SUSE-CU-2026:9715-1: Security update of suse/manager/4.3/proxy-httpd
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Mon Sep 7 09:20:24 UTC 2026
SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9715-1
Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.27 , suse/manager/4.3/proxy-httpd:latest
Container Release : 9.82.27
Severity : critical
Type : security
References : 1207866 1274235 1274237 1274850 1274852 1274854 CVE-2022-25147
CVE-2025-49506 CVE-2026-32327 CVE-2026-34191 CVE-2026-34501 CVE-2026-34502
-----------------------------------------------------------------
The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3937-1
Released: Thu Sep 3 09:28:23 2026
Summary: Security update for apr-util
Type: security
Severity: critical
References: 1207866,1274235,1274237,1274850,1274852,1274854,CVE-2022-25147,CVE-2025-49506,CVE-2026-32327,CVE-2026-34191,CVE-2026-34501,CVE-2026-34502
This update for apr-util fixes the following issues:
- CVE-2022-25147: buffer overflow possible with specially crafted input (bsc#1207866).
- CVE-2025-49506: leaking content via side channel timing attack (bsc#1274237).
- CVE-2026-32327: XML stack recursion crash (bsc#1274235).
- CVE-2026-34191: SQL Injection via apr_dbd_oracle (bsc#1274850).
- CVE-2026-34501: heap buffer overflow in redis client (bsc#1274852).
- CVE-2026-34502: heap buffer overflow in APR memcached client (bsc#1274854).
The following package changes have been done:
- libapr-util1-1.6.1-150300.18.8.1 updated
More information about the sle-container-updates
mailing list