SUSE-CU-2026:10044-1: Security update of suse/kea
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Fri Sep 11 16:27:53 UTC 2026
SUSE Container Update Advisory: suse/kea
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:10044-1
Container Tags : suse/kea:2.6 , suse/kea:2.6-79.22
Container Release : 79.22
Severity : important
Type : security
References : 1266343 1266786 1269489 1274740 1274774 1274774 1274777 1274788
1274788 1274790 1274791 1274792 1274795 1274795 1274796 1274797
1274798 1275001 1275002 1275042 1275043 1275044 1275046 1275047
1275048 1275049 1275050 1275051 1275052 1275053 1275054 1275055
1275056 1275057 1275058 1275059 1275060 1275061 1275062 1275063
1275064 1275065 1275066 1275067 1275068 1275837 1277476 1277479
1277480 CVE-2026-13608 CVE-2026-14456 CVE-2026-14457 CVE-2026-14662
CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669
CVE-2026-14670 CVE-2026-14671 CVE-2026-14672 CVE-2026-14673 CVE-2026-14676
CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-14681
CVE-2026-15741 CVE-2026-15742 CVE-2026-16238 CVE-2026-16239 CVE-2026-16241
CVE-2026-18024 CVE-2026-18408 CVE-2026-18798 CVE-2026-19385 CVE-2026-34181
CVE-2026-42250 CVE-2026-54874 CVE-2026-54874 CVE-2026-58055 CVE-2026-63072
CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076
CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 CVE-2026-75803
CVE-2026-80229 CVE-2026-80230
-----------------------------------------------------------------
The container suse/kea was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3980-1
Released: Sun Sep 6 09:44:23 2026
Summary: Recommended update for libtirpc
Type: recommended
Severity: important
References: 1274740
This update for libtirpc fixes the following issues:
- Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740):
* rpcb_clnt.c: fix memory leak in destroy_addr
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4014-1
Released: Mon Sep 7 09:36:08 2026
Summary: Security update for postgresql18
Type: security
Severity: important
References: 1275001,1275002,1275042,1275043,1275044,1275046,1275047,1275048,1275049,1275050,1275051,1275052,1275053,1275054,1275055,1275056,1275057,1275058,1275059,1275060,1275061,1275062,1275063,1275064,1275065,1275066,1275067,1275068,CVE-2026-14662,CVE-2026-14663,CVE-2026-14664,CVE-2026-14666,CVE-2026-14668,CVE-2026-14669,CVE-2026-14670,CVE-2026-14671,CVE-2026-14672,CVE-2026-14673,CVE-2026-14676,CVE-2026-14677,CVE-2026-14678,CVE-2026-14679,CVE-2026-14680,CVE-2026-14681,CVE-2026-15741,CVE-2026-15742,CVE-2026-16238,CVE-2026-16239,CVE-2026-16241,CVE-2026-18024,CVE-2026-18408,CVE-2026-19385,CVE-2026-6464,CVE-2026-6469,CVE-2026-6470,CVE-2026-6471
This update for postgresql18 fixes the following issues:
- CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046).
- CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044).
- CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043).
- CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042).
- CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001).
- CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext
(bsc#1275002).
- CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068).
- CVE-2026-14666: row security caching disregards role modifications (bsc#1275067).
- CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read
(bsc#1275066).
- CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065).
- CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064).
- CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063).
- CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence
oracle (bsc#1275062).
- CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061).
- CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060).
- CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059).
- CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058).
- CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057).
- CVE-2026-14680: type confusion via 'internal' arguments (bsc#1275056).
- CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055).
- CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054).
- CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053).
- CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052).
- CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051).
- CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050).
- CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049).
- CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql`
client (bsc#1275048).
- CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047).
Changes for postgresql18:
- Update to version 18.6:
* https://www.postgresql.org/docs/18/release-18-6.html
* https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4029-1
Released: Mon Sep 7 09:45:31 2026
Summary: Security update for nghttp2
Type: security
Severity: moderate
References: 1269489,CVE-2026-58055
This update for nghttp2 fixes the following issue:
- CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning
(bsc#1269489).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4039-1
Released: Mon Sep 7 10:29:11 2026
Summary: Security update for openssl-3
Type: security
Severity: important
References: 1266343,1274774,1274777,1274788,1274790,1274791,1274792,1274795,1274796,1274797,1274798,1275837,CVE-2026-14456,CVE-2026-14457,CVE-2026-18798,CVE-2026-34181,CVE-2026-54874,CVE-2026-63072,CVE-2026-63073,CVE-2026-63074,CVE-2026-63075,CVE-2026-63076,CVE-2026-75803
This update for openssl-3 fixes the following issues:
August 2026 release.
- CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791).
- CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792).
- CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777).
- CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343).
- CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795).
- CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788).
- CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796).
- CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797).
- CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798).
- CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790).
- CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4041-1
Released: Mon Sep 7 10:29:44 2026
Summary: Security update for openssl-1_1
Type: security
Severity: important
References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072
This update for openssl-1_1 fixes the following issues:
August 2026 release.
- CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795).
- CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4048-1
Released: Mon Sep 7 15:54:05 2026
Summary: Security update for curl
Type: security
Severity: low
References: 1277476,1277479,1277480,CVE-2026-13608,CVE-2026-80229,CVE-2026-80230
This update for curl fixes the following issues:
- CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476).
- CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479).
- CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4055-1
Released: Mon Sep 7 17:48:12 2026
Summary: Security update for bzip2
Type: security
Severity: low
References: 1266786,CVE-2026-42250
This update for bzip2 fixes the following issue:
- CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a
crash (bsc#1266786).
The following package changes have been done:
- libbz2-1-1.0.8-150400.3.4.1 updated
- libnghttp2-14-1.64.0-150700.3.6.1 updated
- libtirpc-netconfig-1.3.4-150300.3.26.1 updated
- libopenssl3-3.5.0-150700.5.50.1 updated
- libopenssl1_1-1.1.1w-150700.11.30.1 updated
- libtirpc3-1.3.4-150300.3.26.1 updated
- libcurl4-8.14.1-150700.7.26.1 updated
- libpq5-18.6-150600.13.16.1 updated
- container:suse-sle15-15.7-fc9b0275824beb9e76cff94afae273ff944ad5441726dbf9aad8e917f7c0555e-0 updated
- bash-4.4-150400.27.6.1 removed
- bash-sh-4.4-150400.27.6.1 removed
- coreutils-8.32-150400.9.12.1 removed
- filesystem-15.0-11.8.1 removed
- glibc-2.38-150600.14.52.1 removed
- libacl1-2.2.52-4.3.1 removed
- libattr1-2.4.47-2.19 removed
- libcap2-2.63-150400.3.6.1 removed
- libgcc_s1-15.3.0+git11272-150000.1.12.1 removed
- libgmp10-6.1.2-4.9.1 removed
- libncurses6-6.1-150000.5.33.1 removed
- libpcre2-8-0-10.42-150600.1.26 removed
- libreadline7-7.0-150400.27.6.1 removed
- libselinux1-3.5-150600.3.3.1 removed
- libstdc++6-15.3.0+git11272-150000.1.12.1 removed
- sles-release-15.7-150700.67.6.1 removed
- system-user-root-20190513-3.3.1 removed
- terminfo-base-6.1-150000.5.33.1 removed
More information about the sle-container-updates
mailing list