SUSE-CU-2026:9766-1: Security update of rancher/seedimage-builder

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Sep 9 07:07:43 UTC 2026


SUSE Container Update Advisory: rancher/seedimage-builder
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9766-1
Container Tags        : rancher/seedimage-builder:1.6.11 , rancher/seedimage-builder:1.6.11-11.22
Container Release     : 11.22
Severity              : important
Type                  : security
References            : 1259798 1260563 1260908 1261630 1261845 1263656 1263658 1264096
                        1265224 1265384 1271045 1271980 CVE-2025-28162 CVE-2025-54518
                        CVE-2025-64505 CVE-2025-64506 CVE-2025-64720 CVE-2025-65018 CVE-2025-66293
                        CVE-2026-22695 CVE-2026-22801 CVE-2026-23243 CVE-2026-23274 CVE-2026-23317
                        CVE-2026-23437 CVE-2026-25646 CVE-2026-31406 CVE-2026-33416 CVE-2026-33636
                        CVE-2026-34757 CVE-2026-46300 CVE-2026-46333 CVE-2026-50811 CVE-2026-5435
                        CVE-2026-6238 
-----------------------------------------------------------------

The container rancher/seedimage-builder was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 810
Released:    Wed May 27 18:45:13 2026
Summary:     Optional update for xfig
Type:        optional
Severity:    moderate
References:  1271045,CVE-2026-50811
This update for xfig fixes the following issue:

- Remove dependency on update-desktop-files (jsc#PED-15248):

-----------------------------------------------------------------
Advisory ID: 841
Released:    Mon Jun  1 11:46:34 2026
Summary:     Security update for the Linux Kernel RT (Live Patch 0 for SUSE Linux Enterprise 16)
Type:        security
Severity:    important
References:  1259798,1260563,1260908,1264096,1265224,1265384,CVE-2025-28162,CVE-2025-54518,CVE-2025-64505,CVE-2025-64506,CVE-2025-64720,CVE-2025-65018,CVE-2025-66293,CVE-2026-22695,CVE-2026-22801,CVE-2026-23243,CVE-2026-23274,CVE-2026-23317,CVE-2026-25646,CVE-2026-33416,CVE-2026-33636,CVE-2026-34757,CVE-2026-46300,CVE-2026-46333

This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.5.1 fixes various security issues

The following security issues were fixed:

- CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096).
- CVE-2026-23243: RDMA/umad: Reject negative data_len in ib_umad_write (bsc#1259798).
- CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (bsc#1260908).
- CVE-2026-23317: drm/vmwgfx: Return the correct value in vmw_translate_ptr functions (bsc#1260563).
- CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224).
- CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384).

-----------------------------------------------------------------
Advisory ID: 843
Released:    Mon Jun  1 13:24:31 2026
Summary:     Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise 16)
Type:        security
Severity:    important
References:  1261630,1261845,1271980,CVE-2026-23437,CVE-2026-31406

This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.32.1 fixes various security issues

The following security issues were fixed:

- CVE-2026-23437: net: shaper: protect late read accesses to the hierarchy (bsc#1261845).
- CVE-2026-31406: xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini() (bsc#1261630).

-----------------------------------------------------------------
Advisory ID: 784
Released:    Mon Jul  6 15:38:37 2026
Summary:     Security update for glibc
Type:        security
Severity:    moderate
References:  1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues

- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
  (bsc#1263658).


The following package changes have been done:

- boost-license1_84_0-1.84.0-1.4 added
- btrfsprogs-udev-rules-6.1.3-6.19 updated
- compat-usrmerge-tools-84.87-3.1 updated
- crypto-policies-20230920.570ea89-2.1 updated
- elemental-httpfy-1.6.11-1.1 updated
- elemental-seedimage-hooks-1.6.11-1.1 updated
- file-magic-5.44-4.151 updated
- kbd-legacy-2.6.4-1.3 added
- libsemanage-conf-3.5-3.1 updated
- pkgconf-m4-1.8.0-2.205 updated
- system-user-root-20190513-2.208 updated
- filesystem-84.87-5.2 updated
- glibc-2.38-14.1 updated
- libzstd1-1.5.5-8.142 updated
- libz1-1.2.13-7.1 updated
- libxxhash0-0.8.1-2.194 updated
- libuuid1-2.39.3-8.1 updated
- liburcu8-0.14.0-2.8 updated
- libunistring5-1.1-3.1 updated
- libtextstyle0-0.21.1-6.1 updated
- libtasn1-6-4.19.0-5.1 updated
- libsmartcols1-2.39.3-8.1 updated
- libsepol2-3.5-3.1 updated
- libseccomp2-2.5.4-3.1 updated
- libpopt0-1.19-2.184 updated
- libpkgconf3-1.8.0-2.205 added
- libpcre2-8-0-10.42-2.179 updated
- libparted-fs-resize0-3.5-2.11 updated
- libnss_usrfiles2-2.27-3.1 updated
- libnghttp2-14-1.52.0-7.1 updated
- liblzo2-2-2.10-3.1 updated
- liblzma5-5.4.3-6.1 updated
- liblz4-1-1.9.4-4.1 updated
- liblua5_4-5-5.4.6-1.68 updated
- libjson-c5-0.16-3.1 updated
- libjitterentropy3-3.4.1-3.1 updated
- libip4tc2-1.8.9-4.1 added
- libgpg-error0-1.47-4.136 updated
- libgmp10-6.3.0-1.119 updated
- libgcc_s1-13.3.0+git8781-2.1 updated
- libfuse2-2.9.9-3.1 added
- libffi8-3.4.4-3.1 updated
- libexpat1-2.7.1-5.1 updated
- libeconf0-0.6.1-1.13 updated
- libcrypt1-4.4.36-1.134 updated
- libcom_err2-1.47.0-3.1 updated
- libcap2-2.69-3.1 updated
- libcap-ng0-0.8.3-4.1 updated
- libbz2-1-1.0.8-4.1 updated
- libburn4-1.5.4-1.9 updated
- libbtrfsutil1-6.1.3-6.19 updated
- libbtrfs0-6.1.3-6.19 updated
- libbrotlicommon1-1.1.0-1.6 updated
- libblkid1-2.39.3-8.1 updated
- libaudit1-3.0.9-4.1 updated
- libattr1-2.5.1-3.1 updated
- libargon2-1-20190702-3.1 added
- libalternatives1-1.2+30.a5431e9-3.1 updated
- libaio1-0.3.113-3.1 updated
- libacl1-2.3.1-3.1 updated
- fillup-1.42-3.1 updated
- dosfstools-4.2-2.9 updated
- diffutils-3.10-2.101 updated
- libpng16-16-1.6.58-1.1 updated
- libidn2-0-2.3.4-3.1 updated
- pkgconf-1.8.0-2.205 updated
- libselinux1-3.5-3.1 updated
- netcfg-11.6-4.42 updated
- libxml2-2-2.11.6-13.1 updated
- squashfs-4.6.1-3.7 updated
- libgcrypt20-1.10.3-4.1 updated
- libstdc++6-13.3.0+git8781-2.1 updated
- libp11-kit0-0.25.3-1.6 updated
- perl-base-5.38.2-5.1 updated
- libext2fs2-1.47.0-3.1 updated
- libudev1-254.27-4.1 updated
- chkstat-1600_20240206-1.8 added
- libzio1-1.08-3.1 updated
- libmagic1-5.44-4.151 updated
- libjte2-1.22-1.8 updated
- libbrotlidec1-1.1.0-1.6 updated
- libfdisk1-2.39.3-8.1 updated
- alts-1.2+30.a5431e9-3.1 updated
- libpsl5-0.21.2-3.1 updated
- sed-4.9-3.1 updated
- libsubid4-4.15.1-1.1 added
- libsemanage2-3.5-3.1 updated
- libmount1-2.39.3-8.1 updated
- findutils-4.9.0-4.1 updated
- libsystemd0-254.27-4.1 updated
- libncurses6-6.4.20240224-11.1 updated
- terminfo-base-6.4.20240224-11.1 updated
- libinih0-56-3.1 updated
- libboost_thread1_84_0-1.84.0-1.4 added
- p11-kit-0.25.3-1.6 updated
- p11-kit-tools-0.25.3-1.6 updated
- libisofs6-1.5.4-1.9 updated
- libfreetype6-2.14.3-1.1 updated
- ncurses-utils-6.4.20240224-11.1 updated
- libreadline8-8.2-2.180 updated
- libedit0-20210910.3.1-9.169 updated
- gptfdisk-1.0.9-4.1 updated
- libisoburn1-1.5.4-1.9 updated
- bash-5.2.15-3.1 updated
- bash-sh-5.2.15-3.1 updated
- xz-5.4.3-6.1 updated
- systemd-default-settings-branding-openSUSE-0.7-2.4 added
- systemd-default-settings-0.7-2.4 added
- pkgconf-pkg-config-1.8.0-2.205 updated
- login_defs-4.15.1-1.1 updated
- libdevmapper1_03-2.03.22_1.02.196-1.8 updated
- gzip-1.13-3.1 updated
- grep-3.11-4.8 updated
- gettext-runtime-0.21.1-6.1 updated
- coreutils-9.4-5.1 updated
- ALP-dummy-release-0.1-8.67 updated
- libparted2-3.5-2.11 updated
- libdevmapper-event1_03-2.03.22_1.02.196-1.8 updated
- info-7.0.3-4.1 updated
- xfsprogs-6.5.0-1.9 updated
- thin-provisioning-tools-0.9.0-2.10 updated
- systemd-rpm-macros-24-1.205 updated
- systemd-presets-common-SUSE-15-5.1 updated
- rpm-config-SUSE-20240214-1.1 updated
- rpm-4.18.0-8.1 updated
- permissions-config-1600_20240206-1.8 updated
- glibc-locale-base-2.38-14.1 updated
- e2fsprogs-1.47.0-3.1 updated
- ca-certificates-2+git20230406.2dae8b7-3.1 updated
- ca-certificates-mozilla-2.84-1.1 updated
- btrfsprogs-6.1.3-6.19 updated
- parted-3.5-2.11 updated
- liblvm2cmd2_03-2.03.22-1.8 updated
- xorriso-1.5.4-1.9 updated
- device-mapper-2.03.22_1.02.196-1.8 updated
- systemd-presets-branding-ALP-transactional-20230214-3.1 added
- permissions-1600_20240206-1.8 updated
- mtools-4.0.43-4.9 updated
- libopenssl3-3.1.4-17.1 updated
- pam-1.6.0-6.1 updated
- grub2-2.12~rc1-9.1 updated
- grub2-i386-pc-2.12~rc1-9.1 updated
- suse-module-tools-16.0.43-1.1 updated
- kmod-30-12.1 updated
- rsync-3.2.7-8.1 updated
- libkmod2-30-12.1 updated
- libcurl-mini4-8.14.1-8.1 added
- libcryptsetup12-2.6.1-5.1 updated
- util-linux-2.39.3-8.1 updated
- shadow-4.15.1-1.1 updated
- pam-config-2.11-2.1 updated
- kbd-2.6.4-1.3 updated
- curl-8.14.1-8.1 updated
- libsnapper7-0.10.5-2.10 updated
- aaa_base-84.87+git20240906.742565b-1.1 updated
- dbus-1-daemon-1.14.10-1.11 added
- dbus-1-tools-1.14.10-1.11 updated
- systemd-254.27-4.1 updated
- sysuser-shadow-3.1-2.197 updated
- dbus-1-common-1.14.10-1.11 updated
- libdbus-1-3-1.14.10-1.11 updated
- dbus-1-1.14.10-1.11 updated
- system-group-kvm-20170617-2.197 updated
- system-group-hardware-20170617-2.197 updated
- udev-254.27-4.1 updated
- snapper-0.10.5-2.10 updated
- lvm2-2.03.22-1.8 updated
- elemental-toolkit-2.1.6-1.1 updated
- container:suse-toolbox-image-1.0.0-9.163 added
- boost-license1_86_0-1.86.0-160000.2.2 removed
- container:bci-bci-base-16.0-805467666d108312e881b9628f4665193ecf336170d383c8c4781efce42503dc-0 removed
- cpio-2.15-160000.2.2 removed
- dbus-broker-36-160000.3.1 removed
- dbus-broker-block-restart-36-160000.3.1 removed
- dracut-059+suse.722.gdd9d67ff5-160000.1.1 removed
- elfutils-0.192-160000.3.1 removed
- envsubst-0.22.5-160000.2.2 removed
- file-5.46-160000.2.2 removed
- gawk-5.3.2-160000.2.2 removed
- glibc-gconv-modules-extra-2.40-160000.5.1 removed
- grub2-common-2.12-160000.6.1 removed
- krb5-1.21.3-160000.3.1 removed
- libasm1-0.192-160000.3.1 removed
- libboost_thread1_86_0-1.86.0-160000.2.2 removed
- libcurl4-8.14.1-160000.7.1 removed
- libdw1-0.192-160000.3.1 removed
- libelf1-0.192-160000.3.1 removed
- libfuse3-3-3.16.2-160000.2.2 removed
- libkbdfile1-2.7.1-160000.2.2 removed
- libkeymap1-2.7.1-160000.2.2 removed
- libkeyutils1-1.6.3-160000.3.2 removed
- libkfont0-2.7.1-160000.2.2 removed
- liblastlog2-2-2.41.1-160000.4.1 removed
- libldap-2-2.6.10+10-160000.3.1 removed
- libldap-data-2.6.10+10-160000.3.1 removed
- liblz1-1.15-160000.2.2 removed
- libmpdec4-4.0.1-160000.2.2 removed
- libmpfr6-4.2.1-160000.2.2 removed
- libpkgconf5-2.2.0-160000.2.2 removed
- libpython3_13-1_0-3.13.13-160000.1.1 removed
- libsasl2-3-2.1.28-160000.3.1 removed
- libsqlite3-0-3.53.2-160000.1.1 removed
- libssh-config-0.11.4-160000.1.1 removed
- libssh4-0.11.4-160000.1.1 removed
- libsubid5-4.17.2-160000.2.2 removed
- libverto1-0.3.2-160000.2.2 removed
- pam-extra-1.7.1-160000.4.1 removed
- permctl-1699_20250120-160000.2.2 removed
- pigz-2.8-160000.2.2 removed
- python313-base-3.13.13-160000.1.1 removed
- system-user-lp-20170617-160000.2.2 removed
- systemd-default-settings-branding-upstream-0.10-160000.2.2 removed
- systemd-presets-branding-SLE-15.1-160000.4.1 removed
- util-linux-systemd-2.41.1-160000.4.1 removed
- zstd-1.5.7-160000.2.2 removed


More information about the sle-container-updates mailing list