SUSE-CU-2026:10210-1: Security update of bci/bci-sle15-kernel-module-devel

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sun Sep 13 08:29:00 UTC 2026


SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:10210-1
Container Tags        : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-61.4 , bci/bci-sle15-kernel-module-devel:latest
Container Release     : 61.4
Severity              : important
Type                  : security
References            : 1266786 1274774 1274788 1274795 CVE-2026-42250 CVE-2026-54874
                        CVE-2026-63072 
-----------------------------------------------------------------

The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3979-1
Released:    Sun Sep  6 09:43:09 2026
Summary:     Recommended update for python-rpm-macros
Type:        recommended
Severity:    moderate
References:  
This update for python-rpm-macros fixes the following issues:

- Sync with slfo-main
- Update to version 20260821.08c5ec8:
    * Use the primary interpreter for generic python3 macros
    * Add python315 macros, remove python39
- Update to version 20260629.bcd36db:
    * don't use realpath to the interpreter binary
    * doc: add a shot documentation text for %python_site{lib,arch}_module.
    * Add initial pyproject declarative buildsystem
    * fix: handle the situation when either `name` or `meta_name` is not found
    * Consolidate site directory name normalization into %__python_sitedir_name
    * Normalize the name of the directory
    * Definitions of %python_site{lib,arch}_module macros.
- Update to version 20260601.4a231f4:
    * fix: allow function of `%pythonXX_provides` w/o /usr/bin/python3
    * Update python version handling in default-prjconf
    * Rewrite README.md to have headlines for each macro.
- Allow function of `%pythonXX_provides` even without the access to /usr/bin/python3.
- Update to version 20260317.5e02b19:
    * fix: don't double escape %{**} code.
    * Copy libalternatives binaries from buildroot to flavorbin
- Update to version 20250923.c3cfac8:
    * Remove py_setup_args macro completely.
    * Move libalternative conf creation to FLAVOR_alternative_conf
    * Update default-prjconf for primary python: python313
    * Drop python38, add python314
    * Make RPM macro expansions POSIX sh-compatible

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4041-1
Released:    Mon Sep  7 10:29:44 2026
Summary:     Security update for openssl-1_1
Type:        security
Severity:    important
References:  1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072
This update for openssl-1_1 fixes the following issues:

August 2026 release.

- CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795).
- CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4055-1
Released:    Mon Sep  7 17:48:12 2026
Summary:     Security update for bzip2
Type:        security
Severity:    low
References:  1266786,CVE-2026-42250
This update for bzip2 fixes the following issue:

- CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a
  crash (bsc#1266786).


The following package changes have been done:

- bzip2-1.0.8-150400.3.4.1 updated
- libopenssl1_1-1.1.1w-150700.11.30.1 updated
- python-rpm-macros-20260821.08c5ec8-150400.3.21.1 updated


More information about the sle-container-updates mailing list