SUSE-CU-2026:11154-1: Security update of suse/sles/16.0/toolbox
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Sep 24 08:02:13 UTC 2026
SUSE Container Update Advisory: suse/sles/16.0/toolbox
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11154-1
Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.126 , suse/sles/16.0/toolbox:latest
Container Release : 1.126
Severity : important
Type : security
References : 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1279584
1279588 1279593 1279595 1279782 1279783 1279784 1279893 1280049
1280050 1280051 1280052 1280053 1280054 CVE-2026-0799 CVE-2026-18238
CVE-2026-18313 CVE-2026-31911 CVE-2026-31912 CVE-2026-6244 CVE-2026-6554
CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160
CVE-2026-89161 CVE-2026-89162
-----------------------------------------------------------------
The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 1747
Released: Wed Sep 23 21:42:24 2026
Summary: Security update for pcre2
Type: security
Severity: important
References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162
This update for pcre2 fixes the following issues:
- CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893).
- CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054).
- CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053).
- CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052).
- CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject
(bsc#1280051).
- CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match`
(bsc#1280050).
- CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049).
-----------------------------------------------------------------
Advisory ID: 1749
Released: Wed Sep 23 21:44:23 2026
Summary: Security update for libpcap
Type: security
Severity: important
References: 1279584,1279588,1279593,1279595,1279782,1279783,1279784,CVE-2026-0799,CVE-2026-18238,CVE-2026-18313,CVE-2026-31911,CVE-2026-31912,CVE-2026-6244,CVE-2026-6554
This update for libpcap fixes the following issues:
- CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a
scratch memory register and allows for OOB access (bsc#1279782).
- CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the
immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero
(bsc#1279595).
- CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward
jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584).
- CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly
validates its headers and allows for an OOB access (bsc#1279783).
- CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ`
message received from the client and never frees the memory (bsc#1279784).
- CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode.
In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588).
- CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a
return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff
(bsc#1279593).
The following package changes have been done:
- libpcap1-1.10.5-160000.5.1 updated
- libpcre2-8-0-10.45-160000.4.1 updated
More information about the sle-container-updates
mailing list