SUSE-CU-2026:11106-1: Security update of suse/sle-micro-rancher/5.4
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Wed Sep 23 07:17:04 UTC 2026
SUSE Container Update Advisory: suse/sle-micro-rancher/5.4
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11106-1
Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.191 , suse/sle-micro-rancher/5.4:latest
Container Release : 4.5.191
Severity : important
Type : security
References : 1235944 1242405 1261604 1263072 1264734 1266008 1267023 1268659
1269000 1269004 1269238 1269242 1269306 1269655 1269731 1271825
1271830 1272179 1272182 1272230 1272385 1272390 1272868 1272877
1273060 1273105 1273251 1273276 1273303 1273311 1273422 1273484
1273488 1273523 1273555 1273742 1273745 1273748 1273762 1273774
1273869 1273882 1273891 1273930 1273944 1273966 1273995 1274014
1274041 1274208 1274274 1274497 1274547 1274550 1274696 1274705
1274752 1274753 1274754 1274859 1274888 1274898 1274902 1274908
1274941 1275161 1275304 1275307 1275470 1275472 1275474 1275506
1275528 1275535 1275540 1275687 1275696 1275784 1275798 1275827
1275867 1275886 1275905 1275985 1276006 1276350 1276395 1276665
1276931 1277073 1277285 1277391 1277408 1277523 1277553 1277561
1277571 1277813 1277837 1277901 1277908 1278088 1278233 1278236
1278253 1278294 1279422 1279487 1279813 CVE-2023-53109 CVE-2024-57841
CVE-2026-23451 CVE-2026-31502 CVE-2026-43456 CVE-2026-43502 CVE-2026-45968
CVE-2026-52910 CVE-2026-52912 CVE-2026-52929 CVE-2026-52977 CVE-2026-53059
CVE-2026-53163 CVE-2026-53260 CVE-2026-53264 CVE-2026-53381 CVE-2026-53388
CVE-2026-63801 CVE-2026-63823 CVE-2026-63827 CVE-2026-63887 CVE-2026-63888
CVE-2026-63920 CVE-2026-63992 CVE-2026-64002 CVE-2026-64007 CVE-2026-64010
CVE-2026-64011 CVE-2026-64015 CVE-2026-64047 CVE-2026-64048 CVE-2026-64098
CVE-2026-64109 CVE-2026-64114 CVE-2026-64115 CVE-2026-64137 CVE-2026-64266
CVE-2026-64268 CVE-2026-64304 CVE-2026-64355 CVE-2026-64423 CVE-2026-64450
CVE-2026-64481 CVE-2026-64541 CVE-2026-64543 CVE-2026-64556 CVE-2026-64562
CVE-2026-64563 CVE-2026-64572 CVE-2026-64581 CVE-2026-64593 CVE-2026-68121
CVE-2026-68136 CVE-2026-68138 CVE-2026-68155 CVE-2026-68158 CVE-2026-68159
CVE-2026-68160 CVE-2026-68202 CVE-2026-68397 CVE-2026-68398 CVE-2026-68417
CVE-2026-68426 CVE-2026-68480 CVE-2026-72020 CVE-2026-72069 CVE-2026-72083
CVE-2026-72084 CVE-2026-72123 CVE-2026-72135 CVE-2026-72164 CVE-2026-72251
CVE-2026-72288 CVE-2026-72289 CVE-2026-72323 CVE-2026-72339 CVE-2026-72389
CVE-2026-74345 CVE-2026-74377 CVE-2026-74378 CVE-2026-74388 CVE-2026-74390
CVE-2026-74394 CVE-2026-74406 CVE-2026-74454 CVE-2026-74488 CVE-2026-74496
CVE-2026-74518 CVE-2026-74537 CVE-2026-74556 CVE-2026-74582 CVE-2026-74615
CVE-2026-74616 CVE-2026-74669 CVE-2026-74695 CVE-2026-74743 CVE-2026-80580
CVE-2026-80714 CVE-2026-80716 CVE-2026-80737 CVE-2026-80909
-----------------------------------------------------------------
The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4284-1
Released: Tue Sep 22 18:07:33 2026
Summary: Security update for the Linux Kernel
Type: security
Severity: important
References: 1235944,1242405,1261604,1263072,1264734,1266008,1267023,1268659,1269000,1269004,1269238,1269242,1269306,1269655,1269731,1271825,1271830,1272179,1272182,1272230,1272385,1272390,1272868,1272877,1273060,1273105,1273251,1273276,1273303,1273311,1273422,1273484,1273488,1273523,1273555,1273742,1273745,1273748,1273762,1273774,1273869,1273882,1273891,1273930,1273944,1273966,1273995,1274014,1274041,1274208,1274274,1274497,1274547,1274550,1274696,1274705,1274752,1274753,1274754,1274859,1274888,1274898,1274902,1274908,1274941,1275161,1275304,1275307,1275470,1275472,1275474,1275506,1275528,1275535,1275540,1275687,1275696,1275784,1275798,1275827,1275867,1275886,1275905,1275985,1276006,1276350,1276395,1276665,1276931,1277073,1277285,1277391,1277408,1277523,1277553,1277561,1277571,1277813,1277837,1277901,1277908,1278088,1278233,1278236,1278253,1278294,1279422,1279487,1279813,CVE-2023-53109,CVE-2024-57841,CVE-2026-23451,CVE-2026-31502,CVE-2026-43456,CVE-2026-43502,CVE-2026-45968,CVE-2026
-52910,CVE-2026-52912,CVE-2026-52929,CVE-2026-52977,CVE-2026-53059,CVE-2026-53163,CVE-2026-53260,CVE-2026-53264,CVE-2026-53381,CVE-2026-53388,CVE-2026-63801,CVE-2026-63823,CVE-2026-63827,CVE-2026-63887,CVE-2026-63888,CVE-2026-63920,CVE-2026-63992,CVE-2026-64002,CVE-2026-64007,CVE-2026-64010,CVE-2026-64011,CVE-2026-64015,CVE-2026-64047,CVE-2026-64048,CVE-2026-64098,CVE-2026-64109,CVE-2026-64114,CVE-2026-64115,CVE-2026-64137,CVE-2026-64266,CVE-2026-64268,CVE-2026-64304,CVE-2026-64355,CVE-2026-64423,CVE-2026-64450,CVE-2026-64481,CVE-2026-64541,CVE-2026-64543,CVE-2026-64556,CVE-2026-64562,CVE-2026-64563,CVE-2026-64572,CVE-2026-64581,CVE-2026-64593,CVE-2026-68121,CVE-2026-68136,CVE-2026-68138,CVE-2026-68155,CVE-2026-68158,CVE-2026-68159,CVE-2026-68160,CVE-2026-68202,CVE-2026-68397,CVE-2026-68398,CVE-2026-68417,CVE-2026-68426,CVE-2026-68480,CVE-2026-72020,CVE-2026-72069,CVE-2026-72083,CVE-2026-72084,CVE-2026-72123,CVE-2026-72135,CVE-2026-72164,CVE-2026-72251,CVE-2026-72288,CVE-2026-72289,
CVE-2026-72323,CVE-2026-72339,CVE-2026-72389,CVE-2026-74345,CVE-2026-74377,CVE-2026-74378,CVE-2026-74388,CVE-2026-74390,CVE-2026-74394,CVE-2026-74406,CVE-2026-74454,CVE-2026-74488,CVE-2026-74496,CVE-2026-74518,CVE-2026-74537,CVE-2026-74556,CVE-2026-74582,CVE-2026-74615,CVE-2026-74616,CVE-2026-74669,CVE-2026-74695,CVE-2026-74743,CVE-2026-80580,CVE-2026-80714,CVE-2026-80716,CVE-2026-80737,CVE-2026-80909
The SUSE Linux Enterprise 15 SP4 kernel was updated to fix various security issues:
The following security issues were fixed:
- CVE-2023-53109: net: tunnels: annotate lockless accesses to dev->needed_headroom (bsc#1242405 bsc#1275784).
- CVE-2024-57841: net: fix memory leak in tcp_conn_request() (bsc#1235944).
- CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731).
- CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604).
- CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072).
- CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734).
- CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008).
- CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023).
- CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period (bsc#1268659).
- CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000).
- CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004).
- CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242).
- CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655).
- CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306).
- CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238).
- CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830).
- CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230).
- CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182).
- CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179).
- CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385).
- CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390).
- CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877).
- CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868).
- CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774).
- CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105).
- CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882).
- CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891).
- CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762).
- CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060).
- CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484).
- CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488).
- CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748).
- CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742).
- CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745).
- CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276).
- CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944).
- CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422).
- CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274).
- CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523).
- CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547).
- CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303).
- CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311).
- CVE-2026-64556: perf/core: Detach event groups during remove_on_exec (bsc#1273251).
- CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930).
- CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995).
- CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014).
- CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041).
- CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497).
- CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888).
- CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474).
- CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941).
- CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304).
- CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307).
- CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470).
- CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472).
- CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161).
- CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898).
- CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908).
- CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696).
- CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705).
- CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208).
- CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506).
- CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528).
- CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535).
- CVE-2026-72084: scsi: target: core: Generate correct identifiers for PR OUT transport IDs (bsc#1275540).
- CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523).
- CVE-2026-72135: tpm: Make the TPM character devices non-seekable (bsc#1277571).
- CVE-2026-72164: ocfs2: avoid moving extents to occupied clusters (bsc#1277553).
- CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827).
- CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886).
- CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905).
- CVE-2026-72323: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (bsc#1275985).
- CVE-2026-72339: qede: fix off-by-one in BD ring consumption on build_skb failure (bsc#1276006).
- CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869).
- CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285).
- CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236).
- CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233).
- CVE-2026-74388: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data (bsc#1278253).
- CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (bsc#1278088).
- CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408).
- CVE-2026-74406: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() (bsc#1276395).
- CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073).
- CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350).
- CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867).
- CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798).
- CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687).
- CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696).
- CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784).
- CVE-2026-74615: vxlan: do not arm the ageing timer on a device that is down (bsc#1277901).
- CVE-2026-74616: xdp: reject clones that overrun skb_shared_info tailroom (bsc#1277813).
- CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391).
- CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931).
- CVE-2026-74743: macvlan: inherit needed_headroom and needed_tailroom from lowerdev (bsc#1277908).
- CVE-2026-80580: fbdev: bound mode sysfs output to the sysfs buffer (bsc#1278294).
- CVE-2026-80714: ipvs: do not propagate one-packet flag to synced conns (bsc#1277561).
- CVE-2026-80716: ALSA: pcm: wake linked drain waiters on unlink (bsc#1277837).
- CVE-2026-80737: serial: amba-pl011: synchronize DMA teardown (bsc#1279487).
- CVE-2026-80909: drm/amdgpu: Reject UVD message with invalid number of h265 refs (bsc#1279422).
The following non security issues were fixed:
- mkspec-dtb: Move DTS prefix into package list.
- mkspec-dtb: Move provides-obsoletes to package list.
- mkspec-dtb: Put per-architecture package lists into a hash.
- mkspec-dtb: re-indent.
- net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550).
- perf: Reject exited events as group leaders (git-fixes).
- powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752
ltc#221290).
- RDMA/siw: Introduce siw_cep_set_free_and_put (git-fixes).
- RDMA/siw: Introduce siw_destroy_cep_sock (git-fixes).
- RDMA/siw: Introduce siw_free_cm_id (git-fixes).
- RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp (git-fixes).
- smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902).
- smb: client: require net admin for CIFS SWN netlink (bsc#1273966).
The following package changes have been done:
- kernel-default-5.14.21-150400.24.240.2 updated
More information about the sle-container-updates
mailing list