SUSE-CU-2026:9752-1: Security update of rancher/elemental-channel/sl-micro

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Sep 8 18:53:50 UTC 2026


SUSE Container Update Advisory: rancher/elemental-channel/sl-micro
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9752-1
Container Tags        : rancher/elemental-channel/sl-micro:6.0-rt , rancher/elemental-channel/sl-micro:6.0-rt-15.1
Container Release     : 15.1
Severity              : moderate
Type                  : security
References            : 1217586 1263656 1263658 1271544 1271545 1271547 1271548 CVE-2023-42366
                        CVE-2026-38752 CVE-2026-38753 CVE-2026-38754 CVE-2026-38755 CVE-2026-5435
                        CVE-2026-6238 
-----------------------------------------------------------------

The container rancher/elemental-channel/sl-micro was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 784
Released:    Mon Jul  6 15:38:37 2026
Summary:     Security update for glibc
Type:        security
Severity:    moderate
References:  1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues

- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
  (bsc#1263658).

-----------------------------------------------------------------
Advisory ID: 875
Released:    Wed Sep  2 11:40:31 2026
Summary:     Security update for busybox
Type:        security
Severity:    moderate
References:  1217586,1271544,1271545,1271547,1271548,CVE-2023-42366,CVE-2026-38752,CVE-2026-38753,CVE-2026-38754,CVE-2026-38755
This update for busybox fixes the following issues:

- CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586).
- CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544).
- CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545).
- CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547).
- CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548).


The following package changes have been done:

- glibc-2.38-14.1 updated
- busybox-1.36.1-5.1 updated
- container:suse-toolbox-image-1.0.0-9.163 updated


More information about the sle-container-updates mailing list