SUSE-IU-2026:6866-1: Security update of suse/sl-micro/6.2/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Sep 9 08:40:16 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6866-1
Image Tags        : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.129 , suse/sl-micro/6.2/baremetal-os-container:latest
Image Release     : 8.129
Severity          : moderate
Type              : security
References        : 1266664 1266667 1277199 1277203 1277205 1277208 1277209 1277210
                        1277212 CVE-2026-23679 CVE-2026-47104 
-----------------------------------------------------------------

The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 1631
Released:    Mon Sep  7 12:17:39 2026
Summary:     Security update for libusb-1_0
Type:        security
Severity:    moderate
References:  1266664,1266667,CVE-2026-23679,CVE-2026-47104
This update for libusb-1_0 fixes the following issues:

- CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a
  malformed USB configuration descriptor (bsc#1266664).
- CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service
  via a malformed USB descriptor (bsc#1266667).

-----------------------------------------------------------------
Advisory ID: 1633
Released:    Mon Sep  7 17:03:57 2026
Summary:     Security update for multipath-tools
Type:        security
Severity:    moderate
References:  1277199,1277203,1277205,1277208,1277209,1277210,1277212
This update for multipath-tools fixes the following issues:

- Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205).
- Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210).
- SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212).
- Local Denial of Service via Blocking IPC Send Operations (bsc#1277199).
- Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209).
- DoS on multipathd socket by exhausting connections (bsc#1277203).
- Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208).

Changes for multipath-tools:

- Update to version 0.12.4+278+suse.9cf9c5c.
- Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155).


The following package changes have been done:

- libusb-1_0-0-1.0.28-160000.3.1 updated
- kpartx-0.12.4+278+suse.9cf9c5c-160000.1.1 updated
- libmpath0-0.12.4+278+suse.9cf9c5c-160000.1.1 updated
- multipath-tools-0.12.4+278+suse.9cf9c5c-160000.1.1 updated
- container:suse-sl-micro-6.2-base-os-container-latest-d65530abf75418cd43c2da7dfcc5842e3fec2b7be34cbdfdf42ab4a8b927e9e1-0 updated


More information about the sle-container-updates mailing list