SUSE-CU-2026:10570-1: Security update of suse/sle-micro/5.5/toolbox
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Wed Sep 16 07:35:37 UTC 2026
SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:10570-1
Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.196 , suse/sle-micro/5.5/toolbox:latest
Container Release : 3.12.196
Severity : important
Type : security
References : 1279584 1279588 1279593 1279595 1279782 1279783 1279784 CVE-2026-0799
CVE-2026-18238 CVE-2026-18313 CVE-2026-31911 CVE-2026-31912 CVE-2026-6244
CVE-2026-6554
-----------------------------------------------------------------
The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4195-1
Released: Tue Sep 15 16:28:18 2026
Summary: Security update for libpcap
Type: security
Severity: important
References: 1279584,1279588,1279593,1279595,1279782,1279783,1279784,CVE-2026-0799,CVE-2026-18238,CVE-2026-18313,CVE-2026-31911,CVE-2026-31912,CVE-2026-6244,CVE-2026-6554
This update for libpcap fixes the following issues:
- CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a
scratch memory register and allows for OOB access (bsc#1279782).
- CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the
immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero
(bsc#1279595).
- CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward
jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584).
- CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly
validates its headers and allows for an OOB access (bsc#1279783).
- CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ`
message received from the client and never frees the memory (bsc#1279784).
- CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode.
In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588).
- CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a
return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff
(bsc#1279593).
The following package changes have been done:
- libpcap1-1.10.1-150400.3.12.1 updated
More information about the sle-container-updates
mailing list