SUSE-IU-2026:6780-1: Security update of suse/sl-micro/6.2/kvm-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sat Sep 5 11:20:59 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6780-1
Image Tags        : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.108 , suse/sl-micro/6.2/kvm-os-container:latest
Image Release     : 8.108
Severity          : important
Type              : security
References        : 1237515 1254924 1259418 1259650 1261400 1268322 1271444 1273580
                        1274856 1274857 1274858 CVE-2026-16445 CVE-2026-16742 CVE-2026-29111
                        CVE-2026-40226 CVE-2026-4105 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486
                        CVE-2026-6893 
-----------------------------------------------------------------

The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 1595
Released:    Thu Sep  3 16:47:52 2026
Summary:     Security update for cpio
Type:        security
Severity:    moderate
References:  1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486
This update for cpio fixes the following issues:

- CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard
  links outside intended directory via malicious tar archives (bsc#1274856).
- CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of
  service via crafted archives (bsc#1274857).
- CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for
  terminal control sequence injection via crafted archive member names (bsc#1274858).

-----------------------------------------------------------------
Advisory ID: 1597
Released:    Thu Sep  3 18:40:31 2026
Summary:     Security update for dracut
Type:        security
Severity:    important
References:  1268322,1273580,CVE-2026-16445,CVE-2026-6893
This update for dracut fixes the following issues:

Update to version 059+suse.730.g73d3411aa.

- CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution
  within the `initramfs` (bsc#1268322).
- CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution
  within the `initramfs` during system boot (bsc#1273580).

Changes for dracut:

- Update to version 059+suse.730.g73d3411aa:
  * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override
  * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw
  * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname
  * fix(network-legacy): strip DHCP-supplied domain to a safe charset

-----------------------------------------------------------------
Advisory ID: 1602
Released:    Thu Sep  3 22:41:28 2026
Summary:     Security update for systemd
Type:        security
Severity:    moderate
References:  1237515,1254924,1259418,1259650,1261400,1271444,CVE-2026-16742,CVE-2026-29111,CVE-2026-40226,CVE-2026-4105
This update for systemd fixes the following issue:

Security issue fixed:

- CVE-2026-16742: `systemd-homed`: local privilege escalation due to missing home record signature verification on
  the authentication path (bsc#1271444).

Non security issue fixed:

- `systemd-resolved` fails to start due to write access to `tmpfs` denied (bsc#1237515).


The following package changes have been done:

- libudev1-257.13-160000.4.1 updated
- libsystemd0-257.13-160000.4.1 updated
- cpio-2.15-160000.3.1 updated
- systemd-257.13-160000.4.1 updated
- udev-257.13-160000.4.1 updated
- dracut-059+suse.730.g73d3411aa-160000.1.1 updated
- container:suse-sl-micro-6.2-base-os-container-latest-afd566f18c4eb0f88eac54fec12989fa838feff103a3f4065dd1d4af4b90c19e-0 updated


More information about the sle-container-updates mailing list