SUSE-CU-2026:10946-1: Security update of trento/trento-wanda
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sat Sep 19 10:32:14 UTC 2026
SUSE Container Update Advisory: trento/trento-wanda
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:10946-1
Container Tags : trento/trento-wanda:2.1.0 , trento/trento-wanda:2.1.0-build1.35.43 , trento/trento-wanda:latest
Container Release : 1.35.43
Severity : important
Type : security
References : 1212476 1221107 1227370 1236165 1239009 1242233 1243830 1246697
1246934 1250232 1250782 1250782 1252696 1253025 1256834 1256835
1256836 1256837 1256838 1256839 1256840 1258311 1259825 1260441
1260442 1260443 1260444 1261678 1262315 1262684 1266340 1266341
1266342 1266349 1266357 1271712 1274774 1274788 1274795 1275660
CVE-2024-2236 CVE-2025-68160 CVE-2025-69418 CVE-2025-69419 CVE-2025-69420
CVE-2025-69421 CVE-2025-9230 CVE-2026-22795 CVE-2026-22796 CVE-2026-28387
CVE-2026-28388 CVE-2026-28389 CVE-2026-28390 CVE-2026-31789 CVE-2026-34180
CVE-2026-41989 CVE-2026-42766 CVE-2026-45447 CVE-2026-54874 CVE-2026-63072
CVE-2026-7383 CVE-2026-9076
-----------------------------------------------------------------
The container trento/trento-wanda was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:2719-1
Released: Thu Aug 7 05:38:32 2025
Summary: Security update for libgcrypt
Type: security
Severity: moderate
References: 1221107,1246934,CVE-2024-2236
This update for libgcrypt fixes the following issues:
- CVE-2024-2236: timing-based side-channel flaw in RSA implementation can lead to decryption of RSA ciphertexts (bsc#1221107).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:2890-1
Released: Tue Aug 19 09:54:32 2025
Summary: Recommended update for openssl-1_1
Type: recommended
Severity: moderate
References: 1246697
This update for openssl-1_1 fixes the following issues:
- FIPS: Use the NID_X9_62_prime256v1 curve in ECDSA KAT test
instead of NID_secp256k1. [bsc#1246697]
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:3635-1
Released: Fri Oct 17 16:33:06 2025
Summary: Security update for openssl-1_1
Type: security
Severity: important
References: 1250232,CVE-2025-9230
This update for openssl-1_1 fixes the following issues:
- CVE-2025-9230: fixed out of bounds read and write in RFC 3211 KEK unwrap (bsc#1250232)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:331-1
Released: Wed Jan 28 18:12:49 2026
Summary: Security update for openssl-1_1
Type: security
Severity: moderate
References: 1256834,1256835,1256836,1256837,1256838,1256839,1256840,CVE-2025-68160,CVE-2025-69418,CVE-2025-69419,CVE-2025-69420,CVE-2025-69421,CVE-2026-22795,CVE-2026-22796
This update for openssl-1_1 fixes the following issues:
- CVE-2026-22795: Missing ASN1_TYPE validation in PKCS#12 parsing (bsc#1256839).
- CVE-2025-69420: Missing ASN1_TYPE validation in TS_RESP_verify_response() function (bsc#1256837).
- CVE-2025-69421: NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function (bsc#1256838).
- CVE-2026-22796: ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function (bsc#1256840).
- CVE-2025-68160: Heap out-of-bounds write in BIO_f_linebuffer on short writes (bsc#1256834).
- CVE-2025-69418: Unauthenticated/unencrypted trailing bytes with low-level OCB function calls (bsc#1256835).
- CVE-2025-69419: Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversion (bsc#1256836).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1386-1
Released: Thu Apr 16 11:17:06 2026
Summary: Security update for openssl-1_1
Type: security
Severity: important
References: 1260441,1260442,1260443,1260444,1261678,CVE-2026-28387,CVE-2026-28388,CVE-2026-28389,CVE-2026-28390,CVE-2026-31789
This update for openssl-1_1 fixes the following issues:
- CVE-2026-28387: Potential use-after-free in DANE client code (bsc#1260441).
- CVE-2026-28388: NULL Pointer Dereference When Processing a Delta CRL (bsc#1260442).
- CVE-2026-28389: Possible NULL dereference when processing CMS KeyAgreeRecipientInfo (bsc#1260443).
- CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with
KeyTransportRecipientInfo (bsc#1261678).
- CVE-2026-31789: Heap buffer overflow in hexadecimal conversion (bsc#1260444).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2041-1
Released: Thu May 21 16:29:18 2026
Summary: Recommended update for openssl-1_1
Type: recommended
Severity: moderate
References: 1250782
This update for openssl-1_1 fixes the following issues:
- Fix 30-test_fips_sli.t fails intermittently on s390x (bsc#1250782):
* Fix AES_GCM IV test sometimes failing on s390x.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2392-1
Released: Mon Jun 15 10:05:31 2026
Summary: Security update for openssl-1_1
Type: security
Severity: important
References: 1250782,1266340,1266341,1266342,1266349,1266357,CVE-2026-34180,CVE-2026-42766,CVE-2026-45447,CVE-2026-7383,CVE-2026-9076
This update for openssl-1_1 fixes the following issues
- CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340).
- CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341).
- CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342).
- CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349).
- CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3182-1
Released: Wed Jul 22 09:25:44 2026
Summary: Security update for libgcrypt
Type: security
Severity: moderate
References: 1262684,CVE-2026-41989
This update for libgcrypt fixes the following issue
- CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service
(bsc#1262684).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3578-1
Released: Tue Aug 11 15:58:41 2026
Summary: Security update for openssl-1_1
Type: security
Severity: moderate
References: 1271712
This update for openssl-1_1 fixes the following issues:
- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
(bsc#1271712).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4041-1
Released: Mon Sep 7 10:29:44 2026
Summary: Security update for openssl-1_1
Type: security
Severity: important
References: 1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072
This update for openssl-1_1 fixes the following issues:
August 2026 release.
- CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795).
- CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:4110-1
Released: Wed Sep 9 17:00:16 2026
Summary: Recommended update for crypto-policies
Type: recommended
Severity: important
References: 1212476,1227370,1236165,1239009,1242233,1243830,1252696,1253025,1258311,1259825,1262315,1275660
This update for crypto-policies fixes the following issues:
- Update crypto-policies for Post-Quantum Cryptography (PQC) TLS
support in SLE-15-SP7 (jsc#PED-16072):
* Add support for mlkem768x25519-sha256 in openssh 9.6p1 (bsc#1275660)
* Add support for python36 (jsc#PED-16072)
* Add support for sntrup761x25519-sha512 at openssh.com and remove
it for sntrup761x25519-sha512 in openssh 9.6p1 in SLE-15-SP7
as it only lists the former (bsc#1258311, bsc#1259825)
- Allow X25519 as required for sntrup761x25519-sha512 at openssh.com
and sntrup761x25519-sha512 in the DEFAULT policy. (bsc#1259825)
- Add PQC support for OpenSSH (bsc#1258311, bsc#1259825)
* Enable sntrup761x25519-sha512 for OpenSSH by default
- Modify the output of fips-mode-setup to hint the user when
setting the FIPS mode in transactional systems to use the
command 'transactional-update setup-fips'. (bsc#1262315)
- Adapt the manpages to SUSE/openSUSE:
* Compress all the man pages for update-crypto-policies.8.gz,
crypto-policies.7.gz, fips-finish-install.8.gz and
fips-mode-setup.8.gz into man-crypto-policies.tar.xz
- Update to version 20250714.cd6043a: [bsc#1253025, bsc#1252696]
* gnutls: enable ML-DSA, for both secure-sig and secure-sig-for-cert
* python, policies, tests: alias X25519-MLKEM768 to MLKEM768-X25519
* FIPS: disable MLKEM768-X25519 for openssh (no-op)
* FIPS: deprioritize X25519-MLKEM768 over P256-MLKEM768 for openssl...
* TEST-PQ: be more careful with the ordering
* openssl: send one PQ and one classic key_share; prioritize PQ groups
* sequoia: Generate AEAD policy
* Do not include EdDSA in FIPS policy
* sequoia: Add PQC algorithm
* sequoia: Run tests against PQC capable policy-config-check
* Revert 'openssl, policies: implement group_key_share option'
* openssl, policies: implement group_key_share option
* FIPS: enable hybrid ML-KEM (TLS only) and pure ML-DSA
* python/build-crypto-policies: output diffs on --test mismatches
* sequoia, rpm-sequoia: use ignore_invalid with sha3, x25519, ...
* policies, alg_lists, openssl: remove KYBER from allowed values
* openssl: stricter enabling of Ciphersuites
* openssl: make use of -CBC and -AESGCM keywords
* openssl: add TLS 1.3 Brainpool identifiers
* fix warning on using experimental key_exchanges
* update-crypto-policies: don't output FIPS warning in fips mode
* openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256
* openssh, libssh: refactor kx maps to use tuples
* alg_lists: mark MLKEM768/SNTRUP kex experimental
* nss: revert enabling mlkem768secp256r1
* nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber
* gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768
* openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768
* openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768
* openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256
* LEGACY: enable 192-bit ciphers for nss pkcs12/smime
* openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384...
* nss: be stricter with new purposes
* python/update-crypto-policies: pacify pylint
* fips-mode-setup: tolerate fips dracut module presence w/o FIPS
* fips-mode-setup: small Argon2 detection fix
* SHA1: add __openssl_block_sha1_signatures = 0
* fips-mode-setup: block if LUKS devices using Argon2 are detected
* update-crypto-policies: skip warning on --set=FIPS if bootc
* fips-setup-helper: skip warning, BTW
* fips-mode-setup: force --no-bootcfg when UKI is detected
* fips-crypto-policy-overlay: automount FIPS policy
* nss: rewrite backend for 3.101
* cryptopolicies: parent scopes for dumping purposes
* policygenerators: move scoping inside generators
* openssh: make dss no longer enableble, support is dropped
* gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768
* TEST-PQ: disable pure Kyber768
* DEFAULT: switch to rh-allow-sha1-signatures = no...
* java: drop unused javasystem backend
* java: stop specifying jdk.tls.namedGroups in javasystem
* ec_min_size: introduce and use in java, default to 256
* java: use and include jdk.disabled.namedCurves
* BSI: Update BSI policy for new 2024 minimum recommendations
* fips-mode-setup: flashy ticking warning upon use
* fips-mode-setup: add another scary 'unsupported'
* BSI: switch to 3072 minimum RSA key size
* java: make hash, mac and sign more orthogonal
* java: specify jdk.tls.namedGroups system property
* java: respect more key size restrictions
* java: disable anon ciphersuites, tying them to NULL...
* java: start controlling / disable DTLSv1.0
* nss: wire KYBER768 to XYBER768D00
- Update to version 20250425.9267dee:
* openssl: fix mistakes in integrity-only cipher definitions
* NO-PQ, cryptopolicies: add experimental value suppression
* nss: add mlkem768x25519 and mlkem768secp256r1
* gnutls: 'allow-rsa-pkcs1-encrypt = false' everywhere but in LEGACY
* TEST-PQ, openssh: add support for MLKEM768 key_exchange
* LEGACY: drop cipher at pkcs12 = SEED-CBC
* fips-crypto-policy-overlay: automount FIPS policy, follow-up fixes
* nss: TLS-REQUIRE-EMS in FIPS
* DEFAULT: disable RSA key exchange
* LEGACY: disable sign = *-SHA1
* nss: wire XYBER768D00 to X25519-KYBER768, not KYBER768
- Add the FIPS scripts fips-finish-install and fips-mode-setup as
sources in the spec file as they have been removed upstream.
* We will maintain these scripts downstream.
* Update the man pages for update-crypto-policies.8.gz
* Add man pages in text file in compressed form in the file
man-fips-scripts.tar.xz and add them to the Makefile.
- Update to version 20250324.3714354:
* NO-PQ: introduce
* LEGACY/DEFAULT/FUTURE: enable hybrid ML-KEM and pure ML-DSA
* _openssl_block_sha1_signatures: flip the default to 1
* sequoia: add sha3, x25519, ed25519, x448, ed448, but not for rpm-sequoia
* sequoia: refactor a bit
* openssl: specify default key size for req
* gnutls: support P384-MLKEM1024
* openssl: stop generating `openssl` in favour of `opensslcnf`
* gnutls: drop kyber (switching to leancrypto took it away)
* openssl: use both names for P384-MLKEM1024
* Detect the presence of nss-policy-check
* Don't use hardcoded python3 path
* Make xsltproc settable as XSLTPROC
* python/cryptopolicies/validation/scope.py: fix new ruff rule RUF021
* Update the info in the README.SUSE file
* Remove the FEDORA policies and directories
- Allow openssl to load when using the DEFAULT policy, and also
other policies, in FIPS mode. [bsc#1243830, bsc#1242233]
- Relax the nss version requirement since the mlkem768secp256r1
enablement has been reverted.
- Allow sshd in FIPS mode when using the DEFAULT policy [bsc#1227370]
- Enable SHA1 sigver in the DEFAULT policy.
- Remove also sequoia config and generator files
- Remove not needed fips bind mount service
- Update to version 20250124.4d262e7: [bsc#1239009, bsc#1236165]
* openssl: stricter enabling of Ciphersuites
* openssl: make use of -CBC and -AESGCM keywords
* openssl: add TLS 1.3 Brainpool identifiers
* fix warning on using experimental key_exchanges
* update-crypto-policies: don't output FIPS warning in fips mode
* openssh: map mlkem768x25519-sha256 to KEM-ECDH & MLKEM768-X25519 & SHA2-256
* openssh, libssh: refactor kx maps to use tuples
* alg_lists: mark MLKEM768/SNTRUP kex experimental
* nss: revert enabling mlkem768secp256r1
* nss: add mlkem768x25519 and mlkem768secp256r1, remove xyber
* gnutls: add GROUP-X25519-MLKEM768 and GROUP-SECP256R1-MLKEM768
* openssl: use both names for SecP256r1MLKEM768 / X25519MLKEM768
* openssh, TEST-PQ: rename MLKEM key_exchange to MLKEM768
* openssh: add support for sntrup761x25519-sha512 and mlkem768x25519-sha256
* openssl: map NULL to TLS_SHA256_SHA256:TLS_SHA384_SHA384...
* python/update-crypto-policies: pacify pylint
* fips-mode-setup: tolerate fips dracut module presence w/o FIPS
* fips-mode-setup: small Argon2 detection fix
* SHA1: add __openssl_block_sha1_signatures = 0
* fips-mode-setup: block if LUKS devices using Argon2 are detected
* update-crypto-policies: skip warning on --set=FIPS if bootc
* fips-setup-helper: skip warning, BTW
* fips-mode-setup: force --no-bootcfg when UKI is detected
* fips-setup-helper: add a libexec helper for anaconda
* fips-crypto-policy-overlay: automount FIPS policy
* openssh: make dss no longer enableble, support is dropped
* gnutls: wire GROUP-X25519-KYBER768 to X25519-KYBER768
* DEFAULT: switch to rh-allow-sha1-signatures = no...
* java: drop unused javasystem backend
* java: stop specifying jdk.tls.namedGroups in javasystem
* ec_min_size: introduce and use in java, default to 256
* java: use and include jdk.disabled.namedCurves
* BSI: Update BSI policy for new 2024 minimum recommendations
* fips-mode-setup: flashy ticking warning upon use
* fips-mode-setup: add another scary 'unsupported'
* CONTRIBUTING.md: add a small section on updating policies
* CONTRIBUTING.md: remove trailing punctuation from headers
* BSI: switch to 3072 minimum RSA key size
* java: make hash, mac and sign more orthogonal
* java: specify jdk.tls.namedGroups system property
* java: respect more key size restrictions
* java: disable anon ciphersuites, tying them to NULL...
* java: start controlling / disable DTLSv1.0
* nss: wire KYBER768 to XYBER768D00
* nss: unconditionally load p11-kit-proxy.so
* gnutls: make DTLS0.9 controllable again
* gnutls: retire GNUTLS_NO_TLS_SESSION_HASH
* openssh: remove OPENSSH_MIN_RSA_SIZE / OPENSSH_MIN_RSA_SIZE_FORCE
* gnutls: remove extraneous newline
* sequoia: move away from subprocess.getstatusoutput
* python/cryptopolicies/cryptopolicies.py: add trailing commas
* python, tests: rename MalformedLine to MalformedLineError
* Makefile: introduce SKIP_LINTING flag for packagers to use
* Makefile: run ruff
* tests: use pathlib
* tests: run(check=True) + CalledProcessError where convenient
* tests: use subprocess.run
* tests/krb5.py: check all generated policies
* tests: print to stderr on error paths
* tests/nss.py: also use encoding='utf-8'
* tests/nss.py: also use removesuffix
* tests/nss.py: skip creating tempfiles
* tests/java.pl -> tests/java.py
* tests/gnutls.pl -> tests/gnutls.py
* tests/openssl.pl -> tests/openssl.py
* tests/verify-output.pl: remove
* libreswan: do not use up pfs= / ikev2= keywords for default behaviour
- Update to version 20241010.5930b9a:
* LEGACY: enable 192-bit ciphers for nss pkcs12/smime
* nss: be stricter with new purposes
* nss: rewrite backend for 3.101
* cryptopolicies: parent scopes for dumping purposes
* policygenerators: move scoping inside generators
* TEST-PQ: disable pure Kyber768
* nss: wire XYBER768D00 to X25519-KYBER768
* TEST-PQ: update
* TEST-PQ: also enable sntrup761x25519-sha512 at openssh.com
* TEST-PQ, alg_lists, openssl: enable more experimental `sign` values
* TEST-PQ, python: add more groups, mark experimental
* openssl: mark liboqsprovider groups optional with ?
- Update to version 20240201.9f501f3:
* .gitlab-ci.yml: install sequoia-policy-config
* java: disable ChaCha20-Poly1305 where applicable
* fips-mode-setup: make sure ostree is detected in chroot
* fips-finish-install: make sure ostree is detected in chroot
* TEST-PQ: enable X25519-KYBER768 / P384-KYBER768 for openssl
* TEST-PQ: add a no-op subpolicy
* update-crypto-policies: Keep mid-sentence upper case
* fips-mode-setup: Write error messages to stderr
* fips-mode-setup: Fix some shellcheck warnings
* fips-mode-setup: Fix test for empty /boot
* fips-mode-setup: Avoid 'boot=UUID=' if /boot == /
* Update man pages
- Update to version 20231108.adb5572b:
* Print matches in syntax deprecation warnings
* Restore support for scoped ssh_etm directives
* fips-mode-setup: Fix usage with --no-bootcfg
* turn ssh_etm into an etm at SSH tri-state
* fips-mode-setup: increase chroot-friendliness
* bind: fix a typo that led to duplication of ECDSAPxxxSHAxxx
* pylintrc: use-implicit-booleaness-not-comparison-to-*
- avoid the cycle rpm/cmake/crypto-policies/python-rpm-macros:
we only need python3-base here, we don't need the python
macros as no module is being built
- Remove dependency on /usr/bin/python3, making scripts to depends on
the real python3 binary, not the link. bsc#1212476
The following package changes have been done:
- libopenssl1_1-1.1.1w-150700.11.30.1 updated
More information about the sle-container-updates
mailing list