SUSE-CU-2026:10404-1: Security update of trento/trento-wanda
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sun Sep 13 11:02:39 UTC 2026
SUSE Container Update Advisory: trento/trento-wanda
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:10404-1
Container Tags : trento/trento-wanda:2.1.0 , trento/trento-wanda:2.1.0-build1.35.33 , trento/trento-wanda:latest
Container Release : 1.35.33
Severity : important
Type : security
References : 1242233 1243830 1252306 1253043 1257463 1260446 1261400 1261982
1261983 1262305 1263656 1263658 1267644 1267647 1271712 1274774
1274788 1274795 1277267 CVE-2026-40226 CVE-2026-5435 CVE-2026-54874
CVE-2026-6238 CVE-2026-63072
-----------------------------------------------------------------
The container trento/trento-wanda was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3030-1
Released: Wed Jul 15 11:53:06 2026
Summary: Security update for glibc
Type: security
Severity: moderate
References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues
- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
(bsc#1263658).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released: Fri Jul 17 22:18:41 2026
Summary: Recommended update for gcc15
Type: recommended
Severity: moderate
References: 1252306,1253043,1257463
This update for gcc15 fixes the following issues:
- Update to GCC 15.3 release
- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion
from flags to build D target library files. [jsc#PED-15601]
- Remove loongarch64 from quadmath_arch. On LoongArch long double
is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
even when not available at build time. [bsc#1253043]
- Backport fix that cures a miscompile of libgo on arm. [bsc#1252306]
- Check availability of builtins at expand time
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3244-1
Released: Fri Jul 24 15:11:25 2026
Summary: Security update for systemd
Type: security
Severity: moderate
References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226
This update for systemd fixes the following issues
Security issues fixed:
- CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400).
Other updates and bugfixes:
- Fix soft reboot not restarting user services with default.target (bsc#1262305).
- Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644).
- Import commit 429043ca9a (bsc#1261982 bsc#1261983).
- Import commit 58e5d2e21e (bsc#1261982).
- Import commit 4bd91117cc (bsc#1261983).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3515-1
Released: Thu Aug 6 13:08:56 2026
Summary: Security update for openssl-1_1
Type: security
Severity: important
References: 1271712
This update for openssl-1_1 fixes the following issue
- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
(bsc#1271712).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3878-1
Released: Mon Aug 31 11:12:55 2026
Summary: Security update for openssl-1_1
Type: security
Severity: important
References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072
This update for openssl-1_1 fixes the following issues:
- CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795).
- CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788).
Changes for openssl-1_1:
- August 2026 release (bsc#1274774)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3926-1
Released: Thu Sep 3 02:04:11 2026
Summary: Recommended update for crypto-policies
Type: recommended
Severity: important
References: 1242233,1243830,1277267
This update for crypto-policies fixes the following issues:
- Allow openssl to load when using the DEFAULT policy, and also
other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267)
The following package changes have been done:
- crypto-policies-20230920.570ea89-150600.3.19.1 updated
- glibc-2.38-150600.14.52.1 updated
- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- libgcrypt20-1.11.0-150700.5.10.1 updated
- libopenssl1_1-1.1.1w-150600.5.38.1 updated
- libsystemd0-254.27-150600.4.71.2 updated
- container:registry.suse.com-bci-bci-base-15.7-2cca9950fcbe26e5f70a49f9e6f035e27fd7bad46e0133996b8c557bcafe453b-0 updated
More information about the sle-container-updates
mailing list