SUSE-IU-2026:7344-1: Security update of suse-sles-15-sp6-chost-byos-v20260921-x86_64-gen2
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Sep 24 07:04:15 UTC 2026
SUSE Image Update Advisory: suse-sles-15-sp6-chost-byos-v20260921-x86_64-gen2
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:7344-1
Image Tags : suse-sles-15-sp6-chost-byos-v20260921-x86_64-gen2:20260921
Image Release :
Severity : critical
Type : security
References : 1158698 1158707 1159776 1164818 1164819 1169921 1170598 1170599
1170605 1170606 1171479 1172581 1175609 1175609 1175610 1175610
1184720 1194663 1215737 1216982 1218034 1218038 1218760 1220279
1222768 1224024 1226197 1226216 1226216 1228376 1228376 1229193
1229677 1231668 1232616 1234217 1238078 1240656 1240955 1242233
1242233 1243716 1243830 1243830 1246560 1246599 1246914 1247017
1247225 1248600 1254738 1257249 1259542 1260446 1261038 1262043
1262072 1262633 1263440 1264971 1265060 1265061 1265062 1265070
1265071 1265075 1265076 1266664 1266786 1267478 1267610 1268321
1268322 1268412 1268596 1268867 1268900 1269220 1269221 1269390
1270392 1270416 1271730 1272534 1273242 1273580 1274079 1274081
1274083 1274091 1274554 1274610 1274625 1274723 1274726 1274740
1274774 1274774 1274788 1274788 1274790 1274795 1274795 1274797
1274856 1274857 1274858 1275441 1275837 1275902 1275926 1276290
1276291 1276892 1276946 1277247 1277262 1277267 1277267 1277476
1277479 1277480 1277707 1277708 1277709 1277710 1277711 1277713
1277790 1277921 1277922 1278351 1279584 1279588 1279593 1279595
1279782 1279783 1279784 1279893 1280050 1280051 1280052 1280053
1280054 976992 CVE-2015-8863 CVE-2020-12762 CVE-2023-50246 CVE-2023-50268
CVE-2024-25629 CVE-2024-53427 CVE-2025-31498 CVE-2025-62408 CVE-2025-9403
CVE-2026-0799 CVE-2026-13608 CVE-2026-16445 CVE-2026-18238 CVE-2026-18313
CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-23679 CVE-2026-31911
CVE-2026-31912 CVE-2026-33630 CVE-2026-33948 CVE-2026-40164 CVE-2026-40612
CVE-2026-41256 CVE-2026-41257 CVE-2026-42250 CVE-2026-43894 CVE-2026-43895
CVE-2026-43896 CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54369
CVE-2026-54370 CVE-2026-54371 CVE-2026-54679 CVE-2026-54874 CVE-2026-54874
CVE-2026-5773 CVE-2026-6244 CVE-2026-63072 CVE-2026-63072 CVE-2026-63074
CVE-2026-63076 CVE-2026-6368 CVE-2026-6554 CVE-2026-66484 CVE-2026-66485
CVE-2026-66486 CVE-2026-6791 CVE-2026-6893 CVE-2026-69184 CVE-2026-69186
CVE-2026-7168 CVE-2026-72693 CVE-2026-75803 CVE-2026-77117 CVE-2026-80229
CVE-2026-80230 CVE-2026-80489 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157
CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-8926
-----------------------------------------------------------------
The container suse-sles-15-sp6-chost-byos-v20260921-x86_64-gen2 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:925-1
Released: Mon Apr 6 10:08:27 2020
Summary: Recommended update for python3-azuremetadata, regionServiceClientConfigAzure, regionServiceClientConfigSAPAzure
Type: recommended
Severity: moderate
References: 1158698,1158707,1164818,1164819
This update for python3-azuremetadata, regionServiceClientConfigAzure, regionServiceClientConfigSAPAzure fixes the following issues:
regionServiceClientConfigAzure was updated to version 0.0.5:
+ Don't specify root device name explicitly (bsc#1158698, bsc#1158707)
regionServiceClientConfigSAPAzure was updated to version 1.0.2:
+ Don't specify root device name explicitly (bsc#1158698, bsc#1158707)
Changes in python3-azuremetadata:
- Version 5.0.0
- Support new Azure metadata API (bsc#1164818, bsc#1164819)
- Automatically detect root device (bsc#1158698, bsc#1158707)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1097-1
Released: Thu Apr 23 21:12:03 2020
Summary: Recommended update for python3-azuremetadata
Type: recommended
Severity: moderate
References: 1169921
This update for python3-azuremetadata fixes the following issues:
- Use lsblk for root device detection (bsc#1169921)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1159-1
Released: Tue May 5 16:24:36 2020
Summary: Recommended update for python3-azuremetadata
Type: recommended
Severity: moderate
References: 1170598,1170599,1170605,1170606
This update for python3-azuremetadata fixes the following issues:
python3-azuremetadata was updated to version 5.1.0:
- Produce well-formed JSON and XML output when multiple filters
are specified (bsc#1170598, bsc#1170599)
regionServiceClientConfigSAPAzure was updated to 1.0.3 and
regionServiceClientConfigAzure was updated to 0.0.6:
- Report subscriptionId during registration (bsc#1170605, bsc#1170606)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:2556-1
Released: Mon Sep 7 14:31:43 2020
Summary: Recommended update for python3-azuremetadata
Type: recommended
Severity: moderate
References: 1175609,1175610
This update for python3-azuremetadata contains the following fix:
- Fix provides directive (bsc#1175609, bsc#1175610)
+ The provides directive must set a version or update does not work
as expected
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2021:1588-1
Released: Wed May 12 13:44:31 2021
Summary: Recommended update for python3-azuremetadata
Type: recommended
Severity: moderate
References: 1172581,1184720
This update for python3-azuremetadata fixes the following issues:
- Fixed an issue where SUSEConnect was unable to set cloud_provider when registering
an instance the first time (bsc#1172581)
- When querying the metdata server for access verification via a proxy, the wrong
data was delivered. This has been fixed (bsc#1184720)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2022:170-1
Released: Tue Jan 25 11:22:10 2022
Summary: Recommended update for python3-azuremetadata
Type: recommended
Severity: important
References: 1175609,1175610,1194663
This update for python3-azuremetadata fixes the following issues:
- Version 5.1.5 (bsc#1194663)
+ Handle lsblk output format change. The json data now contains
'mountpoints' instead of 'mountpoint'
+ Use versions endpoint to list the available versions
+ Add bypass proxy
+ Update way to check classic vms
- Fix provides directive (bsc#1175609, bsc#1175610)
+ The provides directive must set a version or update does not work
as expected
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2022:184-1
Released: Tue Jan 25 18:20:56 2022
Summary: Security update for json-c
Type: security
Severity: important
References: 1171479,CVE-2020-12762
This update for json-c fixes the following issues:
- CVE-2020-12762: Fixed integer overflow and out-of-bounds write. (bsc#1171479)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:583-1
Released: Wed Feb 21 22:47:47 2024
Summary: Recommended update for python3-azuremetadata
Type: recommended
Severity: moderate
References: 1218760
This update for python3-azuremetadata fixes the following issues:
- Fix empty list attributes (bsc#1218760)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:2573-1
Released: Mon Jul 22 12:35:01 2024
Summary: Recommended update for libkcapi
Type: recommended
Severity: moderate
References: 1222768
This update for libkcapi fixes the following issues:
- FIPS: kcapi-hasher: zeroise temporary values for FIPS 140-3
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:2781-1
Released: Tue Aug 6 14:39:15 2024
Summary: Recommended update for libnvme, nvme-cli
Type: recommended
Severity: moderate
References: 1226197,1226216,1228376
This update for libnvme, nvme-cli fixes the following issues:
- Version updates:
* linux: update TLS version 1 PSK derivation (bsc#1228376)
* linux: add nvme_revoke_tls_key (bsc#1226197)
* test: add hostnqn lookup test (bsc#1226216)
* test: add config-pcie-with-tcp-config test case (bsc#1226216)
* test: add config dump test (bsc#1226216)
* test: revamp sysfs tree dump test (bsc#1226216)
* test: use diff to compare sysfs output (bsc#1226216)
* tree: preserve parsing order of a config file (bsc#1226216)
* tree: add helper to lookup hostnqn/hostid (bsc#1226216)
* json: filter out pcie transport (bsc#1226216)
* fabrics: connect all hosts in config.json (bsc#1226216)
* fabrics: refactor discover from json config (bsc#1226216)
* fabrics: first read config before topology scanning (bsc#1226216)
* fabrics: use helper to lookup default hostnqn/hostid (bsc#1226216)
* fabrics: extend already connected message (bsc#1226216)
* fabrics: Always pass hostid and hostnqn (bsc#1226216)
* fabrics: Make some symbols public (bsc#1226216)
* fabrics: extend hostnqn/hostid variable inject interface (bsc#1226216)
* doc: add tls-key --revoke documentation (bsc#1226197)
* doc: fix tls-key --keyfile shorthand (bsc#1226197)
* build: sort documentation files entries (bsc#1226197)
* nvme: avoid segfault in show-topology (bsc#1226197)
* nvme: add support to revoke TLS key (bsc#1226197)
* nvme: return error code/message for TLS commands (bsc#1226197)
* nvme: factor out import key function (bsc#1226197)
* nvme: use cleanup helper to close file descriptor (bsc#1226216)
* nvme: use cleanup helper for STREAM objects (bsc#1226216)
* nvme: strip newline when parsing TLS key files (bsc#1226197)
* nvme: use stdout for exporting TLS keys (bsc#1226197)
* nvme: change _cleanup_file_ to _cleanup_fd_ (bsc#1226197)
* nvme: use cleanup helper for nvme_root_t objects (bsc#1226197)
* nvme: add new function 'tls_key' (bsc#1226197)
* libnvme: Introduce functions to generate host identifier and host NQN (bsc#1226216)
* libnvme: add missing symbol nvme_scan_tls_keys (bsc#1226197)
* completion: add support for tls-key (bsc#1226197)
* completions: Fix bash-nvme-completion.sh indentation errors (bsc#1226197)
- Always build documentation
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:2865-1
Released: Fri Aug 9 12:06:04 2024
Summary: Recommended update for libnvme, nvme-cli
Type: recommended
Severity: moderate
References: 1224024,1228376
This update for libnvme, nvme-cli fixes the following issues:
- linux: Correct error handling for derive_psk_digest (bsc#1228376).
- tree: Add NVM subsystem controller identifier (bsc#1224024).
- nvme-print: Print cntlid number for controller (bsc#1224024).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:3813-1
Released: Wed Oct 30 16:44:58 2024
Summary: Recommended update for libnvme, nvme-cli
Type: recommended
Severity: moderate
References: 1229193,1229677,1231668
This update for libnvme, nvme-cli fixes the following issues:
- Version update 1.8+50.g2b587d3:
* fabrics: fix incorrect access filename check (bsc#1231668)
* fabrics: check if json config is existing (bsc#1231668)
* fabrics: avoid potential segfault in nvmf_dim() (bsc#1231668)
* ioctl: export nvme_submit_passthru as weak symbol (bsc#1231668)
* logging: Split to output ioctl latency by log info level (bsc#1231668)
* logging: output ioctl debugging info (bsc#1231668)
* netapp: print output for single device too (bsc#1231668)
* netapp: segregate print routines (bsc#1231668)
* netapp: fix uninitialized value from heap error (bsc#1231668)
* netapp-smdevices: print single device output too (bsc#1231668)
* netapp-smdevices: segregate print routines (bsc#1231668)
* nvme: fix uninitialized value in error-log (bsc#1231668)
* nvme: fix verbose logging (bsc#1231668)
* nvme: track verbose level (bsc#1231668)
* nvme: update nvme_insert_tls_key_versioned() return handling (bsc#1231668)
* nvme-print: sanitize error-log output (bsc#1231668)
* nvme-print: update subsys verbose outputs (bsc#1231668)
* nvme-print: add subsystype to the list-subsys output (bsc#1231668)
* nvme-print-stdout: refactor subsys config (bsc#1231668)
* nvme-print-stdout: update changed-ns-list-log output (bsc#1231668)
* nvme-print-json: update JSON verbose output for nvm-id-ctrl (bsc#1231668)
* plugins/sed: add sid password change (bsc#1229677)
* tree: fix segfault in nvme_free_tree() (bsc#1231668)
* tree: fix tls key mem leak (bsc#1231668)
* tree: fix dhchap_ctrl_key mem leak (bsc#1231668)
* tree: fix dhchap_key mem leak (bsc#1231668)
* tree: handle no address phy slot dirs (bsc#1229193)
* types: add new fields added in TP4165 (bsc#1231668)
* types: Changed the space into tap space (bsc#1231668)
* types: add new field added in TP4090 (bsc#1231668)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:4045-1
Released: Mon Nov 25 08:33:05 2024
Summary: Recommended update for patterns-base
Type: recommended
Severity: moderate
References:
This update for patterns-base fixes the following issue:
- Updated patterns-base, removing plymouth recommendation on s390x archs.
Our certification team run into an issue (jsc#PED-10532), when they
run bare metal installation with fully encrypted disk.
If the whole disk is crypted, the prompt for the password is sent to
plymouth, which is obviously showing nothing because for booting bare
metal (LPAR) is used terminal in HMC.
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:4269-1
Released: Mon Dec 9 17:34:34 2024
Summary: Recommended update for libnvme, nvme-cli
Type: recommended
Severity: moderate
References: 1216982,1226216,1232616,1234217
This update for libnvme, nvme-cli fixes the following issues:
- Version update (1.8+79.g69e7772)
* docs: update check-tls-key arguments (bsc#1216982, bsc#1226216).
* docs: update gen-tls-key arguments (bsc#1216982, bsc#1226216).
* docs: update TLS options (bsc#1216982, bsc#1226216).
* fabrics: add support to connect to accept a PSK command line and configuration (bsc#1216982, bsc#1226216).
* fabrics: fix map error level in __nvmf_add_ctrl (bsc#1216982, bsc#1226216).
* fabrics: add ctrl connect interface (bsc#1216982, bsc#1226216).
* fabrics: use hex numbers when generating command line options (bsc#1216982, bsc#1226216).
* fabrics: rename first argument for argument macros (bsc#1216982, bsc#1226216).
* fabrics: do not attempt to import keys if tls is not enabled (bsc#1216982, bsc#1226216).
* fabrics: skip namespace scan for fabric commands (bsc#1232616).
* json: move keystore operations out of the JSON parser (bsc#1216982, bsc#1226216).
* json: do not escape strings when printing the configuration (bsc#1216982, bsc#1226216).
* linux: do not do any keyring ops when no key is provided (bsc#1216982, bsc#1226216).
* linux: do not return w/o OpenSSL support enabled (bsc#1216982, bsc#1226216).
* linux: fix derive_psk_digest OpenSSL 1.1 version (bsc#1216982, bsc#1226216).
* linux: fixup PSK HMAC type '0' handling (bsc#1216982, bsc#1226216).
* linux: handle key import correctly (bsc#1216982, bsc#1226216).
* linux: export keys to config (bsc#1216982, bsc#1226216).
* linux: only return the description of a key (bsc#1216982, bsc#1226216).
* linux: use ssize_t as return type for nvme_identity_len (bsc#1216982, bsc#1226216).
* linux: reorder variable declarations (bsc#1216982 bsc#1226216 (bsc#1216982, bsc#1226216).
* linux: Remove the use of OpenSSL Engine API.
* linux: add import/export function for TLS pre-shared keys (bsc#1216982, bsc#1226216).
* netapp-smdev: remove redundant code (bsc#1234217).
* netapp-smdev: add verbose output (bsc#1234217).
* netapp-smdev-doc: add verbose details (bsc#1234217).
* netapp-ontapdev: fix JSON output for nsze and nuse (bsc#1234217).
* netapp-ontapdev: fix fw version handling (bsc#1234217).
* netapp-ontapdev-doc: add verbose details (bsc#1232616).
* netapp-ontapdev: add verbose output (bsc#1232616).
* nvme: use unsigned char for hmac and identity (bsc#1216982, bsc#1226216).
* nvme: add support to append TLS PSK to keyfile for check-tls-key (bsc#1216982, bsc#1226216).
* nvme: return correct error code in append_keyfile (bsc#1216982, bsc#1226216).
* nvme: add support to add derive TLS PSK to keyfile (bsc#1216982, bsc#1226216).
* nvme: rename identity to version (bsc#1216982, bsc#1226216).
* nvme: set file permission for keyfile to owner only (bsc#1216982, bsc#1226216).
* nvme: export tls keys honoring version and hmac (bsc#1216982, bsc#1226216).
* nvme-netapp: update err messages (bsc#1234217).
* nvmf-keys: add udev rule to import tls keys (bsc#1216982, bsc#1226216).
* test: add pre-shared key json tests (bsc#1216982, bsc#1226216).
* test: extend psk to test new 'versioned' API (bsc#1216982, bsc#1226216).
* test: add test case for importing/exporting PSKs (bsc#1216982, bsc#1226216).
* test: make config-diff more flexible to use (bsc#1216982, bsc#1226216).
* tree: optionally skip namespaces during scanning (bsc#1232616).
* tree: do no export tls keys when not provided by user (bsc#1216982, bsc#1226216).
* tree: read tls_configured_key and tls_keyring from sysfs (bsc#1216982, bsc#1226216).
* tree: move dhchap and tls sysfs parser into separate functions (bsc#1216982, bsc#1226216).
* tree: add getter/setters for TLS PSK (bsc#1216982, bsc#1226216).
* util: added error code for ENOKEY (bsc#1216982, bsc#1226216).
* util: Add string constant for ENVME_CONNECT_IGNORED.
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:1377-1
Released: Fri Apr 25 19:43:34 2025
Summary: Recommended update for patterns-base
Type: recommended
Severity: moderate
References:
This update for patterns-base fixes the following issues:
- add bpftool to patterns enhanced base. jsc#PED-8375
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:1378-1
Released: Fri Apr 25 19:52:18 2025
Summary: Recommended update for nvme-cli
Type: recommended
Severity: important
References: 1240656
This update for nvme-cli fixes the following issues:
- Update to version 2.8+88.g21612f53:
* sed: perform a tper revert after lsp revert (bsc#1240656)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:2839-1
Released: Mon Aug 18 11:19:58 2025
Summary: Recommended update for libnvme, nvme-cli
Type: recommended
Severity: moderate
References: 1243716,1246599
This update for libnvme, nvme-cli fixes the following issues:
- Update to version 1.8+82.g9a64f8f4:
- tree: free ctrl attributes when (re)configure ctrl (bsc#1243716)
- tree: filter tree after scan has completed (bsc#1243716)
- sysfs: minimize heap allocations of sysfs paths
- Update to version 2.8+92.g998dceae:
- nvme: fix mem leak in nvme copy (bsc#1243716)
- nvme-print: suppress output when no ctrl is present for list-subsys (bsc#1243716)
- nvme: extend filter to match device name (bsc#1243716)
- udev-rules-ontap: switch to queue-depth iopolicy (bsc#1246599)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:3250-1
Released: Wed Sep 17 15:38:53 2025
Summary: Recommended update for libnvme, nvme-cli
Type: recommended
Severity: important
References: 1246560,1247017,1247225
This update for libnvme, nvme-cli fixes the following issues:
- tree: do not try to strdup NULL pointer (bsc#1247225)
- tree: always set the host key (bsc#1246560)
- netapp-ontapdev: update invalid device handling (bsc#1247017)
- netapp-smdev: update invalid device handling (bsc#1247017)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:4332-1
Released: Tue Dec 9 12:56:58 2025
Summary: Recommended update for libnvme, nvme-cli
Type: recommended
Severity: important
References: 1246914
This update for libnvme, nvme-cli fixes the following issues:
Fix: libnvme/nvme-cli TLS PSK generation logic not compliant to RFC 8446: (bsc#1246914)
* linux: use EVP_PKEY_CTX_add1_hkdf_info only once in compat function
* nvme/linux: check for empty digest in gen_tls_identity()
* nvme/linux: add fallback implementation for nvme_insert_tls_key_compat()
* linux: fix HKDF TLS key derivation back to OpenSSL 3.0.8
* libnvme: TLS PSK derivation fixes
* linux: rename __nvme_insert_tls_key_versioned() to __nvme_insert_tls_key()
* linux: rename __nvme_insert_tls_key() to __nvme_import_tls_key()
* test/psk: add testcase for TLS identity derivation
* linux: set errno when nvme_generate_tls_key_identity() fails
* nvme: add --compat flag for 'gen-tls-key' and 'check-tls-key'
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3129-1
Released: Mon Jul 20 11:41:29 2026
Summary: Recommended update for tiertune
Type: recommended
Severity: moderate
References:
This update for tiertune fixes the following issues:
- Implement the package 'tiertune' to dynamically configure systemd and kernel settings
based on specific cloud instance types across GCE, AWS, and Azure
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3391-1
Released: Tue Jul 28 18:49:41 2026
Summary: Recommended update for tiertune
Type: recommended
Severity: moderate
References:
This update for tiertune fixes the following issues:
- Add KernelWorkQueue class:
* Introduces KernelWorkQueue, a new settings class parallel
to CPUPower, for managing kernel workqueue parameters. (jsc#PCT-1941)
- Add X4 watchdog settings:
* Add watchdog_thresh=60 and workqueue.watchdog_thresh=120
to be set by the sysctl component. (jsc#PCT-1941)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3833-1
Released: Thu Aug 27 08:41:53 2026
Summary: Recommended update for tiertune
Type: recommended
Severity: moderate
References:
This update for tiertune fixes the following issues:
- Upgrade to version 0.1.3:
* Fix the regular expression for X4 matching:
+ The instance identifier is 'x4-480-8t-metal'.
A missing '.' in the regular expression caused a match failure as
the previous expression stopped matching after the firt hyphen.
* Start after the network is available:
+ We need to reach out to the metadata server to get instance data information.
Therefore we cannot run tiertune until after the network is online.
* Expand instance type matching for X4:
+ Modify the expression to match the configuration for X4 and X5 instances in GCE.
The currently used expression will not match and as such the settings do not get applied.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3860-1
Released: Fri Aug 28 15:04:38 2026
Summary: Security update for rsyslog
Type: security
Severity: important
References: 1275926
This update for rsyslog fixes the following issue:
- Heap buffer overflow in the core `RainerScript` `replace()` function (bsc#1275926).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3866-1
Released: Fri Aug 28 19:29:09 2026
Summary: Security update for openssl-3
Type: security
Severity: important
References: 1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803
This update for openssl-3 fixes the following issues:
August 2026 release .
- CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795).
- CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788).
- CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797).
- CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790).
- CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3878-1
Released: Mon Aug 31 11:12:55 2026
Summary: Security update for openssl-1_1
Type: security
Severity: important
References: 1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072
This update for openssl-1_1 fixes the following issues:
- CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795).
- CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788).
Changes for openssl-1_1:
- August 2026 release (bsc#1274774)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3926-1
Released: Thu Sep 3 02:04:11 2026
Summary: Recommended update for crypto-policies
Type: recommended
Severity: important
References: 1242233,1243830,1277267
This update for crypto-policies fixes the following issues:
- Allow openssl to load when using the DEFAULT policy, and also
other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3927-1
Released: Thu Sep 3 06:27:06 2026
Summary: Recommended update for shadow
Type: recommended
Severity: important
References: 1259542,1275902
This update for shadow fixes the following issues:
- Mark /etc/default/useradd as %config(noreplace) to restore the behavior
prior to the file being removed from shadow. (bsc#1275902)
- Fix regression caused in (bsc#1259542)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3961-1
Released: Thu Sep 3 15:32:38 2026
Summary: Security update for suseconnect-ng
Type: security
Severity: moderate
References: 1159776,1267478,1268596,1268900,1270392
This update for suseconnect-ng fixes the following issue:
- Update version to 1.23.0:
- Use product identifier for product migrations. (bsc#1268596)
- Switch to using go1.26-openssl as the default Go version to
install to support building the package (jsc#SCC-843, bsc#1268900).
- Fix flag parsing so that unknown flags or options are flagged as an
error and the usage message is displayed. (bsc#1159776)
- InstallReleasePackage interactive/noninteractive handling should
be consistent with DistUpgrade (bsc#1267478).
- Add new optional rpm_packages collector, disabled by default, to
collect list of installed SUSE vendored RPM packages. (jsc#TEL-298)
- Allow deregsiter when subscribed regcode has expired (bsc#1270392,
jsc#865)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3966-1
Released: Fri Sep 4 08:10:54 2026
Summary: Recommended update for azure-vm-utils
Type: recommended
Severity: moderate
References: 1274079,1274081,1274083
This update for azure-vm-utils fixes the following issues:
- Update to version 0.7.0 (bsc#1274079, bsc#1274081, bsc#1274083)
* feat(udev): set queue/io_timeout=240s for remote Azure NVMe devices
* ci(main): do a debug build to ensure -Werror is used
* build(deps): bump urllib3 from 2.2.3 to 2.5.0 in /selftest
* build(deps): bump requests from 2.32.3 to 2.32.4 in /selftest
* fix(tests): include stdint.h to fix compilation errors
* feat(azure-ephemeral-disk-setup): introduce experimental service for
managing ephemeral disks
- Update to version 0.6.0:
* feat(unmanaged-sriov): add udev & networkd support for unmanaged devices
* fix(specs/fedora): fix builds for f42/rawhide
* test(selftest): add coverage for networking rules
* feat(networkd): increase priority for azure-unmanaged-sriov.network
- Add new files and directories in %files section
- Add %service_add_pre, %service_del_preun, %service_add_post and
%service_del_postun for azure-ephemeral-disk-setup.service
- Uprev to 0.5.1 which includes minor fixes and man-page improvements
- Update to version 0.5.0:
* Add new dependencies for json-c and libcmocka for unit tests
* Remove selftest executable and manpage from installed files
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3980-1
Released: Sun Sep 6 09:44:23 2026
Summary: Recommended update for libtirpc
Type: recommended
Severity: important
References: 1274740
This update for libtirpc fixes the following issues:
- Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740):
* rpcb_clnt.c: fix memory leak in destroy_addr
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3997-1
Released: Mon Sep 7 09:22:53 2026
Summary: Security update for dracut
Type: security
Severity: important
References: 1268322,1273580,CVE-2026-16445,CVE-2026-6893
This update for dracut fixes the following issues:
Update to version 059+suse.730.g73d3411aa.
- CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution
within the `initramfs` (bsc#1268322).
- CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution
within the `initramfs` during system boot (bsc#1273580).
Changes for dracut:
- Update to version 059+suse.730.g73d3411aa:
* fix(network-legacy): sanitize values written to /tmp/net.${netif}.override
* fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw
* fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname
* fix(network-legacy): strip DHCP-supplied domain to a safe charset
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4012-1
Released: Mon Sep 7 09:34:33 2026
Summary: Security update for cpio
Type: security
Severity: moderate
References: 1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486
This update for cpio fixes the following issues:
- CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard
links outside intended directory via malicious tar archives (bsc#1274856).
- CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of
service via crafted archives (bsc#1274857).
- CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for
terminal control sequence injection via crafted archive member names (bsc#1274858).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4021-1
Released: Mon Sep 7 09:41:23 2026
Summary: Security update for c-ares
Type: security
Severity: important
References: 1220279,1240955,1254738,1270416,1276290,1276291,CVE-2024-25629,CVE-2025-31498,CVE-2025-62408,CVE-2026-33630,CVE-2026-69184,CVE-2026-69186
This update for c-ares fixes the following issues:
- CVE-2024-25629: out of bounds read in ares__read_line() (bsc#1220279).
- CVE-2025-31498: use-after-free in read_answers() when process_answer() may re-enqueue a query (bsc#1240955).
- CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (bsc#1254738).
- CVE-2026-33630: Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via
ares_getaddrinfo() over TCP (bsc#1270416).
- CVE-2026-69184: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290).
- CVE-2026-69186: Memory-amplification denial of service via unvalidated DNS header record counts (bsc#1276291).
Changes for c-ares:
- updated to 1.36.8.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4047-1
Released: Mon Sep 7 15:53:38 2026
Summary: Security update for curl
Type: security
Severity: moderate
References: 1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926
This update for curl fixes the following issues:
- CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633).
- CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440).
- CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412).
- CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476).
- CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479).
- CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480).
Changes for curl:
- Call http_size() first to prioritize Transfer-Encoding: chunked over a zero
Content-Length empty body check (bsc#1264971)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4050-1
Released: Mon Sep 7 15:55:07 2026
Summary: Security update for libusb-1_0
Type: security
Severity: moderate
References: 1266664,CVE-2026-23679
This update for libusb-1_0 fixes the following issue:
- CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a
malformed USB configuration descriptor (bsc#1266664).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4055-1
Released: Mon Sep 7 17:48:12 2026
Summary: Security update for bzip2
Type: security
Severity: low
References: 1266786,CVE-2026-42250
This update for bzip2 fixes the following issue:
- CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a
crash (bsc#1266786).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:4085-1
Released: Tue Sep 8 12:19:46 2026
Summary: Recommended update for cloud-init
Type: recommended
Severity: important
References: 1274554
This update for cloud-init fixes the following issues:
- Fix: SLEM 6.1 is assigned systemd-timesyncd by cloudinit (bsc#1274554)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:4101-1
Released: Wed Sep 9 14:07:04 2026
Summary: Recommended update for rsyslog
Type: recommended
Severity: moderate
References: 1274610
This update for rsyslog fixes the following issues:
- gtls: guard early debug-level lookup (bsc#1274610)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4112-1
Released: Wed Sep 9 18:17:10 2026
Summary: Security update for libzypp, zypper
Type: security
Severity: critical
References: 1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790
This update for libzypp, zypper fixes the following issues:
Security issue fixed:
- invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625).
- hasCredentials() requires both username AND password to be non-empty (bsc#1273242).
- GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730).
Non security issues fixed:
- Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534).
- libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321).
- Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249).
- zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091).
- Zypper patch doesn't give enough details about conflicts (bsc#1277790).
- dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038).
Changes for libzypp:
- Update to version 17.38.15:
- Prevent libgpgme from launching gpg-agents; we don't need them.
- defaultLoadSystem: Hand out the ZYpp::Ptr as return value.
- Replace popen cat/zcat with solv_xfopen for testcase loaders
(fixes #749)
- zypp: Improve Testcase Loading for MCP Tools.
- spec: Remove useless %bcond visibility_hidden (is always ON in
cmake)
- zypp.conf: add solver.NoUpdateProvide (default: false) option.
Changes for zypper:
- Update to version 1.14.101.
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:4116-1
Released: Wed Sep 9 21:41:52 2026
Summary: Recommended update for crypto-policies
Type: recommended
Severity: important
References: 1242233,1243830,1277267
This update for crypto-policies fixes the following issues:
- Revert the previous change since the syntax is not understood in
this crypto-policies version. (bsc#1243830, bsc#1242233, bsc#1277267)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:4124-1
Released: Thu Sep 10 18:11:41 2026
Summary: Recommended update for glibc
Type: recommended
Severity: moderate
References: 1277247
This update for glibc fixes the following issues:
- Add -flive-patching=inline-clone to avoid untraceable inter-procedural
optimizations (bsc#1277247).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:4142-1
Released: Mon Sep 14 09:59:10 2026
Summary: Recommended update for permissions
Type: recommended
Severity: moderate
References: 1278351
This update for permissions fixes the following issue:
- Update to version 20240826:
* profiles: backport nvidia-modprobe (bsc#1278351)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4176-1
Released: Mon Sep 14 12:29:48 2026
Summary: Security update for acl, attr
Type: security
Severity: important
References: 1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371
This update for acl, attr fixes the following issue:
- CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr,
getfacl/setfacl/chacl, libacl (bsc#1268867).
Changes for acl:
- Update to 2.4.0 (jsc#PED-16501):
Major Issues Fixed:
- The libacl library functions acl_get_file(), acl_set_file(),
acl_extended_file(), and acl_delete_def_file() take a pathname argument
and follow symbolic links. When a privileged user calls one of those
functions, an attacker that controls a pathname component can replace a
file or directory with a symbolic link and redirect the operation to a
different file. This can lead to local privilege escalation.
(CVE-2026-54369, bsc#1268867)
The library functions cannot be fixed without breaking compatibility; the
described behaviour is by design.
Instead, version 2.4.0 of the acl package introduces the additional
functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and
acl_delete_def_file_at(). These functions each take a dirfd file
descriptor argument and an at_flags argument and accept the
AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to
control when to follow symbolic links. (CVE-2026-54370, bsc#1268867)
In addition, the libacl functions acl_get_fd(), acl_set_fd(), and
acl_extended_fd() functions always operate on the access ACL; the library
previously did not offer a way to operate on the default ACL of a directory
file descriptor. The new functions remove that restriction.
It will be up to each individual program to start using these new library
functions where appropriate.
- When walking directory trees, the getfacl, setfacl, chacl, and getfattr
utilities constructed the full pathname of each file in the tree and use that
pathname to access the file. When a privileged user used those utilities,
an attacker that controlled a pathname component could replace a directory with
a symbolic link and redirect the operation to a different file, leading to
a local privilege escalation. (CVE-2026-54371, bsc#1268867)
This is fixed by using directory file descriptors and operating relative to
those directory file descriptors.
- When resolving the final pathname component, the getfacl, setfacl, chacl,
getfattr, and setfattr utilities in some cases used functions that resolve
symbolic links. This includes the above mentioned libacl functions, but
also stat(), chmod(), and chown().
This is fixed by using symlink-safe functions throughout the code.
- When restoring a backup, the setfacl and setfattr utilities read the full
pathnames of files from the backup. When those pathnames were resolved,
pathname components that are symbolic links were traversed. An attacker
that controlled a pathname component could replace it with a symbolic link,
causing a privileged user to operate on a file other than the one intended.
This could lead to the same kind of local privilege escalation as discussed
before.
This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the
directory components of a pathname, but see Compatibility Notes below for
the details.
Minor Issues Fixed:
- When a symbolic link was specified on the command line but symbolic link
traversal was disabled using option -P (--physical), the getfacl and
setfacl utilities previously silently ignored the symlink. Now, an ELOOP
('Too many levels of symbolic links') error will result instead.
- acl_delete_entry() now verifies that the specified entry belongs to the
specified acl.
- Numeric uids and gids that cannot be represented in types uid_t and gid_t
are checked more carefully and invalid numbers are rejected.
- Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry
several times when the size of an ACL grows unexpectedly; previously, they
only grew the allocated buffer once before giving up.
- When passed a directory file descriptor, function perm_copy_fd() didn't
copy the default ACL from one directory to the other. It now does.
- setfacl --restore accidentally ignored leading whitespace in filenames. It
no longer does.
- setfacl --restore accidentally called chmod() when in --test mode. It no
longer does.
- When the setfattr --restore option was used multiple times, a buffer was
accessed after being freed. This no longer happens.
- When the setfattr -h (--no-dereference) option was given after --restore,
it was ignored. Now, the options can be passed in any order.
- The -h (--no-dereference) option of getfattr prevented getfattr from
recursing into 'symbolic link directories'. This is wrong. When dirlink
is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now
visit that directory. The -P (--physical) option can be used to prevent
that.
- Similarly, when a symbolic link referring to a directory was specified on
the getfacl or setfacl command line, the -R option did not cause that
directory to be visited. This has been fixed so that those directories
will now be visited. The -P (--physical) option can be used to prevent
Changes for attr:
- Update to 2.6.0 (jsc#PED-16501):
Major Issues Fixed:
- The libacl library functions acl_get_file(), acl_set_file(),
acl_extended_file(), and acl_delete_def_file() take a pathname argument
and follow symbolic links. When a privileged user calls one of those
functions, an attacker that controls a pathname component can replace a
file or directory with a symbolic link and redirect the operation to a
different file. This can lead to local privilege escalation.
(CVE-2026-54369, bsc#1268867)
The library functions cannot be fixed without breaking compatibility; the
described behaviour is by design.
Instead, version 2.4.0 of the acl package introduces the additional
functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and
acl_delete_def_file_at(). These functions each take a dirfd file
descriptor argument and an at_flags argument and accept the
AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to
control when to follow symbolic links. (CVE-2026-54370, bsc#1268867)
In addition, the libacl functions acl_get_fd(), acl_set_fd(), and
acl_extended_fd() functions always operate on the access ACL; the library
previously did not offer a way to operate on the default ACL of a directory
file descriptor. The new functions remove that restriction.
It will be up to each individual program to start using these new library
functions where appropriate.
- When walking directory trees, the getfacl, setfacl, chacl, and getfattr
utilities constructed the full pathname of each file in the tree
and use that
pathname to access the file. When a privileged user used those utilities,
an attacker that controlled a pathname component could replace a
directory with
a symbolic link and redirect the operation to a different file, leading to
a local privilege escalation. (CVE-2026-54371, bsc#1268867)
This is fixed by using directory file descriptors and operating relative to
those directory file descriptors.
- When resolving the final pathname component, the getfacl, setfacl, chacl,
getfattr, and setfattr utilities in some cases used functions that resolve
symbolic links. This includes the above mentioned libacl functions, but
also stat(), chmod(), and chown().
This is fixed by using symlink-safe functions throughout the code.
- When restoring a backup, the setfacl and setfattr utilities read the full
pathnames of files from the backup. When those pathnames were resolved,
pathname components that are symbolic links were traversed. An attacker
that controlled a pathname component could replace it with a symbolic link,
causing a privileged user to operate on a file other than the one intended.
This could lead to the same kind of local privilege escalation as discussed
before.
This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the
directory components of a pathname, but see Compatibility Notes below for
the details.
Minor Issues Fixed:
- When a symbolic link was specified on the command line but symbolic link
traversal was disabled using option -P (--physical), the getfacl and
setfacl utilities previously silently ignored the symlink. Now, an ELOOP
('Too many levels of symbolic links') error will result instead.
- acl_delete_entry() now verifies that the specified entry belongs to the
specified acl.
- Numeric uids and gids that cannot be represented in types uid_t and gid_t
are checked more carefully and invalid numbers are rejected.
- Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry
several times when the size of an ACL grows unexpectedly; previously, they
only grew the allocated buffer once before giving up.
- When passed a directory file descriptor, function perm_copy_fd() didn't
copy the default ACL from one directory to the other. It now does.
- setfacl --restore accidentally ignored leading whitespace in filenames. It
no longer does.
- setfacl --restore accidentally called chmod() when in --test mode. It no
longer does.
- When the setfattr --restore option was used multiple times, a buffer was
accessed after being freed. This no longer happens.
- When the setfattr -h (--no-dereference) option was given after --restore,
it was ignored. Now, the options can be passed in any order.
- The -h (--no-dereference) option of getfattr prevented getfattr from
recursing into 'symbolic link directories'. This is wrong. When dirlink
is a symbolic link that refers to a directory, 'getfattr -Rh
dirlink' will now
visit that directory. The -P (--physical) option can be used to prevent
that.
- Similarly, when a symbolic link referring to a directory was specified on
the getfacl or setfacl command line, the -R option did not cause that
directory to be visited. This has been fixed so that those directories
will now be visited. The -P (--physical) option can be used to prevent
- update to 2.5.2:
* attr: eliminate a dead store in attr_copy_action()
* libattr: Set symbol versions for legacy syscalls via attribute
or asm
* exports: use LGPL for library code
* documentation updates
* translation updates (Polish, Dutch, Gregorian, French)
* build system updates
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4194-1
Released: Tue Sep 15 16:27:47 2026
Summary: Security update for libpcap
Type: security
Severity: important
References: 1279584,1279588,1279593,1279595,1279782,1279783,1279784,CVE-2026-0799,CVE-2026-18238,CVE-2026-18313,CVE-2026-31911,CVE-2026-31912,CVE-2026-6244,CVE-2026-6554
This update for libpcap fixes the following issues:
- CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a
scratch memory register and allows for OOB access (bsc#1279782).
- CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the
immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero
(bsc#1279595).
- CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward
jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584).
- CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly
validates its headers and allows for an OOB access (bsc#1279783).
- CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ`
message received from the client and never frees the memory (bsc#1279784).
- CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode.
In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588).
- CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a
return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff
(bsc#1279593).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4207-1
Released: Wed Sep 16 10:21:54 2026
Summary: Security update for kbd
Type: security
Severity: important
References: 1275441,CVE-2026-72693
This update for kbd fixes the following issue:
- CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows
`passwordless` root login (bsc#1275441).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4241-1
Released: Thu Sep 17 13:48:51 2026
Summary: Security update for pcre2
Type: security
Severity: important
References: 1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161
This update for pcre2 fixes the following issues:
- CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893).
- CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054).
- CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053).
- CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052).
- CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject
(bsc#1280051).
- CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match`
(bsc#1280050).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4250-1
Released: Thu Sep 17 18:00:36 2026
Summary: Security update for glibc
Type: security
Severity: moderate
References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489
This update for glibc fixes the following issues:
- CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726).
- CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723).
- CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262).
- CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892).
- CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946).
- CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921).
- CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4275-1
Released: Mon Sep 21 09:32:08 2026
Summary: Security update for jq
Type: security
Severity: important
References: 1215737,1218034,1218038,1238078,1248600,1262043,1262072,1265060,1265061,1265062,1265070,1265071,1265075,1265076,1269220,1269221,1269390,976992,CVE-2015-8863,CVE-2023-50246,CVE-2023-50268,CVE-2024-53427,CVE-2025-9403,CVE-2026-33948,CVE-2026-40164,CVE-2026-40612,CVE-2026-41256,CVE-2026-41257,CVE-2026-43894,CVE-2026-43895,CVE-2026-43896,CVE-2026-44777,CVE-2026-47770,CVE-2026-49839,CVE-2026-54679
This update for jq fixes the following issues:
Security issues fixed:
- CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992).
- CVE-2023-50246: improper memory handling can lead to a heap buffer overflow in `decNumberToString` (bsc#1218034).
- CVE-2023-50268: stack-based buffer overflow in builds using decNumber (bsc#1218038).
- CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in decNumber.c (bsc#1238078).
- CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600).
- CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043).
- CVE-2026-40164: predictable hash collisions can lead to a denial of service (bsc#1262072).
- CVE-2026-40612: jv_contains recurses into nested arrays/objects with no depth limit and can cause a stack overflow
(bsc#1265060).
- CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f and can lead to execution of unintended
programs (bsc#1265061).
- CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS (bsc#1265062).
- CVE-2026-43894: signed integer overflow in `decNumber` can lead to out-of-bounds memory write (bsc#1265070).
- CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure
(bsc#1265071).
- CVE-2026-43896: unbounded recursion in `jv_object_merge_recursive()` can lead to C stack exhaustion and a process
crash (bsc#1265075).
- CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead
to stack exhaustion and process crash (bsc#1265076).
- CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221).
- CVE-2026-49839: `--rawfile` invalid-state reuse after `String too long` can lead to a heap buffer overflow
(bsc#1269220).
- CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer overrun on 32-bit systems (bsc#1269390).
Changes for jq:
Update to version 1.7.1:
* Make the default background color more suitable for bright
backgrounds.
* Allow passing the inline jq script after --.
* Fix possible uninitialised value dereference if jq_init() fails
* Simplify paths/0 and paths/1.
* Reject U+001F in string literals.
* Remove unused nref accumulator in block_bind_library.
* Remove a bunch of unused variables, and useless assignments.
* main.c: Remove unused EXIT_STATUS_EXACT option.
* Actually use the number correctly casted from double to int as
index.
* src/builtin.c: remove unnecessary jv_copy-s in
type_error/type_error2.
* Remove undefined behavior caught by LLVM 10 UBSAN.
* Convert decnum to binary64 (double) instead of decimal64.
This makes jq behave like the JSON specification suggests and
more similar to other languages.
* Fix memory leaks on invalid input for ltrimstr/1 and
rtrimstr/1.
* Fix memory leak on failed get for setpath/2.
* Fix nan from json parsing also for nans with payload that
start with 'n'.
* Allow carriage return characters in comments.
* Generate links in the man page.
* Add extern C for C++.
* Make object key color configurable using JQ_COLORS environment
variable.
* Change the default color of null to Bright Black.
* Respect NO_COLOR environment variable to disable color output.
* Improved --help output. Now mentions all options and nicer
order.
* Fix multiple issues of exit code using --exit-code/-e option.
* Add --raw-output0 for NUL (zero byte) separated output.
* Fix assert crash and validate JSON for --jsonarg.
* Remove deprecated --argfile option.
* Use decimal number literals to preserve precision. Comparison
operations respects precision but arithmetic operations might
truncate.
* Adds new builtin pick(stream) to emit a projection of the
input object or array.
* Adds new builtin debug(msgs) that works like debug but applies
a filter on the input before writing to stderr.
* Adds new builtin scan($re; $flags). Was documented but not
implemented.
* Adds new builtin abs to get absolute value. This potentially
allows the literal value of numbers to be preserved as length
and fabs convert to float.
* Allow if without else-branch. When skipped the else-branch
will be . (identity).
* Allow use of $binding as key in object literals.
* Allow dot between chained indexes when using .['index']
* Allow dot for chained value iterator .[], .[]?
* Fix try/catch catches more than it should.
* Speed up and refactor some builtins, also remove
scalars_or_empty/0.
* Now halt and halt_error exit immediately instead of continuing
to the next input.
* Fix issue converting string to number after previous convert
error.
* Fix issue representing large numbers on some platforms causing
invalid JSON output.
* Fix deletion using assigning empty against arrays.
* Allow keywords to be used as binding name in more places.
* Allow using nan as NaN in JSON.
* Expose a module's function names in modulemeta.
* Fix contains/1 to handle strings with NUL.
* Fix stderr/0 to output raw text without any decoration.
* Fix nth/2 to emit empty on index out of range.
* Fix implode to not assert and instead replace invalid unicode
codepoints.
* Fix indices/1 and rindex/1 in case of overlapping matches in
strings.
* Fix sub/3 to resolve issues involving global search-and-replace
(gsub) operations.
* Fix empty regular expression matches.
* Fix overflow exception of the modulo operator.
* Fix string multiplication by 0 (and less than 1) to emit empty
string.
* Fix segfault when using libjq and threads.
* Fix constant folding of division and reminder with zero
divisor.
* Fix error/0, error/1 to throw null error.
* Simpler and faster transpose.
* Simple and efficient implementation of walk/1.
* Remove deprecated filters leaf_paths, recurse_down.
The following package changes have been done:
- azure-vm-utils-0.7.0-150500.11.6.1 updated
- cloud-init-config-suse-25.1.3-150400.15.13.3 updated
- cloud-init-25.1.3-150400.15.13.3 updated
- cpio-2.13-150400.3.10.1 updated
- crypto-policies-scripts-20230920.570ea89-150600.3.22.1 added
- crypto-policies-20230920.570ea89-150600.3.22.1 updated
- curl-8.14.1-150600.4.51.1 updated
- dracut-fips-059+suse.571.g3d42218af-150600.3.35.1 added
- dracut-059+suse.571.g3d42218af-150600.3.35.1 updated
- glibc-locale-base-2.38-150600.14.58.1 updated
- glibc-2.38-150600.14.58.1 updated
- jq-1.7.1-150000.3.25.1 updated
- kbd-legacy-2.4.0-150400.5.12.1 updated
- kbd-2.4.0-150400.5.12.1 updated
- libacl1-2.4.0-150000.4.6.1 updated
- libattr1-2.6.0-150000.4.3.1 updated
- libbz2-1-1.0.8-150400.3.4.1 updated
- libcares2-1.34.8-150000.3.29.1 updated
- libcurl4-8.14.1-150600.4.51.1 updated
- libjq1-1.7.1-150000.3.25.1 updated
- libjson-c3-0.13-3.3.1 added
- libkcapi-tools-0.13.0-150600.17.3.1 added
- libnvme-mi1-1.8+93.g5986a5a7-150600.3.21.1 added
- libnvme1-1.8+93.g5986a5a7-150600.3.21.1 added
- libopenssl-3-fips-provider-3.1.4-150600.5.64.1 added
- libopenssl1_1-1.1.1w-150600.5.38.1 updated
- libopenssl3-3.1.4-150600.5.64.1 updated
- libpcap1-1.10.4-150600.3.12.1 updated
- libpcre2-8-0-10.42-150600.3.3.1 updated
- libsubid5-4.17.2-150600.17.24.1 updated
- libtirpc-netconfig-1.3.4-150300.3.26.1 updated
- libtirpc3-1.3.4-150300.3.26.1 updated
- libusb-1_0-0-1.0.24-150400.3.6.1 updated
- libzypp-17.38.15-150600.3.95.1 updated
- login_defs-4.17.2-150600.17.24.1 updated
- nvme-cli-2.8+95.g1a0c2083-150600.3.24.1 added
- openssh-fips-9.6p1-150600.6.49.1 added
- openssl-3-3.1.4-150600.5.64.1 updated
- patterns-base-fips-20200124-150600.32.6.1 added
- permissions-20240826-150600.10.21.1 updated
- python3-azuremetadata-5.1.6-150000.1.26.1 added
- python311-configobj-5.0.8-150400.12.9.1 updated
- python311-jsonpatch-1.32-150400.10.9.1 updated
- python311-jsonpointer-2.3-150400.11.9.1 updated
- python311-pyserial-3.5-150400.12.9.1 updated
- python311-tiertune-0.1.3-150600.13.9.1 added
- python3-3.6.15-150300.10.118.1 added
- rsyslog-module-relp-8.2406.0-150600.12.25.1 updated
- rsyslog-8.2406.0-150600.12.25.1 updated
- scap-security-guide-0.1.80-150600.1.38 updated
- shadow-4.17.2-150600.17.24.1 updated
- suseconnect-ng-1.23.0-150600.3.24.1 updated
- tiertune-azure-0.1.3-150600.13.9.1 added
- zypper-1.14.101-150600.10.58.1 updated
More information about the sle-container-updates
mailing list