SUSE-CU-2026:10037-1: Security update of suse/hpc/warewulf4-x86_64/sle-hpc-node

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Sep 11 16:24:10 UTC 2026


SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:10037-1
Container Tags        : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7.20.8.154 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
Container Release     : 20.8.154
Severity              : moderate
Type                  : security
References            : 1266664 1266786 1277476 1277479 1277480 CVE-2026-13608 CVE-2026-23679
                        CVE-2026-42250 CVE-2026-80229 CVE-2026-80230 
-----------------------------------------------------------------

The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4048-1
Released:    Mon Sep  7 15:54:05 2026
Summary:     Security update for curl
Type:        security
Severity:    low
References:  1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230
This update for curl fixes the following issues:

- CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476).
- CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479).
- CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4050-1
Released:    Mon Sep  7 15:55:07 2026
Summary:     Security update for libusb-1_0
Type:        security
Severity:    moderate
References:  1266664,CVE-2026-23679
This update for libusb-1_0 fixes the following issue:

- CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a
  malformed USB configuration descriptor (bsc#1266664).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4055-1
Released:    Mon Sep  7 17:48:12 2026
Summary:     Security update for bzip2
Type:        security
Severity:    low
References:  1266786,CVE-2026-42250
This update for bzip2 fixes the following issue:

- CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a
  crash (bsc#1266786).


The following package changes have been done:

- curl-8.14.1-150700.7.26.1 updated
- libbz2-1-1.0.8-150400.3.4.1 updated
- libcurl4-8.14.1-150700.7.26.1 updated
- libusb-1_0-0-1.0.24-150400.3.6.1 updated


More information about the sle-container-updates mailing list