SUSE-CU-2026:10922-1: Recommended update of bci/nodejs

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sat Sep 19 10:25:14 UTC 2026


SUSE Container Update Advisory: bci/nodejs
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:10922-1
Container Tags        : bci/node:24-micro , bci/node:24.18.1-micro , bci/node:24.18.1-micro-10.9 , bci/nodejs:24-micro , bci/nodejs:24.18.1-micro , bci/nodejs:24.18.1-micro-10.9
Container Release     : 10.9
Severity              : important
Type                  : recommended
References            : 1239787 1272547 
-----------------------------------------------------------------

The container bci/nodejs was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 1647
Released:    Wed Sep  9 15:16:45 2026
Summary:     Recommended update for libssh
Type:        recommended
Severity:    moderate
References:  1272547
This update for libssh fixes the following issues:

Changes in libssh:

- Fix: libssh ignores system wide crypto policies (bsc#1272547)

-----------------------------------------------------------------
Advisory ID: 1658
Released:    Thu Sep 10 15:05:39 2026
Summary:     Recommended update for openldap2_6
Type:        recommended
Severity:    important
References:  1239787
This update for openldap2_6 fixes the following issues:

Changes in openldap2_6:

- Update to version 2.6.13+157:
    * Add export symbols related to LDAP_CONNECTIONLESS
    * Clear after free:
        + Cleaning up memory and immediately erasing the pointer's memory address
    * prevent double free:
        + Ensuring the application never releases the exact same block of memory twice
    * liblber calloc:
        + OpenLDAP's specialized memory allocator that automatically wipes memory clean
    * Fix: openldap2_5: segfault when try to add bad escaped regex (bsc#1239787):
        + prevent double free in info rewrite
    * Set default ldapi path to be consistent for SUSE
    * guide.html file cherry-picked from
      https://src.opensuse.org/jengelh/openldap2/src/branch/master/openldap-2.6.8.tgz
    * Use OpenSSL API to verify host
    * Change malloc to use calloc to prevent memory reuse corruption
    * Return to release engineering


The following package changes have been done:

- libldap-data-2.6.13+157-160000.1.1 updated
- libssh-config-0.11.5-160000.2.1 updated
- libldap-2-2.6.13+157-160000.1.1 updated
- libssh4-0.11.5-160000.2.1 updated
- container:bci-bci-base-16.0-4e6baf5e20a374e515580441ed10778b88813915f61ee12cc28563acdfcb5552-0 updated
- container:registry.suse.com-bci-bci-micro-16.0-41cf07d1bfacf3030652a17bddc907f8c6cdb73e47efc51e5d3ab73a50ffcb8b-0 updated


More information about the sle-container-updates mailing list