SUSE-IU-2026:6860-1: Security update of suse/sl-micro/6.1/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Sep 9 08:18:38 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6860-1
Image Tags        : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.168 , suse/sl-micro/6.1/baremetal-os-container:latest
Image Release     : 7.168
Severity          : important
Type              : security
References        : 1204562 1218548 1219642 1221342 1221900 1221901 1222171 1231775
                        1231776 1232553 1234383 1243005 1248660 1254324 1257010 1267696
                        1276764 1277199 1277203 1277205 1277208 1277209 1277210 1277212
                        CVE-2024-58251 CVE-2026-10805 CVE-2026-19685 
-----------------------------------------------------------------

The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 714
Released:    Tue Sep  8 11:21:17 2026
Summary:     Security update for multipath-tools
Type:        security
Severity:    moderate
References:  1204562,1234383,1243005,1248660,1254324,1277199,1277203,1277205,1277208,1277209,1277210,1277212,CVE-2024-58251
This update for multipath-tools fixes the following issues:

- Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205).
- Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210).
- SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212).
- Local Denial of Service via Blocking IPC Send Operations (bsc#1277199).
- Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209).
- DoS on multipathd socket by exhausting connections (bsc#1277203).
- Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208).
  
Changes for multipath-tools:

- Update to version 0.10.8+212+suse.3dc4ecc.
- Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155).

-----------------------------------------------------------------
Advisory ID: 713
Released:    Tue Sep  8 11:21:17 2026
Summary:     Security update for NetworkManager
Type:        security
Severity:    important
References:  1218548,1219642,1221342,1221900,1221901,1222171,1231775,1231776,1232553,1257010,1267696,1276764,CVE-2026-10805,CVE-2026-19685
This update for NetworkManager fixes the following issues:

- CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696).
- CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server
  certificate validation bypass (bsc#1276764).


The following package changes have been done:

- libnm0-1.42.6-slfo.1.1_5.1 updated
- NetworkManager-1.42.6-slfo.1.1_5.1 updated
- kpartx-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 updated
- libmpath0-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 updated
- multipath-tools-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 updated
- NetworkManager-wwan-1.42.6-slfo.1.1_5.1 updated
- container:SL-Micro-base-container-2.2.1-5.184 updated


More information about the sle-container-updates mailing list