SUSE-CU-2026:9905-1: Security update of suse/ltss/sle15.6/sle15
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Sep 10 10:54:56 UTC 2026
SUSE Container Update Advisory: suse/ltss/sle15.6/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9905-1
Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.91 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.91 , suse/ltss/sle15.6/sle15:latest
Container Release : 5.91
Severity : critical
Type : security
References : 1242233 1243830 1257249 1261038 1268321 1271730 1272534 1273242
1274091 1274625 1277267 1277790
-----------------------------------------------------------------
The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4112-1
Released: Wed Sep 9 18:17:10 2026
Summary: Security update for libzypp, zypper
Type: security
Severity: critical
References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790
This update for libzypp, zypper fixes the following issues:
Security issue fixed:
- invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625).
- hasCredentials() requires both username AND password to be non-empty (bsc#1273242).
- GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730).
Non security issues fixed:
- Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534).
- libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321).
- Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249).
- zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091).
- Zypper patch doesn't give enough details about conflicts (bsc#1277790).
- dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038).
Changes for libzypp:
- Update to version 17.38.15:
- Prevent libgpgme from launching gpg-agents; we don't need them.
- defaultLoadSystem: Hand out the ZYpp::Ptr as return value.
- Replace popen cat/zcat with solv_xfopen for testcase loaders
(fixes #749)
- zypp: Improve Testcase Loading for MCP Tools.
- spec: Remove useless %bcond visibility_hidden (is always ON in
cmake)
- zypp.conf: add solver.NoUpdateProvide (default: false) option.
Changes for zypper:
- Update to version 1.14.101.
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:4116-1
Released: Wed Sep 9 21:41:52 2026
Summary: Recommended update for crypto-policies
Type: recommended
Severity: important
References: 1242233,1243830,1277267
This update for crypto-policies fixes the following issues:
- Revert the previous change since the syntax is not understood in
this crypto-policies version. (bsc#1243830, bsc#1242233, bsc#1277267)
The following package changes have been done:
- crypto-policies-20230920.570ea89-150600.3.22.1 updated
- libzypp-17.38.15-150600.3.95.1 updated
- zypper-1.14.101-150600.10.58.1 updated
More information about the sle-container-updates
mailing list