SUSE-CU-2026:10216-1: Security update of suse/sle15

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sun Sep 13 10:14:11 UTC 2026


SUSE Container Update Advisory: suse/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:10216-1
Container Tags        : bci/bci-base:15.7 , bci/bci-base:15.7-5.23.29 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.23.29 , suse/sle15:latest
Container Release     : 5.23.29
Severity              : critical
Type                  : security
References            : 1257249 1261038 1268321 1271730 1272534 1273242 1274091 1274625
                        1277790 
-----------------------------------------------------------------

The container suse/sle15 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4092-1
Released:    Tue Sep  8 18:31:37 2026
Summary:     Security update for libzypp, zypper
Type:        security
Severity:    critical
References:  1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790
This update for libzypp, zypper fixes the following issues:

Security issue fixed:

- invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625).
- hasCredentials() requires both username AND password to be non-empty (bsc#1273242).
- GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730).

Non security issues fixed:

- Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534).
- libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321).
- Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249).
- zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091).
- Zypper patch doesn't give enough details about conflicts (bsc#1277790).
- dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038).

Changes for libzypp:

- Update to version 17.38.15:

  - Prevent libgpgme from launching gpg-agents; we don't need them.
  - defaultLoadSystem: Hand out the ZYpp::Ptr as return value.
  - Replace popen cat/zcat with solv_xfopen for testcase loaders
    (fixes #749)
  - zypp: Improve Testcase Loading for MCP Tools.
  - spec: Remove useless %bcond visibility_hidden (is always ON in
    cmake)
  - zypp.conf: add solver.NoUpdateProvide (default: false) option.

Changes for zypper:

- Update to version 1.14.101.


The following package changes have been done:

- container-suseconnect-2.6.0-150700.4.97.2 updated
- libzypp-17.38.15-150700.6.16.1 updated
- zypper-1.14.101-150700.13.9.1 updated


More information about the sle-container-updates mailing list