SKBs on close (bsc#1276840). - CVE-2026-72019: macsec: don't read an unset MAC header in macsec_encrypt() (bsc#1276865). - CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). - CVE-2026-72022: llc: fix SAP refcount leak in llc_ui_autobind() (bsc#1276785). - CVE-2026-72023: octeontx2-pf: fix SQB pointer leak on init failure (bsc#1276793). - CVE-2026-72032: net/mlx5: HWS, fix matcher leak on resize target setup failure (bsc#1276955). - CVE-2026-72034: fhandle: reject detached mounts in capable_wrt_mount() (bsc#1276957). - CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). - CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). - CVE-2026-72045: octeontx2-af: cn10k: restrict VF LMTLINE sharing to its own PF (bsc#1277078). - CVE-2026-72046: gve: fix header buffer corruption with header-split and HW-GRO (bsc#1275519). - CVE-2026-72051: net: ip6_tunnel: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276801). - CVE-2026-72052: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276803). - CVE-2026-72053: net: ipip: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276814). - CVE-2026-72054: net: ip_vti: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276818). - CVE-2026-72055: net: ip6_vti: require CAP_NET_ADMIN in the device netns for changelink (bsc#1276821). - CVE-2026-72061: net: sit: require CAP_NET_ADMIN in the device netns for changelink (bsc#1277249). - CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). - CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). - CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). - CVE-2026-72084: scsi: target: core: Generate correct identifiers for PR OUT transport IDs (bsc#1275540). - CVE-2026-72100: dm-integrity: fix a bug if the bio is out of limits (bsc#1277311). - CVE-2026-72101: dm-integrity: fix leaking uninitialized kernel memory (bsc#1276831). - CVE-2026-72103: dm: avoid leaking the caller's thread keyring via the table device file (bsc#1277315). - CVE-2026-72106: dm-ioctl: fix a possible overflow in list_version_get_info (bsc#1277321). - CVE-2026-72107: dm era: fix out-of-bounds memory access for non-zero start sector (bsc#1277349). - CVE-2026-72108: dm thin metadata: fix metadata snapshot consistency on commit failure (bsc#1277350). - CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). - CVE-2026-72136: xfrm: xfrm_interface: require CAP_NET_ADMIN in the device netns for changelink (bsc#1277574). - CVE-2026-72137: xfrm: nat_keepalive: avoid double free on send error (bsc#1275587). - CVE-2026-72161: ocfs2: add journal NULL check in ocfs2_checkpoint_inode() (bsc#1277233). - CVE-2026-72163: ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits (bsc#1277231). - CVE-2026-72164: ocfs2: avoid moving extents to occupied clusters (bsc#1277553). - CVE-2026-72176: mm/damon/sysfs-schemes: put stats for scheme_add_dirs() internal error (bsc#1277230). - CVE-2026-72177: mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() (bsc#1277227). - CVE-2026-72217: SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing (bsc#1275655). - CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). - CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). - CVE-2026-72234: batman-adv: access unicast_ttvn skb->data only after skb realloc (bsc#1275672). - CVE-2026-72242: selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() (bsc#1277655). - CVE-2026-72243: selinux: check connect-related permissions on TCP Fast Open (bsc#1277656). - CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). - CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). - CVE-2026-72280: KVM: arm64: nv: Drop bogus WARN for write to ZCR_EL2 (bsc#1277726). - CVE-2026-72282: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers (bsc#1277728). - CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). - CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). - CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). - CVE-2026-72297: net: atm: reject out-of-range traffic classes in QoS validation (bsc#1277738). - CVE-2026-72306: vduse: Requeue failed read to send_list head (bsc#1277748). - CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). - CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). - CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). - CVE-2026-72323: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (bsc#1275985). - CVE-2026-72325: perf/x86/amd/core: Avoid enabling BRS from the SVM reload path (bsc#1277761). - CVE-2026-72330: net/tls: Consume empty data records in tls_sw_read_sock() (bsc#1277764). - CVE-2026-72337: Bluetooth: 6lowpan: avoid untracked enable work (bsc#1277773). - CVE-2026-72339: qede: fix off-by-one in BD ring consumption on build_skb failure (bsc#1276006). - CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). - CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). - CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). - CVE-2026-72345: net/mlx5: LAG, Fix off-by-one in single-FDB error rollback (bsc#1277782). - CVE-2026-72347: netfilter: xt_connmark: reject invalid shift parameters (bsc#1277783). - CVE-2026-72350: netfilter: xt_u32: reject invalid shift counts (bsc#1277822). - CVE-2026-72366: netfs: Fix netfs_create_write_req() to handle async cache object creation (bsc#1276333). - CVE-2026-72379: fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid (bsc#1277818). - CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). - CVE-2026-72398: sctp: add INIT verification after cookie unpacking (bsc#1276381). - CVE-2026-72399: net: enetc: check the number of BDs needed for xdp_frame (bsc#1276553). - CVE-2026-72414: net: dsa: sja1105: round up PTP perout pin duration (bsc#1278039). - CVE-2026-72421: ipv4: fib: Don't ignore error route in local/main tables (bsc#1277023). - CVE-2026-72425: ice: fix FDIR CTRL VSI resource leak in ice_reset_all_vfs() (bsc#1277120). - CVE-2026-72430: net/sched: act_ct: fix nf_connlabels leak on two error paths (bsc#1277118). - CVE-2026-72437: md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry (bsc#1277874). - CVE-2026-72438: md/raid10: fix writes_pending and barrier reference leaks on discard failures (bsc#1277115). - CVE-2026-72439: md/raid10: fix writes_pending leak on write request failures (bsc#1277876). - CVE-2026-72440: md/raid1: fix writes_pending and barrier reference leaks on write failures (bsc#1277114). - CVE-2026-72448: octeontx2-pf: Fix leak of SQ timestamp buffer on teardown (bsc#1277108). - CVE-2026-72450: xfrm: validate selector family and prefixlen during match (bsc#1278113). - CVE-2026-72459: apparmor: aa_label_alloc use aa_label_free on alloc failure (bsc#1277092). - CVE-2026-72460: apparmor: check label build before no_new_privs test (bsc#1277229). - CVE-2026-72464: xprtrdma: Post receive buffers after RPC completion (bsc#1277069). - CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). - CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). - CVE-2026-72468: xprtrdma: Initialize re_id before removal registration (bsc#1277062). - CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). - CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). - CVE-2026-72485: coresight: platform: defer connection counter increment until alloc succeeds (bsc#1276771). - CVE-2026-72487: PCI: Introduce named defines for PCI ROM (bsc#1276767). - CVE-2026-72488: soundwire: fix bug in sdw_add_element_group_count found by syzkaller (bsc#1276766). - CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). - CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). - CVE-2026-72497: RDMA/bnxt_re: Add a max slot check for SQ (bsc#1276913). - CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). - CVE-2026-72500: RDMA/bnxt_re: Free SRQ toggle page after firmware teardown (bsc#1276552). - CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). - CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). - CVE-2026-74255: tipc: fix UAF in tipc_l2_send_msg() (bsc#1276547). - CVE-2026-74261: ALSA: seq: avoid stale FIFO cells during resize (bsc#1276528). - CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). - CVE-2026-74270: handshake: Require admin permission for DONE command (bsc#1276512). - CVE-2026-74282: tipc: prevent snt_unacked underflow on CONN_ACK (bsc#1276473). - CVE-2026-74284: net/sched: sch_hfsc: Don't make class passive twice (bsc#1276468). - CVE-2026-74286: net: pfcp: allocate per-cpu tstats for PFCP netdevs (bsc#1276471). - CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). - CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). - CVE-2026-74307: ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT (bsc#1276905). - CVE-2026-74308: ext4: fix kernel BUG in ext4_write_inline_data_end (bsc#1276880). - CVE-2026-74313: vduse: hold vduse_lock across IDR lookup in open path (bsc#1276876). - CVE-2026-74316: NFSD: Handle layout stid in nfsd4_drop_revoked_stid() (bsc#1276870). - CVE-2026-74317: ixgbe: do not configure xps for XDP queues (bsc#1276866). - CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). - CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). - CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). - CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). - CVE-2026-74346: RDMA/irdma: Fix OOB read during CQ MR registration (bsc#1278155). - CVE-2026-74349: ocfs2: reject FITRIM ranges shorter than a cluster (bsc#1278180). - CVE-2026-74363: bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs (bsc#1278070). - CVE-2026-74375: md: replace wait loop with wait_event() in md_handle_request() (bsc#1277649). - CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236). - CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233). - CVE-2026-74382: net/sched: cls_bpf: prevent unbounded recursion in offload rollback (bsc#1278240). - CVE-2026-74388: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data (bsc#1278253). - CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (bsc#1278088). - CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). - CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). - CVE-2026-74397: IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier (bsc#1278098). - CVE-2026-74406: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() (bsc#1276395). - CVE-2026-74464: net: openvswitch: fix skb leak on flow key update failure during ct (bsc#1277070). - CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). - CVE-2026-74475: vxlan: unclone skb head before modifying eth header in route_shortcircuit() (bsc#1276339). - CVE-2026-74476: veth: convert frag_list skbs before running XDP (bsc#1276341). - CVE-2026-74479: net: pktgen: fix proc entry use-after-free (bsc#1276354). - CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). - CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (bsc#1276346). - CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). - CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). - CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). - CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). - CVE-2026-74513: dibs: fix use-after-free of dmb_node in loopback attach/detach/unregister (bsc#1275956). - CVE-2026-74517: KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs (bsc#1276258). - CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). - CVE-2026-74523: qede: sync udp_tunnel ports outside qede_lock in the recovery path (bsc#1275802). - CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). - CVE-2026-74533: Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero (bsc#1275804). - CVE-2026-74534: Bluetooth: ISO: Fix data-race on iso_pi(sk) in socket and HCI event paths (bsc#1275801). - CVE-2026-74535: Bluetooth: ISO: avoid deadlocks in iso_sock_timeout (bsc#1275812). - CVE-2026-74536: Bluetooth: ISO: fix leaking sk after socket release (bsc#1275799). - CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). - CVE-2026-74545: rtase: fix double free of multi-frag skb on DMA map failure (bsc#1275679). - CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). - CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). - CVE-2026-74555: scsi: libsas: Fix HA resume deadlock and hisi_sas disk-wake race (bsc#1275690). - CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). - CVE-2026-74557: scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (bsc#1275685). - CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). - CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). - CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). - CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). - CVE-2026-74577: net: mpls: initialize rtm_tos in mpls_getroute() (bsc#1275572). - CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). - CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). - CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). - CVE-2026-74598: ipv6: fix Route Information option length validation (bsc#1277918). - CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). - CVE-2026-74612: veth: fix skb length accounting after XDP frag adjustment (bsc#1277505). - CVE-2026-74615: vxlan: do not arm the ageing timer on a device that is down (bsc#1277901). - CVE-2026-74616: xdp: reject clones that overrun skb_shared_info tailroom (bsc#1277813). - CVE-2026-74622: net: atlantic: free RX pages of consumed but not refilled buffers (bsc#1277862). - CVE-2026-74644: mm/damon/ops-common: putback folios on invalid migrate nid (bsc#1277033). - CVE-2026-74665: net: fix skb length accounting after generic XDP frag adjustment (bsc#1277407). - CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). - CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). - CVE-2026-74705: udp: fix potential use-after-free in tunnel segmentation (bsc#1276922). - CVE-2026-74712: vdpa/mlx5: Fix buffer length in create_direct_keys() (bsc#1276577). - CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). - CVE-2026-74719: net/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler() (bsc#1276572). - CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). - CVE-2026-74723: btrfs: lzo: reject inline extents without valid headers (bsc#1276562). - CVE-2026-74730: NFS: Pin the 'struct nfs_server' during a FREE_STATEID call (bsc#1276566). - CVE-2026-74737: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG (bsc#1277898). - CVE-2026-74743: macvlan: inherit needed_headroom and needed_tailroom from lowerdev (bsc#1277908). - CVE-2026-74744: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev (bsc#1278094). - CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). - CVE-2026-80530: xfs: fix exchange-range reflink flag clearing issue with INO1_WRITTEN (bsc#1277668). - CVE-2026-80531: xfs: avoid UAF on sc->tempip in xrep_tempfile_create (bsc#1277680). - CVE-2026-80533: xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair (bsc#1277636). - CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). - CVE-2026-80535: xfs: don't double-lock when deleting a self-referential directory (bsc#1277641). - CVE-2026-80557: libceph: fix OOB read in decode_watchers() via missing bounds check (bsc#1277268). - CVE-2026-80558: libceph: Avoid using invalid osd indices from primary_temp (bsc#1277485). - CVE-2026-80561: libceph: fix multiple unsafe decodes in decode_locker() (bsc#1277265). - CVE-2026-80586: mptcp: options: reset DSS fields in case of unexpected size (bsc#1277328). - CVE-2026-80589: block: stop the timeout timer when releasing a never added disk (bsc#1277335). - CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). - CVE-2026-80603: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read (bsc#1278293). - CVE-2026-80609: qede: fix out-of-bounds check for cqe->len_list (bsc#1278334). - CVE-2026-80629: octeontx2-af: npc: Fix size of entry2cntr_map (bsc#1277308). - CVE-2026-80646: ipv6: guard against possible NULL deref in __in6_dev_stats_get() (bsc#1277513). - CVE-2026-80647: RDMA/hns: Fix warning in poll cq direct mode (bsc#1278331). - CVE-2026-80667: net/mlx5: LAG, MPESW, Fix missing complete() on devcom error (bsc#1278324). - CVE-2026-80681: vxlan: re-fetch eth header after route_shortcircuit() (bsc#1278416). - CVE-2026-80693: idpf: bound interrupt-vector register fill to the allocated array (bsc#1278395). - CVE-2026-80714: ipvs: do not propagate one-packet flag to synced conns (bsc#1277561). - CVE-2026-80721: Bluetooth: ISO: ensure no dangling hcon references in iso_conn (bsc#1277845). - CVE-2026-80727: x86/mce: Set up the polling timer before CMCI discovery (bsc#1278703). - CVE-2026-80731: net: remove CAP_SYS_RAWIO zero-padding in dev_validate_header (bsc#1278716). - CVE-2026-80737: serial: amba-pl011: synchronize DMA teardown (bsc#1279487). - CVE-2026-80739: net/mlx5e: TC, Check if flow is PEER before acquiring devcom lock (bsc#1278733). - CVE-2026-80805: xfs: validate attr entry pointer before field access (bsc#1279580). - CVE-2026-80813: nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist() (bsc#1279537). - CVE-2026-80838: vxlan: keep the last remote linked during FDB flush (bsc#1279842). The following non security issues were fixed: - accel/ivpu: Limit firmware log name prints to field size (git-fixes). - accel/ivpu: Validate firmware log buffer metadata (git-fixes). - accel/ivpu: Validate full buffer range in ivpu_to_cpu_addr (git-fixes). - accel/qaic: Address potential out-of-bounds read in resp_worker() (git-fixes). - accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). - accessibility: speakup: unregister tty ldisc on later init failures (git-fixes). - ACPI: APEI: Fix ERST timeout unit conversion (git-fixes). - ACPI: battery: Adjust charging status validation check (git-fixes). - ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). - ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git-fixes). - ACPI: pfr_update: fix stack buffer overflow in query_capability() (git-fixes). - ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). - ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). - ACPI: processor_idle: Mark LPI enter functions as __cpuidle (git-fixes). - ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). - ACPI: video: Release PCI device reference after lookup (git-fixes). - ALSA: 6fire: bound the MIDI event length from the device (git-fixes). - ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). - ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). - ALSA: caiaq: Decoupling ep1_in_urb in caiaq dev (git-fixes). - ALSA: caiaq: Fix potential double-free at error path (git-fixes). - ALSA: control: Don't add invalid kcontrols to LED layer (git-fixes). - ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). - ALSA: ctxfi: Fix CA20K2 S/PDIF passthrough (git-fixes). - ALSA: dummy: Check card index validity at probe (stable-fixes). - ALSA: dummy: Report a change when one capture switch channel moves (git-fixes). - ALSA: harmony: initialize locks before requesting IRQ (git-fixes). - ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). - ALSA: hda/realtek: Enable headset mic on F+ FLAPTOP r (stable-fixes). - ALSA: hda: Fix connection list comparison in proc output (git-fixes). - ALSA: hda: Report a change when only the channel status bytes move (git-fixes). - ALSA: hda: restore MFG widget enumeration after core split (git-fixes). - ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). - ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF (git-fixes). - ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). - ALSA: rawmidi: Return the error from snd_rawmidi_input_params() (git-fixes). - ALSA: scarlett2: Use a private URB for the notification endpoint (git-fixes). - ALSA: seq: Don't leak the extension cell pointer in the bounce payload (git-fixes). - ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). - ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). - ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). - ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). - ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). - ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output() (git-fixes). - ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). - ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). - ALSA: usbusx2y: fix in04_last array size mismatch with in04_buf (git-fixes). - ALSA: usbusx2y: validate URB actual_length in interrupt callback (git-fixes). - ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). - ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git-fixes). - apparmor: advertise the tcp fast open fix is applied (git-fixes). - ASoC: ab8500: Correct digital interface format setup (git-fixes). - ASoC: ab8500: Repair the DAPM capture graph (git-fixes). - ASoC: ab8500: Reset the audio block before configuring it (git-fixes). - ASoC: ab8500: Validate and program TDM slots correctly (git-fixes). - ASoC: adau1761: sort the register default table (git-fixes). - ASoC: amd: renoir: fix disable_pdm_interrupts() to clear mask bits (git-fixes). - ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). - ASoC: amd: yc: fix memory leak in acp6x_pdm_dma_close() (git-fixes). - ASoC: apple: mca: increase SERDES reset delay (git-fixes). - ASoC: bcm: bcm63xx: Publish the OF module aliases (git-fixes). - ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). - ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). - ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). - ASoC: cs35l41: sort the register default table (git-fixes). - ASoC: cs35l45: sort the register default table (git-fixes). - ASoC: cs4265: sort the register default table (git-fixes). - ASoC: cx2072x: sort the register default table (git-fixes). - ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). - ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git-fixes). - ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git-fixes). - ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). - ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). - ASoC: fsl_easrc: sort the register default table (git-fixes). - ASoC: hdac_hda: Fix hlink refcount leak on component registration failure (git-fixes). - ASoC: Intel: avs: Clean up streams if their initialization fails (git-fixes). - ASoC: Intel: avs: Clean up the bus when fetching ML caps fails (git-fixes). - ASoC: Intel: avs: Do not ignore -ENOENT when loading a topology (git-fixes). - ASoC: Intel: avs: Fix unbalanced module reference count (git-fixes). - AsoC: intel: sst: fix PCI device reference leak on probe failure (git-fixes). - ASoC: Intel: SST: Publish the PCI module aliases (git-fixes). - ASoC: loongson: Fix error handling in ACPI property parsing (git-fixes). - ASoC: max9860: sort the register default table (git-fixes). - ASoC: mediatek: mt8183-afe-pcm: Shorten memif_data table using macros (stable-fixes). - ASoC: mediatek: mt8183-afe-pcm: Support >32 bit DMA addresses (git-fixes). - ASoC: mediatek: mt8183-afe-pcm: use local `dev` pointer in driver callbacks (stable-fixes). - ASoC: mediatek: mt8183: Check runtime resume during probe (git-fixes). - ASoC: mediatek: mt8192-afe-pcm: Simplify probe() with local dev variable (stable-fixes). - ASoC: mediatek: mt8192: Check runtime resume during probe (git-fixes). - ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). - ASoC: ml26124: sort the register default table (git-fixes). - ASoC: mt6351: Publish the OF module alias (git-fixes). - ASoC: pcm512x: sort the register default table (git-fixes). - ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). - ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git-fixes). - ASoC: rt274: sort the register default table (git-fixes). - ASoC: rt286: sort the register default table (git-fixes). - ASoC: rt298: sort the register default table (git-fixes). - ASoC: rt700-sdw: always drain jack work on remove (git-fixes). - ASoC: rt700: drop duplicate reg_default entry (git-fixes). - ASoC: rt700: sort the register default table (git-fixes). - ASoC: rt711-sdca: sort the register default tables (git-fixes). - ASoC: rt711: sort the register default table (git-fixes). - ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). - ASoC: rt712-sdca-sdw: sort the register default table (git-fixes). - ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). - ASoC: rt715-sdca: sort the register default tables (git-fixes). - ASoC: rt715: sort the register default table (git-fixes). - ASoC: rt1017-sdca-sdw: sort the register default table (git-fixes). - ASoC: rt1316-sdw: sort the register default table (git-fixes). - ASoC: rt1318-sdw: sort the register default table (git-fixes). - ASoC: rt1318: sort the register default table (git-fixes). - ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). - ASoC: sgtl5000: sort the register default table (git-fixes). - ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git-fixes). - ASoC: SOF: validate topology volume range before allocation (git-fixes). - ASoC: sprd: validate compress buffer sizes against fixed allocations (git-fixes). - ASoC: sti-sas: sort the register default table (git-fixes). - ASoC: sti: initialize IRQ lock before requesting IRQ (git-fixes). - ASoC: tas2552: sort the register default table (git-fixes). - ASoC: tas2764: sort the register default table (git-fixes). - ASoC: tas2780: sort the register default table (git-fixes). - ASoC: tegra210_i2s: sort the register default table (git-fixes). - ASoC: tegra210_mixer: sort the register default table (git-fixes). - ASoC: tegra: Fix the MIXER enable default value (git-fixes). - ASoC: tegra: Sort MBDRC register defaults (git-fixes). - ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). - ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). - ata: ahci: work around lost interrupts on Marvell 88SE61xx (git-fixes). - batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). - batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). - batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). - batman-adv: fix stale receive device on merged fragments (git-fixes). - batman-adv: mcast: ensure unshared skb for multicast packets (git-fixes). - batman-adv: mcast: linearize skbuff for packet generation (git-fixes). - batman-adv: reject unrepresentable multicast TVLV offsets (git-fixes). - blk-mq: reinsert cached request to the list (bsc#1273770). - Bluetooth: btintel: bound firmware ID by TLV length (git-fixes). - Bluetooth: btintel: Fix diagnostics event detection (git-fixes). - Bluetooth: btintel: validate version TLV value lengths (git-fixes). - Bluetooth: btintel_pcie: Clear automask on spurious interrupts (git-fixes). - Bluetooth: btintel_pcie: fix tx_handle bounds off-by-one (git-fixes). - Bluetooth: btintel_pcie: validate packet_len before skb_put_data (git-fixes). - Bluetooth: btmtk: Declare MT7920 (MT7961 1a) Bluetooth firmware (git-fixes). - Bluetooth: btmtk: Do not discard the subsystem reset timeout (git-fixes). - Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() (stable-fixes). - Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). - Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git-fixes). - Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git-fixes). - Bluetooth: btqcomsmd: destroy RPMsg endpoints before freeing hci_dev (git-fixes). - Bluetooth: btrtl: Don't leak return code when parsing firmware format v2 (git-fixes). - Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git-fixes). - Bluetooth: btusb: Fix short read errors in btusb_qca_send_vendor_req() (stable-fixes). - Bluetooth: btusb: Fix UAF of btusb_data by rx_work (git-fixes). - Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). - Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). - Bluetooth: hci_aml: validate firmware segment lengths (git-fixes). - Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378 (git-fixes). - Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_conn: fix the SCO setup context lifetime (git-fixes). - Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). - Bluetooth: hci_conn: re-enable advertising only for peripheral role (git-fixes). - Bluetooth: hci_core: Fix race condition during device registration (git-fixes). - Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb (git-fixes). - Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git-fixes). - Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). - Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). - Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). - Bluetooth: hci_mrvl: Fix wrong return value check of wait_on_bit_timeout() (git-fixes). - Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request (git-fixes). - Bluetooth: hci_sync: Fix accept list UAF during suspend (git-fixes). - Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). - Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). - Bluetooth: hci_sync: Use bt_dev_err() to log error message in hci_update_event_filter_sync() (stable-fixes). - Bluetooth: hci_sysfs: Fix NULL pointer dereference in device_del() (git-fixes). - Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git-fixes). - Bluetooth: ISO: do not force BT_LISTEN after a failed BIG sync (git-fixes). - Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). - Bluetooth: L2CAP: clear FLAG_DEFER_SETUP only for same PID/PSM (git-fixes). - Bluetooth: L2CAP: fix chan mode for LE_CONN_REQ + EXT_FLOWCTL pchan (git-fixes). - Bluetooth: L2CAP: fix out-of-bounds write in l2cap_ecred_connect (git-fixes). - Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync (git-fixes). - Bluetooth: MGMT: free the HCI command when it is cancelled (git-fixes). - Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). - Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 (git-fixes). - Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update (git-fixes). - Bluetooth: MSFT: validate evt_prefix_len against the response length (git-fixes). - Bluetooth: qca: fix NVM tag length underflow in TLV parser (git-fixes). - Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). - Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git-fixes). - Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). - Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). - bnxt_en: Check return value of bnxt_hwrm_vnic_cfg (jsc#PED-16798). - bnxt_en: Delay for 5 seconds after AER DPC for all chips (jsc#PED-16798). - bnxt_en: Don't assume XDP is never enabled in bnxt_init_dflt_ring_mode() (jsc#PED-16798). - bnxt_en: Drop pci_save_state() after pci_restore_state() (jsc#PED-16798). - bnxt_en: Implement XDP RSS hash metadata extraction (jsc#PED-16798). - bnxt_en: Implement XDP RSS hash metadata extraction for V3_CMP (jsc#PED-16798). - bnxt_en: Move bnxt_rss_ext_op into header (jsc#PED-16798). - bnxt_en: Refactor some basic ring setup and adjustment logic (jsc#PED-16798). - bnxt_en: Restore default stat ctxs for ULP when resource is available (jsc#PED-16798). - bnxt_en: Set bp->max_tpa according to what the FW supports (jsc#PED-16798). - bnxt_en: Use absolute target ns from ptp_clock_request (jsc#PED-16798). - bnxt_en: use bnxt_xdp_buff for xdp context (jsc#PED-16798). - bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). - bus: mhi: host: Fix controller cleanup on EDL sysfs failure (git-fixes). - bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). - bus: ti-sysc: Fix /chosen node reference leak (git-fixes). - cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). - can: j1939: add missing calls in NETDEV_UNREGISTER notification handler (git-fixes). - can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). - char: xilinx_hwicap: unregister class on init errors (git-fixes). - cleanup: add a scoped version of CLASS() (stable-fixes). - cleanup: fix scoped_class() (git-fixes). - compiler_types: Introduce __flex_counter() and family (bsc#1280139). - cpufreq: intel_pstate: Add and use hybrid_get_cpu_type() (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Avoid SMP calls to get cpu-type (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Fix hwp_get_cpu_scaling() (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Use correct scaling factor on Raptor Lake-E (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Use CPPC to get scaling factors (bsc#1240957 bsc#1249104 bsc#1265220). - cpufreq: intel_pstate: Use HYBRID_SCALING_FACTOR_ADL for Bartlett Lake (bsc#1240957 bsc#1249104 bsc#1265220). - crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). - crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git-fixes). - crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). - crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). - crypto: ccp - Abort doing SEV INIT if SNP INIT fails (stable-fixes). - crypto: ccp - Add new SEV/SNP platform shutdown API (stable-fixes). - crypto: ccp - Always pass in an error pointer to __sev_platform_shutdown_locked() (git-fixes). - crypto: ccp - Fix __sev_snp_shutdown_locked (git-fixes). - crypto: ccp - Fix dereferencing uninitialized error pointer (git-fixes). - crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). - crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). - crypto: ccp - Fix SNP panic notifier unregistration (git-fixes). - crypto: ccp - Move dev_info/err messages for SEV/SNP init and shutdown (stable-fixes). - crypto: ccp - Move SEV/SNP Platform initialization to KVM (stable-fixes). - crypto: ccp - Register SNP panic notifier only if SNP is enabled (stable-fixes). - crypto: ccp - Reset TMR size at SNP Shutdown (stable-fixes). - crypto: doc - Remove extra parenthesis (git-fixes). - crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). - crypto: keembay - Fix AEAD unregister count in error path (git-fixes). - crypto: keembay - Initialize completion before requesting IRQ (git-fixes). - crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). - crypto: lskcipher - propagate errors from unaligned crypt (git-fixes). - crypto: mxs-dcp - fix source scatterlist length access (git-fixes). - crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). - crypto: qat - clear AES key schedule from stack (git-fixes). - crypto: qce - fix CCM AAD buffer underallocation (git-fixes). - crypto: qce - fix error path in devm_qce_register_algs (git-fixes). - crypto: qcom-rng - Allow zero as a random number (git-fixes). - crypto: qcom-rng - Enable clock in hwrng case (git-fixes). - crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). - crypto: sa2ul - stop probe if context pool creation fails (git-fixes). - crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git-fixes). - crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin (stable-fixes). - crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req() (git-fixes). - cxl/acpi: Fix CXL_ACPI and CXL_PMEM Kconfig tristate mismatch (git-fixes). - cxl: Adjust the startup priority of cxl_pmem to be higher (git-fixes). - default_gfp(): avoid using the 'newfangled' __VA_OPT__ trick (bsc#1280139). - device property: fix infinite loop in fwnode_for_each_child_node() (git-fixes). - dm/amdgpu: fix malformed link_settings debugfs output (git-fixes). - dma-mapping: add __dma_from_device_group_begin()/end() (bsc#1267586). - dmaengine: dw-edma: Clear stale requests on termination (git-fixes). - dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). - dmaengine: dw-edma: Fix HDMA channel status register access (git-fixes). - dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). - dmaengine: dw-edma: Serialize abort state updates (git-fixes). - dmaengine: dw-edma: Serialize channel state checks (git-fixes). - dmaengine: dw-edma: Terminate all descriptors without callbacks (git-fixes). - dmaengine: fsl-edma: tracing: no ptr dereference during log output (git-fixes). - dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). - dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). - dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). - dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). - dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). - dmaengine: zynqmp_dma: fix kernel doc for zynqmp_dma_remove() (git-fixes). - driver core: soc: Unregister bus on early device registration failure (git-fixes). - drivers/virt: pkvm: Fix end calculation in mmio_guard_ioremap_hook() (git-fixes). - Drivers: hv: Use meaningful errnos for hypercall status codes (git-fixes). - drm/amd/display: Add AV mute wait frames to dce110_set_avmute (stable-fixes). - drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). - drm/amd/display: Check for tg ops in dce110_set_avmute (git-fixes). - drm/amd/display: dce100: skip non-DP stream encoders for DP MST (stable-fixes). - drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix (git-fixes). - drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE (git-fixes). - drm/amd/display: fix division by zero in get_estimated_bw() (git-fixes). - drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank() (git-fixes). - drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames (stable-fixes). - drm/amd/display: Remove unused-but-set variable hubp from (git-fixes). - drm/amd/display: validate plane degamma LUT size for private color prop (git-fixes). - drm/amd/pm: adjust the visibility of pp_table sysfs node (stable-fixes). - drm/amd/pm: fix gpu metrics energy accumulator for smu 13.0.0/13.0.7 (git-fixes). - drm/amd/pm: fix smu14 power limit range calculation (stable-fixes). - drm/amd/pm: make pp_features read-only when scpm is enabled (stable-fixes). - drm/amd/pm: Use same metric table for APU (stable-fixes). - drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git-fixes). - drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). - drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). - drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). - drm/amdgpu/gfx8: drop unecessary BUG_ON() (stable-fixes). - drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git-fixes). - drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git-fixes). - drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() (stable-fixes). - drm/amdgpu/uvd: Fix forcing MSG, FB BOs into VCPU segment when it isn't at 0 (v2) (stable-fixes). - drm/amdgpu/uvd: Place VCPU BO only in VRAM for UVD 4.x and older (stable-fixes). - drm/amdgpu/vce: fix integer overflow in image size (stable-fixes). - drm/amdgpu/vcn4: avoid rereading IB param length (stable-fixes). - drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git-fixes). - drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). - drm/amdgpu: check ASPM on the dGPU host link (git-fixes). - drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). - drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). - drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). - drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved (stable-fixes). - drm/amdgpu: fix division by zero with invalid uvd dimensions (stable-fixes). - drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() (stable-fixes). - drm/amdgpu: fix nbif 6.3.1 l1 low power not functional (git-fixes). - drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). - drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). - drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). - drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). - drm/amdgpu: Fix VFCT bus number matching with soft filter (stable-fixes). - drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). - drm/amdgpu: invoke pm_genpd_remove() before freeing genpd (stable-fixes). - drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini (git-fixes). - drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 (git-fixes). - drm/amdgpu: reject oversized IBs with per-ring packet limits (stable-fixes). - drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). - drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable-fixes). - drm/amdgpu: remove unused function parameter (stable-fixes). - drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). - drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). - drm/amdkfd: Check bounds in allocate_event_notification_slot (stable-fixes). - drm/amdkfd: fix 32-bit overflow in CWSR total size calculation (stable-fixes). - drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). - drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). - drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore (git-fixes). - drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). - drm/amdkfd: Use kvcalloc to allocate arrays (stable-fixes). - drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). - drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). - drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). - drm/bridge: tc358767: clamp the reported AUX read size to the request (git-fixes). - drm/connector/hdmi: Fix out of bounds memory read (git-fixes). - drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). - drm/drm_exec: fix up contended obj when num_objects is 0 (git-fixes). - drm/gud: NUL-terminate TV mode names read from the device (git-fixes). - drm/gud: validate TV mode names before creating enum property (git-fixes). - drm/hibmc: Fix list of formats on the primary plane (git-fixes). - drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). - drm/i915/hdcp: check streams bounds before overflow (git-fixes). - drm/i915/hdcp: Move to using intel_display in intel_hdcp (stable-fixes). - drm/i915/hdcp: require monotonically increasing seq_num_v (git-fixes). - drm/i915/hdcp: Skip inactive MST connectors when building stream list (stable-fixes). - drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() (stable-fixes). - drm/i915/vrr: require valid min/max vfreq for VRR (git-fixes). - drm/i915: Fix memory leak in query_perf_config_list() (git-fixes). - drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). - drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg (git-fixes). - drm/msm/a6xx: Fix stale rpmh votes after suspend (git-fixes). - drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). - drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). - drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git-fixes). - drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE (git-fixes). - drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op (git-fixes). - drm/nouveau/uvmm: fix premature region free on failed OP_UNMAP_SPARSE (git-fixes). - drm/nouveau: unsubscribe the channel-kill event before the fence context (git-fixes). - drm/nouveau: Use write-combined maps for coherent (git-fixes). - drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). - drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). - drm/panthor: fix firmware control interface bounds checks (git-fixes). - drm/panthor: return PTR_ERR() from devm_drm_dev_alloc() (git-fixes). - drm/panthor: skip zero-sized firmware sections (git-fixes). - drm/radeon: fix autosuspend cleanup during teardown (git-fixes). - drm/radeon: fix r100_copy_blit for large BOs (stable-fixes). - drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). - drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). - drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). - drm/ssd130x: fix column and row end address in partial updates in ssd133x (git-fixes). - drm/sun4i: crtc: Propagate layer initialization error (git-fixes). - drm/sun4i: Drop node references while building component list (git-fixes). - drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). - drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). - drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). - drm/sun4i: hdmi: Don't leak sync polarity bits into packet control (git-fixes). - drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). - drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). - drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). - drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). - drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). - drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info (git-fixes). - drm/tve200: add OF module alias for autoloading (git-fixes). - drm/virtio: Fix a NULL vs ERR_PTR() bug in virtio_gpu_user_framebuffer_create() (git-fixes). - drm/xe/oa: Check managed mutex initialization errors (git-fixes). - drm/xe/oa: Fix sync entry leak on OA config emit failure (git-fixes). - drm/xe/oa: Remove sysfs entry on idr_alloc failure in xe_oa_add_config_ioctl() (git-fixes). - drm/xe: Introduce xe_gt_dbg_printer() (stable-fixes). - drm/xe: Order ring writes before ring tail updates (git-fixes). - drm/xe: Stub out new pagefault layer (stable-fixes). - drm/xe: tests: fix error message in xe_migrate_sanity_test() (git-fixes). - drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used (git-fixes). - drm: fix race between partial drm_dev_register() failure and ioctl (git-fixes). - drm: lcdif: Wait for vblank before disabling DMA (git-fixes). - drm: Remove unused header in drm_dumb_buffers.c (git-fixes). - efi: fix stale reference to efi_recover_from_page_fault() (git-fixes). - erspan: Initialize options_len before referencing options (bsc#1274727). - ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). - fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). - fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). - fbdev: kyro: Validate overlay viewport coordinates (git-fixes). - fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). - fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). - fbdev: uvesafb: unregister connector callback on init failure (git-fixes). - fbdev: vfb: defer cleanup until the last reference (git-fixes). - firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). - firmware: arm_scmi: Clean up channels on setup failure (git-fixes). - firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). - firmware: arm_scmi: Fix requested device removal race (git-fixes). - firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). - firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). - firmware: arm_scmi: Publish channel state before callbacks (git-fixes). - firmware: arm_scmi: Quiesce notifications before teardown (git-fixes). - firmware: arm_scmi: Rate-limit queue-full warnings in IRQ context (git-fixes). - firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). - firmware: arm_scmi: Roll back partial protocol table registration (git-fixes). - firmware: arm_scmi: Unregister device notifier before IDR teardown (git-fixes). - firmware: arm_scmi: Unrequest devices if driver registration fails (git-fixes). - firmware: arm_scmi: Unwind P2A receiver mailbox setup failure (git-fixes). - firmware: arm_scmi: Unwind TX receiver mailbox setup failure (git-fixes). - firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). - firmware_loader: do not queue completed sysfs fallback requests (git-fixes). - fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git-fixes). - fpga: dfl: fme: add error handling (git-fixes). - fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git-fixes). - fuse: fix race between interrupt and resend (git-fixes). - gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on unbind (git-fixes). - gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). - gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). - gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings (stable-fixes). - HID: asus: fix missing hid_is_usb() check (git-fixes). - HID: asus: simplify RGB init sequence (stable-fixes). - HID: bpf: serialize device reference release in struct_ops destroy path (git-fixes). - HID: core: fix number/pointer type confusion on long items (git-fixes). - HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). - HID: ft260: fix stack-use-after-return write in I2C read race (git-fixes). - HID: ft260: validate i2c input report length (stable-fixes). - HID: hyperv: validate initial device info bounds (git-fixes). - HID: i2c-hid: Fix '(null)' output when reading report descriptor fails (git-fixes). - HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). - HID: lg4ff: validate report length before fixed offsets (git-fixes). - HID: logitech-dj: Fix maxfield check in DJ short report validation (git-fixes). - HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git-fixes). - HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). - HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable-fixes). - HID: magicmouse: do not keep a stale msc->input if no input is claimed (git-fixes). - HID: magicmouse: fix battery reporting for Bluetooth Magic Trackpad USB-C (git-fixes). - HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). - HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git-fixes). - HID: magicmouse: re-enable multitouch after reset-resume (git-fixes). - HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). - HID: multitouch: reclassify HTIX5288 to WIN_8_FORCE_MULTI_INPUT_NSMU (git-fixes). - HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). - HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git-fixes). - HID: nintendo: register input device after capabilities are set (git-fixes). - HID: nintendo: stop device IO before hid_hw_stop on probe failure (git-fixes). - HID: picolcd: clamp eeprom debugfs read to bytes actually received (git-fixes). - HID: pidff: Rework pidff_set_time() to fix warnings (stable-fixes). - HID: pidff: Use ARRAY_SIZE macro instead of sizeof (stable-fixes). - HID: rmi: fix OOB access with undersized RMI reports (git-fixes). - HID: roccat: bound device-supplied profile index (git-fixes). - HID: roccat: free buffered reports when destroying device (git-fixes). - HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git-fixes). - HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). - HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). - HID: synchronize input before cleaning up a failed probe (git-fixes). - HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). - HID: wacom: validate report length in wacom_intuos_pro2_bt_irq (git-fixes). - hwmon: (ads7828) Fix external VREF regulator handling (git-fixes). - hwmon: (applesmc) fix key backlight workqueue leak on register failure (git-fixes). - hwmon: (aspeed-pwm-tacho) Propagate reset deassert errors (git-fixes). - hwmon: (chipcap2) fix channels in humidity alarm notifications (git-fixes). - hwmon: (coretemp) Fix core_data leak on CPUs without PTS (git-fixes). - hwmon: (corsair-cpro) Create debugfs entries after hwmon registration (git-fixes). - hwmon: (corsair-cpro) Remove debugfs entries when probe fails (git-fixes). - hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). - hwmon: (gpio-fan) Fix use-after-free in alarm work (git-fixes). - hwmon: (gpio-fan) take fan_data->lock in gpio_fan_shutdown() (git-fixes). - hwmon: (ina2xx) Add support for has_alerts configuration flag (stable-fixes). - hwmon: (ina2xx) Add support for INA234 (stable-fixes). - hwmon: (ina2xx) Add support for INA260 (stable-fixes). - hwmon: (ina2xx) Fix various overflow issues (git-fixes). - hwmon: (ina2xx) Make it easier to add more devices (stable-fixes). - hwmon: (ina2xx) Shift INA234 shunt and current registers (stable-fixes). - hwmon: (ina226) Add support for SY24655 (stable-fixes). - hwmon: (ltc4282) Avoid overflow in maximum power calculation (git-fixes). - hwmon: (ltc4282) Clamp negative current limits (git-fixes). - hwmon: (ltc4282) Fix parsing adi,current-limit-sense-microvolt (git-fixes). - hwmon: (ltc4282) Make sure clk_init_data is fully initialized (git-fixes). - hwmon: (max6621) fix negative temperature offset and crit readings (git-fixes). - hwmon: (max6621) fix temperature clamp range (git-fixes). - hwmon: (nzxt-smart2) Check return value of init_device() in probe (git-fixes). - hwmon: (pmbus) Clear generic status alarms with CLEAR_FAULTS (git-fixes). - hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). - hwmon: Switch back to struct platform_driver::remove() (stable-fixes). - hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). - hwrng: omap - Fix probe error path cleanup (git-fixes). - hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git-fixes). - i2c: core: fix debugfs UAF on adapter removal (git-fixes). - i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (git-fixes). - i2c: imx: separate atomic, dma and non-dma use case (stable-fixes). - i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). - i2c: mux: Fix channel node leak on adapter add failure (git-fixes). - i2c: ocores: Disable clock on failed resume (git-fixes). - i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). - i3c: dw: rename 'pclk' to 'apb' to match dt-binding (git-fixes). - i3c: master: Fix device_register() error path (git-fixes). - i3c: master: Fix info leak and UAF in device unregister path (git-fixes). - i3c: master: Fix potential UAF in i3c_device_uevent() (git-fixes). - i3c: master: svc: bound IBI payload to the requested max_payload_len (git-fixes). - ieee802154: 6lowpan: fix NULL dereference in lowpan_newlink (git-fixes). - ieee802154: cc2520: fix FIFOP work use-after-free (git-fixes). - ieee802154: hwsim: serialize pib updates to fix double-free (git-fixes). - iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). - iio: adc: max34408: add missing 'select REGMAP_I2C' to Kconfig (git-fixes). - iio: adc: pac1921: fix wrong channel used in trigger handler read (git-fixes). - iio: buffer: Fix potential use-after-free in anonymous buffer release (git-fixes). - iio: buffer: Make IIO DMA fence release RCU-safe (git-fixes). - iio: buffer: Tie IIO dma fence lock lifetime to the fence (git-fixes). - iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). - iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). - iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). - iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). - iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). - iio: light: cm32181: return zero after writing calibscale (git-fixes). - iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). - iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). - iio: light: isl29028: return zero in write_raw() on success (git-fixes). - iio: light: ltrf216a: fix runtime PM reference leak in error path (git-fixes). - iio: light: opt4001: Fix incompatible pointer type passed to div_u64_rem() (git-fixes). - iio: light: opt4001: Fix power down clearing bits of the wrong register (git-fixes). - iio: light: opt4001: Fix reversed GENMASK() arguments in fault count mask (git-fixes). - iio: light: opt4001: Reject integration times with a non-zero seconds part (git-fixes). - iio: light: tsl2583: return zero in write_raw() on success (git-fixes). - iio: light: tsl2772: fix ALS calibscale readback (git-fixes). - iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). - iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git-fixes). - iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). - iio: srf04: fix pm_runtime handling on probe error path (git-fixes). - iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). - Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). - Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). - Input: cs40l50-vibra - validate custom data from user space (git-fixes). - Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). - Input: evdev - sanitize event type index when fetching event masks (stable-fixes). - Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). - Input: focaltech - use signed coordinates to prevent underflow (git-fixes). - Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). - Input: iforce - validate input packet lengths (stable-fixes). - Input: iqs5xx - validate firmware record destination span (git-fixes). - Input: mms114 - fix Y-resolution configuration (git-fixes). - Input: psxpad-spi - set driver data before use (git-fixes). - Input: reject inhibit and uninhibit requests on unregistering devices (git-fixes). - Input: sur40 - fix input device registration ordering (stable-fixes). - Input: sur40 - fix V4L error path cleanup (stable-fixes). - Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). - Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). - Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git-fixes). - Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git-fixes). - Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). - Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). - interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). - io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item (git-fixes). - io_uring/net: Avoid msghdr on op_connect/op_bind async data (git-fixes). - iommu/arm-smmu-v3: Manage teardown with devm (stable-fixes). - ip_tunnel: Use ip_tunnel_info() helper instead of 'info + 1' (bsc#1274727). - ipmi: ipmb: validate write message length (git-fixes). - ipmi: si: Fix NULL pointer dereference after failed registration (git-fixes). - KVM: arm64: Ensure FFA ranges are page aligned (git-fixes). - KVM: arm64: Fix bounds checking in do_ffa_mem_reclaim() (git-fixes). - KVM: arm64: Fix sign-extension of MMIO loads (git-fixes). - KVM: arm64: vgic: Reset in_kernel on private IRQ allocation failure (git-fixes). - KVM: arm64: Zero out the stack initialized data in the FFA handler (git-fixes). - KVM: nSVM: Always inject a #GP if mapping VMCB12 fails on nested VMRUN (git-fixes). - KVM: nSVM: Remove a user-triggerable WARN on nested_svm_load_cr3() succeeding (git-fixes). - KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit (git-fixes). - KVM: nVMX: Service local TLB flushes on failed nested VM-Enter (git-fixes). - KVM: PPC: Book3S HV: Add support for compat CPU capabilities for KVM on PowerNV (bsc#1263864 ltc#217835). - KVM: PPC: Book3S HV: Implement compat CPU capability retrieval for KVM on PowerVM (bsc#1263864 ltc#217835). - KVM: PPC: Book3S HV: Validate arch_compat against host compatibility mode (bsc#1263864 ltc#217835). - KVM: PPC: Document KVM_PPC_GET_COMPAT_CAPS ioctl (bsc#1263864 ltc#217835). - KVM: PPC: Introduce KVM_CAP_PPC_COMPAT_CAPS and wire up ioctl (bsc#1263864 ltc#217835). - KVM: SEV: Use to_kvm_sev_info() for fetching kvm_sev_info struct (git-fixes). - KVM: SVM: Add support to initialize SEV/SNP functionality in KVM (bsc#1279887). - KVM: SVM: Explicitly mark vmcb01 dirty after modifying VMCB intercepts (git-fixes). - KVM: SVM: Serialize accesses to the owner and mirror list with separate lock (git-fixes). - KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (git-fixes). - KVM: TDX: Account all non-transient page allocations for per-TD structures (git-fixes). - KVM: TDX: Fix x2APIC MSR handling in tdx_has_emulated_msr() (git-fixes). - KVM: VMX: Don't register posted interrupt wakeup handler if alloc_kvm_area() fails (git-fixes). - KVM: x86/hyperv: Check for NULL vCPU Hyper-V object in kvm_hv_get_tlb_flush_fifo() (git-fixes). - KVM: x86/hyperv: Ensure vCPU's Hyper-V object is initialized on cross-vCPU accesses (git-fixes). - KVM: x86/hyperv: Get target FIFO in hv_tlb_flush_enqueue(), not caller (git-fixes). - KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050). - KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050). - KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050). - KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). - KVM: x86: Don't WARN if IRQ disappears because it was cleared from the PIC (git-fixes). - KVM: x86: Don't WARN if IRQ disappears when Xen emulation is enabled (git-fixes). - KVM: x86: Fix array_index_nospec() protection in kvm_vcpu_ioctl_x86_set_mce() (git-fixes). - KVM: x86: Fix emulated CPUID features being applied to wrong sub-leaf (git-fixes). - KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock (git-fixes). - leds: pca9532: Fix inverted GPIO output polarity (git-fixes). - leds: pca9532: Fix phantom device registration on missing hardware (git-fixes). - lib/string: fix memchr_inv() for large ranges (git-fixes). - lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). - mac802154: fix data race and NULL deref on local->assoc_dev (git-fixes). - mac802154: fix netdev use-after-free in beacon worker (git-fixes). - mac802154: fix use-after-free of sdata via queued RX frames (git-fixes). - mailbox: pcc: Fix command timeout due to missed interrupt (git-fixes). - mailbox: qcom-cpucp: fix PREEMPT_RT self-deadlock in IRQ handler (git-fixes). - mailbox: qcom-cpucp: handle NULL data in send_data callback (git-fixes). - mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git-fixes). - mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). - maple_tree: fix argument name in header (git-fixes). - md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). - media: airspy: Return queued buffers on start_streaming() failure (git-fixes). - media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). - media: amphion: Remove obsolete frame_count check in venc_start_session (git-fixes). - media: bcm2835-unicam: Fix asc leaked in error/remove path (git-fixes). - media: cec-pin: Fix event FIFO ordering (git-fixes). - media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). - media: cec: extron-da-hd-4k-plus: add sanity check (git-fixes). - media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). - media: cec: Serialize exclusive follower delivery (git-fixes). - media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). - media: cedrus: clean up media device on probe failure (git-fixes). - media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). - media: chips-media: wave5: Guard bit depth check with initial_info_obtained (git-fixes). - media: chips-media: wave5: Move src_buf Removal to finish_encode (git-fixes). - media: cobalt: Avoid freeing ALSA private data twice (git-fixes). - media: cx231xx: fix devres lifetime (git-fixes). - media: cx231xx: reject geometry changes while the VBI queue is busy (git-fixes). - media: cx23885: add ioremap return check and cleanup (git-fixes). - media: cx23885: cancel NetUP CI work before teardown (git-fixes). - media: em28xx: defer audio-only extension registration (git-fixes). - media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git-fixes). - media: go7007: defer the ALSA v4l2 put until card release (git-fixes). - media: hevc: add bounded tile-count helpers (git-fixes). - media: i2c: alvium: fix critical pointer access in alvium_ctrl_init (git-fixes). - media: i2c: alvium: Fix: Correct name of register in alvium_set_ctrl_auto_exposure (git-fixes). - media: i2c: imx219: Rename VTS to FRM_LENGTH (stable-fixes). - media: i2c: imx415: Return test pattern write errors (git-fixes). - media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). - media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). - media: i2c: rdacm21: Fix missing media_entity_cleanup() (git-fixes). - media: imx219: Fix maximum frame length in lines (git-fixes). - media: intel/ipu6: fix async notifier cleanup leak on parse error (git-fixes). - media: intel/ipu6: Improve DWC PHY HSFREQRANGE band selection for overlapping ranges (git-fixes). - media: ipu6: Do not free aux device pdata after init (git-fixes). - media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git-fixes). - media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). - media: mc-entity: Add missing kerneldoc (git-fixes). - media: mediatek: vcodec: bound AV1 tile-start copy to the array capacity (git-fixes). - media: meson: vdec: Fix memory leak in error path of vdec_open (git-fixes). - media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git-fixes). - media: msi2500: Return queued buffers on start_streaming() failure (git-fixes). - media: nuvoton: npcm-video: fix error handling in npcm_video_init() (git-fixes). - media: nuvoton: npcm-video: fix memory leaks in probe and remove (git-fixes). - media: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe (git-fixes). - media: nxp: imx8-isi: Clean up already-initialized pipes on probe failure (git-fixes). - media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). - media: nxp: imx8-isi: Fix missing v4l2_subdev_cleanup() in pipe init error path (git-fixes). - media: nxp: imx8-isi: Fix potential out-of-bounds issues (git-fixes). - media: nxp: imx8-isi: Fix scale factor calculation for hardware rounding (git-fixes). - media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). - media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). - media: platform: exynos4-is: Add hardware sync wait to fimc_is_hw_change_mode() (stable-fixes). - media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup (git-fixes). - media: platform: mtk-mdp3: Fix SCP device refcounting (git-fixes). - media: pwc: Drain fill_buf on start_streaming() failure (git-fixes). - media: pwc: Return queued buffers on start_streaming() failure (git-fixes). - media: qcom: camss: Fix RDI streaming for CSID GEN2 (git-fixes). - media: radio-si476x: Unregister v4l2_device on probe failure (git-fixes). - media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). - media: rtl2832: fix use-after-free in rtl2832_remove() (git-fixes). - media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). - media: rtl2832_sdr: Return queued buffers on start_streaming() failure (git-fixes). - media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). - media: s2255: bound JPEG frame size before copying into the buffer (git-fixes). - media: s2255: check firmware size before reading trailing marker (git-fixes). - media: saa7134: Fix a possible memory leak in saa7134_video_init1 (git-fixes). - media: saa7164: fix cleanup on resource allocation failure (git-fixes). - media: stm32: dcmi: unregister notifier on probe failure (git-fixes). - media: sun4i-csi: Return queued buffers on start_streaming() failure (git-fixes). - media: tda18250: fix possible integer overflow (git-fixes). - media: tegra-video: vi: fix invalid u32 return value in format lookup (git-fixes). - media: usbtv: keep device alive while ALSA card exists (git-fixes). - media: v4l2-async: avoid deleting unlinked ASC entry on link error (git-fixes). - media: v4l2-async: Unregister sub-device if asc_list is empty (git-fixes). - media: v4l2-ctrls-request: add NULL check in v4l2_ctrl_request_complete() (git-fixes). - media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git-fixes). - media: v4l2-ctrls: validate AV1 tile counts (git-fixes). - media: v4l2-ctrls: validate HEVC tile counts (git-fixes). - media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). - media: v4l2-h264: Fix memcmp() size in B1 reference list comparison (git-fixes). - media: v4l2-subdev: Fail {enable,disable}_streams and s_streaming nicely (git-fixes). - media: venus: fix payload size calculation in parse_raw_formats() (git-fixes). - media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). - media: verisilicon: hantro: bound G2 HEVC tile loop to the buffer capacity (git-fixes). - media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer (git-fixes). - media: verisilicon: rockchip: reject AV1 frames exceeding the tile capacity (git-fixes). - media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). - media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). - media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). - media: vivid: add vivid_update_reduced_fps() (git-fixes). - media: vivid: check for vb2_is_busy() when toggling caps (git-fixes). - media: vivid: fix cleanup bugs in vivid_init() (git-fixes). - media: zoran: Avoid freeing a registered video_device twice (git-fixes). - mei: pull kvfree out of spinlock (git-fixes). - mfd: iqs62x: Reject zero-length firmware records (git-fixes). - mfd: rave-sp: validate received frame payload lengths (git-fixes). - mfd: sm501: Fix potential memory leaks during remove (git-fixes). - misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). - misc: fastrpc: fix channel ctx ref leak when session alloc fails (git-fixes). - misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). - misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). - misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git-fixes). - misc: nsm: bound the device-reported response length (git-fixes). - misc: rtsx: add missing write register handling (git-fixes). - misc: sgi-gru: remove interrupt-context page-table walks (git-fixes). - misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git-fixes). - mkspec-dtb: Move DTS prefix into package list. - mkspec-dtb: Move provides-obsoletes to package list. - mkspec-dtb: Put per-architecture package lists into a hash. - mkspec-dtb: re-indent. - mmc: atmel-mci: Fix use-after-free in atmci_remove due to race condition (git-fixes). - mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git-fixes). - mmc: sdhci: unmap the bounce buffer before device release (git-fixes). - mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). - mtd: afs: validate v2 image info bounds (git-fixes). - mtd: fix double free and WARN_ON in add_mtd_device() error paths (git-fixes). - mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). - mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). - mtd: mtdswap: remove debugfs stats file on teardown (git-fixes). - mtd: nand: mtk-ecc: stop on ECC idle timeouts (git-fixes). - mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). - mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). - mtd: spinand: fix direct mapping creation sizes (stable-fixes). - mtd: spinand: repeat reading in regular mode if continuous reading fails (stable-fixes). - mtd: spinand: try a regular dirmap if creating a dirmap for continuous reading fails (stable-fixes). - mtd: ubi: Release device reference on busy detach (git-fixes). - mtd: ubi: skip programming unused bits in ubi headers (stable-fixes). - net: Add options as a flexible array to struct ip_tunnel_info (bsc#1274727). - net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). - net: mana: Add handler for sriov configure (bsc#1272756). - net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). - net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). - net: mana: Fall back to scattered pages for GDMA queues (git-fixes). - net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). - net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). - net: mana: Route ring-buffer access through offset-based helpers (git-fixes). - net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). - net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git-fixes). - net: thunderbolt: Mark the connection down when bringing it up fails (git-fixes). - net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git-fixes). - net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). - net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). - net: usb: cx82310_eth: drop URB after 0xffff reboot sentinel to prevent partial_data heap overflow (git-fixes). - net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). - net: usb: qmi_wwan: add Telit Cinterion FE990D50 composition (git-fixes). - nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). - nfc: digital: Do not dump a NULL response in command completion (git-fixes). - nfc: fdp: bound the device-reported read length and fix an skb leak (git-fixes). - nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). - nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git-fixes). - nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). - nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). - nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git-fixes). - nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). - nfc: microread: validate target discovery payload lengths (git-fixes). - nfc: nci: fix double completion race in nci_data_exchange_complete (git-fixes). - nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git-fixes). - nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git-fixes). - nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git-fixes). - nfc: nci: free destination parameters when closing a connection (git-fixes). - nfc: pn533: hold a reference to the request skb during send_frame (git-fixes). - nfc: pn533: purge fragmented skbs during cleanup (git-fixes). - nfc: st21nfca: validate ATR_REQ length against the received frame (git-fixes). - nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git-fixes). - nvme-tcp: fix usage of page_frag_cache (bsc#1267882). - nvmet-rdma: fix queue leak when connect backlog is exceeded (git-fixes). - of: fix out-of-bounds read in of_alias_scan() stem parser (git-fixes). - PCI/ASPM: Use pcie_capability_clear_and_set_word() for ASPM disable/restore (git-fixes). - PCI/proc: Avoid spurious runtime PM wakeup on config space accesses (git-fixes). - PCI/proc: Use file_ns_capable() when checking config space read access (git-fixes). - PCI/proc: Warn on writes to kernel-exclusive config space regions (git-fixes). - PCI/sysfs: Avoid spurious runtime PM wakeup on config space accesses (git-fixes). - PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). - PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git-fixes). - PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). - PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). - PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() (git-fixes). - PCI: plda: Fix use-after-free of event IRQs during teardown (git-fixes). - perf: Reject exited events as group leaders (git-fixes). - pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). - pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). - pinctrl: rockchip: Reset the pin count when recalculating SoC data (git-fixes). - platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). - platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). - platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git-fixes). - platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). - platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git-fixes). - platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). - platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git-fixes). - platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). - platform/x86/amd/hsmp: Reject negative power cap writes in hwmon (git-fixes). - platform/x86: asus-wmi: fix resource leaks on probe failure (git-fixes). - platform/x86: dell-privacy: Fix race condition (git-fixes). - platform/x86: dell-wmi-base: Fix resource leak on module load failure (git-fixes). - platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). - platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). - platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS (git-fixes). - platform/x86: hp-bioscfg: advance elem past consumed array elements (git-fixes). - platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() (git-fixes). - platform/x86: hp-bioscfg: fix heap OOB read on empty password write (git-fixes). - platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password (git-fixes). - platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() (git-fixes). - platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed (git-fixes). - platform/x86: hp-bioscfg: fix password encoding bounds check (git-fixes). - platform/x86: hp-bioscfg: warn on element type mismatch instead of failing (git-fixes). - platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). - platform/x86: ISST: Add a NULL check for sst_inst (git-fixes). - platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). - platform/x86: ISST: Return error during profile addition (git-fixes). - platform/x86: ISST: Use PP level enable mask (git-fixes). - platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). - platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). - platform/x86: ISST: Validate parameter for core power state (git-fixes). - platform/x86: ISST: Validate parameter for frequency and priority (git-fixes). - platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). - PM: hibernate: Fix memory leak in snapshot_write_next() error path (git-fixes). - PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). - power: supply: bd99954: Drop bad register fields (git-fixes). - power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git-fixes). - power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git-fixes). - power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). - power: supply: bq256xx: drain usb_work before freeing the charger (git-fixes). - power: supply: bq24257: fix use-after-free on remove (git-fixes). - power: supply: bq25890: Fix power_supply reference leak (git-fixes). - power: supply: charger-manager: register regulators before exposing sysfs (git-fixes). - power: supply: cros_usbpd-charger: bound the EC-reported port count (git-fixes). - power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git-fixes). - power: supply: isp1704_charger: cancel work on remove (git-fixes). - power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git-fixes). - power: supply: lp8788-charger: fix use-after-free on remove (git-fixes). - power: supply: max17040: drop incorrect I2C functionality check (git-fixes). - power: supply: max17040: propagate register read errors (git-fixes). - power: supply: max17040: synchronize work cancellation on suspend (git-fixes). - power: supply: qcom_battmgr: terminate the strings from firmware (git-fixes). - power: supply: rt9455: quiesce delayed work before teardown (git-fixes). - power: supply: sbs-battery: Use a per-device serial number buffer (git-fixes). - power: supply: sc2731_charger: cancel work on remove (git-fixes). - power: supply: twl4030_charger: cancel workers via devm (git-fixes). - power: supply: ucs1002: fix use-after-free on remove (git-fixes). - powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). - powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors (bsc#1263864 ltc#217835). - powerpc/kexec_file: Use inclusive range checks in add_usable_mem() (git-fixes). - powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). - powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). - powerpc/pseries: papr-phy-attest - validate cmd.length, plug mem leak (bsc#1274751 ltc#221105 bsc#1274750 ltc#221106). - powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). - powerpc/rtas_pci: No hotplug on permanently removed device on pSeries (git-fixes). - powerpc: Replace __ASSEMBLY__ with __ASSEMBLER__ in non-uapi headers (bsc#1263864 ltc#217835). - powerpc: Replace __ASSEMBLY__ with __ASSEMBLER__ in uapi headers (bsc#1263864 ltc#217835). - ppdev: prevent overflow when setting port timeout (git-fixes). - rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() (git-fixes). - rapidio: clear mport->net when rio_add_net() fails (git-fixes). - rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). - RDMA/bnxt_re: Avoid displaying the kernel pointer (git-fixes). - RDMA/bnxt_re: Proper rollback if the ioremap fails (git-fixes). - RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). - RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). - RDMA/mana_ib: unify QP lookup table (git-fixes). - RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). - regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). - regulator: core: use system_freezable_wq for init complete work (git-fixes). - regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). - regulator: qcom-refgen: correct the regulator type to CURRENT (git-fixes). - regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). - remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). - remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). - remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). - Revert 'drm/amdgpu: fix aperture mapping leak' (git-fixes). - Revert 'media: v4l2-dev: fix error handling in __video_register_device()' (git-fixes). - Revert 'net: thunderbolt: Enable end-to-end flow control also in transmit' (git-fixes). - Revert 'thermal/drivers/hwmon: Cleanup coding style a bit' (stable-fixes). - Revert 'wifi: mt76: Disable napi when removing device' (git-fixes). - rpmsg: core: Fix incorrect return value documentation (git-fixes). - rpmsg: glink: smem: order FIFO read after availability check (git-fixes). - rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). - rtc: pcf8563: fix clock provider leak on unbind (git-fixes). - rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). - rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). - rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git-fixes). - rtc: zynqmp: Return optional clock lookup errors (git-fixes). - s390/pkey: Check length in pkey_pckmo handler implementation (bsc#1270266). - s390/pkey: Check length in PKEY_VERIFYPROTK ioctl (bsc#1270267). - sched/psi: Create the psimon kthread outside of cgroup_mutex (bsc#1269134). - scsi: fnic: Abort timed-out NVMe LS requests (bsc#1236344). - scsi: fnic: Add and improve logs in FDMI and FDMI ABTS paths (bsc#1236344). - scsi: fnic: Add FDLS role handling for NVMe initiators (bsc#1236344). - scsi: fnic: Add the NVMe/FC transport path (bsc#1236344). - scsi: fnic: Advertise NVMe initiator service parameters (bsc#1236344). - scsi: fnic: Bump up version number (bsc#1236344). - scsi: fnic: Decode firmware role configuration (bsc#1236344). - scsi: fnic: Do not use GFP_ZERO for mempools (bsc#1236344). - scsi: fnic: Expose NVMe transport state in debugfs (bsc#1236344). - scsi: fnic: Handle NVMe LS frames in FDLS (bsc#1236344). - scsi: fnic: Make debug logging protocol independent (bsc#1236344). - scsi: fnic: Make fnic_queuecommand() easier to analyze (bsc#1236344). - scsi: fnic: Refactor in_remove flag and call to fnic_fcpio_reset() (bsc#1236344). - scsi: fnic: Remove a useless struct mempool forward declaration (bsc#1236344). - scsi: fnic: Rename fnic_scsi_fcpio_reset() (bsc#1236344). - scsi: fnic: Route completions and resets by initiator role (bsc#1236344). - scsi: fnic: Self-assignment of intr_time_type has no effect (bsc#1236344). - scsi: fnic: Send NVMe LS requests through FDLS (bsc#1236344). - scsi: fnic: Switch to use %ptSp (bsc#1236344). - scsi: fnic: Track NVMe transport statistics (bsc#1236344). - scsi: fnic: Use fnic_num for non-SCSI identifiers (bsc#1236344). - scsi: fnic: Use mempool for receive frames (bsc#1236344). - scsi: qla2xxx: Add support to report MPI FW state (bsc#1275737). - scsi: qla2xxx: Declare qla2xxx_mqueuecommand() static (bsc#1275737). - scsi: qla2xxx: Use nr_cpu_ids instead of NR_CPUS for qp_cpu_map allocation (bsc#1275737). - scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). - sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). - selftests/alsa: Fix the step check for INTEGER controls (git-fixes). - serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). - serial: amba-pl011: unprepare console clock on unregister (git-fixes). - serial: core: clear freed pointers on uart_register_driver() failure (git-fixes). - serial: imx: serialize imx_uart_ports lifetime (git-fixes). - serial: ma35d1: Fix OF node reference leaks in console init (git-fixes). - serial: qcom-geni: do not advance stale DMA completions (git-fixes). - serial: qcom-geni: fix TX DMA buffer flush (git-fixes). - serial: sc16is7xx: enable THRI before filling TX FIFO (git-fixes). - serial: sc16is7xx: rename EFR mutex with generic name (stable-fixes). - serial: sc16is7xx: use guards for simple mutex locks (stable-fixes). - slab.h: disable completely broken overflow handling in flex allocations (bsc#1280139). - slab: Introduce kmalloc_flex() and family (bsc#1280139). - slab: Introduce kmalloc_obj() and family (bsc#1280139). - slab: recognize @GFP parameter as optional in kernel-doc (bsc#1280139). - smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). - smb: client: harden POSIX SID length parsing (bsc#1273557). - smb: client: require net admin for CIFS SWN netlink (bsc#1273966). - smb: client: resolve SWN tcon from live registrations (bsc#1273872). - soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git-fixes). - soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). - soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). - software node: Fix software_node_get_reference_args() with index -1 (git-fixes). - soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git-fixes). - speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git-fixes). - spi: bcm63xx-hsspi: disable clocks on resume failure (git-fixes). - spi: bcm63xx: disable clock on resume failure (git-fixes). - spi: bcmbca-hsspi: disable clocks on resume failure (git-fixes). - spi: davinci: switch to managed controller allocation (git-fixes). - spi: Fix DMA mapping ownership on partial map failure (git-fixes). - spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). - spi: oc-tiny: switch to managed controller allocation (git-fixes). - spi: spi-cadence: enable SPI_CONTROLLER_MUST_TX (git-fixes). - spi: spi-cadence: Move TX FIFO full busy-wait into FIFO (git-fixes). - spi: spi-cadence: supports transmission with bits_per_word of 16 and 32 (stable-fixes). - spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). - spi: sprd-adi: Fix probe succeeding without registering the controller (git-fixes). - staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). - staging: media: tegra-video: fix of_node_put() on VIP parse errors (git-fixes). - staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). - staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git-fixes). - staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). - staging: rtl8723bs: fix missing shared-key auth challenge length check (git-fixes). - staging: rtl8723bs: fix OOB read / stack overflow in rtw_get_wps_attr() (git-fixes). - staging: rtl8723bs: fix OOB read in rtw_action_frame_parse() (git-fixes). - staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). - staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). - staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr() (git-fixes). - staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). - staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). - staging: sm750fb: Add missing Kconfig dependency (git-fixes). - staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). - thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). - thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). - thermal/drivers/rcar: Fix error checking in probe() (git-fixes). - thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). - thermal: sysfs: switch to use scnprintf() to suppress truncation warning (git-fixes). - thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). - thunderbolt: Fix bandwidth group reservation indexing (git-fixes). - thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). - tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). - tpm: st33zp24: Return zero on status read failure (git-fixes). - tpm: st33zp24: Validate locality read result (git-fixes). - tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). - tty: clear cdev pointer after cdev_add() failure (git-fixes). - tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). - tty: skip cdev_del() when no cdev is registered (git-fixes). - uio: Fix stale info pointer in failed registration path (git-fixes). - usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). - usb: atm: ueagle-atm: reject descriptors that confuse probe and disconnect (git-fixes). - usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). - USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). - usb: cdnsp: fix incorrect endian conversions for APB timeout register (git-fixes). - usb: core: Add lock to usb_wakeup_notification() (git-fixes). - usb: core: Add lock to usb_wakeup_notification() (stable-fixes). - usb: core: Strengthen error handling in hub_hub_status() (git-fixes). - usb: core: Strengthen error handling in hub_hub_status() (stable-fixes). - usb: core: sysfs: add lock to bos_descriptors_read() (stable-fixes). - usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). - usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). - usb: dwc3: clear forceRM when issuing EndTransfer (git-fixes). - usb: dwc3: gadget: Fix use-after-free in dwc3_gadget_free_endpoints due to race condition (git-fixes). - usb: f_mass_storage: Bump local buffer size in fsg_common_create_luns() (git-fixes). - usb: fix UAF when probe runs concurrent to dyn ID removal (git-fixes). - usb: gadget: aspeed_udc: check endpoint DMA allocation (git-fixes). - usb: gadget: at91_udc: drain polled-VBUS timer/work before udc is freed (git-fixes). - usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). - usb: gadget: f_fs: Fix fence cleanup in ffs_dmabuf_transfer() error paths (git-fixes). - usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). - usb: gadget: f_midi: initialize work in f_midi_alloc() (git-fixes). - usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). - usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). - usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git-fixes). - usb: gadget: fix null pointer dereference in usb_put_function_instance() (git-fixes). - USB: gadget: fsl-udc: fix dev_printk() device (git-fixes). - usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs (git-fixes). - usb: gadget: midi2: remove default configfs groups on teardown (git-fixes). - usb: gadget: pch_udc: remove excess kernel-doc member for registered (git-fixes). - usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). - usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). - usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git-fixes). - usb: gadget: uac: validate rate list length before storing (git-fixes). - USB: gadget: Use str_enable_disable-like helpers (stable-fixes). - usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). - usb: ljca: bound bank_num in ljca_enumerate_gpio() (git-fixes). - usb: mtu3: allow system suspend during active gadget connection (git-fixes). - usb: musb: omap2430: clean up probe error handling (stable-fixes). - usb: musb: omap2430: Do not put borrowed of_node in probe (git-fixes). - usb: musb: omap2430: Fix use-after-free in omap2430_probe() (git-fixes). - USB: phy: fsl-usb: fix missing static keywords (git-fixes). - usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). - USB: serial: digi_acceleport: fix port registration order (git-fixes). - USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). - USB: serial: option: add TDTECH MT5710-CN (stable-fixes). - USB: serial: option: fix slab OOB read in interrupt URB callback (git-fixes). - USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). - USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). - usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop (git-fixes). - usb: typec: qcom-pmic-typec: drain cc_debounce_dwork if port_start() fails (git-fixes). - usb: typec: qcom-pmic: cancel reset_work on stop (git-fixes). - usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive() (git-fixes). - usb: typec: thunderbolt: Disable work before freeing tbt on remove (git-fixes). - usb: typec: ucsi: displayport: Fix OOB altmode array index (git-fixes). - usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). - usb: typec: ucsi: use UCSI_TIMEOUT_MS for sync command completion (git-fixes). - usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git-fixes). - usb: usbtest: disable dynamic ID support (stable-fixes). - usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). - vfs: Add a sysctl for automated deletion of dentry (bsc#1240890 bsc#1276586). - vt: add permission check for KDSKBMETA ioctl (stable-fixes). - vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable-fixes). - w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). - w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). - watchdog: bd96801_wdt: Fix timeout for enabled WDG (git-fixes). - watchdog: fix hrtimer start when pretimeout is zero (git-fixes). - watchdog: msc313e: Avoid division by zero (git-fixes). - watchdog: msc313e: Enable clock before accessing hardware registers (git-fixes). - watchdog: msc313e: Fix clock leak and spurious timer in settimeout() (git-fixes). - watchdog: msc313e: Fix NULL pointer dereference in PM callbacks (git-fixes). - watchdog: msc313e: Fix spurious reset on suspend (git-fixes). - watchdog: msc313e: Fix undefined behavior (git-fixes). - watchdog: msc313e: Sync timeout value if WDT was running at boot (git-fixes). - watchdog: sunxi_wdt: preserve boot-enabled watchdog (git-fixes). - wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). - wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). - wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). - wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). - wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git-fixes). - wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). - wifi: ath11k: fix overreads in ath11k_wmi_process_csa_switch_count_event() (git-fixes). - wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). - wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). - wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). - wifi: brcmfmac: fix P2P action frame handling without device vif (git-fixes). - wifi: brcmfmac: initialize SDIO data work before cleanup (git-fixes). - wifi: cfg80211: bound element ID read when checking non-inheritance (git-fixes). - wifi: cfg80211: cancel sched scan results work on unregister (git-fixes). - wifi: cfg80211: derive S1G beacon TSF from S1G fields (git-fixes). - wifi: cfg80211: reject unsupported PMSR FTM location requests (git-fixes). - wifi: cfg80211: validate PMSR FTM preamble range (git-fixes). - wifi: cfg80211: validate PMSR measurement type data (git-fixes). - wifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one() (git-fixes). - wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). - wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). - wifi: iwlwifi: mei: check SAP message length before reading it (git-fixes). - wifi: iwlwifi: mei: pass correct argument to function (git-fixes). - wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). - wifi: libertas: fix memory leak in helper_firmware_cb() (git-fixes). - wifi: mac80211: disconnect on CSA to channel 0 (git-fixes). - wifi: mac80211: fix fils_discovery double free on alloc failure (git-fixes). - wifi: mac80211: fix per-STA profile length in cross-link CSA parsing (git-fixes). - wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure (git-fixes). - wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (git-fixes). - wifi: mac80211: send TWT teardown to peer after setup TX failure (git-fixes). - wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). - wifi: mac80211: skip unused probe response countdown offsets (git-fixes). - wifi: mt76: check txfree done event on the WED hw path (git-fixes). - wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). - wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). - wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). - wifi: mt76: fix non-AQL packet accounting for MLO stations (git-fixes). - wifi: mt76: fix stranded frames in mt76_txq_schedule_pending (git-fixes). - wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git-fixes). - wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). - wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete (git-fixes). - wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git-fixes). - wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git-fixes). - wifi: mt76: mt7915: clear wcid mask under mutex after RCU pointer clear (git-fixes). - wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). - wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git-fixes). - wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git-fixes). - wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). - wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). - wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git-fixes). - wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). - wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git-fixes). - wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). - wifi: mt76: mt7921: skip unknown CLC firmware records (git-fixes). - wifi: mt76: mt7921: validate CLC firmware records (git-fixes). - wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git-fixes). - wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git-fixes). - wifi: mt76: mt7925: update clc before setting sar power table (git-fixes). - wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git-fixes). - wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). - wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU (git-fixes). - wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). - wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git-fixes). - wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). - wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git-fixes). - wifi: mt76: only consume the WO drop bit on WED v2 devices (git-fixes). - wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). - wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). - wifi: nl80211: free RNR data on MBSSID mismatch (git-fixes). - wifi: nl80211: validate nested MBSSID IE blobs (git-fixes). - wifi: p54: validate RX frame length in p54_rx_eeprom_readback() (git-fixes). - wifi: rtl8xxxu: fix use-after-free from rx_urb_wq on stop (git-fixes). - wifi: rtl818x: initialize eeprom_93cx6 struct to zero (git-fixes). - wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). - wifi: rtlwifi: rtl8192du: check QoS TID before indexing tids (git-fixes). - wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() (git-fixes). - wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). - wifi: rtw88: pci: fix resource leak on failed NAPI setup (git-fixes). - wifi: rtw89: fix HE extended capability length check (git-fixes). - wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git-fixes). - x86/virt/tdx: Print TDX module version during init (git-fixes). - x86/virt/tdx: Retrieve TDX module version (git-fixes). - xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). - xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). - xhci: fix lost bounce buffers on TDs spanning several ring segments (git-fixes). The following package changes have been done: - libuuid1-2.41.1-160000.5.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - liblastlog2-2-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - util-linux-systemd-2.41.1-160000.5.1 updated - kernel-rt-6.12.0-160000.38.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-423a6bb1dc97d16369d2fe539e2277523c7ba186f45ec7a9f886996c5cfbcc4f-0 updated From sle-container-updates at lists.suse.com Thu Sep 24 07:04:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 09:04:15 +0200 (CEST) Subject: SUSE-IU-2026:7344-1: Security update of suse-sles-15-sp6-chost-byos-v20260921-x86_64-gen2 Message-ID: <20260924070415.536F7FF1E@maintenance.suse.de> SUSE Image Update Advisory: suse-sles-15-sp6-chost-byos-v20260921-x86_64-gen2 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7344-1 Image Tags : suse-sles-15-sp6-chost-byos-v20260921-x86_64-gen2:20260921 Image Release : Severity : critical Type : security References : 1158698 1158707 1159776 1164818 1164819 1169921 1170598 1170599 1170605 1170606 1171479 1172581 1175609 1175609 1175610 1175610 1184720 1194663 1215737 1216982 1218034 1218038 1218760 1220279 1222768 1224024 1226197 1226216 1226216 1228376 1228376 1229193 1229677 1231668 1232616 1234217 1238078 1240656 1240955 1242233 1242233 1243716 1243830 1243830 1246560 1246599 1246914 1247017 1247225 1248600 1254738 1257249 1259542 1260446 1261038 1262043 1262072 1262633 1263440 1264971 1265060 1265061 1265062 1265070 1265071 1265075 1265076 1266664 1266786 1267478 1267610 1268321 1268322 1268412 1268596 1268867 1268900 1269220 1269221 1269390 1270392 1270416 1271730 1272534 1273242 1273580 1274079 1274081 1274083 1274091 1274554 1274610 1274625 1274723 1274726 1274740 1274774 1274774 1274788 1274788 1274790 1274795 1274795 1274797 1274856 1274857 1274858 1275441 1275837 1275902 1275926 1276290 1276291 1276892 1276946 1277247 1277262 1277267 1277267 1277476 1277479 1277480 1277707 1277708 1277709 1277710 1277711 1277713 1277790 1277921 1277922 1278351 1279584 1279588 1279593 1279595 1279782 1279783 1279784 1279893 1280050 1280051 1280052 1280053 1280054 976992 CVE-2015-8863 CVE-2020-12762 CVE-2023-50246 CVE-2023-50268 CVE-2024-25629 CVE-2024-53427 CVE-2025-31498 CVE-2025-62408 CVE-2025-9403 CVE-2026-0799 CVE-2026-13608 CVE-2026-16445 CVE-2026-18238 CVE-2026-18313 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-23679 CVE-2026-31911 CVE-2026-31912 CVE-2026-33630 CVE-2026-33948 CVE-2026-40164 CVE-2026-40612 CVE-2026-41256 CVE-2026-41257 CVE-2026-42250 CVE-2026-43894 CVE-2026-43895 CVE-2026-43896 CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 CVE-2026-54679 CVE-2026-54874 CVE-2026-54874 CVE-2026-5773 CVE-2026-6244 CVE-2026-63072 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-6368 CVE-2026-6554 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-6791 CVE-2026-6893 CVE-2026-69184 CVE-2026-69186 CVE-2026-7168 CVE-2026-72693 CVE-2026-75803 CVE-2026-77117 CVE-2026-80229 CVE-2026-80230 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-8926 ----------------------------------------------------------------- The container suse-sles-15-sp6-chost-byos-v20260921-x86_64-gen2 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2020:925-1 Released: Mon Apr 6 10:08:27 2020 Summary: Recommended update for python3-azuremetadata, regionServiceClientConfigAzure, regionServiceClientConfigSAPAzure Type: recommended Severity: moderate References: 1158698,1158707,1164818,1164819 This update for python3-azuremetadata, regionServiceClientConfigAzure, regionServiceClientConfigSAPAzure fixes the following issues: regionServiceClientConfigAzure was updated to version 0.0.5: + Don't specify root device name explicitly (bsc#1158698, bsc#1158707) regionServiceClientConfigSAPAzure was updated to version 1.0.2: + Don't specify root device name explicitly (bsc#1158698, bsc#1158707) Changes in python3-azuremetadata: - Version 5.0.0 - Support new Azure metadata API (bsc#1164818, bsc#1164819) - Automatically detect root device (bsc#1158698, bsc#1158707) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2020:1097-1 Released: Thu Apr 23 21:12:03 2020 Summary: Recommended update for python3-azuremetadata Type: recommended Severity: moderate References: 1169921 This update for python3-azuremetadata fixes the following issues: - Use lsblk for root device detection (bsc#1169921) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2020:1159-1 Released: Tue May 5 16:24:36 2020 Summary: Recommended update for python3-azuremetadata Type: recommended Severity: moderate References: 1170598,1170599,1170605,1170606 This update for python3-azuremetadata fixes the following issues: python3-azuremetadata was updated to version 5.1.0: - Produce well-formed JSON and XML output when multiple filters are specified (bsc#1170598, bsc#1170599) regionServiceClientConfigSAPAzure was updated to 1.0.3 and regionServiceClientConfigAzure was updated to 0.0.6: - Report subscriptionId during registration (bsc#1170605, bsc#1170606) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2020:2556-1 Released: Mon Sep 7 14:31:43 2020 Summary: Recommended update for python3-azuremetadata Type: recommended Severity: moderate References: 1175609,1175610 This update for python3-azuremetadata contains the following fix: - Fix provides directive (bsc#1175609, bsc#1175610) + The provides directive must set a version or update does not work as expected ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:1588-1 Released: Wed May 12 13:44:31 2021 Summary: Recommended update for python3-azuremetadata Type: recommended Severity: moderate References: 1172581,1184720 This update for python3-azuremetadata fixes the following issues: - Fixed an issue where SUSEConnect was unable to set cloud_provider when registering an instance the first time (bsc#1172581) - When querying the metdata server for access verification via a proxy, the wrong data was delivered. This has been fixed (bsc#1184720) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:170-1 Released: Tue Jan 25 11:22:10 2022 Summary: Recommended update for python3-azuremetadata Type: recommended Severity: important References: 1175609,1175610,1194663 This update for python3-azuremetadata fixes the following issues: - Version 5.1.5 (bsc#1194663) + Handle lsblk output format change. The json data now contains 'mountpoints' instead of 'mountpoint' + Use versions endpoint to list the available versions + Add bypass proxy + Update way to check classic vms - Fix provides directive (bsc#1175609, bsc#1175610) + The provides directive must set a version or update does not work as expected ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:184-1 Released: Tue Jan 25 18:20:56 2022 Summary: Security update for json-c Type: security Severity: important References: 1171479,CVE-2020-12762 This update for json-c fixes the following issues: - CVE-2020-12762: Fixed integer overflow and out-of-bounds write. (bsc#1171479) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:583-1 Released: Wed Feb 21 22:47:47 2024 Summary: Recommended update for python3-azuremetadata Type: recommended Severity: moderate References: 1218760 This update for python3-azuremetadata fixes the following issues: - Fix empty list attributes (bsc#1218760) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2573-1 Released: Mon Jul 22 12:35:01 2024 Summary: Recommended update for libkcapi Type: recommended Severity: moderate References: 1222768 This update for libkcapi fixes the following issues: - FIPS: kcapi-hasher: zeroise temporary values for FIPS 140-3 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2781-1 Released: Tue Aug 6 14:39:15 2024 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: moderate References: 1226197,1226216,1228376 This update for libnvme, nvme-cli fixes the following issues: - Version updates: * linux: update TLS version 1 PSK derivation (bsc#1228376) * linux: add nvme_revoke_tls_key (bsc#1226197) * test: add hostnqn lookup test (bsc#1226216) * test: add config-pcie-with-tcp-config test case (bsc#1226216) * test: add config dump test (bsc#1226216) * test: revamp sysfs tree dump test (bsc#1226216) * test: use diff to compare sysfs output (bsc#1226216) * tree: preserve parsing order of a config file (bsc#1226216) * tree: add helper to lookup hostnqn/hostid (bsc#1226216) * json: filter out pcie transport (bsc#1226216) * fabrics: connect all hosts in config.json (bsc#1226216) * fabrics: refactor discover from json config (bsc#1226216) * fabrics: first read config before topology scanning (bsc#1226216) * fabrics: use helper to lookup default hostnqn/hostid (bsc#1226216) * fabrics: extend already connected message (bsc#1226216) * fabrics: Always pass hostid and hostnqn (bsc#1226216) * fabrics: Make some symbols public (bsc#1226216) * fabrics: extend hostnqn/hostid variable inject interface (bsc#1226216) * doc: add tls-key --revoke documentation (bsc#1226197) * doc: fix tls-key --keyfile shorthand (bsc#1226197) * build: sort documentation files entries (bsc#1226197) * nvme: avoid segfault in show-topology (bsc#1226197) * nvme: add support to revoke TLS key (bsc#1226197) * nvme: return error code/message for TLS commands (bsc#1226197) * nvme: factor out import key function (bsc#1226197) * nvme: use cleanup helper to close file descriptor (bsc#1226216) * nvme: use cleanup helper for STREAM objects (bsc#1226216) * nvme: strip newline when parsing TLS key files (bsc#1226197) * nvme: use stdout for exporting TLS keys (bsc#1226197) * nvme: change _cleanup_file_ to _cleanup_fd_ (bsc#1226197) * nvme: use cleanup helper for nvme_root_t objects (bsc#1226197) * nvme: add new function 'tls_key' (bsc#1226197) * libnvme: Introduce functions to generate host identifier and host NQN (bsc#1226216) * libnvme: add missing symbol nvme_scan_tls_keys (bsc#1226197) * completion: add support for tls-key (bsc#1226197) * completions: Fix bash-nvme-completion.sh indentation errors (bsc#1226197) - Always build documentation ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2865-1 Released: Fri Aug 9 12:06:04 2024 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: moderate References: 1224024,1228376 This update for libnvme, nvme-cli fixes the following issues: - linux: Correct error handling for derive_psk_digest (bsc#1228376). - tree: Add NVM subsystem controller identifier (bsc#1224024). - nvme-print: Print cntlid number for controller (bsc#1224024). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:3813-1 Released: Wed Oct 30 16:44:58 2024 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: moderate References: 1229193,1229677,1231668 This update for libnvme, nvme-cli fixes the following issues: - Version update 1.8+50.g2b587d3: * fabrics: fix incorrect access filename check (bsc#1231668) * fabrics: check if json config is existing (bsc#1231668) * fabrics: avoid potential segfault in nvmf_dim() (bsc#1231668) * ioctl: export nvme_submit_passthru as weak symbol (bsc#1231668) * logging: Split to output ioctl latency by log info level (bsc#1231668) * logging: output ioctl debugging info (bsc#1231668) * netapp: print output for single device too (bsc#1231668) * netapp: segregate print routines (bsc#1231668) * netapp: fix uninitialized value from heap error (bsc#1231668) * netapp-smdevices: print single device output too (bsc#1231668) * netapp-smdevices: segregate print routines (bsc#1231668) * nvme: fix uninitialized value in error-log (bsc#1231668) * nvme: fix verbose logging (bsc#1231668) * nvme: track verbose level (bsc#1231668) * nvme: update nvme_insert_tls_key_versioned() return handling (bsc#1231668) * nvme-print: sanitize error-log output (bsc#1231668) * nvme-print: update subsys verbose outputs (bsc#1231668) * nvme-print: add subsystype to the list-subsys output (bsc#1231668) * nvme-print-stdout: refactor subsys config (bsc#1231668) * nvme-print-stdout: update changed-ns-list-log output (bsc#1231668) * nvme-print-json: update JSON verbose output for nvm-id-ctrl (bsc#1231668) * plugins/sed: add sid password change (bsc#1229677) * tree: fix segfault in nvme_free_tree() (bsc#1231668) * tree: fix tls key mem leak (bsc#1231668) * tree: fix dhchap_ctrl_key mem leak (bsc#1231668) * tree: fix dhchap_key mem leak (bsc#1231668) * tree: handle no address phy slot dirs (bsc#1229193) * types: add new fields added in TP4165 (bsc#1231668) * types: Changed the space into tap space (bsc#1231668) * types: add new field added in TP4090 (bsc#1231668) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:4045-1 Released: Mon Nov 25 08:33:05 2024 Summary: Recommended update for patterns-base Type: recommended Severity: moderate References: This update for patterns-base fixes the following issue: - Updated patterns-base, removing plymouth recommendation on s390x archs. Our certification team run into an issue (jsc#PED-10532), when they run bare metal installation with fully encrypted disk. If the whole disk is crypted, the prompt for the password is sent to plymouth, which is obviously showing nothing because for booting bare metal (LPAR) is used terminal in HMC. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:4269-1 Released: Mon Dec 9 17:34:34 2024 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: moderate References: 1216982,1226216,1232616,1234217 This update for libnvme, nvme-cli fixes the following issues: - Version update (1.8+79.g69e7772) * docs: update check-tls-key arguments (bsc#1216982, bsc#1226216). * docs: update gen-tls-key arguments (bsc#1216982, bsc#1226216). * docs: update TLS options (bsc#1216982, bsc#1226216). * fabrics: add support to connect to accept a PSK command line and configuration (bsc#1216982, bsc#1226216). * fabrics: fix map error level in __nvmf_add_ctrl (bsc#1216982, bsc#1226216). * fabrics: add ctrl connect interface (bsc#1216982, bsc#1226216). * fabrics: use hex numbers when generating command line options (bsc#1216982, bsc#1226216). * fabrics: rename first argument for argument macros (bsc#1216982, bsc#1226216). * fabrics: do not attempt to import keys if tls is not enabled (bsc#1216982, bsc#1226216). * fabrics: skip namespace scan for fabric commands (bsc#1232616). * json: move keystore operations out of the JSON parser (bsc#1216982, bsc#1226216). * json: do not escape strings when printing the configuration (bsc#1216982, bsc#1226216). * linux: do not do any keyring ops when no key is provided (bsc#1216982, bsc#1226216). * linux: do not return w/o OpenSSL support enabled (bsc#1216982, bsc#1226216). * linux: fix derive_psk_digest OpenSSL 1.1 version (bsc#1216982, bsc#1226216). * linux: fixup PSK HMAC type '0' handling (bsc#1216982, bsc#1226216). * linux: handle key import correctly (bsc#1216982, bsc#1226216). * linux: export keys to config (bsc#1216982, bsc#1226216). * linux: only return the description of a key (bsc#1216982, bsc#1226216). * linux: use ssize_t as return type for nvme_identity_len (bsc#1216982, bsc#1226216). * linux: reorder variable declarations (bsc#1216982 bsc#1226216 (bsc#1216982, bsc#1226216). * linux: Remove the use of OpenSSL Engine API. * linux: add import/export function for TLS pre-shared keys (bsc#1216982, bsc#1226216). * netapp-smdev: remove redundant code (bsc#1234217). * netapp-smdev: add verbose output (bsc#1234217). * netapp-smdev-doc: add verbose details (bsc#1234217). * netapp-ontapdev: fix JSON output for nsze and nuse (bsc#1234217). * netapp-ontapdev: fix fw version handling (bsc#1234217). * netapp-ontapdev-doc: add verbose details (bsc#1232616). * netapp-ontapdev: add verbose output (bsc#1232616). * nvme: use unsigned char for hmac and identity (bsc#1216982, bsc#1226216). * nvme: add support to append TLS PSK to keyfile for check-tls-key (bsc#1216982, bsc#1226216). * nvme: return correct error code in append_keyfile (bsc#1216982, bsc#1226216). * nvme: add support to add derive TLS PSK to keyfile (bsc#1216982, bsc#1226216). * nvme: rename identity to version (bsc#1216982, bsc#1226216). * nvme: set file permission for keyfile to owner only (bsc#1216982, bsc#1226216). * nvme: export tls keys honoring version and hmac (bsc#1216982, bsc#1226216). * nvme-netapp: update err messages (bsc#1234217). * nvmf-keys: add udev rule to import tls keys (bsc#1216982, bsc#1226216). * test: add pre-shared key json tests (bsc#1216982, bsc#1226216). * test: extend psk to test new 'versioned' API (bsc#1216982, bsc#1226216). * test: add test case for importing/exporting PSKs (bsc#1216982, bsc#1226216). * test: make config-diff more flexible to use (bsc#1216982, bsc#1226216). * tree: optionally skip namespaces during scanning (bsc#1232616). * tree: do no export tls keys when not provided by user (bsc#1216982, bsc#1226216). * tree: read tls_configured_key and tls_keyring from sysfs (bsc#1216982, bsc#1226216). * tree: move dhchap and tls sysfs parser into separate functions (bsc#1216982, bsc#1226216). * tree: add getter/setters for TLS PSK (bsc#1216982, bsc#1226216). * util: added error code for ENOKEY (bsc#1216982, bsc#1226216). * util: Add string constant for ENVME_CONNECT_IGNORED. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:1377-1 Released: Fri Apr 25 19:43:34 2025 Summary: Recommended update for patterns-base Type: recommended Severity: moderate References: This update for patterns-base fixes the following issues: - add bpftool to patterns enhanced base. jsc#PED-8375 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:1378-1 Released: Fri Apr 25 19:52:18 2025 Summary: Recommended update for nvme-cli Type: recommended Severity: important References: 1240656 This update for nvme-cli fixes the following issues: - Update to version 2.8+88.g21612f53: * sed: perform a tper revert after lsp revert (bsc#1240656) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2839-1 Released: Mon Aug 18 11:19:58 2025 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: moderate References: 1243716,1246599 This update for libnvme, nvme-cli fixes the following issues: - Update to version 1.8+82.g9a64f8f4: - tree: free ctrl attributes when (re)configure ctrl (bsc#1243716) - tree: filter tree after scan has completed (bsc#1243716) - sysfs: minimize heap allocations of sysfs paths - Update to version 2.8+92.g998dceae: - nvme: fix mem leak in nvme copy (bsc#1243716) - nvme-print: suppress output when no ctrl is present for list-subsys (bsc#1243716) - nvme: extend filter to match device name (bsc#1243716) - udev-rules-ontap: switch to queue-depth iopolicy (bsc#1246599) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3250-1 Released: Wed Sep 17 15:38:53 2025 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: important References: 1246560,1247017,1247225 This update for libnvme, nvme-cli fixes the following issues: - tree: do not try to strdup NULL pointer (bsc#1247225) - tree: always set the host key (bsc#1246560) - netapp-ontapdev: update invalid device handling (bsc#1247017) - netapp-smdev: update invalid device handling (bsc#1247017) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4332-1 Released: Tue Dec 9 12:56:58 2025 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: important References: 1246914 This update for libnvme, nvme-cli fixes the following issues: Fix: libnvme/nvme-cli TLS PSK generation logic not compliant to RFC 8446: (bsc#1246914) * linux: use EVP_PKEY_CTX_add1_hkdf_info only once in compat function * nvme/linux: check for empty digest in gen_tls_identity() * nvme/linux: add fallback implementation for nvme_insert_tls_key_compat() * linux: fix HKDF TLS key derivation back to OpenSSL 3.0.8 * libnvme: TLS PSK derivation fixes * linux: rename __nvme_insert_tls_key_versioned() to __nvme_insert_tls_key() * linux: rename __nvme_insert_tls_key() to __nvme_import_tls_key() * test/psk: add testcase for TLS identity derivation * linux: set errno when nvme_generate_tls_key_identity() fails * nvme: add --compat flag for 'gen-tls-key' and 'check-tls-key' ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3129-1 Released: Mon Jul 20 11:41:29 2026 Summary: Recommended update for tiertune Type: recommended Severity: moderate References: This update for tiertune fixes the following issues: - Implement the package 'tiertune' to dynamically configure systemd and kernel settings based on specific cloud instance types across GCE, AWS, and Azure ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3391-1 Released: Tue Jul 28 18:49:41 2026 Summary: Recommended update for tiertune Type: recommended Severity: moderate References: This update for tiertune fixes the following issues: - Add KernelWorkQueue class: * Introduces KernelWorkQueue, a new settings class parallel to CPUPower, for managing kernel workqueue parameters. (jsc#PCT-1941) - Add X4 watchdog settings: * Add watchdog_thresh=60 and workqueue.watchdog_thresh=120 to be set by the sysctl component. (jsc#PCT-1941) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3833-1 Released: Thu Aug 27 08:41:53 2026 Summary: Recommended update for tiertune Type: recommended Severity: moderate References: This update for tiertune fixes the following issues: - Upgrade to version 0.1.3: * Fix the regular expression for X4 matching: + The instance identifier is 'x4-480-8t-metal'. A missing '.' in the regular expression caused a match failure as the previous expression stopped matching after the firt hyphen. * Start after the network is available: + We need to reach out to the metadata server to get instance data information. Therefore we cannot run tiertune until after the network is online. * Expand instance type matching for X4: + Modify the expression to match the configuration for X4 and X5 instances in GCE. The currently used expression will not match and as such the settings do not get applied. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3860-1 Released: Fri Aug 28 15:04:38 2026 Summary: Security update for rsyslog Type: security Severity: important References: 1275926 This update for rsyslog fixes the following issue: - Heap buffer overflow in the core `RainerScript` `replace()` function (bsc#1275926). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3866-1 Released: Fri Aug 28 19:29:09 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release . - CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797). - CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3878-1 Released: Mon Aug 31 11:12:55 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). Changes for openssl-1_1: - August 2026 release (bsc#1274774) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3961-1 Released: Thu Sep 3 15:32:38 2026 Summary: Security update for suseconnect-ng Type: security Severity: moderate References: 1159776,1267478,1268596,1268900,1270392 This update for suseconnect-ng fixes the following issue: - Update version to 1.23.0: - Use product identifier for product migrations. (bsc#1268596) - Switch to using go1.26-openssl as the default Go version to install to support building the package (jsc#SCC-843, bsc#1268900). - Fix flag parsing so that unknown flags or options are flagged as an error and the usage message is displayed. (bsc#1159776) - InstallReleasePackage interactive/noninteractive handling should be consistent with DistUpgrade (bsc#1267478). - Add new optional rpm_packages collector, disabled by default, to collect list of installed SUSE vendored RPM packages. (jsc#TEL-298) - Allow deregsiter when subscribed regcode has expired (bsc#1270392, jsc#865) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3966-1 Released: Fri Sep 4 08:10:54 2026 Summary: Recommended update for azure-vm-utils Type: recommended Severity: moderate References: 1274079,1274081,1274083 This update for azure-vm-utils fixes the following issues: - Update to version 0.7.0 (bsc#1274079, bsc#1274081, bsc#1274083) * feat(udev): set queue/io_timeout=240s for remote Azure NVMe devices * ci(main): do a debug build to ensure -Werror is used * build(deps): bump urllib3 from 2.2.3 to 2.5.0 in /selftest * build(deps): bump requests from 2.32.3 to 2.32.4 in /selftest * fix(tests): include stdint.h to fix compilation errors * feat(azure-ephemeral-disk-setup): introduce experimental service for managing ephemeral disks - Update to version 0.6.0: * feat(unmanaged-sriov): add udev & networkd support for unmanaged devices * fix(specs/fedora): fix builds for f42/rawhide * test(selftest): add coverage for networking rules * feat(networkd): increase priority for azure-unmanaged-sriov.network - Add new files and directories in %files section - Add %service_add_pre, %service_del_preun, %service_add_post and %service_del_postun for azure-ephemeral-disk-setup.service - Uprev to 0.5.1 which includes minor fixes and man-page improvements - Update to version 0.5.0: * Add new dependencies for json-c and libcmocka for unit tests * Remove selftest executable and manpage from installed files ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3997-1 Released: Mon Sep 7 09:22:53 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: Update to version 059+suse.730.g73d3411aa. - CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` (bsc#1268322). - CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` during system boot (bsc#1273580). Changes for dracut: - Update to version 059+suse.730.g73d3411aa: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4021-1 Released: Mon Sep 7 09:41:23 2026 Summary: Security update for c-ares Type: security Severity: important References: 1220279,1240955,1254738,1270416,1276290,1276291,CVE-2024-25629,CVE-2025-31498,CVE-2025-62408,CVE-2026-33630,CVE-2026-69184,CVE-2026-69186 This update for c-ares fixes the following issues: - CVE-2024-25629: out of bounds read in ares__read_line() (bsc#1220279). - CVE-2025-31498: use-after-free in read_answers() when process_answer() may re-enqueue a query (bsc#1240955). - CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (bsc#1254738). - CVE-2026-33630: Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP (bsc#1270416). - CVE-2026-69184: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290). - CVE-2026-69186: Memory-amplification denial of service via unvalidated DNS header record counts (bsc#1276291). Changes for c-ares: - updated to 1.36.8. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4047-1 Released: Mon Sep 7 15:53:38 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4085-1 Released: Tue Sep 8 12:19:46 2026 Summary: Recommended update for cloud-init Type: recommended Severity: important References: 1274554 This update for cloud-init fixes the following issues: - Fix: SLEM 6.1 is assigned systemd-timesyncd by cloudinit (bsc#1274554) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4101-1 Released: Wed Sep 9 14:07:04 2026 Summary: Recommended update for rsyslog Type: recommended Severity: moderate References: 1274610 This update for rsyslog fixes the following issues: - gtls: guard early debug-level lookup (bsc#1274610) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4112-1 Released: Wed Sep 9 18:17:10 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4116-1 Released: Wed Sep 9 21:41:52 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Revert the previous change since the syntax is not understood in this crypto-policies version. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4142-1 Released: Mon Sep 14 09:59:10 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1278351 This update for permissions fixes the following issue: - Update to version 20240826: * profiles: backport nvidia-modprobe (bsc#1278351) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4194-1 Released: Tue Sep 15 16:27:47 2026 Summary: Security update for libpcap Type: security Severity: important References: 1279584,1279588,1279593,1279595,1279782,1279783,1279784,CVE-2026-0799,CVE-2026-18238,CVE-2026-18313,CVE-2026-31911,CVE-2026-31912,CVE-2026-6244,CVE-2026-6554 This update for libpcap fixes the following issues: - CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). - CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). - CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). - CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). - CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ` message received from the client and never frees the memory (bsc#1279784). - CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). - CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4207-1 Released: Wed Sep 16 10:21:54 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4275-1 Released: Mon Sep 21 09:32:08 2026 Summary: Security update for jq Type: security Severity: important References: 1215737,1218034,1218038,1238078,1248600,1262043,1262072,1265060,1265061,1265062,1265070,1265071,1265075,1265076,1269220,1269221,1269390,976992,CVE-2015-8863,CVE-2023-50246,CVE-2023-50268,CVE-2024-53427,CVE-2025-9403,CVE-2026-33948,CVE-2026-40164,CVE-2026-40612,CVE-2026-41256,CVE-2026-41257,CVE-2026-43894,CVE-2026-43895,CVE-2026-43896,CVE-2026-44777,CVE-2026-47770,CVE-2026-49839,CVE-2026-54679 This update for jq fixes the following issues: Security issues fixed: - CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992). - CVE-2023-50246: improper memory handling can lead to a heap buffer overflow in `decNumberToString` (bsc#1218034). - CVE-2023-50268: stack-based buffer overflow in builds using decNumber (bsc#1218038). - CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in decNumber.c (bsc#1238078). - CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600). - CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). - CVE-2026-40164: predictable hash collisions can lead to a denial of service (bsc#1262072). - CVE-2026-40612: jv_contains recurses into nested arrays/objects with no depth limit and can cause a stack overflow (bsc#1265060). - CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f and can lead to execution of unintended programs (bsc#1265061). - CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS (bsc#1265062). - CVE-2026-43894: signed integer overflow in `decNumber` can lead to out-of-bounds memory write (bsc#1265070). - CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). - CVE-2026-43896: unbounded recursion in `jv_object_merge_recursive()` can lead to C stack exhaustion and a process crash (bsc#1265075). - CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). - CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). - CVE-2026-49839: `--rawfile` invalid-state reuse after `String too long` can lead to a heap buffer overflow (bsc#1269220). - CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer overrun on 32-bit systems (bsc#1269390). Changes for jq: Update to version 1.7.1: * Make the default background color more suitable for bright backgrounds. * Allow passing the inline jq script after --. * Fix possible uninitialised value dereference if jq_init() fails * Simplify paths/0 and paths/1. * Reject U+001F in string literals. * Remove unused nref accumulator in block_bind_library. * Remove a bunch of unused variables, and useless assignments. * main.c: Remove unused EXIT_STATUS_EXACT option. * Actually use the number correctly casted from double to int as index. * src/builtin.c: remove unnecessary jv_copy-s in type_error/type_error2. * Remove undefined behavior caught by LLVM 10 UBSAN. * Convert decnum to binary64 (double) instead of decimal64. This makes jq behave like the JSON specification suggests and more similar to other languages. * Fix memory leaks on invalid input for ltrimstr/1 and rtrimstr/1. * Fix memory leak on failed get for setpath/2. * Fix nan from json parsing also for nans with payload that start with 'n'. * Allow carriage return characters in comments. * Generate links in the man page. * Add extern C for C++. * Make object key color configurable using JQ_COLORS environment variable. * Change the default color of null to Bright Black. * Respect NO_COLOR environment variable to disable color output. * Improved --help output. Now mentions all options and nicer order. * Fix multiple issues of exit code using --exit-code/-e option. * Add --raw-output0 for NUL (zero byte) separated output. * Fix assert crash and validate JSON for --jsonarg. * Remove deprecated --argfile option. * Use decimal number literals to preserve precision. Comparison operations respects precision but arithmetic operations might truncate. * Adds new builtin pick(stream) to emit a projection of the input object or array. * Adds new builtin debug(msgs) that works like debug but applies a filter on the input before writing to stderr. * Adds new builtin scan($re; $flags). Was documented but not implemented. * Adds new builtin abs to get absolute value. This potentially allows the literal value of numbers to be preserved as length and fabs convert to float. * Allow if without else-branch. When skipped the else-branch will be . (identity). * Allow use of $binding as key in object literals. * Allow dot between chained indexes when using .['index'] * Allow dot for chained value iterator .[], .[]? * Fix try/catch catches more than it should. * Speed up and refactor some builtins, also remove scalars_or_empty/0. * Now halt and halt_error exit immediately instead of continuing to the next input. * Fix issue converting string to number after previous convert error. * Fix issue representing large numbers on some platforms causing invalid JSON output. * Fix deletion using assigning empty against arrays. * Allow keywords to be used as binding name in more places. * Allow using nan as NaN in JSON. * Expose a module's function names in modulemeta. * Fix contains/1 to handle strings with NUL. * Fix stderr/0 to output raw text without any decoration. * Fix nth/2 to emit empty on index out of range. * Fix implode to not assert and instead replace invalid unicode codepoints. * Fix indices/1 and rindex/1 in case of overlapping matches in strings. * Fix sub/3 to resolve issues involving global search-and-replace (gsub) operations. * Fix empty regular expression matches. * Fix overflow exception of the modulo operator. * Fix string multiplication by 0 (and less than 1) to emit empty string. * Fix segfault when using libjq and threads. * Fix constant folding of division and reminder with zero divisor. * Fix error/0, error/1 to throw null error. * Simpler and faster transpose. * Simple and efficient implementation of walk/1. * Remove deprecated filters leaf_paths, recurse_down. The following package changes have been done: - azure-vm-utils-0.7.0-150500.11.6.1 updated - cloud-init-config-suse-25.1.3-150400.15.13.3 updated - cloud-init-25.1.3-150400.15.13.3 updated - cpio-2.13-150400.3.10.1 updated - crypto-policies-scripts-20230920.570ea89-150600.3.22.1 added - crypto-policies-20230920.570ea89-150600.3.22.1 updated - curl-8.14.1-150600.4.51.1 updated - dracut-fips-059+suse.571.g3d42218af-150600.3.35.1 added - dracut-059+suse.571.g3d42218af-150600.3.35.1 updated - glibc-locale-base-2.38-150600.14.58.1 updated - glibc-2.38-150600.14.58.1 updated - jq-1.7.1-150000.3.25.1 updated - kbd-legacy-2.4.0-150400.5.12.1 updated - kbd-2.4.0-150400.5.12.1 updated - libacl1-2.4.0-150000.4.6.1 updated - libattr1-2.6.0-150000.4.3.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libcares2-1.34.8-150000.3.29.1 updated - libcurl4-8.14.1-150600.4.51.1 updated - libjq1-1.7.1-150000.3.25.1 updated - libjson-c3-0.13-3.3.1 added - libkcapi-tools-0.13.0-150600.17.3.1 added - libnvme-mi1-1.8+93.g5986a5a7-150600.3.21.1 added - libnvme1-1.8+93.g5986a5a7-150600.3.21.1 added - libopenssl-3-fips-provider-3.1.4-150600.5.64.1 added - libopenssl1_1-1.1.1w-150600.5.38.1 updated - libopenssl3-3.1.4-150600.5.64.1 updated - libpcap1-1.10.4-150600.3.12.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated - libzypp-17.38.15-150600.3.95.1 updated - login_defs-4.17.2-150600.17.24.1 updated - nvme-cli-2.8+95.g1a0c2083-150600.3.24.1 added - openssh-fips-9.6p1-150600.6.49.1 added - openssl-3-3.1.4-150600.5.64.1 updated - patterns-base-fips-20200124-150600.32.6.1 added - permissions-20240826-150600.10.21.1 updated - python3-azuremetadata-5.1.6-150000.1.26.1 added - python311-configobj-5.0.8-150400.12.9.1 updated - python311-jsonpatch-1.32-150400.10.9.1 updated - python311-jsonpointer-2.3-150400.11.9.1 updated - python311-pyserial-3.5-150400.12.9.1 updated - python311-tiertune-0.1.3-150600.13.9.1 added - python3-3.6.15-150300.10.118.1 added - rsyslog-module-relp-8.2406.0-150600.12.25.1 updated - rsyslog-8.2406.0-150600.12.25.1 updated - scap-security-guide-0.1.80-150600.1.38 updated - shadow-4.17.2-150600.17.24.1 updated - suseconnect-ng-1.23.0-150600.3.24.1 updated - tiertune-azure-0.1.3-150600.13.9.1 added - zypper-1.14.101-150600.10.58.1 updated From sle-container-updates at lists.suse.com Thu Sep 24 07:04:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 09:04:29 +0200 (CEST) Subject: SUSE-IU-2026:7345-1: Security update of suse-sles-15-sp6-chost-byos-v20260921-hvm-ssd-x86_64 Message-ID: <20260924070429.A1F89FF19@maintenance.suse.de> SUSE Image Update Advisory: suse-sles-15-sp6-chost-byos-v20260921-hvm-ssd-x86_64 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7345-1 Image Tags : suse-sles-15-sp6-chost-byos-v20260921-hvm-ssd-x86_64:20260921 Image Release : Severity : critical Type : security References : 1157901 1157902 1159776 1174743 1174837 1204066 1214215 1215737 1216982 1218034 1218038 1220279 1222768 1224024 1226197 1226216 1226216 1228376 1228376 1229193 1229677 1231668 1232616 1234217 1238078 1240656 1240955 1242233 1242233 1243716 1243830 1243830 1246560 1246599 1246914 1247017 1247225 1248600 1254738 1257249 1259542 1260446 1261038 1262043 1262072 1262633 1263440 1264971 1265060 1265061 1265062 1265070 1265071 1265075 1265076 1266664 1266786 1267478 1267610 1268321 1268322 1268412 1268596 1268867 1268900 1269220 1269221 1269390 1270392 1270416 1271730 1272534 1273242 1273580 1274091 1274554 1274610 1274625 1274723 1274726 1274740 1274774 1274774 1274788 1274788 1274790 1274795 1274795 1274797 1274856 1274857 1274858 1275441 1275837 1275902 1275926 1276290 1276291 1276892 1276946 1277247 1277262 1277267 1277267 1277476 1277479 1277480 1277707 1277708 1277709 1277710 1277711 1277713 1277790 1277921 1277922 1278351 1279584 1279588 1279593 1279595 1279782 1279783 1279784 1279893 1280050 1280051 1280052 1280053 1280054 976992 CVE-2015-8863 CVE-2023-50246 CVE-2023-50268 CVE-2024-25629 CVE-2024-53427 CVE-2025-31498 CVE-2025-62408 CVE-2025-9403 CVE-2026-0799 CVE-2026-13608 CVE-2026-16445 CVE-2026-18238 CVE-2026-18313 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-23679 CVE-2026-31911 CVE-2026-31912 CVE-2026-33630 CVE-2026-33948 CVE-2026-40164 CVE-2026-40612 CVE-2026-41256 CVE-2026-41257 CVE-2026-42250 CVE-2026-43894 CVE-2026-43895 CVE-2026-43896 CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 CVE-2026-54679 CVE-2026-54874 CVE-2026-54874 CVE-2026-5773 CVE-2026-6244 CVE-2026-63072 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-6368 CVE-2026-6554 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-6791 CVE-2026-6893 CVE-2026-69184 CVE-2026-69186 CVE-2026-7168 CVE-2026-72693 CVE-2026-75803 CVE-2026-77117 CVE-2026-80229 CVE-2026-80230 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-8926 ----------------------------------------------------------------- The container suse-sles-15-sp6-chost-byos-v20260921-hvm-ssd-x86_64 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2020:958-1 Released: Wed Apr 8 12:38:15 2020 Summary: Recommended update for python3-ec2metadata Type: recommended Severity: moderate References: 1157901,1157902 This update for python3-ec2metadata contains the following fixes: - Update to version 3.0.2: (bsc#1157901, bsc#1157902) + Add man page. + Support accessing IMDS with a token (API change) to support disabling unauthenticated access of IMDS; ----------------------------------------------------------------- Advisory ID: SUSE-RU-2020:2318-1 Released: Tue Aug 25 15:39:22 2020 Summary: Recommended update for python3-ec2metadata Type: recommended Severity: moderate References: 1174743,1174837 This update for python3-ec2metadata contains the following fixes: - Update to version 3.0.3 (bsc#1174743, bsc#1174837) + Prefer IMDSv2 and switch all IMDS access requests to support v2 token based access method. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:4043-1 Released: Thu Nov 17 09:05:54 2022 Summary: Recommended update for python3-ec2metadata Type: recommended Severity: moderate References: 1204066 This update for python3-ec2metadata fixes the following issues: - Update to version 4.0.0 (bsc#1204066) - Disambiguate cli options for duplicate endpoints. This is an incompatible change for some API versions of IMDS. When a duplicate endpoint is detected the cli option for both endpoints is expanded to a unique name. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3575-1 Released: Mon Sep 11 12:42:41 2023 Summary: Recommended update for python3-ec2metadata Type: recommended Severity: moderate References: 1214215 This update for python3-ec2metadata fixes the following issues: - Update to version 5.0.0 (bsc#1214215) - Remove the '--use-token' command line option as AWS is deprecating access to instance metadata without authentication token, therefore the ability to access metadata without token has been removed. - Support access to the metadata server over IPv6. If the customer enables the IPv6 endpoint for an instance it will be preferred over the IPv4 endpoint ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2573-1 Released: Mon Jul 22 12:35:01 2024 Summary: Recommended update for libkcapi Type: recommended Severity: moderate References: 1222768 This update for libkcapi fixes the following issues: - FIPS: kcapi-hasher: zeroise temporary values for FIPS 140-3 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2781-1 Released: Tue Aug 6 14:39:15 2024 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: moderate References: 1226197,1226216,1228376 This update for libnvme, nvme-cli fixes the following issues: - Version updates: * linux: update TLS version 1 PSK derivation (bsc#1228376) * linux: add nvme_revoke_tls_key (bsc#1226197) * test: add hostnqn lookup test (bsc#1226216) * test: add config-pcie-with-tcp-config test case (bsc#1226216) * test: add config dump test (bsc#1226216) * test: revamp sysfs tree dump test (bsc#1226216) * test: use diff to compare sysfs output (bsc#1226216) * tree: preserve parsing order of a config file (bsc#1226216) * tree: add helper to lookup hostnqn/hostid (bsc#1226216) * json: filter out pcie transport (bsc#1226216) * fabrics: connect all hosts in config.json (bsc#1226216) * fabrics: refactor discover from json config (bsc#1226216) * fabrics: first read config before topology scanning (bsc#1226216) * fabrics: use helper to lookup default hostnqn/hostid (bsc#1226216) * fabrics: extend already connected message (bsc#1226216) * fabrics: Always pass hostid and hostnqn (bsc#1226216) * fabrics: Make some symbols public (bsc#1226216) * fabrics: extend hostnqn/hostid variable inject interface (bsc#1226216) * doc: add tls-key --revoke documentation (bsc#1226197) * doc: fix tls-key --keyfile shorthand (bsc#1226197) * build: sort documentation files entries (bsc#1226197) * nvme: avoid segfault in show-topology (bsc#1226197) * nvme: add support to revoke TLS key (bsc#1226197) * nvme: return error code/message for TLS commands (bsc#1226197) * nvme: factor out import key function (bsc#1226197) * nvme: use cleanup helper to close file descriptor (bsc#1226216) * nvme: use cleanup helper for STREAM objects (bsc#1226216) * nvme: strip newline when parsing TLS key files (bsc#1226197) * nvme: use stdout for exporting TLS keys (bsc#1226197) * nvme: change _cleanup_file_ to _cleanup_fd_ (bsc#1226197) * nvme: use cleanup helper for nvme_root_t objects (bsc#1226197) * nvme: add new function 'tls_key' (bsc#1226197) * libnvme: Introduce functions to generate host identifier and host NQN (bsc#1226216) * libnvme: add missing symbol nvme_scan_tls_keys (bsc#1226197) * completion: add support for tls-key (bsc#1226197) * completions: Fix bash-nvme-completion.sh indentation errors (bsc#1226197) - Always build documentation ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2865-1 Released: Fri Aug 9 12:06:04 2024 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: moderate References: 1224024,1228376 This update for libnvme, nvme-cli fixes the following issues: - linux: Correct error handling for derive_psk_digest (bsc#1228376). - tree: Add NVM subsystem controller identifier (bsc#1224024). - nvme-print: Print cntlid number for controller (bsc#1224024). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:3813-1 Released: Wed Oct 30 16:44:58 2024 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: moderate References: 1229193,1229677,1231668 This update for libnvme, nvme-cli fixes the following issues: - Version update 1.8+50.g2b587d3: * fabrics: fix incorrect access filename check (bsc#1231668) * fabrics: check if json config is existing (bsc#1231668) * fabrics: avoid potential segfault in nvmf_dim() (bsc#1231668) * ioctl: export nvme_submit_passthru as weak symbol (bsc#1231668) * logging: Split to output ioctl latency by log info level (bsc#1231668) * logging: output ioctl debugging info (bsc#1231668) * netapp: print output for single device too (bsc#1231668) * netapp: segregate print routines (bsc#1231668) * netapp: fix uninitialized value from heap error (bsc#1231668) * netapp-smdevices: print single device output too (bsc#1231668) * netapp-smdevices: segregate print routines (bsc#1231668) * nvme: fix uninitialized value in error-log (bsc#1231668) * nvme: fix verbose logging (bsc#1231668) * nvme: track verbose level (bsc#1231668) * nvme: update nvme_insert_tls_key_versioned() return handling (bsc#1231668) * nvme-print: sanitize error-log output (bsc#1231668) * nvme-print: update subsys verbose outputs (bsc#1231668) * nvme-print: add subsystype to the list-subsys output (bsc#1231668) * nvme-print-stdout: refactor subsys config (bsc#1231668) * nvme-print-stdout: update changed-ns-list-log output (bsc#1231668) * nvme-print-json: update JSON verbose output for nvm-id-ctrl (bsc#1231668) * plugins/sed: add sid password change (bsc#1229677) * tree: fix segfault in nvme_free_tree() (bsc#1231668) * tree: fix tls key mem leak (bsc#1231668) * tree: fix dhchap_ctrl_key mem leak (bsc#1231668) * tree: fix dhchap_key mem leak (bsc#1231668) * tree: handle no address phy slot dirs (bsc#1229193) * types: add new fields added in TP4165 (bsc#1231668) * types: Changed the space into tap space (bsc#1231668) * types: add new field added in TP4090 (bsc#1231668) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:4045-1 Released: Mon Nov 25 08:33:05 2024 Summary: Recommended update for patterns-base Type: recommended Severity: moderate References: This update for patterns-base fixes the following issue: - Updated patterns-base, removing plymouth recommendation on s390x archs. Our certification team run into an issue (jsc#PED-10532), when they run bare metal installation with fully encrypted disk. If the whole disk is crypted, the prompt for the password is sent to plymouth, which is obviously showing nothing because for booting bare metal (LPAR) is used terminal in HMC. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:4269-1 Released: Mon Dec 9 17:34:34 2024 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: moderate References: 1216982,1226216,1232616,1234217 This update for libnvme, nvme-cli fixes the following issues: - Version update (1.8+79.g69e7772) * docs: update check-tls-key arguments (bsc#1216982, bsc#1226216). * docs: update gen-tls-key arguments (bsc#1216982, bsc#1226216). * docs: update TLS options (bsc#1216982, bsc#1226216). * fabrics: add support to connect to accept a PSK command line and configuration (bsc#1216982, bsc#1226216). * fabrics: fix map error level in __nvmf_add_ctrl (bsc#1216982, bsc#1226216). * fabrics: add ctrl connect interface (bsc#1216982, bsc#1226216). * fabrics: use hex numbers when generating command line options (bsc#1216982, bsc#1226216). * fabrics: rename first argument for argument macros (bsc#1216982, bsc#1226216). * fabrics: do not attempt to import keys if tls is not enabled (bsc#1216982, bsc#1226216). * fabrics: skip namespace scan for fabric commands (bsc#1232616). * json: move keystore operations out of the JSON parser (bsc#1216982, bsc#1226216). * json: do not escape strings when printing the configuration (bsc#1216982, bsc#1226216). * linux: do not do any keyring ops when no key is provided (bsc#1216982, bsc#1226216). * linux: do not return w/o OpenSSL support enabled (bsc#1216982, bsc#1226216). * linux: fix derive_psk_digest OpenSSL 1.1 version (bsc#1216982, bsc#1226216). * linux: fixup PSK HMAC type '0' handling (bsc#1216982, bsc#1226216). * linux: handle key import correctly (bsc#1216982, bsc#1226216). * linux: export keys to config (bsc#1216982, bsc#1226216). * linux: only return the description of a key (bsc#1216982, bsc#1226216). * linux: use ssize_t as return type for nvme_identity_len (bsc#1216982, bsc#1226216). * linux: reorder variable declarations (bsc#1216982 bsc#1226216 (bsc#1216982, bsc#1226216). * linux: Remove the use of OpenSSL Engine API. * linux: add import/export function for TLS pre-shared keys (bsc#1216982, bsc#1226216). * netapp-smdev: remove redundant code (bsc#1234217). * netapp-smdev: add verbose output (bsc#1234217). * netapp-smdev-doc: add verbose details (bsc#1234217). * netapp-ontapdev: fix JSON output for nsze and nuse (bsc#1234217). * netapp-ontapdev: fix fw version handling (bsc#1234217). * netapp-ontapdev-doc: add verbose details (bsc#1232616). * netapp-ontapdev: add verbose output (bsc#1232616). * nvme: use unsigned char for hmac and identity (bsc#1216982, bsc#1226216). * nvme: add support to append TLS PSK to keyfile for check-tls-key (bsc#1216982, bsc#1226216). * nvme: return correct error code in append_keyfile (bsc#1216982, bsc#1226216). * nvme: add support to add derive TLS PSK to keyfile (bsc#1216982, bsc#1226216). * nvme: rename identity to version (bsc#1216982, bsc#1226216). * nvme: set file permission for keyfile to owner only (bsc#1216982, bsc#1226216). * nvme: export tls keys honoring version and hmac (bsc#1216982, bsc#1226216). * nvme-netapp: update err messages (bsc#1234217). * nvmf-keys: add udev rule to import tls keys (bsc#1216982, bsc#1226216). * test: add pre-shared key json tests (bsc#1216982, bsc#1226216). * test: extend psk to test new 'versioned' API (bsc#1216982, bsc#1226216). * test: add test case for importing/exporting PSKs (bsc#1216982, bsc#1226216). * test: make config-diff more flexible to use (bsc#1216982, bsc#1226216). * tree: optionally skip namespaces during scanning (bsc#1232616). * tree: do no export tls keys when not provided by user (bsc#1216982, bsc#1226216). * tree: read tls_configured_key and tls_keyring from sysfs (bsc#1216982, bsc#1226216). * tree: move dhchap and tls sysfs parser into separate functions (bsc#1216982, bsc#1226216). * tree: add getter/setters for TLS PSK (bsc#1216982, bsc#1226216). * util: added error code for ENOKEY (bsc#1216982, bsc#1226216). * util: Add string constant for ENVME_CONNECT_IGNORED. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:1377-1 Released: Fri Apr 25 19:43:34 2025 Summary: Recommended update for patterns-base Type: recommended Severity: moderate References: This update for patterns-base fixes the following issues: - add bpftool to patterns enhanced base. jsc#PED-8375 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:1378-1 Released: Fri Apr 25 19:52:18 2025 Summary: Recommended update for nvme-cli Type: recommended Severity: important References: 1240656 This update for nvme-cli fixes the following issues: - Update to version 2.8+88.g21612f53: * sed: perform a tper revert after lsp revert (bsc#1240656) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2839-1 Released: Mon Aug 18 11:19:58 2025 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: moderate References: 1243716,1246599 This update for libnvme, nvme-cli fixes the following issues: - Update to version 1.8+82.g9a64f8f4: - tree: free ctrl attributes when (re)configure ctrl (bsc#1243716) - tree: filter tree after scan has completed (bsc#1243716) - sysfs: minimize heap allocations of sysfs paths - Update to version 2.8+92.g998dceae: - nvme: fix mem leak in nvme copy (bsc#1243716) - nvme-print: suppress output when no ctrl is present for list-subsys (bsc#1243716) - nvme: extend filter to match device name (bsc#1243716) - udev-rules-ontap: switch to queue-depth iopolicy (bsc#1246599) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3250-1 Released: Wed Sep 17 15:38:53 2025 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: important References: 1246560,1247017,1247225 This update for libnvme, nvme-cli fixes the following issues: - tree: do not try to strdup NULL pointer (bsc#1247225) - tree: always set the host key (bsc#1246560) - netapp-ontapdev: update invalid device handling (bsc#1247017) - netapp-smdev: update invalid device handling (bsc#1247017) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4332-1 Released: Tue Dec 9 12:56:58 2025 Summary: Recommended update for libnvme, nvme-cli Type: recommended Severity: important References: 1246914 This update for libnvme, nvme-cli fixes the following issues: Fix: libnvme/nvme-cli TLS PSK generation logic not compliant to RFC 8446: (bsc#1246914) * linux: use EVP_PKEY_CTX_add1_hkdf_info only once in compat function * nvme/linux: check for empty digest in gen_tls_identity() * nvme/linux: add fallback implementation for nvme_insert_tls_key_compat() * linux: fix HKDF TLS key derivation back to OpenSSL 3.0.8 * libnvme: TLS PSK derivation fixes * linux: rename __nvme_insert_tls_key_versioned() to __nvme_insert_tls_key() * linux: rename __nvme_insert_tls_key() to __nvme_import_tls_key() * test/psk: add testcase for TLS identity derivation * linux: set errno when nvme_generate_tls_key_identity() fails * nvme: add --compat flag for 'gen-tls-key' and 'check-tls-key' ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3129-1 Released: Mon Jul 20 11:41:29 2026 Summary: Recommended update for tiertune Type: recommended Severity: moderate References: This update for tiertune fixes the following issues: - Implement the package 'tiertune' to dynamically configure systemd and kernel settings based on specific cloud instance types across GCE, AWS, and Azure ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3391-1 Released: Tue Jul 28 18:49:41 2026 Summary: Recommended update for tiertune Type: recommended Severity: moderate References: This update for tiertune fixes the following issues: - Add KernelWorkQueue class: * Introduces KernelWorkQueue, a new settings class parallel to CPUPower, for managing kernel workqueue parameters. (jsc#PCT-1941) - Add X4 watchdog settings: * Add watchdog_thresh=60 and workqueue.watchdog_thresh=120 to be set by the sysctl component. (jsc#PCT-1941) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3833-1 Released: Thu Aug 27 08:41:53 2026 Summary: Recommended update for tiertune Type: recommended Severity: moderate References: This update for tiertune fixes the following issues: - Upgrade to version 0.1.3: * Fix the regular expression for X4 matching: + The instance identifier is 'x4-480-8t-metal'. A missing '.' in the regular expression caused a match failure as the previous expression stopped matching after the firt hyphen. * Start after the network is available: + We need to reach out to the metadata server to get instance data information. Therefore we cannot run tiertune until after the network is online. * Expand instance type matching for X4: + Modify the expression to match the configuration for X4 and X5 instances in GCE. The currently used expression will not match and as such the settings do not get applied. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3860-1 Released: Fri Aug 28 15:04:38 2026 Summary: Security update for rsyslog Type: security Severity: important References: 1275926 This update for rsyslog fixes the following issue: - Heap buffer overflow in the core `RainerScript` `replace()` function (bsc#1275926). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3866-1 Released: Fri Aug 28 19:29:09 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release . - CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797). - CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3878-1 Released: Mon Aug 31 11:12:55 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). Changes for openssl-1_1: - August 2026 release (bsc#1274774) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3961-1 Released: Thu Sep 3 15:32:38 2026 Summary: Security update for suseconnect-ng Type: security Severity: moderate References: 1159776,1267478,1268596,1268900,1270392 This update for suseconnect-ng fixes the following issue: - Update version to 1.23.0: - Use product identifier for product migrations. (bsc#1268596) - Switch to using go1.26-openssl as the default Go version to install to support building the package (jsc#SCC-843, bsc#1268900). - Fix flag parsing so that unknown flags or options are flagged as an error and the usage message is displayed. (bsc#1159776) - InstallReleasePackage interactive/noninteractive handling should be consistent with DistUpgrade (bsc#1267478). - Add new optional rpm_packages collector, disabled by default, to collect list of installed SUSE vendored RPM packages. (jsc#TEL-298) - Allow deregsiter when subscribed regcode has expired (bsc#1270392, jsc#865) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3997-1 Released: Mon Sep 7 09:22:53 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: Update to version 059+suse.730.g73d3411aa. - CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` (bsc#1268322). - CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` during system boot (bsc#1273580). Changes for dracut: - Update to version 059+suse.730.g73d3411aa: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4021-1 Released: Mon Sep 7 09:41:23 2026 Summary: Security update for c-ares Type: security Severity: important References: 1220279,1240955,1254738,1270416,1276290,1276291,CVE-2024-25629,CVE-2025-31498,CVE-2025-62408,CVE-2026-33630,CVE-2026-69184,CVE-2026-69186 This update for c-ares fixes the following issues: - CVE-2024-25629: out of bounds read in ares__read_line() (bsc#1220279). - CVE-2025-31498: use-after-free in read_answers() when process_answer() may re-enqueue a query (bsc#1240955). - CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (bsc#1254738). - CVE-2026-33630: Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP (bsc#1270416). - CVE-2026-69184: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290). - CVE-2026-69186: Memory-amplification denial of service via unvalidated DNS header record counts (bsc#1276291). Changes for c-ares: - updated to 1.36.8. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4047-1 Released: Mon Sep 7 15:53:38 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4085-1 Released: Tue Sep 8 12:19:46 2026 Summary: Recommended update for cloud-init Type: recommended Severity: important References: 1274554 This update for cloud-init fixes the following issues: - Fix: SLEM 6.1 is assigned systemd-timesyncd by cloudinit (bsc#1274554) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4101-1 Released: Wed Sep 9 14:07:04 2026 Summary: Recommended update for rsyslog Type: recommended Severity: moderate References: 1274610 This update for rsyslog fixes the following issues: - gtls: guard early debug-level lookup (bsc#1274610) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4112-1 Released: Wed Sep 9 18:17:10 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4116-1 Released: Wed Sep 9 21:41:52 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Revert the previous change since the syntax is not understood in this crypto-policies version. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4142-1 Released: Mon Sep 14 09:59:10 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1278351 This update for permissions fixes the following issue: - Update to version 20240826: * profiles: backport nvidia-modprobe (bsc#1278351) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4194-1 Released: Tue Sep 15 16:27:47 2026 Summary: Security update for libpcap Type: security Severity: important References: 1279584,1279588,1279593,1279595,1279782,1279783,1279784,CVE-2026-0799,CVE-2026-18238,CVE-2026-18313,CVE-2026-31911,CVE-2026-31912,CVE-2026-6244,CVE-2026-6554 This update for libpcap fixes the following issues: - CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). - CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). - CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). - CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). - CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ` message received from the client and never frees the memory (bsc#1279784). - CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). - CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4207-1 Released: Wed Sep 16 10:21:54 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4275-1 Released: Mon Sep 21 09:32:08 2026 Summary: Security update for jq Type: security Severity: important References: 1215737,1218034,1218038,1238078,1248600,1262043,1262072,1265060,1265061,1265062,1265070,1265071,1265075,1265076,1269220,1269221,1269390,976992,CVE-2015-8863,CVE-2023-50246,CVE-2023-50268,CVE-2024-53427,CVE-2025-9403,CVE-2026-33948,CVE-2026-40164,CVE-2026-40612,CVE-2026-41256,CVE-2026-41257,CVE-2026-43894,CVE-2026-43895,CVE-2026-43896,CVE-2026-44777,CVE-2026-47770,CVE-2026-49839,CVE-2026-54679 This update for jq fixes the following issues: Security issues fixed: - CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992). - CVE-2023-50246: improper memory handling can lead to a heap buffer overflow in `decNumberToString` (bsc#1218034). - CVE-2023-50268: stack-based buffer overflow in builds using decNumber (bsc#1218038). - CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in decNumber.c (bsc#1238078). - CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600). - CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). - CVE-2026-40164: predictable hash collisions can lead to a denial of service (bsc#1262072). - CVE-2026-40612: jv_contains recurses into nested arrays/objects with no depth limit and can cause a stack overflow (bsc#1265060). - CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f and can lead to execution of unintended programs (bsc#1265061). - CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS (bsc#1265062). - CVE-2026-43894: signed integer overflow in `decNumber` can lead to out-of-bounds memory write (bsc#1265070). - CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). - CVE-2026-43896: unbounded recursion in `jv_object_merge_recursive()` can lead to C stack exhaustion and a process crash (bsc#1265075). - CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). - CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). - CVE-2026-49839: `--rawfile` invalid-state reuse after `String too long` can lead to a heap buffer overflow (bsc#1269220). - CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer overrun on 32-bit systems (bsc#1269390). Changes for jq: Update to version 1.7.1: * Make the default background color more suitable for bright backgrounds. * Allow passing the inline jq script after --. * Fix possible uninitialised value dereference if jq_init() fails * Simplify paths/0 and paths/1. * Reject U+001F in string literals. * Remove unused nref accumulator in block_bind_library. * Remove a bunch of unused variables, and useless assignments. * main.c: Remove unused EXIT_STATUS_EXACT option. * Actually use the number correctly casted from double to int as index. * src/builtin.c: remove unnecessary jv_copy-s in type_error/type_error2. * Remove undefined behavior caught by LLVM 10 UBSAN. * Convert decnum to binary64 (double) instead of decimal64. This makes jq behave like the JSON specification suggests and more similar to other languages. * Fix memory leaks on invalid input for ltrimstr/1 and rtrimstr/1. * Fix memory leak on failed get for setpath/2. * Fix nan from json parsing also for nans with payload that start with 'n'. * Allow carriage return characters in comments. * Generate links in the man page. * Add extern C for C++. * Make object key color configurable using JQ_COLORS environment variable. * Change the default color of null to Bright Black. * Respect NO_COLOR environment variable to disable color output. * Improved --help output. Now mentions all options and nicer order. * Fix multiple issues of exit code using --exit-code/-e option. * Add --raw-output0 for NUL (zero byte) separated output. * Fix assert crash and validate JSON for --jsonarg. * Remove deprecated --argfile option. * Use decimal number literals to preserve precision. Comparison operations respects precision but arithmetic operations might truncate. * Adds new builtin pick(stream) to emit a projection of the input object or array. * Adds new builtin debug(msgs) that works like debug but applies a filter on the input before writing to stderr. * Adds new builtin scan($re; $flags). Was documented but not implemented. * Adds new builtin abs to get absolute value. This potentially allows the literal value of numbers to be preserved as length and fabs convert to float. * Allow if without else-branch. When skipped the else-branch will be . (identity). * Allow use of $binding as key in object literals. * Allow dot between chained indexes when using .['index'] * Allow dot for chained value iterator .[], .[]? * Fix try/catch catches more than it should. * Speed up and refactor some builtins, also remove scalars_or_empty/0. * Now halt and halt_error exit immediately instead of continuing to the next input. * Fix issue converting string to number after previous convert error. * Fix issue representing large numbers on some platforms causing invalid JSON output. * Fix deletion using assigning empty against arrays. * Allow keywords to be used as binding name in more places. * Allow using nan as NaN in JSON. * Expose a module's function names in modulemeta. * Fix contains/1 to handle strings with NUL. * Fix stderr/0 to output raw text without any decoration. * Fix nth/2 to emit empty on index out of range. * Fix implode to not assert and instead replace invalid unicode codepoints. * Fix indices/1 and rindex/1 in case of overlapping matches in strings. * Fix sub/3 to resolve issues involving global search-and-replace (gsub) operations. * Fix empty regular expression matches. * Fix overflow exception of the modulo operator. * Fix string multiplication by 0 (and less than 1) to emit empty string. * Fix segfault when using libjq and threads. * Fix constant folding of division and reminder with zero divisor. * Fix error/0, error/1 to throw null error. * Simpler and faster transpose. * Simple and efficient implementation of walk/1. * Remove deprecated filters leaf_paths, recurse_down. The following package changes have been done: - cloud-init-config-suse-25.1.3-150400.15.13.3 updated - cloud-init-25.1.3-150400.15.13.3 updated - cpio-2.13-150400.3.10.1 updated - crypto-policies-scripts-20230920.570ea89-150600.3.22.1 added - crypto-policies-20230920.570ea89-150600.3.22.1 updated - curl-8.14.1-150600.4.51.1 updated - dracut-fips-059+suse.571.g3d42218af-150600.3.35.1 added - dracut-059+suse.571.g3d42218af-150600.3.35.1 updated - glibc-locale-base-2.38-150600.14.58.1 updated - glibc-2.38-150600.14.58.1 updated - jq-1.7.1-150000.3.25.1 updated - kbd-legacy-2.4.0-150400.5.12.1 updated - kbd-2.4.0-150400.5.12.1 updated - libacl1-2.4.0-150000.4.6.1 updated - libattr1-2.6.0-150000.4.3.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libcares2-1.34.8-150000.3.29.1 updated - libcurl4-8.14.1-150600.4.51.1 updated - libjq1-1.7.1-150000.3.25.1 updated - libkcapi-tools-0.13.0-150600.17.3.1 added - libnvme-mi1-1.8+93.g5986a5a7-150600.3.21.1 added - libnvme1-1.8+93.g5986a5a7-150600.3.21.1 added - libopenssl-3-fips-provider-3.1.4-150600.5.64.1 added - libopenssl1_1-1.1.1w-150600.5.38.1 updated - libopenssl3-3.1.4-150600.5.64.1 updated - libpcap1-1.10.4-150600.3.12.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - libsubid5-4.17.2-150600.17.24.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated - libzypp-17.38.15-150600.3.95.1 updated - login_defs-4.17.2-150600.17.24.1 updated - nvme-cli-2.8+95.g1a0c2083-150600.3.24.1 added - openssh-fips-9.6p1-150600.6.49.1 added - openssl-3-3.1.4-150600.5.64.1 updated - patterns-base-fips-20200124-150600.32.6.1 added - permissions-20240826-150600.10.21.1 updated - python3-ec2metadata-5.0.0-150000.3.12.1 added - python311-configobj-5.0.8-150400.12.9.1 updated - python311-jsonpatch-1.32-150400.10.9.1 updated - python311-jsonpointer-2.3-150400.11.9.1 updated - python311-pyserial-3.5-150400.12.9.1 updated - python311-tiertune-0.1.3-150600.13.9.1 added - python3-3.6.15-150300.10.118.1 added - rsyslog-module-relp-8.2406.0-150600.12.25.1 updated - rsyslog-8.2406.0-150600.12.25.1 updated - scap-security-guide-0.1.80-150600.1.38 updated - shadow-4.17.2-150600.17.24.1 updated - suseconnect-ng-1.23.0-150600.3.24.1 updated - tiertune-aws-0.1.3-150600.13.9.1 added - zypper-1.14.101-150600.10.58.1 updated From sle-container-updates at lists.suse.com Thu Sep 24 07:04:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 24 Sep 2026 09:04:56 +0200 (CEST) Subject: SUSE-IU-2026:7346-1: Security update of sles-15-sp6-chost-byos-v20260923-arm64 Message-ID: <20260924070456.04CECFF19@maintenance.suse.de> SUSE Image Update Advisory: sles-15-sp6-chost-byos-v20260923-arm64 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7346-1 Image Tags : sles-15-sp6-chost-byos-v20260923-arm64:20260923 Image Release : Severity : critical Type : security References : 1097505 1134510 1159776 1173136 1210617 1212476 1215737 1216545 1218034 1218038 1218588 1218664 1220279 1222768 1222985 1223571 1224014 1224016 1225660 1226447 1226448 1227308 1227378 1227999 1228105 1228165 1228780 1229596 1229704 1230227 1230906 1231795 1232241 1236705 1238078 1238450 1239210 1240955 1241067 1242233 1242233 1243197 1243273 1243313 1243830 1243830 1244032 1244056 1244059 1244060 1244061 1244705 1245938 1245939 1245942 1245943 1245946 1246570 1247249 1248600 1251305 1252974 1252974 1253357 1254255 1254400 1254400 1254401 1254401 1254738 1254997 1254997 1257029 1257029 1257031 1257031 1257041 1257042 1257042 1257044 1257046 1257046 1257108 1257181 1257249 1258364 1259240 1259542 1259611 1259734 1259735 1259989 1260026 1260264 1260446 1261038 1261969 1261970 1262043 1262072 1262098 1262319 1262633 1262654 1263083 1263440 1264962 1264971 1265060 1265061 1265062 1265070 1265071 1265075 1265076 1265268 1266664 1266786 1267478 1267581 1267610 1267821 1268321 1268322 1268375 1268412 1268596 1268867 1268900 1268977 1269066 1269220 1269221 1269390 1269788 1269959 1270392 1270416 1271192 1271730 1272118 1272118 1272534 1273242 1273580 1274091 1274610 1274625 1274723 1274726 1274740 1274774 1274774 1274788 1274788 1274790 1274795 1274795 1274797 1274856 1274857 1274858 1275441 1275837 1275902 1275926 1276290 1276291 1276722 1276892 1276946 1277247 1277262 1277267 1277267 1277476 1277479 1277480 1277707 1277708 1277709 1277710 1277711 1277713 1277790 1277921 1277922 1278351 1278597 1278597 1278967 1278967 1279297 1279297 1279414 1279414 1279584 1279588 1279593 1279595 1279782 1279783 1279784 1279893 1280050 1280051 1280052 1280053 1280054 976992 CVE-2015-8863 CVE-2023-27043 CVE-2023-30608 CVE-2023-50246 CVE-2023-50268 CVE-2024-0397 CVE-2024-12718 CVE-2024-25629 CVE-2024-4032 CVE-2024-53427 CVE-2024-6232 CVE-2024-6345 CVE-2024-6923 CVE-2024-7592 CVE-2024-8088 CVE-2024-9287 CVE-2025-0938 CVE-2025-11468 CVE-2025-11468 CVE-2025-12084 CVE-2025-12084 CVE-2025-12781 CVE-2025-13462 CVE-2025-13836 CVE-2025-13836 CVE-2025-13837 CVE-2025-13837 CVE-2025-15282 CVE-2025-15282 CVE-2025-15366 CVE-2025-15367 CVE-2025-1795 CVE-2025-27613 CVE-2025-27614 CVE-2025-31498 CVE-2025-4138 CVE-2025-4330 CVE-2025-4435 CVE-2025-4516 CVE-2025-4517 CVE-2025-46835 CVE-2025-47273 CVE-2025-48384 CVE-2025-48385 CVE-2025-6069 CVE-2025-6075 CVE-2025-6075 CVE-2025-62408 CVE-2025-8194 CVE-2025-8291 CVE-2025-9403 CVE-2026-0672 CVE-2026-0672 CVE-2026-0799 CVE-2026-0864 CVE-2026-0865 CVE-2026-0865 CVE-2026-11940 CVE-2026-11972 CVE-2026-1299 CVE-2026-13608 CVE-2026-1502 CVE-2026-15308 CVE-2026-16445 CVE-2026-18238 CVE-2026-18313 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-2297 CVE-2026-23679 CVE-2026-31911 CVE-2026-31912 CVE-2026-3276 CVE-2026-3276 CVE-2026-33186 CVE-2026-33630 CVE-2026-33948 CVE-2026-3446 CVE-2026-3479 CVE-2026-3644 CVE-2026-40164 CVE-2026-40612 CVE-2026-41178 CVE-2026-41256 CVE-2026-41257 CVE-2026-4224 CVE-2026-42250 CVE-2026-4360 CVE-2026-43894 CVE-2026-43895 CVE-2026-43896 CVE-2026-44777 CVE-2026-4519 CVE-2026-47770 CVE-2026-4786 CVE-2026-49839 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371 CVE-2026-54679 CVE-2026-54874 CVE-2026-54874 CVE-2026-56852 CVE-2026-56852 CVE-2026-56854 CVE-2026-56854 CVE-2026-56855 CVE-2026-56855 CVE-2026-5773 CVE-2026-6019 CVE-2026-6019 CVE-2026-6100 CVE-2026-6244 CVE-2026-63072 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-6368 CVE-2026-6554 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-6791 CVE-2026-6893 CVE-2026-69184 CVE-2026-69186 CVE-2026-7168 CVE-2026-7210 CVE-2026-72693 CVE-2026-75803 CVE-2026-77117 CVE-2026-7774 CVE-2026-78662 CVE-2026-78662 CVE-2026-80229 CVE-2026-80230 CVE-2026-80489 CVE-2026-8328 CVE-2026-84303 CVE-2026-84303 CVE-2026-84304 CVE-2026-84304 CVE-2026-84445 CVE-2026-84445 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-8926 ----------------------------------------------------------------- The container sles-15-sp6-chost-byos-v20260923-arm64 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2018:1897-1 Released: Thu Sep 13 15:18:20 2018 Summary: Recommended update for python3-gcemetadata Type: recommended Severity: moderate References: 1097505 This update for python3-gcemetadata fixes the following issues: - Support instances with multiple Nics. (bsc#1097505) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2020:1323-1 Released: Mon May 18 11:49:02 2020 Summary: Recommended update for python3-gcemetadata Type: recommended Severity: important References: 1134510 This update for python3-gcemetadata fixes the following issues: - Fix for the identity data of the instance may not be accessible from the metadata server in Google Cloud client. (bsc#1134510) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2020:1727-1 Released: Tue Jun 23 15:33:07 2020 Summary: Recommended update for python3-gcemetadata Type: recommended Severity: moderate References: 1173136 This update for python3-gcemetadata fixes the following issues: Update to version 1.0.4 (bsc#1173136) - Fixed typo, missing '=' for 'identity' option in processed command line options causes mis-identification of instance as missing identity data access ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:1637-1 Released: Tue May 14 14:22:14 2024 Summary: Recommended update for google-cloud SDK Type: recommended Severity: moderate References: 1210617,CVE-2023-30608 This update for google-cloud SDK fixes the following issues: - Add python311 cloud services packages and dependencies (jsc#PED-7987, jsc#PED-6697) - Bellow 5 binaries Obsolete the python3.6 counterpart: python311-google-resumable-media python311-google-api-core python311-google-cloud-storage python311-google-cloud-core python311-googleapis-common-protos - Regular python311 updates (without Obsoletes): python-google-auth python-grpcio python-sqlparse - New python311 packages: libcrc32c python-google-cloud-appengine-logging python-google-cloud-artifact-registry python-google-cloud-audit-log python-google-cloud-build python-google-cloud-compute python-google-cloud-dns python-google-cloud-domains python-google-cloud-iam python-google-cloud-kms-inventory python-google-cloud-kms python-google-cloud-logging python-google-cloud-run python-google-cloud-secret-manager python-google-cloud-service-directory python-google-cloud-spanner python-google-cloud-vpc-access python-google-crc32c python-grpc-google-iam-v1 python-grpcio-status python-proto-plus In python-sqlparse this security issue was fixed: CVE-2023-30608: Fixed parser that contained a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service) (bsc#1210617) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2573-1 Released: Mon Jul 22 12:35:01 2024 Summary: Recommended update for libkcapi Type: recommended Severity: moderate References: 1222768 This update for libkcapi fixes the following issues: - FIPS: kcapi-hasher: zeroise temporary values for FIPS 140-3 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:2912-1 Released: Wed Aug 14 20:20:13 2024 Summary: Recommended update for cloud-regionsrv-client Type: recommended Severity: important References: 1222985,1223571,1224014,1224016,1227308 This update for cloud-regionsrv-client contains the following fixes: - Update to version 10.3.0 (bsc#1227308, bsc#1222985) + Add support for sidecar registry Podman and rootless Docker support to set up the necessary configuration for the container engines to run as defined + Add running command as root through sudoers file - Update to version 10.2.0 (bsc#1223571, bsc#1224014, bsc#1224016) + In addition to logging, write message to stderr when registration fails + Detect transactional-update system with read only setup and use the transactional-update command to register + Handle operation in a different target root directory for credentials checking ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:2982-1 Released: Tue Aug 20 11:08:55 2024 Summary: Security update for python311 Type: security Severity: important References: 1225660,1226447,1226448,1227378,1227999,1228780,CVE-2023-27043,CVE-2024-0397,CVE-2024-4032,CVE-2024-6923 This update for python311 fixes the following issues: Security issues fixed: - CVE-2024-6923: Fixed email header injection due to unquoted newlines (bsc#1228780) - CVE-2024-5642: Removed support for anything but OpenSSL 1.1.1 or newer (bsc#1227233) - CVE-2024-4032: Fixed incorrect IPv4 and IPv6 private ranges (bsc#1226448) Non-security issues fixed: - Fixed executable bits for /usr/bin/idle* (bsc#1227378). - Improve python reproducible builds (bsc#1227999) - Make pip and modern tools install directly in /usr/local when used by the user (bsc#1225660) - %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:3055-1 Released: Wed Aug 28 14:49:28 2024 Summary: Security update for python-setuptools Type: security Severity: important References: 1228105,CVE-2024-6345 This update for python-setuptools fixes the following issues: - CVE-2024-6345: Fixed code execution via download functions in the package_index module (bsc#1228105) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:3427-1 Released: Tue Sep 24 18:42:49 2024 Summary: Security update for python311 Type: security Severity: important References: 1229596,1229704,1230227,CVE-2024-6232,CVE-2024-7592,CVE-2024-8088 This update for python311 fixes the following issues: Update python311 to version 3.11.10. - CVE-2024-6232: excessive backtracking when parsing tarfile headers leads to ReDoS. (bsc#1230227) - CVE-2024-7592: quadratic algorithm used when parsing cookies leads to excessive resource consumption. (bsc#1229596) - CVE-2024-8088: lack of name validation when extracting a zip archive leads to infinite loops. (bsc#1229704) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:3958-1 Released: Fri Nov 8 16:25:08 2024 Summary: Security update for python311 Type: security Severity: moderate References: 1230906,1232241,CVE-2024-9287 This update for python311 fixes the following issues: - CVE-2024-9287: Fixed quoted path names provided when creating a virtual environment (bsc#1232241). Bug fixes: - Drop .pyc files from docdir for reproducible builds (bsc#1230906). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:4045-1 Released: Mon Nov 25 08:33:05 2024 Summary: Recommended update for patterns-base Type: recommended Severity: moderate References: This update for patterns-base fixes the following issue: - Updated patterns-base, removing plymouth recommendation on s390x archs. Our certification team run into an issue (jsc#PED-10532), when they run bare metal installation with fully encrypted disk. If the whole disk is crypted, the prompt for the password is sent to plymouth, which is obviously showing nothing because for booting bare metal (LPAR) is used terminal in HMC. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:551-1 Released: Fri Feb 14 16:09:46 2025 Summary: Security update for python311 Type: security Severity: moderate References: 1228165,1231795,1236705,CVE-2025-0938 This update for python311 fixes the following issues: - CVE-2025-0938: domain names containing square brackets are not identified as incorrect by urlparse. (bsc#1236705) Other fixes: - Update to version 3.11.11. - Remove -IVendor/ from python-config. (bsc#1231795) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:982-1 Released: Fri Mar 21 15:17:03 2025 Summary: Security update for python311 Type: security Severity: low References: 1238450,1239210,CVE-2025-1795 This update for python311 fixes the following issues: - CVE-2025-1795: Fixed mishandling of comma during folding and unicode-encoding of email headers (bsc#1238450). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:1377-1 Released: Fri Apr 25 19:43:34 2025 Summary: Recommended update for patterns-base Type: recommended Severity: moderate References: This update for patterns-base fixes the following issues: - add bpftool to patterns enhanced base. jsc#PED-8375 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:1704-1 Released: Mon May 26 13:02:41 2025 Summary: Security update for python-setuptools Type: security Severity: important References: 1243313,CVE-2025-47273 This update for python-setuptools fixes the following issues: - CVE-2025-47273: path traversal in PackageIndex.download may lead to an arbitrary file write (bsc#1243313). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2057-1 Released: Sat Jun 21 11:04:24 2025 Summary: Security update for python311 Type: security Severity: important References: 1241067,1243273,1244032,1244056,1244059,1244060,CVE-2024-12718,CVE-2025-4138,CVE-2025-4330,CVE-2025-4516,CVE-2025-4517 This update for python311 fixes the following issues: python311 was updated from version 3.11.10 to 3.11.13: - Security issues fixed: * CVE-2025-4516: Fixed blocking DecodeError handling vulnerability, which could lead to DoS (bsc#1243273). * CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4517: Fixed multiple issues that allowed tarfile extraction filters to be bypassed using crafted symlinks and hard links (bsc#1244056, bsc#1244059, bsc#1244060, bsc#1244032) - Other changes and bugs fixed: * Improved handling of system call failures that OpenSSL reports (bsc#1241067) * Disable GC during thread operations to prevent deadlocks. * Fixed a potential denial of service vulnerability in the imaplib module. * Fixed bugs in the in the folding of rfc2047 encoded-words and in the folding of quoted strings when flattening an email message using a modern email policy. * Fixed parsing long IPv6 addresses with embedded IPv4 address. * Fixed ipaddress.IPv6Address.reverse_pointer output according to RFC 3596 * Improved the textual representation of IPv4-mapped IPv6 addresses in ipaddress. * ipaddress: fixed hash collisions for IPv4Network and IPv6Network objects * os.path.realpath() now accepts a strict keyword-only argument. * Stop the processing of long IPv6 addresses early in ipaddress to prevent excessive memory consumption and a minor denial-of-service. * Updated bundled libexpat to 2.7.1 * Writers of CPython documentation can now use next as the version for the versionchanged, versionadded, deprecated directives. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2717-1 Released: Wed Aug 6 15:39:46 2025 Summary: Security update for python311 Type: security Severity: important References: 1244061,1244705,1247249,CVE-2025-4435,CVE-2025-6069,CVE-2025-8194 This update for python311 fixes the following issues: - CVE-2025-8194: Fixed denial of service caused by tar archives with negative offsets (bsc#1247249). - CVE-2025-6069: Avoid worst case quadratic complexity when processing certain crafted malformed inputs with HTMLParser (bsc#1244705). - CVE-2025-4435: Fixed Tarfile extracting filtered members when errorlevel=0 (bsc#1244061). ----------------------------------------------------------------- Advisory ID: SUSE-OU-2025:2763-1 Released: Tue Aug 12 14:45:40 2025 Summary: Optional update for libyaml Type: optional Severity: moderate References: 1246570 This update for libyaml ships the missing libyaml-0-2 library package to SUSE MicroOS 5.1 and 5.2. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3012-1 Released: Fri Aug 29 02:07:38 2025 Summary: security update for git, git-lfs, obs-scm-bridge, python-PyYAML Type: security Severity: important References: 1212476,1216545,1218588,1218664,1243197,1245938,1245939,1245942,1245943,1245946,CVE-2025-27613,CVE-2025-27614,CVE-2025-46835,CVE-2025-48384,CVE-2025-48385 This update for git, git-lfs, obs-scm-bridge, python-PyYAML fixes the following issues: git was updated from version 2.43.0 to 2.51.0 (bsc#1243197): - Security issues fixed: * CVE-2025-27613 Fixed arbitrary writable file creation and truncation in Gitk(bsc#1245938) * CVE-2025-27614 Fixed arbitrary script execution via repository clonation in gitk(bsc#1245939) * CVE-2025-46835 Fixed arbitrary writable file creation in Git GUI when untrusted repository is cloned (bsc#1245942) * CVE-2025-48384 Fixed the unintentional execution of a script after checkout due to CRLF transforming (bsc#1245943) * CVE-2025-48385 Fixed arbitrary code execution due to protocol injection via fetching advertised bundle(bsc#1245946) - Other changes and bugs fixed: - Other changes and bugs fixed: * Added SHA256 support (bsc#1243197) * Git moved to /usr/libexec/git/git and updated AppArmor profile accordingly (bsc#1218588) * gitweb AppArmor profile: allow reading etc/gitweb-common.conf (bsc#1218664) * Do not replace apparmor configuration (bsc#1216545) * Fixed the Python version required (bsc#1212476) - Version Updates Release Notes: * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.51.0.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.50.1.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.50.0.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.49.0.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.48.1.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.48.0.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.47.1.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.47.0.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.46.2.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.46.1.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.46.0.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.45.3.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.45.2.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.45.1.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.45.0.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.44.0.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.3.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.2.adoc * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.1.adoc git-lfs is included in version 3.7.0. python-PyYAML was updated from version 6.0.1 to 6.0.2: - Added support for Cython 3.x and Python 3.13 obs-scm-bridge was updated from version 0.5.4 to 0.7.4: - New Features and Improvements: * Manifest File Support: Support has been added for a `_manifest file`, which serves as a successor to the `_subdirs` file. * Control Over Git Information: A new noobsinfo query parameter was added to hide git information in source and binary files. * Enhanced Submodule Handling: The system now records the configured branch of submodules and stays on that branch during checkout. * Git SHA Tracking: In project mode, the tool now uses git SHA sums instead of md5sum to track package sources. * SSH URL Support: ssh:// SCM URLs can now be used. * Improved Error Messages: Error reporting for invalid files within package subdirectories has been improved. * Standardized Config Location: In project mode, the _config file is now always located in the top-level directory, even when using subdirs. * Reduced Unnecessary Changes: In project mode, unnecessary modifications to the package meta URL are now avoided. * Limit Asset Handling: A new mechanism has been introduced to limit how assets are handled. * Branch Information Export: The trackingbranch is now exported to scmsync.obsinfo. - Bugs fixed: * Syntax Fix: A syntax issue was corrected. * Git Submodule Parsing: The .gitsubmodule parser was fixed to correctly handle files that contain a mix of spaces and tabs. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4297-1 Released: Fri Nov 28 11:03:19 2025 Summary: Security update for python311 Type: security Severity: low References: 1251305,1252974,CVE-2025-6075,CVE-2025-8291 This update for python311 fixes the following issues: Update to 3.11.14: - CVE-2025-6075: Fixed simple quadratic complexity vulnerabilities of os.path.expandvars() (bsc#1252974) - CVE-2025-8291: Fixed validity of the ZIP64 End of Central Directory (EOCD) not checked by the 'zipfile' module (bsc#1251305) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:271-1 Released: Fri Jan 23 12:00:51 2026 Summary: Recommended update for python-setuptools Type: recommended Severity: important References: 1254255 This update for python-setuptools fixes the following issues: - Implement basic PEP 639 support, (jsc#PED-14457, bsc#1254255) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:314-1 Released: Wed Jan 28 14:28:46 2026 Summary: Security update for python311 Type: security Severity: moderate References: 1254400,1254401,1254997,CVE-2025-12084,CVE-2025-13836,CVE-2025-13837 This update for python311 fixes the following issues: - CVE-2025-12084: prevent quadratic behavior in node ID cache clearing (bsc#1254997). - CVE-2025-13836: prevent reading an HTTP response from a server, if no read amount is specified, with using Content-Length per default as the length (bsc#1254400). - CVE-2025-13837: protect against OOM when loading malicious content (bsc#1254401). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:653-1 Released: Thu Feb 26 11:55:45 2026 Summary: Recommended update for python3-gcemetadata, regionServiceClientConfigGCE Type: recommended Severity: moderate References: This update for python3-gcemetadata, regionServiceClientConfigGCE fixes the following issues: Changes for python3-gcemetadata: - Update to version 1.1.0 (jsc#PCT-590): * Add licenses option in identity command. Changes for regionServiceClientConfigGCE: - Update to version 5.2.0: * Drop the if condition for gcemetdata requirement - Update to version 5.1.0 (jsc#PCT-590): * Add licenses info in the metdata - Accomodate build setup * SLE 16 python-requests requires SSL v3 certificates. Update 2 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:767-1 Released: Tue Mar 3 14:05:42 2026 Summary: Security update for python311 Type: security Severity: important References: 1257029,1257031,1257041,1257042,1257044,1257046,1257108,CVE-2025-11468,CVE-2025-12781,CVE-2025-15282,CVE-2025-15366,CVE-2025-15367,CVE-2026-0672,CVE-2026-0865 This update for python311 fixes the following issues: - CVE-2025-11468: header injection when folding a long comment in an email header containing exclusively unfoldable characters (bsc#1257029). - CVE-2025-12781: inadequate parameter check can cause data integrity issues (bsc#1257108). - CVE-2025-15282: user-controlled data URLs parsed may allow injecting headers (bsc#1257046). - CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044). - CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041). - CVE-2026-0672: HTTP header injection via user-controlled cookie values and parameters when using http.cookies.Morsel (bsc#1257031). - CVE-2026-0865: user-controlled header containing newlines can allow injecting HTTP headers (bsc#1257042). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1349-1 Released: Wed Apr 15 15:35:54 2026 Summary: Security update for python311 Type: security Severity: important References: 1252974,1254400,1254401,1254997,1257029,1257031,1257042,1257046,1257181,1259240,1259611,1259734,1259735,1259989,1260026,CVE-2025-11468,CVE-2025-12084,CVE-2025-13462,CVE-2025-13836,CVE-2025-13837,CVE-2025-15282,CVE-2025-6075,CVE-2026-0672,CVE-2026-0865,CVE-2026-1299,CVE-2026-2297,CVE-2026-3479,CVE-2026-3644,CVE-2026-4224,CVE-2026-4519 This update for python311 fixes the following issues: - Updated to Python 3.11.15 - CVE-2025-6075: If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables (bsc#1252974). - CVE-2025-11468: header injection when folding a long comment in an email header containing exclusively unfoldable characters (bsc#1257029). - CVE-2025-12084: cpython: python: cpython: Quadratic algorithm in xml.dom.minidom leads to denial of service (bsc#1254997). - CVE-2025-13462: incorrect parsing of TarInfo header when GNU long name and type AREGTYPE are combined (bsc#1259611). - CVE-2025-13836: When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length (bsc#1254400). - CVE-2025-13837: When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues (bsc#1254401). - CVE-2025-15282: user-controlled data URLs parsed may allow injecting headers (bsc#1257046). - CVE-2026-0672: HTTP header injection via user-controlled cookie values and parameters when using http.cookies.Morsel (bsc#1257031). - CVE-2026-0865: user-controlled header containing newlines can allow injecting HTTP headers (bsc#1257042). - CVE-2026-1299: header injection when an email is serialized due to improper newline quoting in `BytesGenerator` (bsc#1257181). - CVE-2026-2297: cpython: incorrectly handled hook in FileLoader can lead to validation bypass (bsc#1259240). - CVE-2026-3479: python: improper resource argument validation can allow path traversal (bsc#1259989). - CVE-2026-3644: incomplete control character validation in http.cookies (bsc#1259734). - CVE-2026-4224: C stack overflow when parsing XML with deeply nested DTD content models (bsc#1259735). - CVE-2026-4519: leading dashes in URLs are accepted by the `webbrowser.open()` API and allow for web browser command line option injection (bsc#1260026). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2298-1 Released: Mon Jun 8 12:17:11 2026 Summary: Security update for python311 Type: security Severity: moderate References: 1258364,1261970,CVE-2026-3446 This update for python311 fixes the following issues: - CVE-2026-3446: Base64 decoding stops at first padded quad by default (bsc#1261970). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3104-1 Released: Fri Jul 17 15:31:14 2026 Summary: Security update for python311 Type: security Severity: important References: 1261969,1262098,1262319,1262654,CVE-2026-1502,CVE-2026-4786,CVE-2026-6019,CVE-2026-6100 This update for python311 fixes the following issues - CVE-2026-1502: CR/LF bytes not rejected by HTTP client proxy tunnel headers or host (bsc#1261969). - CVE-2026-4786: URLs containing `%action` can bypass mitigation that allows command injection via the `webbrowser.open()` API (bsc#1262319). - CVE-2026-6019: HTML parser-sensitive sequence not neutralized by `http.cookies.Morsel.js_output()` (bsc#1262654). - CVE-2026-6100: use-after-free in decompression modules when a memory allocation fails with a `MemoryError` and the decompression instance is re-used (bsc#1262098). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3129-1 Released: Mon Jul 20 11:41:29 2026 Summary: Recommended update for tiertune Type: recommended Severity: moderate References: This update for tiertune fixes the following issues: - Implement the package 'tiertune' to dynamically configure systemd and kernel settings based on specific cloud instance types across GCE, AWS, and Azure ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3391-1 Released: Tue Jul 28 18:49:41 2026 Summary: Recommended update for tiertune Type: recommended Severity: moderate References: This update for tiertune fixes the following issues: - Add KernelWorkQueue class: * Introduces KernelWorkQueue, a new settings class parallel to CPUPower, for managing kernel workqueue parameters. (jsc#PCT-1941) - Add X4 watchdog settings: * Add watchdog_thresh=60 and workqueue.watchdog_thresh=120 to be set by the sysctl component. (jsc#PCT-1941) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3560-1 Released: Mon Aug 10 20:09:08 2026 Summary: Security update for python311 Type: security Severity: important References: 1264962,1265268,1267581,1267821,1268375,1268977,1269066,1269788,1269959,1271192,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-3276,CVE-2026-4360,CVE-2026-7210,CVE-2026-7774,CVE-2026-8328 This update for python311 fixes the following issues: Security issues fixed: - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581). - CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). - CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection (bsc#1264962). - CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). Non security issue fixed: - [kernel 7.1] udplite was removed -> python fails in tests (bsc#1268375). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3648-1 Released: Wed Aug 19 11:54:08 2026 Summary: Security update for python311 Type: security Severity: important References: 1263083,CVE-2026-3276,CVE-2026-6019 This update for python311 fixes the following issues: - Regression in `http.cookies` (bsc#1263083). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3833-1 Released: Thu Aug 27 08:41:53 2026 Summary: Recommended update for tiertune Type: recommended Severity: moderate References: This update for tiertune fixes the following issues: - Upgrade to version 0.1.3: * Fix the regular expression for X4 matching: + The instance identifier is 'x4-480-8t-metal'. A missing '.' in the regular expression caused a match failure as the previous expression stopped matching after the firt hyphen. * Start after the network is available: + We need to reach out to the metadata server to get instance data information. Therefore we cannot run tiertune until after the network is online. * Expand instance type matching for X4: + Modify the expression to match the configuration for X4 and X5 instances in GCE. The currently used expression will not match and as such the settings do not get applied. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3860-1 Released: Fri Aug 28 15:04:38 2026 Summary: Security update for rsyslog Type: security Severity: important References: 1275926 This update for rsyslog fixes the following issue: - Heap buffer overflow in the core `RainerScript` `replace()` function (bsc#1275926). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3866-1 Released: Fri Aug 28 19:29:09 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803 This update for openssl-3 fixes the following issues: August 2026 release . - CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795). - CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). - CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797). - CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790). - CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3878-1 Released: Mon Aug 31 11:12:55 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072 This update for openssl-1_1 fixes the following issues: - CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). - CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). Changes for openssl-1_1: - August 2026 release (bsc#1274774) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3926-1 Released: Thu Sep 3 02:04:11 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Allow openssl to load when using the DEFAULT policy, and also other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3927-1 Released: Thu Sep 3 06:27:06 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1259542,1275902 This update for shadow fixes the following issues: - Mark /etc/default/useradd as %config(noreplace) to restore the behavior prior to the file being removed from shadow. (bsc#1275902) - Fix regression caused in (bsc#1259542) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3961-1 Released: Thu Sep 3 15:32:38 2026 Summary: Security update for suseconnect-ng Type: security Severity: moderate References: 1159776,1267478,1268596,1268900,1270392 This update for suseconnect-ng fixes the following issue: - Update version to 1.23.0: - Use product identifier for product migrations. (bsc#1268596) - Switch to using go1.26-openssl as the default Go version to install to support building the package (jsc#SCC-843, bsc#1268900). - Fix flag parsing so that unknown flags or options are flagged as an error and the usage message is displayed. (bsc#1159776) - InstallReleasePackage interactive/noninteractive handling should be consistent with DistUpgrade (bsc#1267478). - Add new optional rpm_packages collector, disabled by default, to collect list of installed SUSE vendored RPM packages. (jsc#TEL-298) - Allow deregsiter when subscribed regcode has expired (bsc#1270392, jsc#865) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3980-1 Released: Sun Sep 6 09:44:23 2026 Summary: Recommended update for libtirpc Type: recommended Severity: important References: 1274740 This update for libtirpc fixes the following issues: - Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740): * rpcb_clnt.c: fix memory leak in destroy_addr ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3997-1 Released: Mon Sep 7 09:22:53 2026 Summary: Security update for dracut Type: security Severity: important References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893 This update for dracut fixes the following issues: Update to version 059+suse.730.g73d3411aa. - CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` (bsc#1268322). - CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` during system boot (bsc#1273580). Changes for dracut: - Update to version 059+suse.730.g73d3411aa: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4012-1 Released: Mon Sep 7 09:34:33 2026 Summary: Security update for cpio Type: security Severity: moderate References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486 This update for cpio fixes the following issues: - CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). - CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). - CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4021-1 Released: Mon Sep 7 09:41:23 2026 Summary: Security update for c-ares Type: security Severity: important References: 1220279,1240955,1254738,1270416,1276290,1276291,CVE-2024-25629,CVE-2025-31498,CVE-2025-62408,CVE-2026-33630,CVE-2026-69184,CVE-2026-69186 This update for c-ares fixes the following issues: - CVE-2024-25629: out of bounds read in ares__read_line() (bsc#1220279). - CVE-2025-31498: use-after-free in read_answers() when process_answer() may re-enqueue a query (bsc#1240955). - CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (bsc#1254738). - CVE-2026-33630: Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP (bsc#1270416). - CVE-2026-69184: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290). - CVE-2026-69186: Memory-amplification denial of service via unvalidated DNS header record counts (bsc#1276291). Changes for c-ares: - updated to 1.36.8. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4047-1 Released: Mon Sep 7 15:53:38 2026 Summary: Security update for curl Type: security Severity: moderate References: 1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926 This update for curl fixes the following issues: - CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). - CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). - CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). - CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). - CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). - CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4050-1 Released: Mon Sep 7 15:55:07 2026 Summary: Security update for libusb-1_0 Type: security Severity: moderate References: 1266664,CVE-2026-23679 This update for libusb-1_0 fixes the following issue: - CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4055-1 Released: Mon Sep 7 17:48:12 2026 Summary: Security update for bzip2 Type: security Severity: low References: 1266786,CVE-2026-42250 This update for bzip2 fixes the following issue: - CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4101-1 Released: Wed Sep 9 14:07:04 2026 Summary: Recommended update for rsyslog Type: recommended Severity: moderate References: 1274610 This update for rsyslog fixes the following issues: - gtls: guard early debug-level lookup (bsc#1274610) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4112-1 Released: Wed Sep 9 18:17:10 2026 Summary: Security update for libzypp, zypper Type: security Severity: critical References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790 This update for libzypp, zypper fixes the following issues: Security issue fixed: - invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625). - hasCredentials() requires both username AND password to be non-empty (bsc#1273242). - GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730). Non security issues fixed: - Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). - libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). - Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). - zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). - Zypper patch doesn't give enough details about conflicts (bsc#1277790). - dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038). Changes for libzypp: - Update to version 17.38.15: - Prevent libgpgme from launching gpg-agents; we don't need them. - defaultLoadSystem: Hand out the ZYpp::Ptr as return value. - Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) - zypp: Improve Testcase Loading for MCP Tools. - spec: Remove useless %bcond visibility_hidden (is always ON in cmake) - zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: - Update to version 1.14.101. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4116-1 Released: Wed Sep 9 21:41:52 2026 Summary: Recommended update for crypto-policies Type: recommended Severity: important References: 1242233,1243830,1277267 This update for crypto-policies fixes the following issues: - Revert the previous change since the syntax is not understood in this crypto-policies version. (bsc#1243830, bsc#1242233, bsc#1277267) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4124-1 Released: Thu Sep 10 18:11:41 2026 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1277247 This update for glibc fixes the following issues: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:4142-1 Released: Mon Sep 14 09:59:10 2026 Summary: Recommended update for permissions Type: recommended Severity: moderate References: 1278351 This update for permissions fixes the following issue: - Update to version 20240826: * profiles: backport nvidia-modprobe (bsc#1278351) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4176-1 Released: Mon Sep 14 12:29:48 2026 Summary: Security update for acl, attr Type: security Severity: important References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371 This update for acl, attr fixes the following issue: - CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: - Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: - Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: - The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. - When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. - When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. - When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: - When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ('Too many levels of symbolic links') error will result instead. - acl_delete_entry() now verifies that the specified entry belongs to the specified acl. - Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. - When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. - setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. - setfacl --restore accidentally called chmod() when in --test mode. It no longer does. - When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. - When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. - The -h (--no-dereference) option of getfattr prevented getfattr from recursing into 'symbolic link directories'. This is wrong. When dirlink is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now visit that directory. The -P (--physical) option can be used to prevent that. - Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent - update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4194-1 Released: Tue Sep 15 16:27:47 2026 Summary: Security update for libpcap Type: security Severity: important References: 1279584,1279588,1279593,1279595,1279782,1279783,1279784,CVE-2026-0799,CVE-2026-18238,CVE-2026-18313,CVE-2026-31911,CVE-2026-31912,CVE-2026-6244,CVE-2026-6554 This update for libpcap fixes the following issues: - CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). - CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). - CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). - CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). - CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ` message received from the client and never frees the memory (bsc#1279784). - CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). - CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4207-1 Released: Wed Sep 16 10:21:54 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4241-1 Released: Thu Sep 17 13:48:51 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4250-1 Released: Thu Sep 17 18:00:36 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4270-1 Released: Mon Sep 21 09:29:29 2026 Summary: Security update for google-guest-agent Type: security Severity: important References: 1253357,1260264,1272118,1278597,1278967,1279297,1279414,CVE-2026-33186,CVE-2026-56852,CVE-2026-56854,CVE-2026-56855,CVE-2026-78662,CVE-2026-84303,CVE-2026-84304,CVE-2026-84445 This update for google-guest-agent fixes the following issues: - CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260264). - CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118). - CVE-2026-56854: golang.org/x/crypto/ssh: source-address critical option not enforced for non-public-key auth callbacks (bsc#1278597) - CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1278597) - CVE-2026-78662: golang.org/x/crypto/ssh: prevent DoS on deadlocked undecided channel (bsc#1278597). - CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279297). - CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414). - CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278967). Changes for google-guest-agent: - Updated to version 20260903.01 ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4275-1 Released: Mon Sep 21 09:32:08 2026 Summary: Security update for jq Type: security Severity: important References: 1215737,1218034,1218038,1238078,1248600,1262043,1262072,1265060,1265061,1265062,1265070,1265071,1265075,1265076,1269220,1269221,1269390,976992,CVE-2015-8863,CVE-2023-50246,CVE-2023-50268,CVE-2024-53427,CVE-2025-9403,CVE-2026-33948,CVE-2026-40164,CVE-2026-40612,CVE-2026-41256,CVE-2026-41257,CVE-2026-43894,CVE-2026-43895,CVE-2026-43896,CVE-2026-44777,CVE-2026-47770,CVE-2026-49839,CVE-2026-54679 This update for jq fixes the following issues: Security issues fixed: - CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992). - CVE-2023-50246: improper memory handling can lead to a heap buffer overflow in `decNumberToString` (bsc#1218034). - CVE-2023-50268: stack-based buffer overflow in builds using decNumber (bsc#1218038). - CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in decNumber.c (bsc#1238078). - CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600). - CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). - CVE-2026-40164: predictable hash collisions can lead to a denial of service (bsc#1262072). - CVE-2026-40612: jv_contains recurses into nested arrays/objects with no depth limit and can cause a stack overflow (bsc#1265060). - CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f and can lead to execution of unintended programs (bsc#1265061). - CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS (bsc#1265062). - CVE-2026-43894: signed integer overflow in `decNumber` can lead to out-of-bounds memory write (bsc#1265070). - CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). - CVE-2026-43896: unbounded recursion in `jv_object_merge_recursive()` can lead to C stack exhaustion and a process crash (bsc#1265075). - CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). - CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). - CVE-2026-49839: `--rawfile` invalid-state reuse after `String too long` can lead to a heap buffer overflow (bsc#1269220). - CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer overrun on 32-bit systems (bsc#1269390). Changes for jq: Update to version 1.7.1: * Make the default background color more suitable for bright backgrounds. * Allow passing the inline jq script after --. * Fix possible uninitialised value dereference if jq_init() fails * Simplify paths/0 and paths/1. * Reject U+001F in string literals. * Remove unused nref accumulator in block_bind_library. * Remove a bunch of unused variables, and useless assignments. * main.c: Remove unused EXIT_STATUS_EXACT option. * Actually use the number correctly casted from double to int as index. * src/builtin.c: remove unnecessary jv_copy-s in type_error/type_error2. * Remove undefined behavior caught by LLVM 10 UBSAN. * Convert decnum to binary64 (double) instead of decimal64. This makes jq behave like the JSON specification suggests and more similar to other languages. * Fix memory leaks on invalid input for ltrimstr/1 and rtrimstr/1. * Fix memory leak on failed get for setpath/2. * Fix nan from json parsing also for nans with payload that start with 'n'. * Allow carriage return characters in comments. * Generate links in the man page. * Add extern C for C++. * Make object key color configurable using JQ_COLORS environment variable. * Change the default color of null to Bright Black. * Respect NO_COLOR environment variable to disable color output. * Improved --help output. Now mentions all options and nicer order. * Fix multiple issues of exit code using --exit-code/-e option. * Add --raw-output0 for NUL (zero byte) separated output. * Fix assert crash and validate JSON for --jsonarg. * Remove deprecated --argfile option. * Use decimal number literals to preserve precision. Comparison operations respects precision but arithmetic operations might truncate. * Adds new builtin pick(stream) to emit a projection of the input object or array. * Adds new builtin debug(msgs) that works like debug but applies a filter on the input before writing to stderr. * Adds new builtin scan($re; $flags). Was documented but not implemented. * Adds new builtin abs to get absolute value. This potentially allows the literal value of numbers to be preserved as length and fabs convert to float. * Allow if without else-branch. When skipped the else-branch will be . (identity). * Allow use of $binding as key in object literals. * Allow dot between chained indexes when using .['index'] * Allow dot for chained value iterator .[], .[]? * Fix try/catch catches more than it should. * Speed up and refactor some builtins, also remove scalars_or_empty/0. * Now halt and halt_error exit immediately instead of continuing to the next input. * Fix issue converting string to number after previous convert error. * Fix issue representing large numbers on some platforms causing invalid JSON output. * Fix deletion using assigning empty against arrays. * Allow keywords to be used as binding name in more places. * Allow using nan as NaN in JSON. * Expose a module's function names in modulemeta. * Fix contains/1 to handle strings with NUL. * Fix stderr/0 to output raw text without any decoration. * Fix nth/2 to emit empty on index out of range. * Fix implode to not assert and instead replace invalid unicode codepoints. * Fix indices/1 and rindex/1 in case of overlapping matches in strings. * Fix sub/3 to resolve issues involving global search-and-replace (gsub) operations. * Fix empty regular expression matches. * Fix overflow exception of the modulo operator. * Fix string multiplication by 0 (and less than 1) to emit empty string. * Fix segfault when using libjq and threads. * Fix constant folding of division and reminder with zero divisor. * Fix error/0, error/1 to throw null error. * Simpler and faster transpose. * Simple and efficient implementation of walk/1. * Remove deprecated filters leaf_paths, recurse_down. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4293-1 Released: Wed Sep 23 09:55:45 2026 Summary: Security update for google-osconfig-agent Type: security Severity: important References: 1272118,1276722,1278597,1278967,1279297,1279414,CVE-2026-41178,CVE-2026-56852,CVE-2026-56854,CVE-2026-56855,CVE-2026-78662,CVE-2026-84303,CVE-2026-84304,CVE-2026-84445 This update for google-osconfig-agent fixes the following issues: - CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276722). - CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118). - CVE-2026-56854: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). - CVE-2026-56855: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). - CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). - CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279297). - CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414). - CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278967). Changes for google-osconfig-agent: - Update to version 20260908.00 The following package changes have been done: - cpio-2.13-150400.3.10.1 updated - crypto-policies-scripts-20230920.570ea89-150600.3.22.1 added - crypto-policies-20230920.570ea89-150600.3.22.1 updated - curl-8.14.1-150600.4.51.1 updated - dracut-fips-059+suse.571.g3d42218af-150600.3.35.1 added - dracut-059+suse.571.g3d42218af-150600.3.35.1 updated - glibc-locale-base-2.38-150600.14.58.1 updated - glibc-2.38-150600.14.58.1 updated - google-guest-agent-20260903.01-150000.1.85.1 updated - google-osconfig-agent-20260911.00-150000.1.67.1 updated - jq-1.7.1-150000.3.25.1 updated - kbd-legacy-2.4.0-150400.5.12.1 updated - kbd-2.4.0-150400.5.12.1 updated - libacl1-2.4.0-150000.4.6.1 updated - libattr1-2.6.0-150000.4.3.1 updated - libbz2-1-1.0.8-150400.3.4.1 updated - libcares2-1.34.8-150000.3.29.1 updated - libcurl4-8.14.1-150600.4.51.1 updated - libjq1-1.7.1-150000.3.25.1 updated - libkcapi-tools-0.13.0-150600.17.3.1 added - libopenssl-3-fips-provider-3.1.4-150600.5.64.1 added - libopenssl1_1-1.1.1w-150600.5.38.1 updated - libopenssl3-3.1.4-150600.5.64.1 updated - libpcap1-1.10.4-150600.3.12.1 updated - libpcre2-8-0-10.42-150600.3.3.1 updated - libpython3_11-1_0-3.11.15-150600.3.65.1 added - libsubid5-4.17.2-150600.17.24.1 updated - libtirpc-netconfig-1.3.4-150300.3.26.1 updated - libtirpc3-1.3.4-150300.3.26.1 updated - libusb-1_0-0-1.0.24-150400.3.6.1 updated - libyaml-0-2-0.1.7-150000.3.4.1 added - libzypp-17.38.15-150600.3.95.1 updated - login_defs-4.17.2-150600.17.24.1 updated - openssh-fips-9.6p1-150600.6.49.1 added - openssl-3-3.1.4-150600.5.64.1 updated - patterns-base-fips-20200124-150600.32.6.1 added - permissions-20240826-150600.10.21.1 updated - python3-gcemetadata-1.1.0-150000.3.12.1 added - python311-PyYAML-6.0.2-150600.10.3.1 added - python311-base-3.11.15-150600.3.65.1 added - python311-setuptools-67.7.2-150400.3.22.1 added - python311-tiertune-0.1.3-150600.13.9.1 added - python311-3.11.15-150600.3.65.1 added - python3-3.6.15-150300.10.118.1 added - rsyslog-module-relp-8.2406.0-150600.12.25.1 updated - rsyslog-8.2406.0-150600.12.25.1 updated - scap-security-guide-0.1.80-150600.1.38 updated - shadow-4.17.2-150600.17.24.1 updated - suseconnect-ng-1.23.0-150600.3.24.1 updated - tiertune-gce-0.1.3-150600.13.9.1 added - zypper-1.14.101-150600.10.58.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 07:09:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 09:09:22 +0200 (CEST) Subject: SUSE-IU-2026:7394-1: Security update of suse/sle-micro/rt-5.5 Message-ID: <20260925070922.AC738FCF8@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7394-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.730 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.730 Severity : important Type : security References : 1235944 1261604 1263072 1264734 1267023 1268659 1269000 1269004 1269238 1269242 1269306 1269655 1269731 1269792 1271825 1271830 1272179 1272182 1272230 1272385 1272390 1272756 1272868 1272877 1273060 1273105 1273276 1273303 1273311 1273422 1273484 1273488 1273523 1273555 1273742 1273745 1273748 1273762 1273774 1273869 1273882 1273891 1273930 1273944 1273966 1273995 1274014 1274031 1274041 1274208 1274274 1274497 1274547 1274550 1274696 1274705 1274752 1274753 1274754 1274859 1274888 1274898 1274902 1274908 1274941 1275161 1275472 1275474 1275506 1275528 1275687 1275782 1275798 1275827 1275867 1275886 1275905 1276350 1276665 1276931 1277073 1277155 1277285 1277391 1277408 1277523 1277571 1277678 1277860 1278088 1278233 1278236 1279554 1279813 CVE-2024-57841 CVE-2026-23451 CVE-2026-31502 CVE-2026-43456 CVE-2026-45968 CVE-2026-52910 CVE-2026-52912 CVE-2026-52929 CVE-2026-52977 CVE-2026-53059 CVE-2026-53163 CVE-2026-53260 CVE-2026-53264 CVE-2026-53381 CVE-2026-53388 CVE-2026-63801 CVE-2026-63823 CVE-2026-63827 CVE-2026-63887 CVE-2026-63888 CVE-2026-63920 CVE-2026-63992 CVE-2026-64002 CVE-2026-64007 CVE-2026-64010 CVE-2026-64011 CVE-2026-64015 CVE-2026-64047 CVE-2026-64048 CVE-2026-64098 CVE-2026-64109 CVE-2026-64114 CVE-2026-64115 CVE-2026-64137 CVE-2026-64266 CVE-2026-64268 CVE-2026-64304 CVE-2026-64355 CVE-2026-64423 CVE-2026-64450 CVE-2026-64481 CVE-2026-64541 CVE-2026-64543 CVE-2026-64562 CVE-2026-64563 CVE-2026-64572 CVE-2026-64577 CVE-2026-64581 CVE-2026-64593 CVE-2026-68121 CVE-2026-68136 CVE-2026-68138 CVE-2026-68160 CVE-2026-68202 CVE-2026-68397 CVE-2026-68398 CVE-2026-68417 CVE-2026-68426 CVE-2026-68480 CVE-2026-72020 CVE-2026-72069 CVE-2026-72072 CVE-2026-72123 CVE-2026-72135 CVE-2026-72251 CVE-2026-72262 CVE-2026-72288 CVE-2026-72289 CVE-2026-72389 CVE-2026-74345 CVE-2026-74377 CVE-2026-74378 CVE-2026-74390 CVE-2026-74394 CVE-2026-74454 CVE-2026-74488 CVE-2026-74496 CVE-2026-74518 CVE-2026-74537 CVE-2026-74581 CVE-2026-74582 CVE-2026-74669 CVE-2026-74695 CVE-2026-80722 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4347-1 Released: Thu Sep 24 16:36:19 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1235944,1261604,1263072,1264734,1267023,1268659,1269000,1269004,1269238,1269242,1269306,1269655,1269731,1269792,1271825,1271830,1272179,1272182,1272230,1272385,1272390,1272756,1272868,1272877,1273060,1273105,1273276,1273303,1273311,1273422,1273484,1273488,1273523,1273555,1273742,1273745,1273748,1273762,1273774,1273869,1273882,1273891,1273930,1273944,1273966,1273995,1274014,1274031,1274041,1274208,1274274,1274497,1274547,1274550,1274696,1274705,1274752,1274753,1274754,1274859,1274888,1274898,1274902,1274908,1274941,1275161,1275472,1275474,1275506,1275528,1275687,1275782,1275798,1275827,1275867,1275886,1275905,1276350,1276665,1276931,1277073,1277155,1277285,1277391,1277408,1277523,1277571,1277678,1277860,1278088,1278233,1278236,1279554,1279813,CVE-2024-57841,CVE-2026-23451,CVE-2026-31502,CVE-2026-43456,CVE-2026-45968,CVE-2026-52910,CVE-2026-52912,CVE-2026-52929,CVE-2026-52977,CVE-2026-53059,CVE-2026-53163,CVE-2026-53260,CVE-2026-53264,CVE-2026-53381,CVE-2026-53388,CVE-2026 -63801,CVE-2026-63823,CVE-2026-63827,CVE-2026-63887,CVE-2026-63888,CVE-2026-63920,CVE-2026-63992,CVE-2026-64002,CVE-2026-64007,CVE-2026-64010,CVE-2026-64011,CVE-2026-64015,CVE-2026-64047,CVE-2026-64048,CVE-2026-64098,CVE-2026-64109,CVE-2026-64114,CVE-2026-64115,CVE-2026-64137,CVE-2026-64266,CVE-2026-64268,CVE-2026-64304,CVE-2026-64355,CVE-2026-64423,CVE-2026-64450,CVE-2026-64481,CVE-2026-64541,CVE-2026-64543,CVE-2026-64562,CVE-2026-64563,CVE-2026-64572,CVE-2026-64577,CVE-2026-64581,CVE-2026-64593,CVE-2026-68121,CVE-2026-68136,CVE-2026-68138,CVE-2026-68160,CVE-2026-68202,CVE-2026-68397,CVE-2026-68398,CVE-2026-68417,CVE-2026-68426,CVE-2026-68480,CVE-2026-72020,CVE-2026-72069,CVE-2026-72072,CVE-2026-72123,CVE-2026-72135,CVE-2026-72251,CVE-2026-72262,CVE-2026-72288,CVE-2026-72289,CVE-2026-72389,CVE-2026-74345,CVE-2026-74377,CVE-2026-74378,CVE-2026-74390,CVE-2026-74394,CVE-2026-74454,CVE-2026-74488,CVE-2026-74496,CVE-2026-74518,CVE-2026-74537,CVE-2026-74581,CVE-2026-74582,CVE-2026-74669, CVE-2026-74695,CVE-2026-80722 The SUSE Linux Enterprise 15 SP5 RT kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2024-57841,CVE-2026-53260: net: fix memory leak in tcp_conn_request() (bsc#1235944 bsc#1269731). - CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). - CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). - CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). - CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). - CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period (bsc#1268659). - CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000). - CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). - CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). - CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). - CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). - CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). - CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). - CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). - CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). - CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). - CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). - CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). - CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). - CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). - CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). - CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). - CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). - CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). - CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). - CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). - CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). - CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). - CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). - CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). - CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). - CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). - CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). - CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). - CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). - CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). - CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). - CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). - CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). - CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). - CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). - CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). - CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). - CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). - CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). - CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). - CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). - CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). - CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). - CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). - CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). - CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). - CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). - CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). - CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). - CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). - CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). - CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). - CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). - CVE-2026-72135: tpm: Make the TPM character devices non-seekable (bsc#1277571). - CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). - CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678). - CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). - CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). - CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). - CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). - CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236). - CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233). - CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (bsc#1278088). - CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). - CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). - CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). - CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). - CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). - CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). - CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). - CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). - CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). - CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). - CVE-2026-80722: wifi: mac80211: validate individual TWT params before driver setup (bsc#1277860). The following non security issues were fixed: - mkspec-dtb: Move DTS prefix into package list. - mkspec-dtb: Move provides-obsoletes to package list. - mkspec-dtb: Put per-architecture package lists into a hash. - mkspec-dtb: re-indent. - net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). - net: mana: Add handler for sriov configure (bsc#1272756). - net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). - net: mana: Route ring-buffer access through offset-based helpers (git-fixes). - net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). - PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git-fixes). - powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). - RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). - RDMA/mana_ib: unify QP lookup table (git-fixes). - RDMA/siw: Introduce siw_cep_set_free_and_put (git-fixes). - RDMA/siw: Introduce siw_destroy_cep_sock (git-fixes). - RDMA/siw: Introduce siw_free_cm_id (git-fixes). - RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp (git-fixes). - scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). - smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). - smb: client: require net admin for CIFS SWN netlink (bsc#1273966). The following package changes have been done: - kernel-rt-5.14.21-150500.13.161.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 07:14:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 09:14:36 +0200 (CEST) Subject: SUSE-IU-2026:7396-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260925071436.7F953FCF8@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7396-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.156 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.156 Severity : important Type : security References : 1262263 1264713 1267631 1268572 1268573 1275096 1275594 1275732 1275859 1275860 1275915 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 The following package changes have been done: - libexpat1-2.8.4-160000.1.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-5b0b3fb408f870e03ddbe0810bfa713fe816b001d05960d19c582e86fed99ab6-0 updated From sle-container-updates at lists.suse.com Fri Sep 25 07:24:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 09:24:50 +0200 (CEST) Subject: SUSE-IU-2026:7405-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260925072450.B158AFCE1@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7405-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.83 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.83 Severity : important Type : security References : 1262263 1264713 1267631 1268572 1268573 1275096 1275594 1275732 1275859 1275860 1275915 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 The following package changes have been done: - libexpat1-2.8.4-160000.1.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 07:33:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 09:33:43 +0200 (CEST) Subject: SUSE-IU-2026:7412-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260925073343.21748FCE1@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7412-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.142 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.142 Severity : important Type : security References : 1262263 1264713 1267631 1268572 1268573 1275096 1275594 1275732 1275859 1275860 1275915 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 The following package changes have been done: - libexpat1-2.8.4-160000.1.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-5b0b3fb408f870e03ddbe0810bfa713fe816b001d05960d19c582e86fed99ab6-0 updated From sle-container-updates at lists.suse.com Fri Sep 25 07:43:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 09:43:43 +0200 (CEST) Subject: SUSE-IU-2026:7421-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260925074343.1DACDFCE1@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7421-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.180 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.180 Severity : important Type : security References : 1275441 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1279893 1280049 1280050 1280051 1280052 1280053 1280054 CVE-2026-72693 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1747 Released: Wed Sep 23 21:42:24 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). - CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049). ----------------------------------------------------------------- Advisory ID: 1748 Released: Wed Sep 23 21:47:23 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). The following package changes have been done: - libpcre2-8-0-10.45-160000.4.1 updated - libkbdfile1-2.7.1-160000.3.1 updated - libkfont0-2.7.1-160000.3.1 updated - libkeymap1-2.7.1-160000.3.1 updated - kbd-2.7.1-160000.3.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-64854e29967d32ecd59ed4ff6f8a9a23e6fa0fc62ed94ddf237684f1ac295e39-0 updated From sle-container-updates at lists.suse.com Fri Sep 25 07:43:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 09:43:46 +0200 (CEST) Subject: SUSE-IU-2026:7423-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260925074346.96556FCFE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7423-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.182 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.182 Severity : important Type : security References : 1262263 1264713 1267631 1268572 1268573 1275096 1275594 1275732 1275859 1275860 1275915 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 The following package changes have been done: - libexpat1-2.8.4-160000.1.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-1a73c649fe203118dc13c7c78c6dc9889ed66809d2c9acf91d873c48ed077209-0 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:00:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:00:25 +0200 (CEST) Subject: SUSE-CU-2026:11160-1: Security update of suse/389-ds Message-ID: <20260925080025.5E1D6FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/389-ds ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11160-1 Container Tags : suse/389-ds:3.0 , suse/389-ds:3.0.6 , suse/389-ds:3.0.6-18.10 , suse/389-ds:latest Container Release : 18.10 Severity : critical Type : security References : 1261606 1262698 1266262 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 1279863 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/389-ds was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1722 Released: Mon Sep 21 11:58:27 2026 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1262698,1266262,1279863 This update for mozilla-nss fixes the following issues: Changes in mozilla-nss: - Fix potential crash when verifying password length in PBKDF2 (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libuuid1-2.41.1-160000.5.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - libfreebl3-3.125-160000.2.1 updated - mozilla-nss-certs-3.125-160000.2.1 updated - mozilla-nss-3.125-160000.2.1 updated - libsoftokn3-3.125-160000.2.1 updated - mozilla-nss-tools-3.125-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:01:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:01:07 +0200 (CEST) Subject: SUSE-CU-2026:11161-1: Security update of bci/bci-base-fips Message-ID: <20260925080107.11710FCF8@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11161-1 Container Tags : bci/bci-base-fips:16.0 , bci/bci-base-fips:16.0-20.8 Container Release : 20.8 Severity : important Type : security References : 1261606 1268886 1269583 1270219 1275441 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container bci/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libblkid1-2.41.1-160000.5.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:01:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:01:08 +0200 (CEST) Subject: SUSE-CU-2026:11162-1: Recommended update of bci/bci-base-fips Message-ID: <20260925080108.33F3FFD07@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11162-1 Container Tags : bci/bci-base-fips:16.0 , bci/bci-base-fips:16.0-20.9 Container Release : 20.9 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container bci/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - container:registry.suse.com-bci-bci-base-16.0-62985aa8edf7f04db3b4310e94844af1c7f442499fe4445a61e4c6cd4df2333b-0 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:01:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:01:52 +0200 (CEST) Subject: SUSE-CU-2026:11163-1: Recommended update of bci/bci-base Message-ID: <20260925080152.8A606FCF8@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11163-1 Container Tags : bci/bci-base:16.0 , bci/bci-base:16.0-23.6 Container Release : 23.6 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container bci/bci-base was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - skelcd-EULA-BCI-20250701-160000.3.30 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:02:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:02:28 +0200 (CEST) Subject: SUSE-CU-2026:11164-1: Recommended update of suse/bind Message-ID: <20260925080229.44655FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/bind ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11164-1 Container Tags : suse/bind:9 , suse/bind:9.20 , suse/bind:9.20.26 , suse/bind:9.20.26-19.10 , suse/bind:latest Container Release : 19.10 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/bind was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:03:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:03:15 +0200 (CEST) Subject: SUSE-CU-2026:11166-1: Recommended update of suse/sles/16.0/cdi-apiserver Message-ID: <20260925080315.26C3CFCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-apiserver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11166-1 Container Tags : suse/sles/16.0/cdi-apiserver:1.65 , suse/sles/16.0/cdi-apiserver:1.65.0 , suse/sles/16.0/cdi-apiserver:1.65.0-6.12 Container Release : 6.12 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-apiserver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:03:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:03:35 +0200 (CEST) Subject: SUSE-CU-2026:11168-1: Security update of suse/sles/16.0/cdi-cloner Message-ID: <20260925080335.7381EFCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-cloner ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11168-1 Container Tags : suse/sles/16.0/cdi-cloner:1.65 , suse/sles/16.0/cdi-cloner:1.65.0 , suse/sles/16.0/cdi-cloner:1.65.0-6.12 Container Release : 6.12 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-cloner was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:03:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:03:54 +0200 (CEST) Subject: SUSE-CU-2026:11170-1: Recommended update of suse/sles/16.0/cdi-controller Message-ID: <20260925080354.7DCA6FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-controller ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11170-1 Container Tags : suse/sles/16.0/cdi-controller:1.65 , suse/sles/16.0/cdi-controller:1.65.0 , suse/sles/16.0/cdi-controller:1.65.0-6.12 Container Release : 6.12 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-controller was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:04:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:04:16 +0200 (CEST) Subject: SUSE-CU-2026:11172-1: Security update of suse/sles/16.0/cdi-importer Message-ID: <20260925080416.200E3FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-importer ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11172-1 Container Tags : suse/sles/16.0/cdi-importer:1.65 , suse/sles/16.0/cdi-importer:1.65.0 , suse/sles/16.0/cdi-importer:1.65.0-6.12 Container Release : 6.12 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-importer was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:04:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:04:34 +0200 (CEST) Subject: SUSE-CU-2026:11174-1: Recommended update of suse/sles/16.0/cdi-operator Message-ID: <20260925080434.9BAA4FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-operator ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11174-1 Container Tags : suse/sles/16.0/cdi-operator:1.65 , suse/sles/16.0/cdi-operator:1.65.0 , suse/sles/16.0/cdi-operator:1.65.0-6.12 Container Release : 6.12 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-operator was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:04:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:04:55 +0200 (CEST) Subject: SUSE-CU-2026:11176-1: Recommended update of suse/sles/16.0/cdi-uploadproxy Message-ID: <20260925080455.11230FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-uploadproxy ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11176-1 Container Tags : suse/sles/16.0/cdi-uploadproxy:1.65 , suse/sles/16.0/cdi-uploadproxy:1.65.0 , suse/sles/16.0/cdi-uploadproxy:1.65.0-6.12 Container Release : 6.12 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-uploadproxy was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:05:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:05:16 +0200 (CEST) Subject: SUSE-CU-2026:11178-1: Security update of suse/sles/16.0/cdi-uploadserver Message-ID: <20260925080516.07DBBFCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-uploadserver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11178-1 Container Tags : suse/sles/16.0/cdi-uploadserver:1.65 , suse/sles/16.0/cdi-uploadserver:1.65.0 , suse/sles/16.0/cdi-uploadserver:1.65.0-6.12 Container Release : 6.12 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-uploadserver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:05:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:05:21 +0200 (CEST) Subject: SUSE-CU-2026:11180-1: Recommended update of suse/sles/16.0/cdi-apiserver Message-ID: <20260925080521.CC5BAFD07@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-apiserver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11180-1 Container Tags : suse/sles/16.0/cdi-apiserver:1.66 , suse/sles/16.0/cdi-apiserver:1.66.1 , suse/sles/16.0/cdi-apiserver:1.66.1-1.2 Container Release : 1.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-apiserver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:05:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:05:32 +0200 (CEST) Subject: SUSE-CU-2026:11182-1: Security update of suse/sles/16.0/cdi-cloner Message-ID: <20260925080532.AD809FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-cloner ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11182-1 Container Tags : suse/sles/16.0/cdi-cloner:1.66 , suse/sles/16.0/cdi-cloner:1.66.1 , suse/sles/16.0/cdi-cloner:1.66.1-1.2 Container Release : 1.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-cloner was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:05:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:05:43 +0200 (CEST) Subject: SUSE-CU-2026:11184-1: Recommended update of suse/sles/16.0/cdi-controller Message-ID: <20260925080543.07A22FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-controller ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11184-1 Container Tags : suse/sles/16.0/cdi-controller:1.66 , suse/sles/16.0/cdi-controller:1.66.1 , suse/sles/16.0/cdi-controller:1.66.1-1.2 Container Release : 1.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-controller was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:05:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:05:53 +0200 (CEST) Subject: SUSE-CU-2026:11186-1: Security update of suse/sles/16.0/cdi-importer Message-ID: <20260925080553.2216DFCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-importer ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11186-1 Container Tags : suse/sles/16.0/cdi-importer:1.66 , suse/sles/16.0/cdi-importer:1.66.1 , suse/sles/16.0/cdi-importer:1.66.1-1.2 Container Release : 1.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-importer was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:06:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:06:03 +0200 (CEST) Subject: SUSE-CU-2026:11188-1: Recommended update of suse/sles/16.0/cdi-operator Message-ID: <20260925080603.6F0D7FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-operator ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11188-1 Container Tags : suse/sles/16.0/cdi-operator:1.66 , suse/sles/16.0/cdi-operator:1.66.1 , suse/sles/16.0/cdi-operator:1.66.1-1.2 Container Release : 1.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-operator was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:06:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:06:14 +0200 (CEST) Subject: SUSE-CU-2026:11190-1: Recommended update of suse/sles/16.0/cdi-uploadproxy Message-ID: <20260925080614.26B12FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-uploadproxy ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11190-1 Container Tags : suse/sles/16.0/cdi-uploadproxy:1.66 , suse/sles/16.0/cdi-uploadproxy:1.66.1 , suse/sles/16.0/cdi-uploadproxy:1.66.1-1.2 Container Release : 1.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-uploadproxy was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:06:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:06:24 +0200 (CEST) Subject: SUSE-CU-2026:11192-1: Security update of suse/sles/16.0/cdi-uploadserver Message-ID: <20260925080624.570B5FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-uploadserver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11192-1 Container Tags : suse/sles/16.0/cdi-uploadserver:1.66 , suse/sles/16.0/cdi-uploadserver:1.66.1 , suse/sles/16.0/cdi-uploadserver:1.66.1-1.2 Container Release : 1.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-uploadserver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:09:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:09:18 +0200 (CEST) Subject: SUSE-CU-2026:11195-1: Security update of suse/registry Message-ID: <20260925080918.A7080FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11195-1 Container Tags : suse/registry:3.1 , suse/registry:3.1 , suse/registry:3.1-7.11 , suse/registry:latest Container Release : 7.11 Severity : critical Type : security References : 1261606 1268884 1268886 1269583 1270219 1275441 1276677 1277919 1277966 1278347 1278348 1278349 1278997 1279219 1279316 CVE-2026-13595 CVE-2026-27456 CVE-2026-37236 CVE-2026-39827 CVE-2026-41178 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 ----------------------------------------------------------------- The container suse/registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1726 Released: Mon Sep 21 14:23:04 2026 Summary: Security update for distribution Type: security Severity: important References: 1268884,1276677,1277966,1278997,1279219,1279316,CVE-2026-37236,CVE-2026-39827,CVE-2026-41178,CVE-2026-84303,CVE-2026-84304,CVE-2026-84445 This update for distribution fixes the following issues: - CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method-Override header and bypass established access control (bsc#1277966). - CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276677). - CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279316). - CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279219). - CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS servers (bsc#1278997). - CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276677). - CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279316). - CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279219). - CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278997). ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - distribution-registry-3.1.1-160000.3.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:09:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:09:40 +0200 (CEST) Subject: SUSE-CU-2026:11196-1: Security update of suse/git Message-ID: <20260925080940.B4D9CFCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/git ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11196-1 Container Tags : suse/git:2 , suse/git:2.51 , suse/git:2.51.0 , suse/git:2.51.0-87.7 , suse/git:latest Container Release : 87.7 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/git was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libuuid1-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:10:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:10:25 +0200 (CEST) Subject: SUSE-CU-2026:11197-1: Security update of bci/bci-init Message-ID: <20260925081025.1C220FCE1@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11197-1 Container Tags : bci/bci-init:16.0 , bci/bci-init:16.0-13.22 Container Release : 13.22 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libblkid1-2.41.1-160000.5.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - container:registry.suse.com-bci-bci-base-16.0-62985aa8edf7f04db3b4310e94844af1c7f442499fe4445a61e4c6cd4df2333b-0 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:10:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:10:49 +0200 (CEST) Subject: SUSE-CU-2026:11198-1: Security update of suse/kea Message-ID: <20260925081049.AEF09FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/kea ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11198-1 Container Tags : suse/kea:3.0 , suse/kea:3.0-20.7 , suse/kea:latest Container Release : 20.7 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/kea was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:11:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:11:04 +0200 (CEST) Subject: SUSE-CU-2026:11199-1: Recommended update of suse/sles/16.0/virt-api Message-ID: <20260925081104.08AE8FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-api ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11199-1 Container Tags : suse/sles/16.0/virt-api:1.8 , suse/sles/16.0/virt-api:1.8.4 , suse/sles/16.0/virt-api:1.8.4-11.2 Container Release : 11.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/virt-api was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:11:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:11:33 +0200 (CEST) Subject: SUSE-CU-2026:11201-1: Recommended update of suse/sles/16.0/virt-controller Message-ID: <20260925081133.B5A4AFCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-controller ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11201-1 Container Tags : suse/sles/16.0/virt-controller:1.8 , suse/sles/16.0/virt-controller:1.8.4 , suse/sles/16.0/virt-controller:1.8.4-11.2 Container Release : 11.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/virt-controller was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:12:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:12:10 +0200 (CEST) Subject: SUSE-CU-2026:11203-1: Recommended update of suse/sles/16.0/virt-exportproxy Message-ID: <20260925081210.015A9FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-exportproxy ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11203-1 Container Tags : suse/sles/16.0/virt-exportproxy:1.8 , suse/sles/16.0/virt-exportproxy:1.8.4 , suse/sles/16.0/virt-exportproxy:1.8.4-11.2 Container Release : 11.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/virt-exportproxy was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:12:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:12:42 +0200 (CEST) Subject: SUSE-CU-2026:11205-1: Recommended update of suse/sles/16.0/virt-exportserver Message-ID: <20260925081242.E4584FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-exportserver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11205-1 Container Tags : suse/sles/16.0/virt-exportserver:1.8 , suse/sles/16.0/virt-exportserver:1.8.4 , suse/sles/16.0/virt-exportserver:1.8.4-11.2 Container Release : 11.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/virt-exportserver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:13:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:13:23 +0200 (CEST) Subject: SUSE-CU-2026:11207-1: Security update of suse/sles/16.0/virt-handler Message-ID: <20260925081323.EABA3FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-handler ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11207-1 Container Tags : suse/sles/16.0/virt-handler:1.8 , suse/sles/16.0/virt-handler:1.8.4 , suse/sles/16.0/virt-handler:1.8.4-11.2 Container Release : 11.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/virt-handler was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - liblastlog2-2-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - util-linux-systemd-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:14:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:14:08 +0200 (CEST) Subject: SUSE-CU-2026:11209-1: Security update of suse/sles/16.0/virt-launcher Message-ID: <20260925081408.4FF6EFCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-launcher ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11209-1 Container Tags : suse/sles/16.0/virt-launcher:1.8 , suse/sles/16.0/virt-launcher:1.8.4 , suse/sles/16.0/virt-launcher:1.8.4-11.2 Container Release : 11.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/virt-launcher was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:14:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:14:32 +0200 (CEST) Subject: SUSE-CU-2026:11211-1: Security update of suse/sles/16.0/libguestfs-tools Message-ID: <20260925081432.DBF0EFCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/libguestfs-tools ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11211-1 Container Tags : suse/sles/16.0/libguestfs-tools:1.8 , suse/sles/16.0/libguestfs-tools:1.8.4 , suse/sles/16.0/libguestfs-tools:1.8.4-11.2 Container Release : 11.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1271401 1275441 1277919 1278347 1278348 1278349 1279238 1279239 CVE-2026-12478 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 CVE-2026-85197 CVE-2026-85534 ----------------------------------------------------------------- The container suse/sles/16.0/libguestfs-tools was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1693 Released: Thu Sep 17 09:56:20 2026 Summary: Security update for libsoup Type: security Severity: moderate References: 1271401,CVE-2026-12478 This update for libsoup fixes the following issues - CVE-2026-0716: out-of-bounds read when processing a crafted unmasked frame with a payload length near `UINT64_MAX` sent by a WebSocket server (bsc#1256418). ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1729 Released: Mon Sep 21 14:40:18 2026 Summary: Security update for libsoup Type: security Severity: important References: 1279238,1279239,CVE-2026-85197,CVE-2026-85534 This update for libsoup fixes the following issues: - CVE-2026-85197: heap use-after-free in HTTP/2 `client on_data_read()` via `GOAWAY` during body upload (bsc#1279238). - CVE-2026-85534: heap buffer overflow in `SoupSession` through `on_data_source_read_callback()` via `SETTINGS` frame with crafted `INITIAL_WINDOW_SIZE` (bsc#1279239). ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - libsoup-3_0-0-3.6.6-160000.4.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:15:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:15:16 +0200 (CEST) Subject: SUSE-CU-2026:11213-1: Recommended update of suse/sles/16.0/virt-operator Message-ID: <20260925081516.10E2DFCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-operator ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11213-1 Container Tags : suse/sles/16.0/virt-operator:1.8 , suse/sles/16.0/virt-operator:1.8.4 , suse/sles/16.0/virt-operator:1.8.4-11.2 Container Release : 11.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/virt-operator was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:15:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:15:58 +0200 (CEST) Subject: SUSE-CU-2026:11215-1: Security update of suse/sles/16.0/pr-helper Message-ID: <20260925081558.22A09FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/pr-helper ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11215-1 Container Tags : suse/sles/16.0/pr-helper:1.8 , suse/sles/16.0/pr-helper:1.8.4 , suse/sles/16.0/pr-helper:1.8.4-11.2 Container Release : 11.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/pr-helper was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:16:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:16:28 +0200 (CEST) Subject: SUSE-CU-2026:11217-1: Security update of suse/sles/16.0/sidecar-shim Message-ID: <20260925081628.6C2DFFCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/sidecar-shim ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11217-1 Container Tags : suse/sles/16.0/sidecar-shim:1.8 , suse/sles/16.0/sidecar-shim:1.8.4 , suse/sles/16.0/sidecar-shim:1.8.4-11.2 Container Release : 11.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/sidecar-shim was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libuuid1-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:17:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:17:02 +0200 (CEST) Subject: SUSE-CU-2026:11219-1: Recommended update of suse/sles/16.0/virt-synchronization-controller Message-ID: <20260925081702.5C364FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-synchronization-controller ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11219-1 Container Tags : suse/sles/16.0/virt-synchronization-controller:1.8 , suse/sles/16.0/virt-synchronization-controller:1.8.4 , suse/sles/16.0/virt-synchronization-controller:1.8.4-11.2 Container Release : 11.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/virt-synchronization-controller was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:17:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:17:13 +0200 (CEST) Subject: SUSE-CU-2026:11221-1: Recommended update of suse/sles/16.0/virt-api Message-ID: <20260925081713.A742CFCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-api ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11221-1 Container Tags : suse/sles/16.0/virt-api:1.9 , suse/sles/16.0/virt-api:1.9.0 , suse/sles/16.0/virt-api:1.9.0-2.2 Container Release : 2.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/virt-api was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:17:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:17:50 +0200 (CEST) Subject: SUSE-CU-2026:11223-1: Recommended update of suse/sles/16.0/virt-controller Message-ID: <20260925081750.19435FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-controller ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11223-1 Container Tags : suse/sles/16.0/virt-controller:1.9 , suse/sles/16.0/virt-controller:1.9.0 , suse/sles/16.0/virt-controller:1.9.0-2.2 Container Release : 2.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/virt-controller was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:18:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:18:22 +0200 (CEST) Subject: SUSE-CU-2026:11225-1: Recommended update of suse/sles/16.0/virt-exportproxy Message-ID: <20260925081822.76918FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-exportproxy ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11225-1 Container Tags : suse/sles/16.0/virt-exportproxy:1.9 , suse/sles/16.0/virt-exportproxy:1.9.0 , suse/sles/16.0/virt-exportproxy:1.9.0-2.2 Container Release : 2.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/virt-exportproxy was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:18:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:18:42 +0200 (CEST) Subject: SUSE-CU-2026:11227-1: Recommended update of suse/sles/16.0/virt-exportserver Message-ID: <20260925081842.745B3FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-exportserver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11227-1 Container Tags : suse/sles/16.0/virt-exportserver:1.9 , suse/sles/16.0/virt-exportserver:1.9.0 , suse/sles/16.0/virt-exportserver:1.9.0-2.2 Container Release : 2.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/virt-exportserver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:19:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:19:05 +0200 (CEST) Subject: SUSE-CU-2026:11229-1: Security update of suse/sles/16.0/virt-handler Message-ID: <20260925081905.737EDFCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-handler ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11229-1 Container Tags : suse/sles/16.0/virt-handler:1.9 , suse/sles/16.0/virt-handler:1.9.0 , suse/sles/16.0/virt-handler:1.9.0-2.2 Container Release : 2.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/virt-handler was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - liblastlog2-2-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - util-linux-systemd-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:19:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:19:30 +0200 (CEST) Subject: SUSE-CU-2026:11231-1: Security update of suse/sles/16.0/virt-launcher Message-ID: <20260925081930.8D2B0FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-launcher ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11231-1 Container Tags : suse/sles/16.0/virt-launcher:1.9 , suse/sles/16.0/virt-launcher:1.9.0 , suse/sles/16.0/virt-launcher:1.9.0-2.2 Container Release : 2.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/virt-launcher was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:19:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:19:54 +0200 (CEST) Subject: SUSE-CU-2026:11233-1: Security update of suse/sles/16.0/libguestfs-tools Message-ID: <20260925081954.D899EFCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/libguestfs-tools ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11233-1 Container Tags : suse/sles/16.0/libguestfs-tools:1.9 , suse/sles/16.0/libguestfs-tools:1.9.0 , suse/sles/16.0/libguestfs-tools:1.9.0-2.2 Container Release : 2.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1271401 1275441 1277919 1278347 1278348 1278349 1279238 1279239 CVE-2026-12478 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 CVE-2026-85197 CVE-2026-85534 ----------------------------------------------------------------- The container suse/sles/16.0/libguestfs-tools was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1693 Released: Thu Sep 17 09:56:20 2026 Summary: Security update for libsoup Type: security Severity: moderate References: 1271401,CVE-2026-12478 This update for libsoup fixes the following issues - CVE-2026-0716: out-of-bounds read when processing a crafted unmasked frame with a payload length near `UINT64_MAX` sent by a WebSocket server (bsc#1256418). ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1729 Released: Mon Sep 21 14:40:18 2026 Summary: Security update for libsoup Type: security Severity: important References: 1279238,1279239,CVE-2026-85197,CVE-2026-85534 This update for libsoup fixes the following issues: - CVE-2026-85197: heap use-after-free in HTTP/2 `client on_data_read()` via `GOAWAY` during body upload (bsc#1279238). - CVE-2026-85534: heap buffer overflow in `SoupSession` through `on_data_source_read_callback()` via `SETTINGS` frame with crafted `INITIAL_WINDOW_SIZE` (bsc#1279239). ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - libsoup-3_0-0-3.6.6-160000.4.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:20:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:20:25 +0200 (CEST) Subject: SUSE-CU-2026:11235-1: Recommended update of suse/sles/16.0/virt-operator Message-ID: <20260925082025.2C1BDFCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-operator ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11235-1 Container Tags : suse/sles/16.0/virt-operator:1.9 , suse/sles/16.0/virt-operator:1.9.0 , suse/sles/16.0/virt-operator:1.9.0-2.2 Container Release : 2.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/virt-operator was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:20:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:20:51 +0200 (CEST) Subject: SUSE-CU-2026:11237-1: Security update of suse/sles/16.0/pr-helper Message-ID: <20260925082051.8B745FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/pr-helper ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11237-1 Container Tags : suse/sles/16.0/pr-helper:1.9 , suse/sles/16.0/pr-helper:1.9.0 , suse/sles/16.0/pr-helper:1.9.0-2.2 Container Release : 2.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/pr-helper was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:21:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:21:12 +0200 (CEST) Subject: SUSE-CU-2026:11239-1: Security update of suse/sles/16.0/sidecar-shim Message-ID: <20260925082112.5BFCBFCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/sidecar-shim ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11239-1 Container Tags : suse/sles/16.0/sidecar-shim:1.9 , suse/sles/16.0/sidecar-shim:1.9.0 , suse/sles/16.0/sidecar-shim:1.9.0-2.2 Container Release : 2.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/sles/16.0/sidecar-shim was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libuuid1-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Sep 25 08:21:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 25 Sep 2026 10:21:53 +0200 (CEST) Subject: SUSE-CU-2026:11241-1: Recommended update of suse/sles/16.0/virt-synchronization-controller Message-ID: <20260925082153.53890FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-synchronization-controller ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11241-1 Container Tags : suse/sles/16.0/virt-synchronization-controller:1.9 , suse/sles/16.0/virt-synchronization-controller:1.9.0 , suse/sles/16.0/virt-synchronization-controller:1.9.0-2.2 Container Release : 2.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/virt-synchronization-controller was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 07:11:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 09:11:04 +0200 (CEST) Subject: SUSE-IU-2026:7434-1: Recommended update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260926071104.94EEEFCF8@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7434-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.159 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.159 Severity : moderate Type : recommended References : 1271272 1280941 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) The following package changes have been done: - tar-1.35-160000.5.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-9677e36550ecda1ae23762a64bf7ad0872b46a1a8576ac06fc703313f09f4c9a-0 updated From sle-container-updates at lists.suse.com Sat Sep 26 07:22:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 09:22:05 +0200 (CEST) Subject: SUSE-IU-2026:7439-1: Recommended update of suse/sl-micro/6.2/base-os-container Message-ID: <20260926072205.CF8D2FCE1@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7439-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.85 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.85 Severity : moderate Type : recommended References : 1271272 1280941 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) The following package changes have been done: - tar-1.35-160000.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:10:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:10:45 +0200 (CEST) Subject: SUSE-CU-2026:11241-1: Recommended update of suse/sles/16.0/virt-synchronization-controller Message-ID: <20260926081045.824FAFCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-synchronization-controller ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11241-1 Container Tags : suse/sles/16.0/virt-synchronization-controller:1.9 , suse/sles/16.0/virt-synchronization-controller:1.9.0 , suse/sles/16.0/virt-synchronization-controller:1.9.0-2.2 Container Release : 2.2 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/sles/16.0/virt-synchronization-controller was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:15:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:15:52 +0200 (CEST) Subject: SUSE-CU-2026:11287-1: Recommended update of bci/bci-minimal Message-ID: <20260926081552.42872FCE1@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-minimal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11287-1 Container Tags : bci/bci-minimal:16.0 , bci/bci-minimal:16.0-18.11 Container Release : 18.11 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container bci/bci-minimal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - skelcd-EULA-BCI-20250701-160000.3.30 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:16:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:16:42 +0200 (CEST) Subject: SUSE-CU-2026:11289-1: Recommended update of suse/nginx Message-ID: <20260926081642.0D973FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/nginx ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11289-1 Container Tags : suse/nginx:1.27 , suse/nginx:1.27-21.10 , suse/nginx:latest Container Release : 21.10 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/nginx was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:17:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:17:53 +0200 (CEST) Subject: SUSE-CU-2026:11291-1: Security update of suse/pcp Message-ID: <20260926081753.8BC5CFCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/pcp ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11291-1 Container Tags : suse/pcp:6 , suse/pcp:6.2 , suse/pcp:6.2.0 , suse/pcp:6.2.0-12.25 , suse/pcp:latest Container Release : 12.25 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container suse/pcp was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - liblastlog2-2-2.41.1-160000.5.1 updated - util-linux-systemd-2.41.1-160000.5.1 updated - cpp15-15.3.0+git11272-160000.2.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:18:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:18:48 +0200 (CEST) Subject: SUSE-CU-2026:11293-1: Security update of bci/bci-sle16-kernel-module-devel Message-ID: <20260926081848.14DCAFCE1@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle16-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11293-1 Container Tags : bci/bci-sle16-kernel-module-devel:16.0 , bci/bci-sle16-kernel-module-devel:16.0-32.10 Container Release : 32.10 Severity : critical Type : security References : 1261606 1262698 1266262 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 1279863 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container bci/bci-sle16-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1722 Released: Mon Sep 21 11:58:27 2026 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1262698,1266262,1279863 This update for mozilla-nss fixes the following issues: Changes in mozilla-nss: - Fix potential crash when verifying password length in PBKDF2 (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - libasan8-16.2.0+git9497-160000.2.1 updated - libatomic1-16.2.0+git9497-160000.2.1 updated - libblkid1-2.41.1-160000.5.1 updated - libfreebl3-3.125-160000.2.1 updated - libgomp1-16.2.0+git9497-160000.2.1 updated - libhwasan0-16.2.0+git9497-160000.2.1 updated - libitm1-16.2.0+git9497-160000.2.1 updated - liblsan0-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libtsan2-16.2.0+git9497-160000.2.1 updated - libubsan1-16.2.0+git9497-160000.2.1 updated - libuuid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - mozilla-nss-certs-3.125-160000.2.1 updated - cpp15-15.3.0+git11272-160000.2.1 updated - mozilla-nss-3.125-160000.2.1 updated - libsoftokn3-3.125-160000.2.1 updated - util-linux-2.41.1-160000.5.1 updated - mozilla-nss-tools-3.125-160000.2.1 updated - gcc15-15.3.0+git11272-160000.2.1 updated - container:registry.suse.com-bci-bci-base-16.0-62985aa8edf7f04db3b4310e94844af1c7f442499fe4445a61e4c6cd4df2333b-0 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:19:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:19:23 +0200 (CEST) Subject: SUSE-CU-2026:11294-1: Recommended update of suse/stunnel Message-ID: <20260926081923.4EA51FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/stunnel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11294-1 Container Tags : suse/stunnel:5 , suse/stunnel:5.74 , suse/stunnel:5.74-18.10 , suse/stunnel:latest Container Release : 18.10 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/stunnel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:20:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:20:19 +0200 (CEST) Subject: SUSE-CU-2026:11296-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260926082019.D0596FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11296-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.127 , suse/sles/16.0/toolbox:latest Container Release : 1.127 Severity : important Type : security References : 1262263 1264713 1267631 1268572 1268573 1275096 1275594 1275732 1275859 1275860 1275915 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 The following package changes have been done: - libexpat1-2.8.4-160000.1.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:20:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:20:20 +0200 (CEST) Subject: SUSE-CU-2026:11297-1: Recommended update of suse/sles/16.0/toolbox Message-ID: <20260926082020.D2114FCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11297-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.128 , suse/sles/16.0/toolbox:latest Container Release : 1.128 Severity : moderate Type : recommended References : 1271272 1280941 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) The following package changes have been done: - tar-1.35-160000.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:20:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:20:40 +0200 (CEST) Subject: SUSE-CU-2026:11298-1: Recommended update of suse/valkey Message-ID: <20260926082040.A9390FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/valkey ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11298-1 Container Tags : suse/valkey:8 , suse/valkey:8.0 , suse/valkey:8.0.10 , suse/valkey:8.0.10-17.10 , suse/valkey:latest Container Release : 17.10 Severity : critical Type : recommended References : 1277919 ----------------------------------------------------------------- The container suse/valkey was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:22:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:22:26 +0200 (CEST) Subject: SUSE-CU-2026:11304-1: Security update of third-party/amd/amdgpu-driver Message-ID: <20260926082226.A3945FCE1@maintenance.suse.de> SUSE Container Update Advisory: third-party/amd/amdgpu-driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11304-1 Container Tags : third-party/amd/amdgpu-driver:sles-16.0-31.10 , third-party/amd/amdgpu-driver:sles-16.0-31.10-14.2 , third-party/amd/amdgpu-driver:sles-16.0-6.12.0-160000.5-default-31.10 Container Release : 14.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container third-party/amd/amdgpu-driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:22:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:22:55 +0200 (CEST) Subject: SUSE-CU-2026:11306-1: Security update of third-party/amd/amdgpu-driver Message-ID: <20260926082255.B27BFFCE1@maintenance.suse.de> SUSE Container Update Advisory: third-party/amd/amdgpu-driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11306-1 Container Tags : third-party/amd/amdgpu-driver:sles-16.0-31.20 , third-party/amd/amdgpu-driver:sles-16.0-31.20-14.2 , third-party/amd/amdgpu-driver:sles-16.0-6.12.0-160000.5-default-31.20 Container Release : 14.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container third-party/amd/amdgpu-driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:23:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:23:23 +0200 (CEST) Subject: SUSE-CU-2026:11308-1: Security update of third-party/amd/amdgpu-driver Message-ID: <20260926082323.99FC9FCE1@maintenance.suse.de> SUSE Container Update Advisory: third-party/amd/amdgpu-driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11308-1 Container Tags : third-party/amd/amdgpu-driver:sles-16.0-31.30 , third-party/amd/amdgpu-driver:sles-16.0-31.30-14.2 , third-party/amd/amdgpu-driver:sles-16.0-6.12.0-160000.5-default-31.30 Container Release : 14.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container third-party/amd/amdgpu-driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:23:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:23:37 +0200 (CEST) Subject: SUSE-CU-2026:11310-1: Security update of third-party/amd/amdgpu-driver Message-ID: <20260926082337.8586FFCE1@maintenance.suse.de> SUSE Container Update Advisory: third-party/amd/amdgpu-driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11310-1 Container Tags : third-party/amd/amdgpu-driver:sles-16.0-31.40.1 , third-party/amd/amdgpu-driver:sles-16.0-31.40.1-14.2 , third-party/amd/amdgpu-driver:sles-16.0-6.12.0-160000.5-default-31.40.1 Container Release : 14.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container third-party/amd/amdgpu-driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:23:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:23:45 +0200 (CEST) Subject: SUSE-CU-2026:11312-1: Security update of third-party/amd/amdgpu-driver Message-ID: <20260926082345.D0D09FCFE@maintenance.suse.de> SUSE Container Update Advisory: third-party/amd/amdgpu-driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11312-1 Container Tags : third-party/amd/amdgpu-driver:sles-16.0-31.50 , third-party/amd/amdgpu-driver:sles-16.0-31.50-14.2 , third-party/amd/amdgpu-driver:sles-16.0-6.12.0-160000.5-default-31.50 Container Release : 14.2 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container third-party/amd/amdgpu-driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:24:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:24:22 +0200 (CEST) Subject: SUSE-CU-2026:11314-1: Security update of third-party/nvidia/driver Message-ID: <20260926082422.1AF36FCE1@maintenance.suse.de> SUSE Container Update Advisory: third-party/nvidia/driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11314-1 Container Tags : third-party/nvidia/driver:595-6.12.0-160000.29-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.30-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.32-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.33-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.34-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.35-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.36-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.37-default-sles16.0 , third-party/nvidia/driver:595-sles16.0 , third-party/nvidia/driver:595-sles16.0-46.9 Container Release : 46.9 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container third-party/nvidia/driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - liblastlog2-2-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - util-linux-systemd-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Sat Sep 26 08:24:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 26 Sep 2026 10:24:46 +0200 (CEST) Subject: SUSE-CU-2026:11316-1: Security update of third-party/nvidia/driver Message-ID: <20260926082446.A06BDFCE1@maintenance.suse.de> SUSE Container Update Advisory: third-party/nvidia/driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11316-1 Container Tags : third-party/nvidia/driver:610-6.12.0-160000.37-default-sles16.0 , third-party/nvidia/driver:610-sles16.0 , third-party/nvidia/driver:610-sles16.0-46.9 Container Release : 46.9 Severity : critical Type : security References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container third-party/nvidia/driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - liblastlog2-2-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - util-linux-systemd-2.41.1-160000.5.1 updated From sle-container-updates at lists.suse.com Tue Sep 29 07:22:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 29 Sep 2026 09:22:18 +0200 (CEST) Subject: SUSE-IU-2026:7517-1: Recommended update of suse/sl-micro/6.2/base-os-container Message-ID: <20260929072218.77239FCE1@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7517-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.86 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.86 Severity : moderate Type : recommended References : 1279541 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1766 Released: Mon Sep 28 12:03:37 2026 Summary: Recommended update for libzypp, libsolv Type: recommended Severity: moderate References: 1279541 This update for libzypp, libsolv fixes the following issues: Changes in libzypp: version 17.38.16 (35): - This fix resolves issues in online migrations to SLES 16.1. (bsc#1279541) Changes in libsolv: bump version to 0.7.39: - improve SUSE product link dependency generation if there are multiple release packages for the same product [bsc#1279541] - fix possible segfault in the SUSE namespace dependency generation The following package changes have been done: - libsolv-tools-base-0.7.40-160000.1.1 updated - libzypp-17.38.16-160000.1.1 updated From sle-container-updates at lists.suse.com Tue Sep 29 07:51:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 29 Sep 2026 09:51:50 +0200 (CEST) Subject: SUSE-CU-2026:11322-1: Security update of suse/hpc/warewulf4-x86_64/sle-hpc-node Message-ID: <20260929075150.14C23FCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11322-1 Container Tags : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7.20.8.172 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest Container Release : 20.8.172 Severity : important Type : security References : 1215737 1218034 1218038 1238078 1248600 1262043 1262072 1265060 1265061 1265062 1265070 1265071 1265075 1265076 1269220 1269221 1269390 1272206 976992 CVE-2015-8863 CVE-2023-50246 CVE-2023-50268 CVE-2024-53427 CVE-2025-9403 CVE-2026-15588 CVE-2026-33948 CVE-2026-40164 CVE-2026-40612 CVE-2026-41256 CVE-2026-41257 CVE-2026-43894 CVE-2026-43895 CVE-2026-43896 CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54679 ----------------------------------------------------------------- The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4275-1 Released: Mon Sep 21 09:32:08 2026 Summary: Security update for jq Type: security Severity: important References: 1215737,1218034,1218038,1238078,1248600,1262043,1262072,1265060,1265061,1265062,1265070,1265071,1265075,1265076,1269220,1269221,1269390,976992,CVE-2015-8863,CVE-2023-50246,CVE-2023-50268,CVE-2024-53427,CVE-2025-9403,CVE-2026-33948,CVE-2026-40164,CVE-2026-40612,CVE-2026-41256,CVE-2026-41257,CVE-2026-43894,CVE-2026-43895,CVE-2026-43896,CVE-2026-44777,CVE-2026-47770,CVE-2026-49839,CVE-2026-54679 This update for jq fixes the following issues: Security issues fixed: - CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992). - CVE-2023-50246: improper memory handling can lead to a heap buffer overflow in `decNumberToString` (bsc#1218034). - CVE-2023-50268: stack-based buffer overflow in builds using decNumber (bsc#1218038). - CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in decNumber.c (bsc#1238078). - CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600). - CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). - CVE-2026-40164: predictable hash collisions can lead to a denial of service (bsc#1262072). - CVE-2026-40612: jv_contains recurses into nested arrays/objects with no depth limit and can cause a stack overflow (bsc#1265060). - CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f and can lead to execution of unintended programs (bsc#1265061). - CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS (bsc#1265062). - CVE-2026-43894: signed integer overflow in `decNumber` can lead to out-of-bounds memory write (bsc#1265070). - CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). - CVE-2026-43896: unbounded recursion in `jv_object_merge_recursive()` can lead to C stack exhaustion and a process crash (bsc#1265075). - CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). - CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). - CVE-2026-49839: `--rawfile` invalid-state reuse after `String too long` can lead to a heap buffer overflow (bsc#1269220). - CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer overrun on 32-bit systems (bsc#1269390). Changes for jq: Update to version 1.7.1: * Make the default background color more suitable for bright backgrounds. * Allow passing the inline jq script after --. * Fix possible uninitialised value dereference if jq_init() fails * Simplify paths/0 and paths/1. * Reject U+001F in string literals. * Remove unused nref accumulator in block_bind_library. * Remove a bunch of unused variables, and useless assignments. * main.c: Remove unused EXIT_STATUS_EXACT option. * Actually use the number correctly casted from double to int as index. * src/builtin.c: remove unnecessary jv_copy-s in type_error/type_error2. * Remove undefined behavior caught by LLVM 10 UBSAN. * Convert decnum to binary64 (double) instead of decimal64. This makes jq behave like the JSON specification suggests and more similar to other languages. * Fix memory leaks on invalid input for ltrimstr/1 and rtrimstr/1. * Fix memory leak on failed get for setpath/2. * Fix nan from json parsing also for nans with payload that start with 'n'. * Allow carriage return characters in comments. * Generate links in the man page. * Add extern C for C++. * Make object key color configurable using JQ_COLORS environment variable. * Change the default color of null to Bright Black. * Respect NO_COLOR environment variable to disable color output. * Improved --help output. Now mentions all options and nicer order. * Fix multiple issues of exit code using --exit-code/-e option. * Add --raw-output0 for NUL (zero byte) separated output. * Fix assert crash and validate JSON for --jsonarg. * Remove deprecated --argfile option. * Use decimal number literals to preserve precision. Comparison operations respects precision but arithmetic operations might truncate. * Adds new builtin pick(stream) to emit a projection of the input object or array. * Adds new builtin debug(msgs) that works like debug but applies a filter on the input before writing to stderr. * Adds new builtin scan($re; $flags). Was documented but not implemented. * Adds new builtin abs to get absolute value. This potentially allows the literal value of numbers to be preserved as length and fabs convert to float. * Allow if without else-branch. When skipped the else-branch will be . (identity). * Allow use of $binding as key in object literals. * Allow dot between chained indexes when using .['index'] * Allow dot for chained value iterator .[], .[]? * Fix try/catch catches more than it should. * Speed up and refactor some builtins, also remove scalars_or_empty/0. * Now halt and halt_error exit immediately instead of continuing to the next input. * Fix issue converting string to number after previous convert error. * Fix issue representing large numbers on some platforms causing invalid JSON output. * Fix deletion using assigning empty against arrays. * Allow keywords to be used as binding name in more places. * Allow using nan as NaN in JSON. * Expose a module's function names in modulemeta. * Fix contains/1 to handle strings with NUL. * Fix stderr/0 to output raw text without any decoration. * Fix nth/2 to emit empty on index out of range. * Fix implode to not assert and instead replace invalid unicode codepoints. * Fix indices/1 and rindex/1 in case of overlapping matches in strings. * Fix sub/3 to resolve issues involving global search-and-replace (gsub) operations. * Fix empty regular expression matches. * Fix overflow exception of the modulo operator. * Fix string multiplication by 0 (and less than 1) to emit empty string. * Fix segfault when using libjq and threads. * Fix constant folding of division and reminder with zero divisor. * Fix error/0, error/1 to throw null error. * Simpler and faster transpose. * Simple and efficient implementation of walk/1. * Remove deprecated filters leaf_paths, recurse_down. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4367-1 Released: Mon Sep 28 17:01:44 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1272206,CVE-2026-15588 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - glib2-tools-2.78.6-150600.4.41.1 updated - jq-1.7.1-150000.3.25.1 updated - libgio-2_0-0-2.78.6-150600.4.41.1 updated - libglib-2_0-0-2.78.6-150600.4.41.1 updated - libgmodule-2_0-0-2.78.6-150600.4.41.1 updated - libgobject-2_0-0-2.78.6-150600.4.41.1 updated - libjq1-1.7.1-150000.3.25.1 updated From sle-container-updates at lists.suse.com Tue Sep 29 08:05:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 29 Sep 2026 10:05:39 +0200 (CEST) Subject: SUSE-CU-2026:11323-1: Recommended update of suse/sles/16.0/toolbox Message-ID: <20260929080539.AD821FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11323-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.129 , suse/sles/16.0/toolbox:latest Container Release : 1.129 Severity : moderate Type : recommended References : 1279541 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1766 Released: Mon Sep 28 12:03:37 2026 Summary: Recommended update for libzypp, libsolv Type: recommended Severity: moderate References: 1279541 This update for libzypp, libsolv fixes the following issues: Changes in libzypp: version 17.38.16 (35): - This fix resolves issues in online migrations to SLES 16.1. (bsc#1279541) Changes in libsolv: bump version to 0.7.39: - improve SUSE product link dependency generation if there are multiple release packages for the same product [bsc#1279541] - fix possible segfault in the SUSE namespace dependency generation The following package changes have been done: - libsolv-tools-base-0.7.40-160000.1.1 updated - libzypp-17.38.16-160000.1.1 updated From sle-container-updates at lists.suse.com Wed Sep 30 07:12:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 30 Sep 2026 09:12:17 +0200 (CEST) Subject: SUSE-IU-2026:7533-1: Recommended update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260930071217.41F19FCF8@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7533-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.162 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.162 Severity : moderate Type : recommended References : 1279051 1282303 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1767 Released: Tue Sep 29 10:27:00 2026 Summary: Recommended update for selinux-policy Type: recommended Severity: moderate References: 1279051,1282303 This update for selinux-policy fixes the following issues: Changes in selinux-policy: Update to version 20250627+git405.e266baf49: * Add common criteria banner labels (bsc#1282303) * Fix corrupted formatting in files.if * Allow rsync to getattr pipes and sockes if rsync_export_all_ro is set (bsc#1279051) * Introduce files_getattr_non_auth_sockets * Introduce files_getattr_non_auth_pipes interface The following package changes have been done: - selinux-policy-20250627+git405.e266baf49-160000.1.1 updated - selinux-policy-targeted-20250627+git405.e266baf49-160000.1.1 updated From sle-container-updates at lists.suse.com Wed Sep 30 07:12:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 30 Sep 2026 09:12:18 +0200 (CEST) Subject: SUSE-IU-2026:7534-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260930071218.E6973FD07@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7534-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.164 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.164 Severity : important Type : security References : 1274723 1274726 1276892 1276946 1277247 1277262 1277921 1277922 1281297 1282326 1282509 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-8674 CVE-2026-86805 CVE-2026-94640 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). ----------------------------------------------------------------- Advisory ID: 1784 Released: Tue Sep 29 18:14:17 2026 Summary: Security update for rpcbind Type: security Severity: important References: 1282326,CVE-2026-94640 This update for rpcbind fixes the following issue: - CVE-2026-94640: unbounded memory allocation in statistics tracking allows for unauthenticated remote denial of service (bsc#1282326). The following package changes have been done: - glibc-2.40-160000.7.1 updated - glibc-gconv-modules-extra-2.40-160000.7.1 updated - glibc-locale-base-2.40-160000.7.1 updated - rpcbind-1.2.9-160000.3.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-244c4eae08ad48f0c22ff4713f9e0ede54113dfdc193df4a0a5e7e7e8cab0401-0 updated From sle-container-updates at lists.suse.com Wed Sep 30 07:18:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 30 Sep 2026 09:18:27 +0200 (CEST) Subject: SUSE-IU-2026:7535-1: Security update of suse/sl-micro/6.2/baremetal-iso-image Message-ID: <20260930071827.DCAD5FCE1@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-iso-image ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7535-1 Image Tags : suse/sl-micro/6.2/baremetal-iso-image:2.3.1 , suse/sl-micro/6.2/baremetal-iso-image:2.3.1-8.151 , suse/sl-micro/6.2/baremetal-iso-image:latest Image Release : 8.151 Severity : important Type : security References : 1274723 1274726 1276892 1276946 1277247 1277262 1277921 1277922 1281297 1282509 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-8674 CVE-2026-86805 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.40-160000.7.1 updated From sle-container-updates at lists.suse.com Wed Sep 30 07:22:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 30 Sep 2026 09:22:18 +0200 (CEST) Subject: SUSE-IU-2026:7540-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260930072218.DB3B1FCE1@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7540-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.87 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.87 Severity : important Type : security References : 1274723 1274726 1276892 1276946 1277247 1277262 1277921 1277922 1281297 1282509 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-8674 CVE-2026-86805 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.40-160000.7.1 updated - glibc-gconv-modules-extra-2.40-160000.7.1 updated - glibc-locale-base-2.40-160000.7.1 updated From sle-container-updates at lists.suse.com Wed Sep 30 07:27:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 30 Sep 2026 09:27:41 +0200 (CEST) Subject: SUSE-IU-2026:7541-1: Security update of suse/sl-micro/6.2/base-iso-image Message-ID: <20260930072741.92B08FCE1@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-iso-image ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7541-1 Image Tags : suse/sl-micro/6.2/base-iso-image:2.3.1 , suse/sl-micro/6.2/base-iso-image:2.3.1-8.80 , suse/sl-micro/6.2/base-iso-image:latest Image Release : 8.80 Severity : important Type : security References : 1274723 1274726 1276892 1276946 1277247 1277262 1277921 1277922 1281297 1282509 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-8674 CVE-2026-86805 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.40-160000.7.1 updated From sle-container-updates at lists.suse.com Wed Sep 30 07:30:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 30 Sep 2026 09:30:35 +0200 (CEST) Subject: SUSE-IU-2026:7545-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260930073035.CB1F9FCE1@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7545-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.147 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.147 Severity : important Type : security References : 1274723 1274726 1276892 1276946 1277247 1277262 1277921 1277922 1281297 1282509 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-8674 CVE-2026-86805 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.40-160000.7.1 updated - glibc-gconv-modules-extra-2.40-160000.7.1 updated - glibc-locale-base-2.40-160000.7.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-244c4eae08ad48f0c22ff4713f9e0ede54113dfdc193df4a0a5e7e7e8cab0401-0 updated From sle-container-updates at lists.suse.com Wed Sep 30 07:35:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 30 Sep 2026 09:35:20 +0200 (CEST) Subject: SUSE-IU-2026:7546-1: Security update of suse/sl-micro/6.2/kvm-iso-image Message-ID: <20260930073520.04CA5FCE1@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-iso-image ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7546-1 Image Tags : suse/sl-micro/6.2/kvm-iso-image:2.3.1 , suse/sl-micro/6.2/kvm-iso-image:2.3.1-8.134 , suse/sl-micro/6.2/kvm-iso-image:latest Image Release : 8.134 Severity : important Type : security References : 1274723 1274726 1276892 1276946 1277247 1277262 1277921 1277922 1281297 1282509 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-8674 CVE-2026-86805 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.40-160000.7.1 updated From sle-container-updates at lists.suse.com Wed Sep 30 07:39:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 30 Sep 2026 09:39:43 +0200 (CEST) Subject: SUSE-IU-2026:7553-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260930073943.57775FCE1@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7553-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.189 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.189 Severity : important Type : security References : 1274723 1274726 1276892 1276946 1277247 1277262 1277921 1277922 1281297 1282509 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-8674 CVE-2026-86805 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.40-160000.7.1 updated - glibc-gconv-modules-extra-2.40-160000.7.1 updated - glibc-locale-base-2.40-160000.7.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-08c64430b991cba524151a7f5430426f8da9d182b052354393cf0bc58a3706f3-0 updated From sle-container-updates at lists.suse.com Wed Sep 30 07:45:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 30 Sep 2026 09:45:59 +0200 (CEST) Subject: SUSE-IU-2026:7554-1: Security update of suse/sl-micro/6.2/rt-iso-image Message-ID: <20260930074559.C98D3FCE1@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-iso-image ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7554-1 Image Tags : suse/sl-micro/6.2/rt-iso-image:2.3.1 , suse/sl-micro/6.2/rt-iso-image:2.3.1-7.165 , suse/sl-micro/6.2/rt-iso-image:latest Image Release : 7.165 Severity : important Type : security References : 1274723 1274726 1276892 1276946 1277247 1277262 1277921 1277922 1281297 1282509 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-8674 CVE-2026-86805 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-iso-image was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.40-160000.7.1 updated From sle-container-updates at lists.suse.com Wed Sep 30 08:09:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 30 Sep 2026 10:09:40 +0200 (CEST) Subject: SUSE-CU-2026:11332-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260930080940.05D9BFCE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11332-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.130 , suse/sles/16.0/toolbox:latest Container Release : 1.130 Severity : important Type : security References : 1274723 1274726 1276892 1276946 1277247 1277262 1277921 1277922 1281297 1282509 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-8674 CVE-2026-86805 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-locale-base-2.40-160000.7.1 updated - glibc-locale-2.40-160000.7.1 updated - glibc-2.40-160000.7.1 updated From sle-container-updates at lists.suse.com Wed Sep 30 08:12:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 30 Sep 2026 10:12:25 +0200 (CEST) Subject: SUSE-CU-2026:11333-1: Security update of third-party/nvidia/driver Message-ID: <20260930081225.5CB92FCE1@maintenance.suse.de> SUSE Container Update Advisory: third-party/nvidia/driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11333-1 Container Tags : third-party/nvidia/driver:595-6.12.0-160000.29-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.30-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.32-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.33-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.34-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.35-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.36-default-sles16.0 , third-party/nvidia/driver:595-6.12.0-160000.37-default-sles16.0 , third-party/nvidia/driver:595-sles16.0 , third-party/nvidia/driver:595-sles16.0-46.12 Container Release : 46.12 Severity : important Type : security References : 1262263 1264713 1267631 1268572 1268573 1275096 1275441 1275594 1275732 1275859 1275860 1275915 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-72693 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 ----------------------------------------------------------------- The container third-party/nvidia/driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1748 Released: Wed Sep 23 21:47:23 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 The following package changes have been done: - libexpat1-2.8.4-160000.1.1 updated - libkbdfile1-2.7.1-160000.3.1 updated - libkfont0-2.7.1-160000.3.1 updated - libkeymap1-2.7.1-160000.3.1 updated - kbd-2.7.1-160000.3.1 updated From sle-container-updates at lists.suse.com Wed Sep 30 08:12:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 30 Sep 2026 10:12:46 +0200 (CEST) Subject: SUSE-CU-2026:11334-1: Security update of third-party/nvidia/driver Message-ID: <20260930081246.8C3EAFCE1@maintenance.suse.de> SUSE Container Update Advisory: third-party/nvidia/driver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11334-1 Container Tags : third-party/nvidia/driver:610-6.12.0-160000.37-default-sles16.0 , third-party/nvidia/driver:610-sles16.0 , third-party/nvidia/driver:610-sles16.0-46.12 Container Release : 46.12 Severity : important Type : security References : 1262263 1264713 1267631 1268572 1268573 1275096 1275441 1275594 1275732 1275859 1275860 1275915 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-72693 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 ----------------------------------------------------------------- The container third-party/nvidia/driver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1748 Released: Wed Sep 23 21:47:23 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 The following package changes have been done: - libexpat1-2.8.4-160000.1.1 updated - libkbdfile1-2.7.1-160000.3.1 updated - libkfont0-2.7.1-160000.3.1 updated - libkeymap1-2.7.1-160000.3.1 updated - kbd-2.7.1-160000.3.1 updated