SUSE-CU-2026:9801-1: Security update of suse/sle-micro-rancher/5.4
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Wed Sep 9 07:34:45 UTC 2026
SUSE Container Update Advisory: suse/sle-micro-rancher/5.4
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9801-1
Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.182 , suse/sle-micro-rancher/5.4:latest
Container Release : 4.5.182
Severity : important
Type : security
References : 1267696 1268322 1273580 1276764 CVE-2026-10805 CVE-2026-16445
CVE-2026-19685 CVE-2026-6893
-----------------------------------------------------------------
The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4066-1
Released: Tue Sep 8 09:03:11 2026
Summary: Security update for NetworkManager
Type: security
Severity: important
References: 1267696,1276764,CVE-2026-10805,CVE-2026-19685
This update for NetworkManager fixes the following issues:
- CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696).
- CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server
certificate validation bypass (bsc#1276764).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4078-1
Released: Tue Sep 8 09:12:54 2026
Summary: Security update for dracut
Type: security
Severity: important
References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893
This update for dracut fixes the following issues:
- CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322).
- CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580).
Changes for dracut:
- Update to version 055+suse.371.g92f67c2:
* fix(network-legacy): sanitize values written to /tmp/net.${netif}.override
* fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw
* fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname
* fix(network-legacy): strip DHCP-supplied domain to a safe charset
The following package changes have been done:
- NetworkManager-1.38.2-150400.3.9.1 updated
- dracut-mkinitrd-deprecated-055+suse.371.g92f67c2-150400.3.55.1 updated
- dracut-055+suse.371.g92f67c2-150400.3.55.1 updated
- libnm0-1.38.2-150400.3.9.1 updated
More information about the sle-container-updates
mailing list