SUSE-IU-2026:7011-1: Security update of suse/sl-micro/6.1/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Mon Sep 14 17:21:23 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:7011-1
Image Tags        : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.172 , suse/sl-micro/6.1/baremetal-os-container:latest
Image Release     : 7.172
Severity          : moderate
Type              : security
References        : 1263704 1263705 1263707 1263708 1263709 1263710 1263711 1263712
                        1263713 1263714 1263715 1263716 1265071 1269221 CVE-2026-33845
                        CVE-2026-33846 CVE-2026-3833 CVE-2026-42009 CVE-2026-42010 CVE-2026-42011
                        CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015 CVE-2026-43895
                        CVE-2026-47770 CVE-2026-5260 CVE-2026-5419 
-----------------------------------------------------------------

The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 725
Released:    Mon Sep 14 11:42:12 2026
Summary:     Security update for jq
Type:        security
Severity:    moderate
References:  1263704,1263705,1263707,1263708,1263709,1263710,1263711,1263712,1263713,1263714,1263715,1263716,1265071,1269221,CVE-2026-33845,CVE-2026-33846,CVE-2026-3833,CVE-2026-42009,CVE-2026-42010,CVE-2026-42011,CVE-2026-42012,CVE-2026-42013,CVE-2026-42014,CVE-2026-42015,CVE-2026-43895,CVE-2026-47770,CVE-2026-5260,CVE-2026-5419
This update for jq fixes the following issues:

- CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure
  (bsc#1265071).
- CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221).


The following package changes have been done:

- libjq1-1.7.1-slfo.1.1_5.1 updated
- jq-1.7.1-slfo.1.1_5.1 updated


More information about the sle-container-updates mailing list