SUSE-IU-2026:6793-1: Security update of suse/sl-micro/6.2/rt-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sat Sep 5 11:27:54 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6793-1
Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.141 , suse/sl-micro/6.2/rt-os-container:latest
Image Release : 7.141
Severity : important
Type : security
References : 1237515 1254924 1259418 1259650 1261400 1268322 1271444 1273580
1274856 1274857 1274858 CVE-2026-16445 CVE-2026-16742 CVE-2026-29111
CVE-2026-40226 CVE-2026-4105 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486
CVE-2026-6893
-----------------------------------------------------------------
The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 1595
Released: Thu Sep 3 16:47:52 2026
Summary: Security update for cpio
Type: security
Severity: moderate
References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486
This update for cpio fixes the following issues:
- CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard
links outside intended directory via malicious tar archives (bsc#1274856).
- CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of
service via crafted archives (bsc#1274857).
- CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for
terminal control sequence injection via crafted archive member names (bsc#1274858).
-----------------------------------------------------------------
Advisory ID: 1597
Released: Thu Sep 3 18:40:31 2026
Summary: Security update for dracut
Type: security
Severity: important
References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893
This update for dracut fixes the following issues:
Update to version 059+suse.730.g73d3411aa.
- CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution
within the `initramfs` (bsc#1268322).
- CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution
within the `initramfs` during system boot (bsc#1273580).
Changes for dracut:
- Update to version 059+suse.730.g73d3411aa:
* fix(network-legacy): sanitize values written to /tmp/net.${netif}.override
* fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw
* fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname
* fix(network-legacy): strip DHCP-supplied domain to a safe charset
-----------------------------------------------------------------
Advisory ID: 1602
Released: Thu Sep 3 22:41:28 2026
Summary: Security update for systemd
Type: security
Severity: moderate
References: 1237515,1254924,1259418,1259650,1261400,1271444,CVE-2026-16742,CVE-2026-29111,CVE-2026-40226,CVE-2026-4105
This update for systemd fixes the following issue:
Security issue fixed:
- CVE-2026-16742: `systemd-homed`: local privilege escalation due to missing home record signature verification on
the authentication path (bsc#1271444).
Non security issue fixed:
- `systemd-resolved` fails to start due to write access to `tmpfs` denied (bsc#1237515).
The following package changes have been done:
- libudev1-257.13-160000.4.1 updated
- libsystemd0-257.13-160000.4.1 updated
- cpio-2.15-160000.3.1 updated
- systemd-257.13-160000.4.1 updated
- udev-257.13-160000.4.1 updated
- dracut-059+suse.730.g73d3411aa-160000.1.1 updated
- container:suse-sl-micro-6.2-baremetal-os-container-latest-5326c78245c2601103244f0121f243b17dae6b17bf5661486c34b7b469de7b6a-0 updated
More information about the sle-container-updates
mailing list