SUSE-IU-2026:6852-1: Security update of suse/sle-micro/5.5

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Sep 8 18:46:39 UTC 2026


SUSE Image Update Advisory: suse/sle-micro/5.5
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6852-1
Image Tags        : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.109 , suse/sle-micro/5.5:latest
Image Release     : 5.8.109
Severity          : important
Type              : security
References        : 1224868 1267696 1268322 1273580 1276764 1277199 1277203 1277205
                        1277208 1277209 1277210 1277212 CVE-2026-10805 CVE-2026-16445
                        CVE-2026-19685 CVE-2026-6893 
-----------------------------------------------------------------

The container suse/sle-micro/5.5 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4063-1
Released:    Tue Sep  8 09:01:59 2026
Summary:     Security update for NetworkManager
Type:        security
Severity:    important
References:  1224868,1267696,1276764,CVE-2026-10805,CVE-2026-19685
This update for NetworkManager fixes the following issues:

- CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696).
- CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server
  certificate validation bypass (bsc#1276764).

Changes for NetworkManager:

- Add config-server subpackage (bsc#1224868).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4064-1
Released:    Tue Sep  8 09:02:39 2026
Summary:     Security update for multipath-tools
Type:        security
Severity:    moderate
References:  1277199,1277203,1277205,1277208,1277209,1277210,1277212
This update for multipath-tools fixes the following issues:

- Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205).
- Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210).
- SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212).
- Local Denial of Service via Blocking IPC Send Operations (bsc#1277199).
- Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209).
- DoS on multipathd socket by exhausting connections (bsc#1277203).
- Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208).

Changes for multipath-tools:

- Update to version 0.9.4+153+suse.eec9ef1.
- Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4079-1
Released:    Tue Sep  8 09:13:46 2026
Summary:     Security update for dracut
Type:        security
Severity:    important
References:  1268322,1273580,CVE-2026-16445,CVE-2026-6893
This update for dracut fixes the following issues:

- CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322).
- CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580).

Changes for dracut:

- Update to version 055+suse.408.g34171a9:
 * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override
 * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw
 * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname
 * fix(network-legacy): strip DHCP-supplied domain to a safe charset


The following package changes have been done:

- dracut-055+suse.408.g34171a9-150500.3.47.1 updated
- libnm0-1.38.6-150500.3.10.1 updated
- NetworkManager-1.38.6-150500.3.10.1 updated
- kpartx-0.9.4+153+suse.eec9ef1-150500.3.15.1 updated
- libmpath0-0.9.4+153+suse.eec9ef1-150500.3.15.1 updated
- multipath-tools-0.9.4+153+suse.eec9ef1-150500.3.15.1 updated
- NetworkManager-wwan-1.38.6-150500.3.10.1 updated
- container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.315 updated


More information about the sle-container-updates mailing list