SUSE-IU-2026:7085-1: Security update of suse/sl-micro/6.1/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Sep 17 08:40:22 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:7085-1
Image Tags        : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.177 , suse/sl-micro/6.1/baremetal-os-container:latest
Image Release     : 7.177
Severity          : important
Type              : security
References        : 1237409 1246281 1257065 1259240 1259611 1259734 1259735 1260026
                        1261969 1261970 1262098 1262319 1263891 1264962 1265268 1265413
                        1265578 1265580 1265581 1265582 1265583 1265584 1265585 1265586
                        1265587 1265588 1265589 1265903 1267581 1267821 1267974 1268314
                        1268977 1269066 1269788 1269959 1271192 1275441 1276223 1276226
                        CVE-2021-4189 CVE-2025-13462 CVE-2025-4330 CVE-2026-0864 CVE-2026-11940
                        CVE-2026-11972 CVE-2026-1502 CVE-2026-15308 CVE-2026-15806 CVE-2026-17084
                        CVE-2026-2297 CVE-2026-3276 CVE-2026-32792 CVE-2026-33278 CVE-2026-3446
                        CVE-2026-3644 CVE-2026-40622 CVE-2026-41292 CVE-2026-4224 CVE-2026-42534
                        CVE-2026-42923 CVE-2026-42944 CVE-2026-42959 CVE-2026-42960 CVE-2026-4360
                        CVE-2026-44390 CVE-2026-44608 CVE-2026-45186 CVE-2026-4519 CVE-2026-45409
                        CVE-2026-4786 CVE-2026-6100 CVE-2026-7210 CVE-2026-72522 CVE-2026-72693
                        CVE-2026-7774 CVE-2026-8328 CVE-2026-9669 
-----------------------------------------------------------------

The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 690
Released:    Thu Aug 27 15:46:55 2026
Summary:     Recommended update for powerpc-utils
Type:        recommended
Severity:    important
References:  1237409,1246281,1257065,1261970,1263891,1265903,1268314,CVE-2026-3446
This update for powerpc-utils fixes the following issues:

- Add timeoout for DLPAR memory remove operation (bsc#1265903, bsc#1268314):
    * drmgr: Use 30 secs timeout for each LMB removal kernel interface
- Fix description of lcpu field in the output of 'lparstat' (bsc#1257065):
    * lparstat: report virtual cpus as vcpu in non-legacy mode
- Fix adding Ethernet entries in bootlist (bsc#1246281):
    * bootlist: ensure non-nvme devices are processed with add_logical
- Bring power mode reporting inline with PAPR and ASMI
    * ppc64_cpu: bring power mode reporting inline with PAPR and ASMI
- Fix: Memory mode mismatch, When HMC Memory mode is set to Dedicated Mode
  while on LPAR it appears as Shared Mode (bsc#1237409)

-----------------------------------------------------------------
Advisory ID: 732
Released:    Wed Sep 16 11:16:27 2026
Summary:     Security update for kbd
Type:        security
Severity:    important
References:  1265578,1265580,1265581,1265582,1265583,1265584,1265585,1265586,1265587,1265588,1265589,1275441,CVE-2026-32792,CVE-2026-33278,CVE-2026-40622,CVE-2026-41292,CVE-2026-42534,CVE-2026-42923,CVE-2026-42944,CVE-2026-42959,CVE-2026-42960,CVE-2026-44390,CVE-2026-44608,CVE-2026-72693
This update for kbd fixes the following issue:

- CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows
  `passwordless` root login (bsc#1275441).

-----------------------------------------------------------------
Advisory ID: 733
Released:    Wed Sep 16 11:53:12 2026
Summary:     Security update for python311
Type:        security
Severity:    important
References:  1259240,1259611,1259734,1259735,1260026,1261969,1262098,1262319,1264962,1265268,1265413,1267581,1267821,1267974,1268977,1269066,1269788,1269959,1271192,1276223,1276226,CVE-2021-4189,CVE-2025-13462,CVE-2025-4330,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-1502,CVE-2026-15308,CVE-2026-15806,CVE-2026-17084,CVE-2026-2297,CVE-2026-3276,CVE-2026-3644,CVE-2026-4224,CVE-2026-4360,CVE-2026-45186,CVE-2026-4519,CVE-2026-45409,CVE-2026-4786,CVE-2026-6100,CVE-2026-7210,CVE-2026-72522,CVE-2026-7774,CVE-2026-8328,CVE-2026-9669
This update for python311 fixes the following issues:

- CVE-2025-13462: incorrect parsing of TarInfo header when GNU long name and type AREGTYPE are combined (bsc#1259611).
- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the
  `configparser` module is used (bsc#1269066).
- CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF (bsc#1261969).
- CVE-2026-2297: cpython: incorrectly handled hook in FileLoader can lead to validation bypass (bsc#1259240).
- CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted
  Unicode input (bsc#1267581).
- CVE-2026-3644: incomplete control character validation in http.cookies (bsc#1259734).
- CVE-2026-4224: C stack overflow when parsing XML with deeply nested DTD content models (bsc#1259735).
- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting
  hardlinks (bsc#1269959).
- CVE-2026-4519: leading dashes in URLs are accepted by the `webbrowser.open()` API and allow for web browser command
  line option injection (bsc#1260026).
- CVE-2026-4786: Incomplete mitigation of %action expansion for command injection to webbrowser.open() (bsc#1262319).
- CVE-2026-6100: Arbitrary code execution or information disclosure via use-after-free in decompression modules
  (bsc#1262098).
- CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding
  protection (bsc#1264962).
- CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory
  (bsc#1267821).
- CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268).
- CVE-2026-9669: crafted input can cause a stack buffer overflow (bsc#1267974).
- CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and
  enables arbitrary file reads and writes (bsc#1268977).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS
  (bsc#1269788).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
  (bsc#1271192).
- CVE-2026-15806: urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over another
  scheme (bsc#1276223).
- CVE-2026-17084: StringPrep algorithm considered Unicode codepoint attributes outside Unicode 3.2.0 (bsc#1276226).

Changes for python311:

- Update to 3.11.16:
 - Build
 - gh-153438: Update Windows build and installer tooling and
 documentation to use the current download URL for
 nuget.exe.
 - Library
 - gh-109638: Fix exponential time in csv.Sniffer.sniff() for
 a sample which contains many quote characters. A doubled
 quote character is now also detected in a field which
 contains the delimiter or a line break.
 - gh-98820: Fix quadratic time in csv.Sniffer.sniff() for
 a sample which contains quoted fields, in particular for
 a single column of quoted fields.
 - gh-149231: In tomllib, the number of parts in TOML keys is
 now limited.
 - gh-146083: Update bundled libexpat to version 2.7.5.
 - gh-141707: Don't change tarfile.TarInfo type from AREGTYPE
 to DIRTYPE when parsing GNU long name or link headers
 (bsc#1259611, CVE-2025-13462).
 - gh-90949: Add
 SetBillionLaughsAttackProtectionActivationThreshold() and
 SetBillionLaughsAttackProtectionMaximumAmplification() to
 xmlparser objects to tune protections against billion
 laughs attacks. Patch by Bénédikt Tran.
 - gh-100372: ssl.SSLContext.load_verify_locations() no longer
 incorrectly accepts some cases of trailing data when
 parsing DER.
 - Security
 - gh-155558: Update bundled libexpat to version 2.8.3 for the
 fix to CVE-2026-72522.
 - gh-153030: Fixed quadratic complexity in incremental
 parsing of long unterminated constructs (such as tags or
 comments) in html.parser.HTMLParser, which could be
 exploited for a denial of service (bsc#1271192,
 CVE-2026-15308).
 - gh-152674: The xml.etree.ElementTree.Element methods
 findall(), iterfind() and find() avoid quadratic behavior
 when using XPath index predicates ([1], [last()],
 [last()-N]) on XML documents with many same-tag siblings.
 - gh-152216: Update bundled libexpat to version 2.8.2.
 - gh-151987: The tarfile.TarFile.extract() method now applies
 the given filter when it extracts a link target from the
 archive as a fallback (bsc#1269959, CVE-2026-4360).
 - gh-151981: In tarfile, seeking a stream now stops when end
 of the stream is reached (bsc#1269788, CVE-2026-11972).
 - gh-151544: Modules/Setup.local is no longer used as
 a landmark to discover whether Python is running in
 a source tree, as it could potentially affect actual
 installs. The pybuilddir.txt file is now the sole indicator
 of running in a source tree.
 - gh-151558: Fixed an vulnerability in the tarfile data and
 tar extraction filters where crafted archives could create
 a symlink pointing outside the destination directory. This
 was a bypass of CVE-2025-4330 (bsc#1268977,
 CVE-2026-11940).
 - gh-150599: Fix a possible stack buffer overflow in bz2 when
 a bz2.BZ2Decompressor is reused after a decompression
 error. The decompressor now becomes unusable after libbz2
 reports an error (bsc#1267974, CVE-2026-9669).
 - gh-150743: http.client now limits the number of
 chunked-response trailer lines it will read to 100, and the
 number of interim (1xx) responses it will skip to 100.
 A malicious or broken server could previously stream
 trailer lines or 100 Continue responses forever, hanging
 the client even when a socket timeout was in use. Reported
 by @YLChen-007 via GHSA-w4q2-g22w-6fr4.
 - gh-149698: Update bundled libexpat to version 2.8.1 for the
 fix for CVE-2026-45186.
 - gh-87451: The ftplib module's undocumented ftpcp function
 no longer trusts the IPv4 address value returned from the
 source server in response to the PASV command by default,
 completing the fix for CVE-2021-4189. As with ftplib.FTP,
 the former behavior can be re-enabled by setting the
 trust_server_pasv_ipv4_address attribute on the source
 ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape
 AI for the report (bsc#1265268, CVE-2026-8328).
 - gh-149486: tarfile.data_filter() now validates link targets
 using the same normalised value that is written to disk,
 strips trailing separators from the member name when
 resolving a symlink's directory, and rejects link members
 that would replace the destination directory itself. This
 closes several path-traversal bypasses of the data
 extraction filter (bsc#1267821, CVE-2026-7774).
 - gh-149079: Fix a potential denial of service in
 unicodedata.normalize(). The canonical ordering step of
 Unicode normalization used a quadratic-time insertion sort
 for reordering combining characters, which could be
 exploited with crafted input containing many combining
 characters in non-canonical order. Replaced with
 a linear-time counting sort for long runs (bsc#1267581,
 CVE-2026-3276).
 - gh-149018: Improved protection against XML hash-flooding
 attacks in xml.parsers.expat and xml.etree.ElementTree when
 Python is compiled with libExpat 2.8.0 or later
 (bsc#1264962, CVE-2026-7210).
 - gh-149017: Update bundled libexpat to version 2.8.0.
 - gh-148808: Added buffer boundary check when using nbytes
 parameter with
 asyncio.AbstractEventLoop.sock_recvfrom_into(). Only
 relevant for Windows and the asyncio.ProactorEventLoop.
 - gh-148395: Fix a dangling input pointer in
 lzma.LZMADecompressor, and bz2.BZ2Decompressor when memory
 allocation fails with MemoryError, which could let
 a subsequent decompress() call read or write through
 a stale pointer to the already-released caller buffer
 (bsc#1262098, CVE-2026-6100).
 - gh-148169: A bypass in webbrowser allowed URLs prefixed
 with %action to pass the dash-prefix safety check
 (bsc#1262319, CVE-2026-4786).
 - gh-146581: Fix vulnerability in shutil.unpack_archive() for
 ZIP files on Windows which allowed to write files outside
 of the destination tree if the patch in the archive
 contains a Windows drive prefix. Now such invalid paths
 will be skipped. Files containing '..' in the name (like
 'foo..bar') are no longer skipped.
 - gh-146333: Fix quadratic backtracking in
 configparser.RawConfigParser option parsing regexes (OPTCRE
 and OPTCRE_NV). A crafted configuration line with many
 whitespace characters could cause excessive CPU usage.
 - gh-146211: Reject CR/LF characters in tunnel request
 headers for the HTTPConnection.set_tunnel() method
 (bsc#1261969, CVE-2026-1502).
 - gh-145986: xml.parsers.expat: Fixed a crash caused by
 unbounded C recursion when converting deeply nested XML
 content models with ElementDeclHandler(). This addresses
 CVE-2026-4224 (bsc#1259735, CVE-2026-4224).
 - gh-145599: Reject control characters in http.cookies.Morsel
 update() and js_output(). This addresses CVE-2026-3644
 (bsc#1259734, CVE-2026-3644).
 - gh-145506: Fixes CVE-2026-2297 by ensuring that
 SourcelessFileLoader uses io.open_code() when opening .pyc
 files (bsc#1259240, CVE-2026-2297).
 - gh-144370: Disallow usage of control characters in status
 in wsgiref.handlers to prevent HTTP header injections.
 Patch by Benedikt Johannes.
 - gh-143930: Reject leading dashes in URLs passed to
 webbrowser.open() (bsc#1260026, CVE-2026-4519).
 - gh-143927: Normalize all line endings (CR, CRLF, and LF) to
 LF+TAB when writing multi-line configparser values
 (bsc#1269066, CVE-2026-0864).
 - Tests
 - gh-149776: Fix test_socket on Linux kernel 7.1 and newer:
 skip UDP Lite tests if it's not supported. Patch by Victor
 Stinner.


The following package changes have been done:

- kbd-2.6.4-slfo.1.1_2.1 updated
- SL-Micro-release-6.1-slfo.1.12.76 updated
- python311-base-3.11.16-slfo.1.1_1.1 updated
- libpython3_11-1_0-3.11.16-slfo.1.1_1.1 updated
- python311-3.11.16-slfo.1.1_1.1 updated
- container:SL-Micro-base-container-2.2.1-5.190 updated


More information about the sle-container-updates mailing list