SUSE-IU-2026:6630-1: Security update of suse/sl-micro/6.0/baremetal-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Tue Sep 1 07:33:27 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6630-1
Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.236 , suse/sl-micro/6.0/baremetal-os-container:latest
Image Release : 6.236
Severity : moderate
Type : security
References : 1221712 1274856 1274857 1274858 CVE-2026-66484 CVE-2026-66485
CVE-2026-66486
-----------------------------------------------------------------
The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 871
Released: Mon Aug 31 21:29:34 2026
Summary: Security update for cpio
Type: security
Severity: moderate
References: 1221712,1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486
This update for cpio fixes the following issues:
Security issues fixed:
- CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard
links outside intended directory via malicious tar archives (bsc#1274856).
- CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of
service via crafted archives (bsc#1274857).
- CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for
terminal control sequence injection via crafted archive member names (bsc#1274858).
Non security issue fixed:
- GCC 14: cpio package fails (bsc#1221712).
The following package changes have been done:
- cpio-2.15-2.1 updated
- SL-Micro-release-6.0-25.127 updated
- container:SL-Micro-base-container-2.1.3-7.200 updated
More information about the sle-container-updates
mailing list