SUSE-CU-2026:10920-1: Security update of bci/kiwi
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sat Sep 19 10:19:15 UTC 2026
SUSE Container Update Advisory: bci/kiwi
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:10920-1
Container Tags : bci/kiwi:10 , bci/kiwi:10.2 , bci/kiwi:10.2.33 , bci/kiwi:10.2.33-20.6
Container Release : 20.6
Severity : critical
Type : security
References : 1257249 1268867 1271730 1272534 1273242 1274091 1274579 1274625
1277790 CVE-2026-54369 CVE-2026-54370 CVE-2026-54371
-----------------------------------------------------------------
The container bci/kiwi was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 1639
Released: Tue Sep 8 17:42:08 2026
Summary: Security update for libzypp, zypper
Type: security
Severity: critical
References: 1257249,1271730,1272534,1273242,1274091,1274625,1277790
This update for libzypp, zypper fixes the following issues:
Security issue fixed:
- invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625).
Non security issues fixed:
- Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534).
- Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249).
- zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091).
- Zypper patch doesn't give enough details about conflicts (bsc#1277790).
Changes for libzypp:
Update to version 17.38.1:
- Prevent libgpgme from launching gpg-agents; we don't need them.
- defaultLoadSystem: Hand out the ZYpp::Ptr as return value.
- Log all solver problem rules (bsc#1277790)
The log contains the most relevant problem rule, but sometimes it
helps to know all rules associated with this problem. zypper
shows them on demand as 'detail'. The log now remembers them as
well.
- Replace popen cat/zcat with solv_xfopen for testcase loaders
(fixes #749)
- repoGpgCheck: Strictly follow the repo_gpgcheck setting
(bsc#1274625)
There's been a legacy exception for unsigned repositories which
were explicitly accepted in the past. After switching the
repo_gpgcheck from off to on, they were allowed to stay unsigned
until a first signed version was retrieved. From there on the
handling was strict.
Now the handling is strict as soon as the repo_gpgcheck turned
on. The next set of metadata retrieved must be signed.
- Iniparser: each new file starts in the unnamed section
(bsc#1272534)
- Fix hasCredentials() to require both username AND password to
be non-empty (bsc#1273242)
This avoids an unnecessary 2nd 401 response sending just the
username in case the username but no password is known. Now it
immediately fetches the credentials from disk if no password is
known.
- GPG Key hints in repoindex.xml require at least a long id to
allow auto-import (bsc#1271730)
The short Id (32bit/8byte) is not considered to be a safe
identifier for a gpg key. A long id (64bit/16byte) or even better
the full fingerprint is needed to identify the key.
- zypp: Improve Testcase Loading for MCP Tools.
Changes for zypper:
Update to version 1.14.99:
- Show solver problem details per default in not-interactive mode
(bsc#1277790)
This way they see all details when capturing zypper's output
because the (d)etail button can't be pressed in not-interactive
mode.
- Add --servicesd-dir global option to relocate
/etc/zypp/services.d (bsc#1257249)
- info: check for missing positional args before systemSetup
(bsc#1274091)
- Remove deprecated installRecommends option from zypper.conf.
The system wide default for all libzypp based applications is
defined in zypp.conf(5). It is not recommended to define this in
zypper exclusively.
-----------------------------------------------------------------
Advisory ID: 1645
Released: Wed Sep 9 10:09:38 2026
Summary: Recommended update for qemu
Type: recommended
Severity: important
References: 1274579
This update for qemu fixes the following issues:
Changes in qemu:
- Fix: Live migration does not work in 16.0/virt-operator:1.8.3-2.2 (bsc#1274579):
* target/i386: Add compatibility property for pdcm feature
- Update to version 10.0.13:
* target/riscv/tcg: sret in virtual user mode raises virtual instruction exception
* target/riscv:
+ Enforce even register constraints for Zdinx fcvt pairs
+ Reject FMV.X.W/FMV.W.X under Zfinx
+ Honor zicbo* envcfg gating in linux-user mode
+ Allow menvcfg/henvcfg LPE and SSE bits on RV32
+ Use SXL instead of MXL for read_sstatus
+ Fix PC sync in trans_sspopchk for CFI exception handling
* disas/riscv:
+ Fix typo in th.lbib format
+ Fix isa decoding of rev8
+ Fix rv32 encoding of zext.h
* hw/riscv/riscv-iommu:
+ Preserve requested perm in spa_fetch()
+ Fix U-bit check to apply only to leaf S/VS-stage PTEs
* disas/riscv:
+ Decode unsigned vector immediates as unsigned
+ Use signed type for vector immediates
+ Fix 6-bit immediate extraction
+ Fix th.srri decoding
* hw/watchdog: Add lower bound check for watchdogNumber
* tcg:
+ Export tcg_gen_ussub_i{32,64,tl}
+ Defer tb_flush when initial thread region alloc fails
+ Return success from tcg_region_alloc
+ Return success from tcg_region_alloc__locked
* target/loongarch: Check FPE before reading fcc in bceqz/bcnez
* meson: Make linker warnings non-fatal on Linux
* serial: Clear transmit retry callback on unrealize
* target/i386:
+ Decode opcode extensions group 3 /1 as TEST
+ Allow transition to virtual-8086 mode only if CPL == 0 and CPU is not in long mode
+ Fix long mode segment override prefix decoding
+ Fix incorrect decoding of EXTRQ_i
+ Clear OF, SF, and AF for fcomi/fucomi
+ Use correct type for get_float_exception_flags() values
* tcg/optimize:
+ Fix s_mask computation for shifts
+ INDEX_op_mul is commutative
* hw/elf_ops: Defend against weird elf headers
* hw/nvme: Add SPDM_SOCKET Kconfig dependency
* hw/block/pflash_cfi01: Restore ROMD mode after migration
* hw/net/rtl8139:
+ Send whole of vlan-tagged packet when doing loopback
+ Fix handling of VLAN tags on incoming short packets
* tests/qtest/ahci: Regression test for ATAPI read vs. drain
* hw/ide/atapi: Read the whole elementary transfer asynchronously
* tests/qtest/ahci: Cover raw (2352-byte) ATAPI CD reads
* tests/qtest/libqos/ahci: Support raw (2352-byte) READ CD
* tests/qtest/ide-test:
+ Cover raw (2352-byte) ATAPI CD reads
+ Add a multi-sector ATAPI DMA read test
+ Parametrize the ATAPI CD-ROM read test
-----------------------------------------------------------------
Advisory ID: 1661
Released: Fri Sep 11 13:45:57 2026
Summary: Security update for acl, attr
Type: security
Severity: important
References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371
This update for acl, attr fixes the following issue:
- CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr,
getfacl/setfacl/chacl, libacl (bsc#1268867).
Changes for acl:
- Update to 2.4.0 (jsc#PED-16501):
Major Issues Fixed:
- The libacl library functions acl_get_file(), acl_set_file(),
acl_extended_file(), and acl_delete_def_file() take a pathname argument
and follow symbolic links. When a privileged user calls one of those
functions, an attacker that controls a pathname component can replace a
file or directory with a symbolic link and redirect the operation to a
different file. This can lead to local privilege escalation.
(CVE-2026-54369, bsc#1268867)
The library functions cannot be fixed without breaking compatibility; the
described behaviour is by design.
Instead, version 2.4.0 of the acl package introduces the additional
functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and
acl_delete_def_file_at(). These functions each take a dirfd file
descriptor argument and an at_flags argument and accept the
AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to
control when to follow symbolic links. (CVE-2026-54370, bsc#1268867)
In addition, the libacl functions acl_get_fd(), acl_set_fd(), and
acl_extended_fd() functions always operate on the access ACL; the library
previously did not offer a way to operate on the default ACL of a directory
file descriptor. The new functions remove that restriction.
It will be up to each individual program to start using these new library
functions where appropriate.
- When walking directory trees, the getfacl, setfacl, chacl, and getfattr
utilities constructed the full pathname of each file in the tree and use that
pathname to access the file. When a privileged user used those utilities,
an attacker that controlled a pathname component could replace a directory with
a symbolic link and redirect the operation to a different file, leading to
a local privilege escalation. (CVE-2026-54371, bsc#1268867)
This is fixed by using directory file descriptors and operating relative to
those directory file descriptors.
- When resolving the final pathname component, the getfacl, setfacl, chacl,
getfattr, and setfattr utilities in some cases used functions that resolve
symbolic links. This includes the above mentioned libacl functions, but
also stat(), chmod(), and chown().
This is fixed by using symlink-safe functions throughout the code.
- When restoring a backup, the setfacl and setfattr utilities read the full
pathnames of files from the backup. When those pathnames were resolved,
pathname components that are symbolic links were traversed. An attacker
that controlled a pathname component could replace it with a symbolic link,
causing a privileged user to operate on a file other than the one intended.
This could lead to the same kind of local privilege escalation as discussed
before.
This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the
directory components of a pathname, but see Compatibility Notes below for
the details.
Minor Issues Fixed:
- When a symbolic link was specified on the command line but symbolic link
traversal was disabled using option -P (--physical), the getfacl and
setfacl utilities previously silently ignored the symlink. Now, an ELOOP
('Too many levels of symbolic links') error will result instead.
- acl_delete_entry() now verifies that the specified entry belongs to the
specified acl.
- Numeric uids and gids that cannot be represented in types uid_t and gid_t
are checked more carefully and invalid numbers are rejected.
- Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry
several times when the size of an ACL grows unexpectedly; previously, they
only grew the allocated buffer once before giving up.
- When passed a directory file descriptor, function perm_copy_fd() didn't
copy the default ACL from one directory to the other. It now does.
- setfacl --restore accidentally ignored leading whitespace in filenames. It
no longer does.
- setfacl --restore accidentally called chmod() when in --test mode. It no
longer does.
- When the setfattr --restore option was used multiple times, a buffer was
accessed after being freed. This no longer happens.
- When the setfattr -h (--no-dereference) option was given after --restore,
it was ignored. Now, the options can be passed in any order.
- The -h (--no-dereference) option of getfattr prevented getfattr from
recursing into 'symbolic link directories'. This is wrong. When dirlink
is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now
visit that directory. The -P (--physical) option can be used to prevent
that.
- Similarly, when a symbolic link referring to a directory was specified on
the getfacl or setfacl command line, the -R option did not cause that
directory to be visited. This has been fixed so that those directories
will now be visited. The -P (--physical) option can be used to prevent
Changes for attr:
- Update to 2.6.0 (jsc#PED-16501):
Major Issues Fixed:
- The libacl library functions acl_get_file(), acl_set_file(),
acl_extended_file(), and acl_delete_def_file() take a pathname argument
and follow symbolic links. When a privileged user calls one of those
functions, an attacker that controls a pathname component can replace a
file or directory with a symbolic link and redirect the operation to a
different file. This can lead to local privilege escalation.
(CVE-2026-54369, bsc#1268867)
The library functions cannot be fixed without breaking compatibility; the
described behaviour is by design.
Instead, version 2.4.0 of the acl package introduces the additional
functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and
acl_delete_def_file_at(). These functions each take a dirfd file
descriptor argument and an at_flags argument and accept the
AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to
control when to follow symbolic links. (CVE-2026-54370, bsc#1268867)
In addition, the libacl functions acl_get_fd(), acl_set_fd(), and
acl_extended_fd() functions always operate on the access ACL; the library
previously did not offer a way to operate on the default ACL of a directory
file descriptor. The new functions remove that restriction.
It will be up to each individual program to start using these new library
functions where appropriate.
- When walking directory trees, the getfacl, setfacl, chacl, and getfattr
utilities constructed the full pathname of each file in the tree
and use that
pathname to access the file. When a privileged user used those utilities,
an attacker that controlled a pathname component could replace a
directory with
a symbolic link and redirect the operation to a different file, leading to
a local privilege escalation. (CVE-2026-54371, bsc#1268867)
This is fixed by using directory file descriptors and operating relative to
those directory file descriptors.
- When resolving the final pathname component, the getfacl, setfacl, chacl,
getfattr, and setfattr utilities in some cases used functions that resolve
symbolic links. This includes the above mentioned libacl functions, but
also stat(), chmod(), and chown().
This is fixed by using symlink-safe functions throughout the code.
- When restoring a backup, the setfacl and setfattr utilities read the full
pathnames of files from the backup. When those pathnames were resolved,
pathname components that are symbolic links were traversed. An attacker
that controlled a pathname component could replace it with a symbolic link,
causing a privileged user to operate on a file other than the one intended.
This could lead to the same kind of local privilege escalation as discussed
before.
This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the
directory components of a pathname, but see Compatibility Notes below for
the details.
Minor Issues Fixed:
- When a symbolic link was specified on the command line but symbolic link
traversal was disabled using option -P (--physical), the getfacl and
setfacl utilities previously silently ignored the symlink. Now, an ELOOP
('Too many levels of symbolic links') error will result instead.
- acl_delete_entry() now verifies that the specified entry belongs to the
specified acl.
- Numeric uids and gids that cannot be represented in types uid_t and gid_t
are checked more carefully and invalid numbers are rejected.
- Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry
several times when the size of an ACL grows unexpectedly; previously, they
only grew the allocated buffer once before giving up.
- When passed a directory file descriptor, function perm_copy_fd() didn't
copy the default ACL from one directory to the other. It now does.
- setfacl --restore accidentally ignored leading whitespace in filenames. It
no longer does.
- setfacl --restore accidentally called chmod() when in --test mode. It no
longer does.
- When the setfattr --restore option was used multiple times, a buffer was
accessed after being freed. This no longer happens.
- When the setfattr -h (--no-dereference) option was given after --restore,
it was ignored. Now, the options can be passed in any order.
- The -h (--no-dereference) option of getfattr prevented getfattr from
recursing into 'symbolic link directories'. This is wrong. When dirlink
is a symbolic link that refers to a directory, 'getfattr -Rh
dirlink' will now
visit that directory. The -P (--physical) option can be used to prevent
that.
- Similarly, when a symbolic link referring to a directory was specified on
the getfacl or setfacl command line, the -R option did not cause that
directory to be visited. This has been fixed so that those directories
will now be visited. The -P (--physical) option can be used to prevent
The following package changes have been done:
- libattr1-2.6.0-160000.1.1 updated
- libacl1-2.4.0-160000.1.1 updated
- libzypp-17.38.15-160000.1.1 updated
- zypper-1.14.101-160000.1.1 updated
- qemu-vmsr-helper-10.0.13-160000.1.1 updated
- qemu-pr-helper-10.0.13-160000.1.1 updated
- qemu-img-10.0.13-160000.1.1 updated
- qemu-tools-10.0.13-160000.1.1 updated
- container:registry.suse.com-bci-bci-base-16.0-4e6baf5e20a374e515580441ed10778b88813915f61ee12cc28563acdfcb5552-0 updated
More information about the sle-container-updates
mailing list