SUSE-IU-2026:6713-1: Security update of suse/sl-micro/6.1/base-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Sep 3 07:46:16 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6713-1
Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.179 , suse/sl-micro/6.1/base-os-container:latest
Image Release : 5.179
Severity : important
Type : security
References : 1221342 1226091 1231775 1231776 1235517 1235834 1243992 1243997
1252930 1252931 1252932 1252933 1252934 1252935 1254157 1254158
1254159 1254160 1254480 1256525 1256526 1257010 1257364 1257365
1258020 1258251 1260754 1260755 1261957 1268322 1268395 1268396
1268397 1269947 1271171 1273580 CVE-2023-49441 CVE-2025-28162
CVE-2025-28162 CVE-2025-28164 CVE-2025-54770 CVE-2025-54771 CVE-2025-61661
CVE-2025-61662 CVE-2025-61663 CVE-2025-61664 CVE-2025-64505 CVE-2025-64505
CVE-2025-64506 CVE-2025-64506 CVE-2025-64720 CVE-2025-64720 CVE-2025-65018
CVE-2025-65018 CVE-2025-66293 CVE-2025-66293 CVE-2026-16445 CVE-2026-22695
CVE-2026-22695 CVE-2026-22801 CVE-2026-22801 CVE-2026-2291 CVE-2026-25646
CVE-2026-25646 CVE-2026-33416 CVE-2026-33416 CVE-2026-33636 CVE-2026-33636
CVE-2026-34757 CVE-2026-34757 CVE-2026-49853 CVE-2026-49854 CVE-2026-49855
CVE-2026-57585 CVE-2026-6893
-----------------------------------------------------------------
The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 536
Released: Wed May 20 07:42:10 2026
Summary: Recommended update for google-guest-oslogin
Type: recommended
Severity: important
References: 1221342,1231775,1231776,1243992,1243997,1254157,1254158,1254159,1254160,1254480,1257010,CVE-2025-64505,CVE-2025-64506,CVE-2025-64720,CVE-2025-65018,CVE-2025-66293
This update for google-guest-oslogin fixes the following issues:
- Update to version 20260430.00:
* URLEncode request parameters sent to the metadata server.
- Add /var/google-sudoers.d to tmpfile config
* The /var/google-users.d directory is pre-created in the Makefile but
the google-sudoers.d is not.
- Update to version 20260227.00 (bsc#1257010)
* Fix broken cache_refresh behavior when groups are disabled.
+ Implement a binary cache for OS Login passwd entries.
This change introduces a new binary cache format for storing OS Login
passwd information. It includes:
- `OsLoginPasswdCacheWriter`: A C++ class to build and write the cache
file. It buffers user entries, sorts them, and writes them to a
temporary file before atomically renaming it.
- `oslogin_passwd_cache_reader`: A C implementation for reading from
the cache file using mmap. It provides functions compatible with
NSS modules for looking up entries by UID, name, and iterating through all entries.
- `eytzinger_layout.h`: A template function to convert a sorted vector
into an Eytzinger layout, used for the name index to improve cache locality during lookups.
- `oslogin_index_structs.h`: Defines the structures used for the UID and Name indices.
- New unit tests (`eytzinger_layout_test.cc`,
`oslogin_passwd_cache_reader_test.cc`, `round_trip_test.cc`) to
validate the cache functionality, including concurrent read access.
- The `Makefile` is updated to build and run the new tests. The `main`
function is removed from `oslogin_utils_test.cc` as `gtest_main.cc` is now linked.
+ Fix incorrect cache_refresh return value.
* Add google-guest-oslogin.conf and ggosl no var content (jsc#PED-14688)
- Update SELinux module dir as macro to allow root path move from
/var/lib/selinux to /etc/selinux (bsc#1221342)
- Update to version 20251022.00:
* Log the response body when an auth failure occurs;
it usually has helpful info in it.
- Update to version 20250821.00:
* Check policy uses adminLogin for cloud run
- from version 20250807.00:
* Extract the principal from certs when cloud_run enabled
- Update to version 20250710.00:
* Add the cloudrun support
- Update to version 20250624.00:
* Pass c-strings to logging functions
- from version 20241216.00:
* Send the correct type to SysLogErr; the clang sanitizer
dislikes the type mismatch.
* Add Eric to the owners file.
* Revert 'new client component and tests'
- from version 20241214.00:
* Remove pat from owners
- from version 20241206.00:
* Fix json include
* build: remove oslogin_sshca from binaries list
* Fix bad struct initialization pattern `= { 0 }`
* Apply 'include what you use,' fixing missing include statements broadly.
* Fix base64.h's missing includes and BSD types
* Fix a bug where very large GIDs would cause integer overflow errors
- from version 20241127.00:
* Rename openbsd.h to base64.h and move it into the src/ folder
- from version 20241126.01:
* Follow the Google style guide by using the 'local include style'
to include files from this project.
- from version 20241126.00:
* Delete oslogin_sshca binary, add it to the ignore list
- from version 20241120.00:
* OS Login agent searches for full fingerprint extension instead of equals
- from version 20241116.00:
* Log an error when user has no challenges configured
-----------------------------------------------------------------
Advisory ID: 593
Released: Fri Jun 26 11:54:16 2026
Summary: Security update for python-tornado6
Type: security
Severity: important
References: 1256525,1256526,1257364,1257365,1258020,1268395,1268396,1268397,CVE-2025-28162,CVE-2025-28164,CVE-2026-22695,CVE-2026-22801,CVE-2026-25646,CVE-2026-49853,CVE-2026-49854,CVE-2026-49855
This update for python-tornado6 fixes the following issues
- CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395).
- CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396).
- CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397).
-----------------------------------------------------------------
Advisory ID: 660
Released: Thu Aug 6 15:56:28 2026
Summary: Security update for python-msgpack
Type: security
Severity: important
References: 1260754,1260755,1269947,CVE-2026-33416,CVE-2026-33636,CVE-2026-57585
This update for python-msgpack fixes the following issue
- CVE-2026-57585: `Unpacker` reuse after a caught error can lead to an out-of-bounds read and a crash (bsc#1269947).
-----------------------------------------------------------------
Advisory ID: 680
Released: Thu Aug 20 10:24:36 2026
Summary: Recommended update for python-kiwi
Type: recommended
Severity: important
References: 1261957,1271171,CVE-2026-34757
This update for python-kiwi fixes the following issues:
- Recreate VTOC with fdasd before recreating partitions (bsc#1271171)
Changing partitions with fdasd after a parted resize leads to an internal
error because some internal structures mismatch. Work around that by
recreating the partition table initially.
-----------------------------------------------------------------
Advisory ID: 703
Released: Wed Sep 2 11:14:10 2026
Summary: Security update for dracut
Type: security
Severity: important
References: 1226091,1235517,1235834,1258251,1268322,1273580,CVE-2023-49441,CVE-2026-16445,CVE-2026-2291,CVE-2026-6893
This update for dracut fixes the following issues:
- CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322).
- CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580).
Changes for dracut:
- Update to version 059+suse.649.g0274006:
* fix(network-legacy): sanitize values written to /tmp/net.${netif}.override
* fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw
* fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname
* fix(network-legacy): strip DHCP-supplied domain to a safe charset
* fix(network-manager): ensure safe content of /tmp/dhclient.'$ifname'.dhcpopts
-----------------------------------------------------------------
Advisory ID: 702
Released: Wed Sep 2 11:15:54 2026
Summary: Security update for libpng16
Type: security
Severity: important
References: 1252930,1252931,1252932,1252933,1252934,1252935,CVE-2025-28162,CVE-2025-54770,CVE-2025-54771,CVE-2025-61661,CVE-2025-61662,CVE-2025-61663,CVE-2025-61664,CVE-2025-64505,CVE-2025-64506,CVE-2025-64720,CVE-2025-65018,CVE-2025-66293,CVE-2026-22695,CVE-2026-22801,CVE-2026-25646,CVE-2026-33416,CVE-2026-33636,CVE-2026-34757
This update for libpng16 fixes the following issues:
Changes for libpng16:
- Version update to 1.6.58 (jsc#PED-16190).
The following package changes have been done:
- libpng16-16-1.6.58-slfo.1.1_1.1 updated
- libopenssl3-3.1.4-slfo.1.1_13.1 updated
- SL-Micro-release-6.1-slfo.1.12.72 updated
- dracut-059+suse.649.g0274006-slfo.1.1_1.1 updated
- openssl-3-3.1.4-slfo.1.1_13.1 updated
- container:suse-toolbox-image-1.0.0-5.99 updated
More information about the sle-container-updates
mailing list