SUSE-CU-2026:9449-1: Security update of suse/sl-micro/6.0/rt-iso-image
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Sep 3 07:41:41 UTC 2026
SUSE Container Update Advisory: suse/sl-micro/6.0/rt-iso-image
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9449-1
Container Tags : suse/sl-micro/6.0/rt-iso-image:2.1.4 , suse/sl-micro/6.0/rt-iso-image:2.1.4-6.226 , suse/sl-micro/6.0/rt-iso-image:latest
Container Release : 6.226
Severity : moderate
Type : security
References : 1217586 1271544 1271545 1271547 1271548 CVE-2023-42366 CVE-2026-38752
CVE-2026-38753 CVE-2026-38754 CVE-2026-38755
-----------------------------------------------------------------
The container suse/sl-micro/6.0/rt-iso-image was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 875
Released: Wed Sep 2 11:40:31 2026
Summary: Security update for busybox
Type: security
Severity: moderate
References: 1217586,1271544,1271545,1271547,1271548,CVE-2023-42366,CVE-2026-38752,CVE-2026-38753,CVE-2026-38754,CVE-2026-38755
This update for busybox fixes the following issues:
- CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586).
- CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544).
- CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545).
- CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547).
- CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548).
The following package changes have been done:
- busybox-1.36.1-5.1 updated
- container:SL-Micro-rt-container-2.1.3-7.232 updated
- container:SL-Micro-container-2.1.3-6.239 updated
More information about the sle-container-updates
mailing list