SUSE-IU-2026:6630-1: Security update of suse/sl-micro/6.0/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Sep 1 07:33:27 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6630-1
Image Tags        : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.236 , suse/sl-micro/6.0/baremetal-os-container:latest
Image Release     : 6.236
Severity          : moderate
Type              : security
References        : 1221712 1274856 1274857 1274858 CVE-2026-66484 CVE-2026-66485
                        CVE-2026-66486 
-----------------------------------------------------------------

The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 871
Released:    Mon Aug 31 21:29:34 2026
Summary:     Security update for cpio
Type:        security
Severity:    moderate
References:  1221712,1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486
This update for cpio fixes the following issues:

Security issues fixed:

- CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard
  links outside intended directory via malicious tar archives (bsc#1274856).
- CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of
  service via crafted archives (bsc#1274857).
- CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for
  terminal control sequence injection via crafted archive member names (bsc#1274858).

Non security issue fixed:

- GCC 14: cpio package fails (bsc#1221712).



The following package changes have been done:

- cpio-2.15-2.1 updated
- SL-Micro-release-6.0-25.127 updated
- container:SL-Micro-base-container-2.1.3-7.200 updated


More information about the sle-container-updates mailing list