SUSE-IU-2026:7346-1: Security update of sles-15-sp6-chost-byos-v20260923-arm64

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Sep 24 07:04:56 UTC 2026


SUSE Image Update Advisory: sles-15-sp6-chost-byos-v20260923-arm64
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:7346-1
Image Tags        : sles-15-sp6-chost-byos-v20260923-arm64:20260923
Image Release     : 
Severity          : critical
Type              : security
References        : 1097505 1134510 1159776 1173136 1210617 1212476 1215737 1216545
                        1218034 1218038 1218588 1218664 1220279 1222768 1222985 1223571
                        1224014 1224016 1225660 1226447 1226448 1227308 1227378 1227999
                        1228105 1228165 1228780 1229596 1229704 1230227 1230906 1231795
                        1232241 1236705 1238078 1238450 1239210 1240955 1241067 1242233
                        1242233 1243197 1243273 1243313 1243830 1243830 1244032 1244056
                        1244059 1244060 1244061 1244705 1245938 1245939 1245942 1245943
                        1245946 1246570 1247249 1248600 1251305 1252974 1252974 1253357
                        1254255 1254400 1254400 1254401 1254401 1254738 1254997 1254997
                        1257029 1257029 1257031 1257031 1257041 1257042 1257042 1257044
                        1257046 1257046 1257108 1257181 1257249 1258364 1259240 1259542
                        1259611 1259734 1259735 1259989 1260026 1260264 1260446 1261038
                        1261969 1261970 1262043 1262072 1262098 1262319 1262633 1262654
                        1263083 1263440 1264962 1264971 1265060 1265061 1265062 1265070
                        1265071 1265075 1265076 1265268 1266664 1266786 1267478 1267581
                        1267610 1267821 1268321 1268322 1268375 1268412 1268596 1268867
                        1268900 1268977 1269066 1269220 1269221 1269390 1269788 1269959
                        1270392 1270416 1271192 1271730 1272118 1272118 1272534 1273242
                        1273580 1274091 1274610 1274625 1274723 1274726 1274740 1274774
                        1274774 1274788 1274788 1274790 1274795 1274795 1274797 1274856
                        1274857 1274858 1275441 1275837 1275902 1275926 1276290 1276291
                        1276722 1276892 1276946 1277247 1277262 1277267 1277267 1277476
                        1277479 1277480 1277707 1277708 1277709 1277710 1277711 1277713
                        1277790 1277921 1277922 1278351 1278597 1278597 1278967 1278967
                        1279297 1279297 1279414 1279414 1279584 1279588 1279593 1279595
                        1279782 1279783 1279784 1279893 1280050 1280051 1280052 1280053
                        1280054 976992 CVE-2015-8863 CVE-2023-27043 CVE-2023-30608 CVE-2023-50246
                        CVE-2023-50268 CVE-2024-0397 CVE-2024-12718 CVE-2024-25629 CVE-2024-4032
                        CVE-2024-53427 CVE-2024-6232 CVE-2024-6345 CVE-2024-6923 CVE-2024-7592
                        CVE-2024-8088 CVE-2024-9287 CVE-2025-0938 CVE-2025-11468 CVE-2025-11468
                        CVE-2025-12084 CVE-2025-12084 CVE-2025-12781 CVE-2025-13462 CVE-2025-13836
                        CVE-2025-13836 CVE-2025-13837 CVE-2025-13837 CVE-2025-15282 CVE-2025-15282
                        CVE-2025-15366 CVE-2025-15367 CVE-2025-1795 CVE-2025-27613 CVE-2025-27614
                        CVE-2025-31498 CVE-2025-4138 CVE-2025-4330 CVE-2025-4435 CVE-2025-4516
                        CVE-2025-4517 CVE-2025-46835 CVE-2025-47273 CVE-2025-48384 CVE-2025-48385
                        CVE-2025-6069 CVE-2025-6075 CVE-2025-6075 CVE-2025-62408 CVE-2025-8194
                        CVE-2025-8291 CVE-2025-9403 CVE-2026-0672 CVE-2026-0672 CVE-2026-0799
                        CVE-2026-0864 CVE-2026-0865 CVE-2026-0865 CVE-2026-11940 CVE-2026-11972
                        CVE-2026-1299 CVE-2026-13608 CVE-2026-1502 CVE-2026-15308 CVE-2026-16445
                        CVE-2026-18238 CVE-2026-18313 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542
                        CVE-2026-2297 CVE-2026-23679 CVE-2026-31911 CVE-2026-31912 CVE-2026-3276
                        CVE-2026-3276 CVE-2026-33186 CVE-2026-33630 CVE-2026-33948 CVE-2026-3446
                        CVE-2026-3479 CVE-2026-3644 CVE-2026-40164 CVE-2026-40612 CVE-2026-41178
                        CVE-2026-41256 CVE-2026-41257 CVE-2026-4224 CVE-2026-42250 CVE-2026-4360
                        CVE-2026-43894 CVE-2026-43895 CVE-2026-43896 CVE-2026-44777 CVE-2026-4519
                        CVE-2026-47770 CVE-2026-4786 CVE-2026-49839 CVE-2026-54369 CVE-2026-54370
                        CVE-2026-54371 CVE-2026-54679 CVE-2026-54874 CVE-2026-54874 CVE-2026-56852
                        CVE-2026-56852 CVE-2026-56854 CVE-2026-56854 CVE-2026-56855 CVE-2026-56855
                        CVE-2026-5773 CVE-2026-6019 CVE-2026-6019 CVE-2026-6100 CVE-2026-6244
                        CVE-2026-63072 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-6368
                        CVE-2026-6554 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 CVE-2026-6791
                        CVE-2026-6893 CVE-2026-69184 CVE-2026-69186 CVE-2026-7168 CVE-2026-7210
                        CVE-2026-72693 CVE-2026-75803 CVE-2026-77117 CVE-2026-7774 CVE-2026-78662
                        CVE-2026-78662 CVE-2026-80229 CVE-2026-80230 CVE-2026-80489 CVE-2026-8328
                        CVE-2026-84303 CVE-2026-84303 CVE-2026-84304 CVE-2026-84304 CVE-2026-84445
                        CVE-2026-84445 CVE-2026-86145 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158
                        CVE-2026-89160 CVE-2026-89161 CVE-2026-8926 
-----------------------------------------------------------------

The container sles-15-sp6-chost-byos-v20260923-arm64 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2018:1897-1
Released:    Thu Sep 13 15:18:20 2018
Summary:     Recommended update for python3-gcemetadata
Type:        recommended
Severity:    moderate
References:  1097505
This update for python3-gcemetadata fixes the following issues:

- Support instances with multiple Nics. (bsc#1097505)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1323-1
Released:    Mon May 18 11:49:02 2020
Summary:     Recommended update for python3-gcemetadata
Type:        recommended
Severity:    important
References:  1134510
This update for python3-gcemetadata fixes the following issues:

- Fix for the identity data of the instance may not be accessible from the metadata server in Google Cloud client. (bsc#1134510)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2020:1727-1
Released:    Tue Jun 23 15:33:07 2020
Summary:     Recommended update for python3-gcemetadata
Type:        recommended
Severity:    moderate
References:  1173136
This update for python3-gcemetadata fixes the following issues:

Update to version 1.0.4 (bsc#1173136)

- Fixed typo, missing '=' for 'identity' option in processed command
  line options causes mis-identification of instance as missing identity
  data access

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:1637-1
Released:    Tue May 14 14:22:14 2024
Summary:     Recommended update for google-cloud SDK
Type:        recommended
Severity:    moderate
References:  1210617,CVE-2023-30608
This update for  google-cloud SDK fixes the following issues:

- Add python311 cloud services packages and dependencies (jsc#PED-7987, jsc#PED-6697)
- Bellow 5 binaries Obsolete the python3.6 counterpart:
    python311-google-resumable-media
    python311-google-api-core
    python311-google-cloud-storage
    python311-google-cloud-core
    python311-googleapis-common-protos

- Regular python311 updates (without Obsoletes):
    python-google-auth
    python-grpcio
    python-sqlparse

- New python311 packages:
    libcrc32c
    python-google-cloud-appengine-logging
    python-google-cloud-artifact-registry
    python-google-cloud-audit-log
    python-google-cloud-build
    python-google-cloud-compute
    python-google-cloud-dns
    python-google-cloud-domains
    python-google-cloud-iam
    python-google-cloud-kms-inventory
    python-google-cloud-kms
    python-google-cloud-logging
    python-google-cloud-run
    python-google-cloud-secret-manager
    python-google-cloud-service-directory
    python-google-cloud-spanner
    python-google-cloud-vpc-access
    python-google-crc32c
    python-grpc-google-iam-v1
    python-grpcio-status
    python-proto-plus

In python-sqlparse this security issue was fixed:

CVE-2023-30608: Fixed parser that contained a regular expression that is vulnerable to ReDOS (Regular Expression Denial of Service) (bsc#1210617)


-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:2573-1
Released:    Mon Jul 22 12:35:01 2024
Summary:     Recommended update for libkcapi
Type:        recommended
Severity:    moderate
References:  1222768
This update for libkcapi fixes the following issues:

- FIPS: kcapi-hasher: zeroise temporary values for FIPS 140-3

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:2912-1
Released:    Wed Aug 14 20:20:13 2024
Summary:     Recommended update for cloud-regionsrv-client
Type:        recommended
Severity:    important
References:  1222985,1223571,1224014,1224016,1227308
This update for cloud-regionsrv-client contains the following fixes:

- Update to version 10.3.0 (bsc#1227308, bsc#1222985)
  + Add support for sidecar registry
    Podman and rootless Docker support to set up the necessary
    configuration for the container engines to run as defined
  + Add running command as root through sudoers file

- Update to version 10.2.0 (bsc#1223571, bsc#1224014, bsc#1224016)
  + In addition to logging, write message to stderr when registration fails
  + Detect transactional-update system with read only setup and use
    the transactional-update command to register
  + Handle operation in a different target root directory for credentials
    checking

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:2982-1
Released:    Tue Aug 20 11:08:55 2024
Summary:     Security update for python311
Type:        security
Severity:    important
References:  1225660,1226447,1226448,1227378,1227999,1228780,CVE-2023-27043,CVE-2024-0397,CVE-2024-4032,CVE-2024-6923
This update for python311 fixes the following issues:

Security issues fixed:

- CVE-2024-6923: Fixed email header injection due to unquoted newlines (bsc#1228780)
- CVE-2024-5642: Removed support for anything but OpenSSL 1.1.1 or newer (bsc#1227233)
- CVE-2024-4032: Fixed incorrect IPv4 and IPv6 private ranges (bsc#1226448)

Non-security issues fixed:

- Fixed executable bits for /usr/bin/idle* (bsc#1227378).
- Improve python reproducible builds (bsc#1227999)
- Make pip and modern tools install directly in /usr/local when used by the user (bsc#1225660)
- %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:3055-1
Released:    Wed Aug 28 14:49:28 2024
Summary:     Security update for python-setuptools
Type:        security
Severity:    important
References:  1228105,CVE-2024-6345
This update for python-setuptools fixes the following issues:

- CVE-2024-6345: Fixed code execution via download functions in the package_index module (bsc#1228105)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:3427-1
Released:    Tue Sep 24 18:42:49 2024
Summary:     Security update for python311
Type:        security
Severity:    important
References:  1229596,1229704,1230227,CVE-2024-6232,CVE-2024-7592,CVE-2024-8088
This update for python311 fixes the following issues:

Update python311 to version 3.11.10.

- CVE-2024-6232: excessive backtracking when parsing tarfile headers leads to ReDoS. (bsc#1230227)
- CVE-2024-7592: quadratic algorithm used when parsing cookies leads to excessive resource consumption. (bsc#1229596)
- CVE-2024-8088: lack of name validation when extracting a zip archive leads to infinite loops. (bsc#1229704)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:3958-1
Released:    Fri Nov  8 16:25:08 2024
Summary:     Security update for python311
Type:        security
Severity:    moderate
References:  1230906,1232241,CVE-2024-9287
This update for python311 fixes the following issues:

- CVE-2024-9287: Fixed quoted path names provided when creating a virtual environment (bsc#1232241).

Bug fixes:

- Drop .pyc files from docdir for reproducible builds (bsc#1230906).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2024:4045-1
Released:    Mon Nov 25 08:33:05 2024
Summary:     Recommended update for patterns-base
Type:        recommended
Severity:    moderate
References:  
This update for patterns-base fixes the following issue:

- Updated patterns-base, removing plymouth recommendation on s390x archs.
  Our certification team run into an issue (jsc#PED-10532), when they
  run bare metal installation with fully encrypted disk.
  If the whole disk is crypted, the prompt for the password is sent to
  plymouth, which is obviously showing nothing because for booting bare
  metal (LPAR) is used terminal in HMC. 

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:551-1
Released:    Fri Feb 14 16:09:46 2025
Summary:     Security update for python311
Type:        security
Severity:    moderate
References:  1228165,1231795,1236705,CVE-2025-0938
This update for python311 fixes the following issues:

- CVE-2025-0938: domain names containing square brackets are not identified as incorrect by urlparse. (bsc#1236705)
    
Other fixes:

- Update to version 3.11.11.
- Remove -IVendor/ from python-config. (bsc#1231795)
  
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:982-1
Released:    Fri Mar 21 15:17:03 2025
Summary:     Security update for python311
Type:        security
Severity:    low
References:  1238450,1239210,CVE-2025-1795
This update for python311 fixes the following issues:

- CVE-2025-1795: Fixed mishandling of comma during folding and unicode-encoding of email headers (bsc#1238450).
  
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2025:1377-1
Released:    Fri Apr 25 19:43:34 2025
Summary:     Recommended update for patterns-base
Type:        recommended
Severity:    moderate
References:  
This update for patterns-base fixes the following issues:

- add bpftool to patterns enhanced base. jsc#PED-8375

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:1704-1
Released:    Mon May 26 13:02:41 2025
Summary:     Security update for python-setuptools
Type:        security
Severity:    important
References:  1243313,CVE-2025-47273
This update for python-setuptools fixes the following issues:

- CVE-2025-47273: path traversal in PackageIndex.download may lead to an arbitrary file write (bsc#1243313).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:2057-1
Released:    Sat Jun 21 11:04:24 2025
Summary:     Security update for python311
Type:        security
Severity:    important
References:  1241067,1243273,1244032,1244056,1244059,1244060,CVE-2024-12718,CVE-2025-4138,CVE-2025-4330,CVE-2025-4516,CVE-2025-4517
This update for python311 fixes the following issues:
  
python311 was updated from version 3.11.10 to 3.11.13:

- Security issues fixed:

  * CVE-2025-4516: Fixed blocking DecodeError handling vulnerability, which could lead to DoS (bsc#1243273).
  * CVE-2024-12718, CVE-2025-4138, CVE-2025-4330, CVE-2025-4517: Fixed multiple issues that allowed tarfile 
    extraction filters to be bypassed using crafted symlinks and hard links
    (bsc#1244056, bsc#1244059, bsc#1244060, bsc#1244032)

- Other changes and bugs fixed:
 
  * Improved handling of system call failures that OpenSSL reports (bsc#1241067)
  * Disable GC during thread operations to prevent deadlocks.
  * Fixed a potential denial of service vulnerability in the imaplib module.
  * Fixed bugs in the in the folding of rfc2047 encoded-words and in the folding of quoted strings when flattening an
    email message using a modern email policy.
  * Fixed parsing long IPv6 addresses with embedded IPv4 address.
  * Fixed ipaddress.IPv6Address.reverse_pointer output according to RFC 3596
  * Improved the textual representation of IPv4-mapped IPv6 addresses in ipaddress.
  * ipaddress: fixed hash collisions for IPv4Network and IPv6Network objects
  * os.path.realpath() now accepts a strict keyword-only argument.
  * Stop the processing of long IPv6 addresses early in ipaddress to prevent excessive memory consumption and a minor
    denial-of-service.
  * Updated bundled libexpat to 2.7.1
  * Writers of CPython documentation can now use next as the version for the versionchanged, versionadded,
    deprecated directives.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:2717-1
Released:    Wed Aug  6 15:39:46 2025
Summary:     Security update for python311
Type:        security
Severity:    important
References:  1244061,1244705,1247249,CVE-2025-4435,CVE-2025-6069,CVE-2025-8194
This update for python311 fixes the following issues:

- CVE-2025-8194: Fixed denial of service caused by tar archives with negative offsets (bsc#1247249).
- CVE-2025-6069: Avoid worst case quadratic complexity when processing certain crafted malformed inputs with HTMLParser (bsc#1244705).
- CVE-2025-4435: Fixed Tarfile extracting filtered members when errorlevel=0 (bsc#1244061).
  
-----------------------------------------------------------------
Advisory ID: SUSE-OU-2025:2763-1
Released:    Tue Aug 12 14:45:40 2025
Summary:     Optional update for libyaml
Type:        optional
Severity:    moderate
References:  1246570

This update for libyaml ships the missing libyaml-0-2 library package to
SUSE MicroOS 5.1 and 5.2.


-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:3012-1
Released:    Fri Aug 29 02:07:38 2025
Summary:     security update for git, git-lfs, obs-scm-bridge, python-PyYAML
Type:        security
Severity:    important
References:  1212476,1216545,1218588,1218664,1243197,1245938,1245939,1245942,1245943,1245946,CVE-2025-27613,CVE-2025-27614,CVE-2025-46835,CVE-2025-48384,CVE-2025-48385
This update for git, git-lfs, obs-scm-bridge, python-PyYAML fixes the following issues:

git was updated from version 2.43.0 to 2.51.0 (bsc#1243197):

- Security issues fixed:

  * CVE-2025-27613 Fixed arbitrary writable file creation and truncation in Gitk(bsc#1245938)
  * CVE-2025-27614 Fixed arbitrary script execution via repository clonation in gitk(bsc#1245939)
  * CVE-2025-46835 Fixed arbitrary writable file creation in Git GUI when untrusted repository is cloned (bsc#1245942)
  * CVE-2025-48384 Fixed the unintentional execution of a script after checkout due to CRLF transforming (bsc#1245943)
  * CVE-2025-48385 Fixed arbitrary code execution due to protocol injection via fetching advertised bundle(bsc#1245946)

- Other changes and bugs fixed:
    
- Other changes and bugs fixed:
    
  * Added SHA256 support (bsc#1243197)
  * Git moved to /usr/libexec/git/git and updated AppArmor profile
    accordingly (bsc#1218588)
  * gitweb AppArmor profile: allow reading etc/gitweb-common.conf (bsc#1218664)
  * Do not replace apparmor configuration  (bsc#1216545)
  * Fixed the Python version required (bsc#1212476)
    
- Version Updates Release Notes:

  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.51.0.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.50.1.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.50.0.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.49.0.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.48.1.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.48.0.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.47.1.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.47.0.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.46.2.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.46.1.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.46.0.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.45.3.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.45.2.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.45.1.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.45.0.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.44.0.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.3.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.2.adoc
  * https://raw.githubusercontent.com/git/git/master/Documentation/RelNotes/2.43.1.adoc

git-lfs is included in version 3.7.0.

python-PyYAML was updated from version 6.0.1 to 6.0.2:

- Added support for Cython 3.x and Python 3.13

obs-scm-bridge was updated from version 0.5.4 to 0.7.4:

- New Features and Improvements:

  * Manifest File Support: Support has been added for a `_manifest file`, which serves as a successor to the `_subdirs`
    file.
  * Control Over Git Information: A new noobsinfo query parameter was added to hide git information in source and binary
    files.
  * Enhanced Submodule Handling: The system now records the configured branch of submodules and stays on that branch
    during checkout.
  * Git SHA Tracking: In project mode, the tool now uses git SHA sums instead of md5sum to track package sources.
  * SSH URL Support: ssh:// SCM URLs can now be used.
  * Improved Error Messages: Error reporting for invalid files within package subdirectories has been improved.
  * Standardized Config Location: In project mode, the _config file is now always located in the top-level directory,
    even when using subdirs.
  * Reduced Unnecessary Changes: In project mode, unnecessary modifications to the package meta URL are now avoided.
  * Limit Asset Handling: A new mechanism has been introduced to limit how assets are handled.
  * Branch Information Export: The trackingbranch is now exported to scmsync.obsinfo.

- Bugs fixed:

  * Syntax Fix: A syntax issue was corrected.
  * Git Submodule Parsing: The .gitsubmodule parser was fixed to correctly handle files that contain a mix of spaces and
    tabs.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:4297-1
Released:    Fri Nov 28 11:03:19 2025
Summary:     Security update for python311
Type:        security
Severity:    low
References:  1251305,1252974,CVE-2025-6075,CVE-2025-8291
This update for python311 fixes the following issues:

Update to 3.11.14:

  - CVE-2025-6075: Fixed simple quadratic complexity vulnerabilities of os.path.expandvars() (bsc#1252974)
  - CVE-2025-8291: Fixed validity of the ZIP64 End of Central Directory (EOCD) not checked by the 'zipfile' module (bsc#1251305)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:271-1
Released:    Fri Jan 23 12:00:51 2026
Summary:     Recommended update for python-setuptools
Type:        recommended
Severity:    important
References:  1254255
This update for python-setuptools fixes the following issues:

- Implement basic PEP 639 support, (jsc#PED-14457, bsc#1254255)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:314-1
Released:    Wed Jan 28 14:28:46 2026
Summary:     Security update for python311
Type:        security
Severity:    moderate
References:  1254400,1254401,1254997,CVE-2025-12084,CVE-2025-13836,CVE-2025-13837
This update for python311 fixes the following issues:

- CVE-2025-12084: prevent quadratic behavior in node ID cache clearing (bsc#1254997).
- CVE-2025-13836: prevent reading an HTTP response from a server, if no read amount is specified, with using Content-Length per default as the length (bsc#1254400).
- CVE-2025-13837: protect against OOM when loading malicious content (bsc#1254401).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:653-1
Released:    Thu Feb 26 11:55:45 2026
Summary:     Recommended update for python3-gcemetadata, regionServiceClientConfigGCE
Type:        recommended
Severity:    moderate
References:  
This update for python3-gcemetadata, regionServiceClientConfigGCE fixes the following issues:

Changes for python3-gcemetadata:
    
- Update to version 1.1.0 (jsc#PCT-590):
    * Add licenses option in identity command.
    
Changes for regionServiceClientConfigGCE:
    
- Update to version 5.2.0:
    * Drop the if condition for gcemetdata requirement
- Update to version 5.1.0 (jsc#PCT-590):
    * Add licenses info in the metdata
- Accomodate build setup
    * SLE 16 python-requests requires SSL v3 certificates. Update 2

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:767-1
Released:    Tue Mar  3 14:05:42 2026
Summary:     Security update for python311
Type:        security
Severity:    important
References:  1257029,1257031,1257041,1257042,1257044,1257046,1257108,CVE-2025-11468,CVE-2025-12781,CVE-2025-15282,CVE-2025-15366,CVE-2025-15367,CVE-2026-0672,CVE-2026-0865
This update for python311 fixes the following issues:

- CVE-2025-11468: header injection when folding a long comment in an email header containing exclusively unfoldable
  characters (bsc#1257029).
- CVE-2025-12781: inadequate parameter check can cause data integrity issues (bsc#1257108).
- CVE-2025-15282: user-controlled data URLs parsed may allow injecting headers (bsc#1257046).
- CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044).
- CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041).
- CVE-2026-0672: HTTP header injection via user-controlled cookie values and parameters when using http.cookies.Morsel
  (bsc#1257031).
- CVE-2026-0865: user-controlled header containing newlines can allow injecting HTTP headers (bsc#1257042).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1349-1
Released:    Wed Apr 15 15:35:54 2026
Summary:     Security update for python311
Type:        security
Severity:    important
References:  1252974,1254400,1254401,1254997,1257029,1257031,1257042,1257046,1257181,1259240,1259611,1259734,1259735,1259989,1260026,CVE-2025-11468,CVE-2025-12084,CVE-2025-13462,CVE-2025-13836,CVE-2025-13837,CVE-2025-15282,CVE-2025-6075,CVE-2026-0672,CVE-2026-0865,CVE-2026-1299,CVE-2026-2297,CVE-2026-3479,CVE-2026-3644,CVE-2026-4224,CVE-2026-4519
This update for python311 fixes the following issues:

- Updated to Python 3.11.15
- CVE-2025-6075: If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables (bsc#1252974).
- CVE-2025-11468: header injection when folding a long comment in an email header containing exclusively unfoldable characters (bsc#1257029).
- CVE-2025-12084: cpython: python: cpython: Quadratic algorithm in xml.dom.minidom leads to denial of service (bsc#1254997).
- CVE-2025-13462: incorrect parsing of TarInfo header when GNU long name and type AREGTYPE are combined (bsc#1259611).
- CVE-2025-13836: When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length (bsc#1254400).
- CVE-2025-13837: When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues (bsc#1254401).
- CVE-2025-15282: user-controlled data URLs parsed may allow injecting headers (bsc#1257046).
- CVE-2026-0672: HTTP header injection via user-controlled cookie values and parameters when using http.cookies.Morsel (bsc#1257031).
- CVE-2026-0865: user-controlled header containing newlines can allow injecting HTTP headers (bsc#1257042).
- CVE-2026-1299: header injection when an email is serialized due to improper newline quoting in `BytesGenerator` (bsc#1257181).
- CVE-2026-2297: cpython: incorrectly handled hook in FileLoader can lead to validation bypass (bsc#1259240).
- CVE-2026-3479: python: improper resource argument validation can allow path traversal (bsc#1259989).
- CVE-2026-3644: incomplete control character validation in http.cookies (bsc#1259734).
- CVE-2026-4224: C stack overflow when parsing XML with deeply nested DTD content models (bsc#1259735).
- CVE-2026-4519: leading dashes in URLs are accepted by the `webbrowser.open()` API and allow for web browser command line option injection (bsc#1260026).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2298-1
Released:    Mon Jun  8 12:17:11 2026
Summary:     Security update for python311
Type:        security
Severity:    moderate
References:  1258364,1261970,CVE-2026-3446
This update for python311 fixes the following issues:

- CVE-2026-3446: Base64 decoding stops at first padded quad by default (bsc#1261970).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3104-1
Released:    Fri Jul 17 15:31:14 2026
Summary:     Security update for python311
Type:        security
Severity:    important
References:  1261969,1262098,1262319,1262654,CVE-2026-1502,CVE-2026-4786,CVE-2026-6019,CVE-2026-6100
This update for python311 fixes the following issues

- CVE-2026-1502: CR/LF bytes not rejected by HTTP client proxy tunnel headers or host (bsc#1261969).
- CVE-2026-4786: URLs containing `%action` can bypass mitigation that allows command injection via the
  `webbrowser.open()` API (bsc#1262319).
- CVE-2026-6019: HTML parser-sensitive sequence not neutralized by `http.cookies.Morsel.js_output()` (bsc#1262654).
- CVE-2026-6100: use-after-free in decompression modules when a memory allocation fails with a `MemoryError` and the
  decompression instance is re-used (bsc#1262098).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3129-1
Released:    Mon Jul 20 11:41:29 2026
Summary:     Recommended update for tiertune
Type:        recommended
Severity:    moderate
References:  
This update for tiertune fixes the following issues:

- Implement the package 'tiertune' to dynamically configure systemd and kernel settings 
based on specific cloud instance types across GCE, AWS, and Azure
    
  
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3391-1
Released:    Tue Jul 28 18:49:41 2026
Summary:     Recommended update for tiertune
Type:        recommended
Severity:    moderate
References:  
This update for tiertune fixes the following issues:

- Add KernelWorkQueue class:
    * Introduces KernelWorkQueue, a new settings class parallel
      to CPUPower, for managing kernel workqueue parameters. (jsc#PCT-1941)
- Add X4 watchdog settings:
    * Add watchdog_thresh=60 and workqueue.watchdog_thresh=120
      to be set by the sysctl component. (jsc#PCT-1941)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3560-1
Released:    Mon Aug 10 20:09:08 2026
Summary:     Security update for python311
Type:        security
Severity:    important
References:  1264962,1265268,1267581,1267821,1268375,1268977,1269066,1269788,1269959,1271192,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-3276,CVE-2026-4360,CVE-2026-7210,CVE-2026-7774,CVE-2026-8328
This update for python311 fixes the following issues:

Security issues fixed:

- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the
  `configparser` module is used (bsc#1269066).
- CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted
  Unicode input (bsc#1267581).
- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting
  hardlinks (bsc#1269959).
- CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding
  protection (bsc#1264962).
- CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory
  (bsc#1267821).
- CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268).
- CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and
  enables arbitrary file reads and writes (bsc#1268977).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS
  (bsc#1269788).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
  (bsc#1271192).

Non security issue fixed:

- [kernel 7.1] udplite was removed -> python fails in tests (bsc#1268375).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3648-1
Released:    Wed Aug 19 11:54:08 2026
Summary:     Security update for python311
Type:        security
Severity:    important
References:  1263083,CVE-2026-3276,CVE-2026-6019
This update for python311 fixes the following issues:

- Regression in `http.cookies` (bsc#1263083).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3833-1
Released:    Thu Aug 27 08:41:53 2026
Summary:     Recommended update for tiertune
Type:        recommended
Severity:    moderate
References:  
This update for tiertune fixes the following issues:

- Upgrade to version 0.1.3:
    * Fix the regular expression for X4 matching:
        + The instance identifier is 'x4-480-8t-metal'. 
          A missing '.' in the regular expression caused a match failure as 
          the previous expression stopped matching after the firt hyphen.
    * Start after the network is available:
        + We need to reach out to the metadata server to get instance data information.
          Therefore we cannot run tiertune until after the network is online.
    * Expand instance type matching for X4:
        + Modify the expression to match the configuration for X4 and X5 instances in GCE.
          The currently used expression will not match and as such the settings do not get applied.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3860-1
Released:    Fri Aug 28 15:04:38 2026
Summary:     Security update for rsyslog
Type:        security
Severity:    important
References:  1275926
This update for rsyslog fixes the following issue:

- Heap buffer overflow in the core `RainerScript` `replace()` function (bsc#1275926).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3866-1
Released:    Fri Aug 28 19:29:09 2026
Summary:     Security update for openssl-3
Type:        security
Severity:    important
References:  1274774,1274788,1274790,1274795,1274797,1275837,CVE-2026-54874,CVE-2026-63072,CVE-2026-63074,CVE-2026-63076,CVE-2026-75803
This update for openssl-3 fixes the following issues:

August 2026 release .

- CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795).
- CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788).
- CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797).
- CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790).
- CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). 

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3878-1
Released:    Mon Aug 31 11:12:55 2026
Summary:     Security update for openssl-1_1
Type:        security
Severity:    important
References:  1260446,1274774,1274788,1274795,CVE-2026-54874,CVE-2026-63072
This update for openssl-1_1 fixes the following issues:

- CVE-2026-54874: Excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795).
- CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788).

Changes for openssl-1_1:

- August 2026 release (bsc#1274774)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3926-1
Released:    Thu Sep  3 02:04:11 2026
Summary:     Recommended update for crypto-policies
Type:        recommended
Severity:    important
References:  1242233,1243830,1277267
This update for crypto-policies fixes the following issues:

- Allow openssl to load when using the DEFAULT policy, and also
  other policies, in FIPS mode. (bsc#1243830, bsc#1242233, bsc#1277267)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3927-1
Released:    Thu Sep  3 06:27:06 2026
Summary:     Recommended update for shadow
Type:        recommended
Severity:    important
References:  1259542,1275902
This update for shadow fixes the following issues:

- Mark /etc/default/useradd as %config(noreplace) to restore the behavior 
  prior to the file being removed from shadow. (bsc#1275902)
- Fix regression caused in (bsc#1259542)  

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3961-1
Released:    Thu Sep  3 15:32:38 2026
Summary:     Security update for suseconnect-ng
Type:        security
Severity:    moderate
References:  1159776,1267478,1268596,1268900,1270392
This update for suseconnect-ng fixes the following issue:

- Update version to 1.23.0:
 
  - Use product identifier for product migrations. (bsc#1268596)
  - Switch to using go1.26-openssl as the default Go version to 
  install to support building the package (jsc#SCC-843, bsc#1268900).
  - Fix flag parsing so that unknown flags or options are flagged as an 
  error and the usage message is displayed. (bsc#1159776)
  - InstallReleasePackage interactive/noninteractive handling should 
  be consistent with DistUpgrade (bsc#1267478).
  - Add new optional rpm_packages collector, disabled by default, to 
  collect list of installed SUSE vendored RPM packages. (jsc#TEL-298)
  - Allow deregsiter when subscribed regcode has expired (bsc#1270392, 
  jsc#865)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3980-1
Released:    Sun Sep  6 09:44:23 2026
Summary:     Recommended update for libtirpc
Type:        recommended
Severity:    important
References:  1274740
This update for libtirpc fixes the following issues:

- Fix: Possible mem leak from libtirpc [ thread::XRF51s_MK4mkPFEu7JKj0Ss:: ] (bsc#1274740):
    * rpcb_clnt.c: fix memory leak in destroy_addr

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3997-1
Released:    Mon Sep  7 09:22:53 2026
Summary:     Security update for dracut
Type:        security
Severity:    important
References:  1268322,1273580,CVE-2026-16445,CVE-2026-6893
This update for dracut fixes the following issues:

Update to version 059+suse.730.g73d3411aa.

- CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution
  within the `initramfs` (bsc#1268322).
- CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution
  within the `initramfs` during system boot (bsc#1273580).

Changes for dracut:

- Update to version 059+suse.730.g73d3411aa:
  * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override
  * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw
  * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname
  * fix(network-legacy): strip DHCP-supplied domain to a safe charset

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4012-1
Released:    Mon Sep  7 09:34:33 2026
Summary:     Security update for cpio
Type:        security
Severity:    moderate
References:  1274856,1274857,1274858,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486
This update for cpio fixes the following issues:

- CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard
  links outside intended directory via malicious tar archives (bsc#1274856).
- CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of
  service via crafted archives (bsc#1274857).
- CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for
  terminal control sequence injection via crafted archive member names (bsc#1274858).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4021-1
Released:    Mon Sep  7 09:41:23 2026
Summary:     Security update for c-ares
Type:        security
Severity:    important
References:  1220279,1240955,1254738,1270416,1276290,1276291,CVE-2024-25629,CVE-2025-31498,CVE-2025-62408,CVE-2026-33630,CVE-2026-69184,CVE-2026-69186
This update for c-ares fixes the following issues:

- CVE-2024-25629: out of bounds read in ares__read_line() (bsc#1220279).
- CVE-2025-31498: use-after-free in read_answers() when process_answer() may re-enqueue a query (bsc#1240955).
- CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (bsc#1254738).
- CVE-2026-33630: Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via
  ares_getaddrinfo() over TCP (bsc#1270416).
- CVE-2026-69184: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290).
- CVE-2026-69186: Memory-amplification denial of service via unvalidated DNS header record counts (bsc#1276291).

Changes for c-ares:

- updated to 1.36.8.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4047-1
Released:    Mon Sep  7 15:53:38 2026
Summary:     Security update for curl
Type:        security
Severity:    moderate
References:  1262633,1263440,1264971,1268412,1277476,1277479,1277480,CVE-2026-13608,CVE-2026-5773,CVE-2026-7168,CVE-2026-80229,CVE-2026-80230,CVE-2026-8926
This update for curl fixes the following issues:

- CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633).
- CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440).
- CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412).
- CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476).
- CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479).
- CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480).

Changes for curl:

- Call http_size() first to prioritize Transfer-Encoding: chunked over a zero
 Content-Length empty body check (bsc#1264971)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4050-1
Released:    Mon Sep  7 15:55:07 2026
Summary:     Security update for libusb-1_0
Type:        security
Severity:    moderate
References:  1266664,CVE-2026-23679
This update for libusb-1_0 fixes the following issue:

- CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a
  malformed USB configuration descriptor (bsc#1266664).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4055-1
Released:    Mon Sep  7 17:48:12 2026
Summary:     Security update for bzip2
Type:        security
Severity:    low
References:  1266786,CVE-2026-42250
This update for bzip2 fixes the following issue:

- CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a
  crash (bsc#1266786).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:4101-1
Released:    Wed Sep  9 14:07:04 2026
Summary:     Recommended update for rsyslog
Type:        recommended
Severity:    moderate
References:  1274610
This update for rsyslog fixes the following issues:

- gtls: guard early debug-level lookup (bsc#1274610)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4112-1
Released:    Wed Sep  9 18:17:10 2026
Summary:     Security update for libzypp, zypper
Type:        security
Severity:    critical
References:  1257249,1261038,1268321,1271730,1272534,1273242,1274091,1274625,1277790
This update for libzypp, zypper fixes the following issues:

Security issue fixed:

- invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY-CACHE-01] (bsc#1274625).
- hasCredentials() requires both username AND password to be non-empty (bsc#1273242).
- GPG Key hints in repoindex.xml require at least a long id to allow auto-import (bsc#1271730).

Non security issues fixed:

- Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534).
- libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321).
- Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249).
- zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091).
- Zypper patch doesn't give enough details about conflicts (bsc#1277790).
- dependency issue for package 'python3-vsts-cd-manager' after starting the upgrade (bsc#1261038).
Changes for libzypp:

- Update to version 17.38.15:

  - Prevent libgpgme from launching gpg-agents; we don't need them.
  - defaultLoadSystem: Hand out the ZYpp::Ptr as return value.
  - Replace popen cat/zcat with solv_xfopen for testcase loaders
    (fixes #749)
  - zypp: Improve Testcase Loading for MCP Tools.
  - spec: Remove useless %bcond visibility_hidden (is always ON in
    cmake)
  - zypp.conf: add solver.NoUpdateProvide (default: false) option.

Changes for zypper:

- Update to version 1.14.101.

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:4116-1
Released:    Wed Sep  9 21:41:52 2026
Summary:     Recommended update for crypto-policies
Type:        recommended
Severity:    important
References:  1242233,1243830,1277267
This update for crypto-policies fixes the following issues:

- Revert the previous change since the syntax is not understood in
  this crypto-policies version. (bsc#1243830, bsc#1242233, bsc#1277267)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:4124-1
Released:    Thu Sep 10 18:11:41 2026
Summary:     Recommended update for glibc
Type:        recommended
Severity:    moderate
References:  1277247
This update for glibc fixes the following issues:

- Add -flive-patching=inline-clone to avoid untraceable inter-procedural
  optimizations (bsc#1277247).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:4142-1
Released:    Mon Sep 14 09:59:10 2026
Summary:     Recommended update for permissions
Type:        recommended
Severity:    moderate
References:  1278351
This update for permissions fixes the following issue:

- Update to version 20240826:
 * profiles: backport nvidia-modprobe (bsc#1278351)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4176-1
Released:    Mon Sep 14 12:29:48 2026
Summary:     Security update for acl, attr
Type:        security
Severity:    important
References:  1268867,CVE-2026-54369,CVE-2026-54370,CVE-2026-54371
This update for acl, attr fixes the following issue:

- CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr,
  getfacl/setfacl/chacl, libacl (bsc#1268867).

Changes for acl:

- Update to 2.4.0 (jsc#PED-16501):
 Major Issues Fixed:
 - The libacl library functions acl_get_file(), acl_set_file(),
 acl_extended_file(), and acl_delete_def_file() take a pathname argument
 and follow symbolic links. When a privileged user calls one of those
 functions, an attacker that controls a pathname component can replace a
 file or directory with a symbolic link and redirect the operation to a
 different file. This can lead to local privilege escalation.
 (CVE-2026-54369, bsc#1268867)
 The library functions cannot be fixed without breaking compatibility; the
 described behaviour is by design.
 Instead, version 2.4.0 of the acl package introduces the additional
 functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and
 acl_delete_def_file_at(). These functions each take a dirfd file
 descriptor argument and an at_flags argument and accept the
 AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to
 control when to follow symbolic links. (CVE-2026-54370, bsc#1268867)
 In addition, the libacl functions acl_get_fd(), acl_set_fd(), and
 acl_extended_fd() functions always operate on the access ACL; the library
 previously did not offer a way to operate on the default ACL of a directory
 file descriptor. The new functions remove that restriction.
 It will be up to each individual program to start using these new library
 functions where appropriate.
 - When walking directory trees, the getfacl, setfacl, chacl, and getfattr
 utilities constructed the full pathname of each file in the tree and use that
 pathname to access the file. When a privileged user used those utilities,
 an attacker that controlled a pathname component could replace a directory with
 a symbolic link and redirect the operation to a different file, leading to
 a local privilege escalation. (CVE-2026-54371, bsc#1268867)
 This is fixed by using directory file descriptors and operating relative to
 those directory file descriptors.
 - When resolving the final pathname component, the getfacl, setfacl, chacl,
 getfattr, and setfattr utilities in some cases used functions that resolve
 symbolic links. This includes the above mentioned libacl functions, but
 also stat(), chmod(), and chown().
 This is fixed by using symlink-safe functions throughout the code.
 - When restoring a backup, the setfacl and setfattr utilities read the full
 pathnames of files from the backup. When those pathnames were resolved,
 pathname components that are symbolic links were traversed. An attacker
 that controlled a pathname component could replace it with a symbolic link,
 causing a privileged user to operate on a file other than the one intended.
 This could lead to the same kind of local privilege escalation as discussed
 before.
 This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the
 directory components of a pathname, but see Compatibility Notes below for
 the details.
Minor Issues Fixed:
 - When a symbolic link was specified on the command line but symbolic link
 traversal was disabled using option -P (--physical), the getfacl and
 setfacl utilities previously silently ignored the symlink. Now, an ELOOP
 ('Too many levels of symbolic links') error will result instead.
 - acl_delete_entry() now verifies that the specified entry belongs to the
 specified acl.
 - Numeric uids and gids that cannot be represented in types uid_t and gid_t
 are checked more carefully and invalid numbers are rejected.
 - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry
 several times when the size of an ACL grows unexpectedly; previously, they
 only grew the allocated buffer once before giving up.
 - When passed a directory file descriptor, function perm_copy_fd() didn't
 copy the default ACL from one directory to the other. It now does.
 - setfacl --restore accidentally ignored leading whitespace in filenames. It
 no longer does.
 - setfacl --restore accidentally called chmod() when in --test mode. It no
 longer does.
 - When the setfattr --restore option was used multiple times, a buffer was
 accessed after being freed. This no longer happens.
 - When the setfattr -h (--no-dereference) option was given after --restore,
 it was ignored. Now, the options can be passed in any order.
 - The -h (--no-dereference) option of getfattr prevented getfattr from
 recursing into 'symbolic link directories'. This is wrong. When dirlink
 is a symbolic link that refers to a directory, 'getfattr -Rh dirlink' will now
 visit that directory. The -P (--physical) option can be used to prevent
 that.
 - Similarly, when a symbolic link referring to a directory was specified on
 the getfacl or setfacl command line, the -R option did not cause that
 directory to be visited. This has been fixed so that those directories
 will now be visited. The -P (--physical) option can be used to prevent

Changes for attr:

- Update to 2.6.0 (jsc#PED-16501):
Major Issues Fixed:
 - The libacl library functions acl_get_file(), acl_set_file(),
 acl_extended_file(), and acl_delete_def_file() take a pathname argument
 and follow symbolic links. When a privileged user calls one of those
 functions, an attacker that controls a pathname component can replace a
 file or directory with a symbolic link and redirect the operation to a
 different file. This can lead to local privilege escalation.
 (CVE-2026-54369, bsc#1268867)
 The library functions cannot be fixed without breaking compatibility; the
 described behaviour is by design.
 Instead, version 2.4.0 of the acl package introduces the additional
 functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and
 acl_delete_def_file_at(). These functions each take a dirfd file
 descriptor argument and an at_flags argument and accept the
 AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to
 control when to follow symbolic links. (CVE-2026-54370, bsc#1268867)
 In addition, the libacl functions acl_get_fd(), acl_set_fd(), and
 acl_extended_fd() functions always operate on the access ACL; the library
 previously did not offer a way to operate on the default ACL of a directory
 file descriptor. The new functions remove that restriction.
 It will be up to each individual program to start using these new library
 functions where appropriate.
 - When walking directory trees, the getfacl, setfacl, chacl, and getfattr
 utilities constructed the full pathname of each file in the tree
and use that
 pathname to access the file. When a privileged user used those utilities,
 an attacker that controlled a pathname component could replace a
directory with
 a symbolic link and redirect the operation to a different file, leading to
 a local privilege escalation. (CVE-2026-54371, bsc#1268867)
 This is fixed by using directory file descriptors and operating relative to
 those directory file descriptors.
 - When resolving the final pathname component, the getfacl, setfacl, chacl,
 getfattr, and setfattr utilities in some cases used functions that resolve
 symbolic links. This includes the above mentioned libacl functions, but
 also stat(), chmod(), and chown().
 This is fixed by using symlink-safe functions throughout the code.
 - When restoring a backup, the setfacl and setfattr utilities read the full
 pathnames of files from the backup. When those pathnames were resolved,
 pathname components that are symbolic links were traversed. An attacker
 that controlled a pathname component could replace it with a symbolic link,
 causing a privileged user to operate on a file other than the one intended.
 This could lead to the same kind of local privilege escalation as discussed
 before.
 This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the
 directory components of a pathname, but see Compatibility Notes below for
 the details.
Minor Issues Fixed:
 - When a symbolic link was specified on the command line but symbolic link
 traversal was disabled using option -P (--physical), the getfacl and
 setfacl utilities previously silently ignored the symlink. Now, an ELOOP
 ('Too many levels of symbolic links') error will result instead.
 - acl_delete_entry() now verifies that the specified entry belongs to the
 specified acl.
 - Numeric uids and gids that cannot be represented in types uid_t and gid_t
 are checked more carefully and invalid numbers are rejected.
 - Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry
 several times when the size of an ACL grows unexpectedly; previously, they
 only grew the allocated buffer once before giving up.
 - When passed a directory file descriptor, function perm_copy_fd() didn't
 copy the default ACL from one directory to the other. It now does.
 - setfacl --restore accidentally ignored leading whitespace in filenames. It
 no longer does.
 - setfacl --restore accidentally called chmod() when in --test mode. It no
 longer does.
 - When the setfattr --restore option was used multiple times, a buffer was
 accessed after being freed. This no longer happens.
 - When the setfattr -h (--no-dereference) option was given after --restore,
 it was ignored. Now, the options can be passed in any order.
 - The -h (--no-dereference) option of getfattr prevented getfattr from
 recursing into 'symbolic link directories'. This is wrong. When dirlink
 is a symbolic link that refers to a directory, 'getfattr -Rh
dirlink' will now
 visit that directory. The -P (--physical) option can be used to prevent
 that.
 - Similarly, when a symbolic link referring to a directory was specified on
 the getfacl or setfacl command line, the -R option did not cause that
 directory to be visited. This has been fixed so that those directories
 will now be visited. The -P (--physical) option can be used to prevent
- update to 2.5.2:
 * attr: eliminate a dead store in attr_copy_action()
 * libattr: Set symbol versions for legacy syscalls via attribute
 or asm
 * exports: use LGPL for library code
 * documentation updates
 * translation updates (Polish, Dutch, Gregorian, French)
 * build system updates

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4194-1
Released:    Tue Sep 15 16:27:47 2026
Summary:     Security update for libpcap
Type:        security
Severity:    important
References:  1279584,1279588,1279593,1279595,1279782,1279783,1279784,CVE-2026-0799,CVE-2026-18238,CVE-2026-18313,CVE-2026-31911,CVE-2026-31912,CVE-2026-6244,CVE-2026-6554
This update for libpcap fixes the following issues:

- CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a
  scratch memory register and allows for OOB access (bsc#1279782).
- CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the
  immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero
  (bsc#1279595).
- CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward
  jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584).
- CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly
  validates its headers and allows for an OOB access (bsc#1279783).
- CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ`
  message received from the client and never frees the memory (bsc#1279784).
- CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode.
  In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588).
- CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a
  return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff
  (bsc#1279593).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4207-1
Released:    Wed Sep 16 10:21:54 2026
Summary:     Security update for kbd
Type:        security
Severity:    important
References:  1275441,CVE-2026-72693
This update for kbd fixes the following issue:

- CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows
  `passwordless` root login (bsc#1275441).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4241-1
Released:    Thu Sep 17 13:48:51 2026
Summary:     Security update for pcre2
Type:        security
Severity:    important
References:  1277707,1277708,1277709,1277710,1277711,1277713,1279893,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161
This update for pcre2 fixes the following issues:

- CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893).
- CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054).
- CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053).
- CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052).
- CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject
  (bsc#1280051).
- CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match`
  (bsc#1280050).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4250-1
Released:    Thu Sep 17 18:00:36 2026
Summary:     Security update for glibc
Type:        security
Severity:    moderate
References:  1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489
This update for glibc fixes the following issues:

- CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726).
- CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723).
- CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262).
- CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892).
- CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946).
- CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921).
- CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4270-1
Released:    Mon Sep 21 09:29:29 2026
Summary:     Security update for google-guest-agent
Type:        security
Severity:    important
References:  1253357,1260264,1272118,1278597,1278967,1279297,1279414,CVE-2026-33186,CVE-2026-56852,CVE-2026-56854,CVE-2026-56855,CVE-2026-78662,CVE-2026-84303,CVE-2026-84304,CVE-2026-84445
This update for google-guest-agent fixes the following issues:

- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo-
  header (bsc#1260264).
- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118).
- CVE-2026-56854: golang.org/x/crypto/ssh: source-address critical option not enforced for non-public-key auth callbacks (bsc#1278597)
- CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1278597)
- CVE-2026-78662: golang.org/x/crypto/ssh: prevent DoS on deadlocked undecided channel (bsc#1278597).
- CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization
  policies via mixed-case or canonical-case header matches (bsc#1279297).
- CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414).
- CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS
  servers (bsc#1278967).

Changes for google-guest-agent:

- Updated to version 20260903.01

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4275-1
Released:    Mon Sep 21 09:32:08 2026
Summary:     Security update for jq
Type:        security
Severity:    important
References:  1215737,1218034,1218038,1238078,1248600,1262043,1262072,1265060,1265061,1265062,1265070,1265071,1265075,1265076,1269220,1269221,1269390,976992,CVE-2015-8863,CVE-2023-50246,CVE-2023-50268,CVE-2024-53427,CVE-2025-9403,CVE-2026-33948,CVE-2026-40164,CVE-2026-40612,CVE-2026-41256,CVE-2026-41257,CVE-2026-43894,CVE-2026-43895,CVE-2026-43896,CVE-2026-44777,CVE-2026-47770,CVE-2026-49839,CVE-2026-54679
This update for jq fixes the following issues:

Security issues fixed:

- CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992).
- CVE-2023-50246: improper memory handling can lead to a heap buffer overflow in `decNumberToString` (bsc#1218034).
- CVE-2023-50268: stack-based buffer overflow in builds using decNumber (bsc#1218038).
- CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in decNumber.c (bsc#1238078).
- CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600).
- CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043).
- CVE-2026-40164: predictable hash collisions can lead to a denial of service (bsc#1262072).
- CVE-2026-40612: jv_contains recurses into nested arrays/objects with no depth limit and can cause a stack overflow
  (bsc#1265060).
- CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f and can lead to execution of unintended
  programs (bsc#1265061).
- CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS (bsc#1265062).
- CVE-2026-43894: signed integer overflow in `decNumber` can lead to out-of-bounds memory write (bsc#1265070).
- CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure
  (bsc#1265071).
- CVE-2026-43896: unbounded recursion in `jv_object_merge_recursive()` can lead to C stack exhaustion and a process
  crash (bsc#1265075).
- CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead
  to stack exhaustion and process crash (bsc#1265076).
- CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221).
- CVE-2026-49839: `--rawfile` invalid-state reuse after `String too long` can lead to a heap buffer overflow
  (bsc#1269220).
- CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer overrun on 32-bit systems (bsc#1269390).

Changes for jq:

Update to version 1.7.1:

 * Make the default background color more suitable for bright
 backgrounds.
 * Allow passing the inline jq script after --.
 * Fix possible uninitialised value dereference if jq_init() fails
 * Simplify paths/0 and paths/1.
 * Reject U+001F in string literals.
 * Remove unused nref accumulator in block_bind_library.
 * Remove a bunch of unused variables, and useless assignments.
 * main.c: Remove unused EXIT_STATUS_EXACT option.
 * Actually use the number correctly casted from double to int as
 index.
 * src/builtin.c: remove unnecessary jv_copy-s in
 type_error/type_error2.
 * Remove undefined behavior caught by LLVM 10 UBSAN.
 * Convert decnum to binary64 (double) instead of decimal64.
 This makes jq behave like the JSON specification suggests and
 more similar to other languages.
 * Fix memory leaks on invalid input for ltrimstr/1 and
 rtrimstr/1.
 * Fix memory leak on failed get for setpath/2.
 * Fix nan from json parsing also for nans with payload that
 start with 'n'.
 * Allow carriage return characters in comments.
 * Generate links in the man page.
 * Add extern C for C++.
 * Make object key color configurable using JQ_COLORS environment
 variable.
 * Change the default color of null to Bright Black.
 * Respect NO_COLOR environment variable to disable color output.
 * Improved --help output. Now mentions all options and nicer
 order.
 * Fix multiple issues of exit code using --exit-code/-e option.
 * Add --raw-output0 for NUL (zero byte) separated output.
 * Fix assert crash and validate JSON for --jsonarg.
 * Remove deprecated --argfile option.
 * Use decimal number literals to preserve precision. Comparison
 operations respects precision but arithmetic operations might
 truncate.
 * Adds new builtin pick(stream) to emit a projection of the
 input object or array.
 * Adds new builtin debug(msgs) that works like debug but applies
 a filter on the input before writing to stderr.
 * Adds new builtin scan($re; $flags). Was documented but not
 implemented.
 * Adds new builtin abs to get absolute value. This potentially
 allows the literal value of numbers to be preserved as length
 and fabs convert to float.
 * Allow if without else-branch. When skipped the else-branch
 will be . (identity).
 * Allow use of $binding as key in object literals.
 * Allow dot between chained indexes when using .['index']
 * Allow dot for chained value iterator .[], .[]?
 * Fix try/catch catches more than it should.
 * Speed up and refactor some builtins, also remove
 scalars_or_empty/0.
 * Now halt and halt_error exit immediately instead of continuing
 to the next input.
 * Fix issue converting string to number after previous convert
 error.
 * Fix issue representing large numbers on some platforms causing
 invalid JSON output.
 * Fix deletion using assigning empty against arrays.
 * Allow keywords to be used as binding name in more places.
 * Allow using nan as NaN in JSON.
 * Expose a module's function names in modulemeta.
 * Fix contains/1 to handle strings with NUL.
 * Fix stderr/0 to output raw text without any decoration.
 * Fix nth/2 to emit empty on index out of range.
 * Fix implode to not assert and instead replace invalid unicode
 codepoints.
 * Fix indices/1 and rindex/1 in case of overlapping matches in
 strings.
 * Fix sub/3 to resolve issues involving global search-and-replace
 (gsub) operations.
 * Fix empty regular expression matches.
 * Fix overflow exception of the modulo operator.
 * Fix string multiplication by 0 (and less than 1) to emit empty
 string.
 * Fix segfault when using libjq and threads.
 * Fix constant folding of division and reminder with zero
 divisor.
 * Fix error/0, error/1 to throw null error.
 * Simpler and faster transpose.
 * Simple and efficient implementation of walk/1.
 * Remove deprecated filters leaf_paths, recurse_down.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4293-1
Released:    Wed Sep 23 09:55:45 2026
Summary:     Security update for google-osconfig-agent
Type:        security
Severity:    important
References:  1272118,1276722,1278597,1278967,1279297,1279414,CVE-2026-41178,CVE-2026-56852,CVE-2026-56854,CVE-2026-56855,CVE-2026-78662,CVE-2026-84303,CVE-2026-84304,CVE-2026-84445
This update for google-osconfig-agent fixes the following issues:

- CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS
  via oversized inputs (bsc#1276722).
- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118).
- CVE-2026-56854: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597).
- CVE-2026-56855: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597).
- CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597).
- CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization
  policies via mixed-case or canonical-case header matches (bsc#1279297).
- CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414).
- CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS
  servers (bsc#1278967).

Changes for google-osconfig-agent:

- Update to version 20260908.00


The following package changes have been done:

- cpio-2.13-150400.3.10.1 updated
- crypto-policies-scripts-20230920.570ea89-150600.3.22.1 added
- crypto-policies-20230920.570ea89-150600.3.22.1 updated
- curl-8.14.1-150600.4.51.1 updated
- dracut-fips-059+suse.571.g3d42218af-150600.3.35.1 added
- dracut-059+suse.571.g3d42218af-150600.3.35.1 updated
- glibc-locale-base-2.38-150600.14.58.1 updated
- glibc-2.38-150600.14.58.1 updated
- google-guest-agent-20260903.01-150000.1.85.1 updated
- google-osconfig-agent-20260911.00-150000.1.67.1 updated
- jq-1.7.1-150000.3.25.1 updated
- kbd-legacy-2.4.0-150400.5.12.1 updated
- kbd-2.4.0-150400.5.12.1 updated
- libacl1-2.4.0-150000.4.6.1 updated
- libattr1-2.6.0-150000.4.3.1 updated
- libbz2-1-1.0.8-150400.3.4.1 updated
- libcares2-1.34.8-150000.3.29.1 updated
- libcurl4-8.14.1-150600.4.51.1 updated
- libjq1-1.7.1-150000.3.25.1 updated
- libkcapi-tools-0.13.0-150600.17.3.1 added
- libopenssl-3-fips-provider-3.1.4-150600.5.64.1 added
- libopenssl1_1-1.1.1w-150600.5.38.1 updated
- libopenssl3-3.1.4-150600.5.64.1 updated
- libpcap1-1.10.4-150600.3.12.1 updated
- libpcre2-8-0-10.42-150600.3.3.1 updated
- libpython3_11-1_0-3.11.15-150600.3.65.1 added
- libsubid5-4.17.2-150600.17.24.1 updated
- libtirpc-netconfig-1.3.4-150300.3.26.1 updated
- libtirpc3-1.3.4-150300.3.26.1 updated
- libusb-1_0-0-1.0.24-150400.3.6.1 updated
- libyaml-0-2-0.1.7-150000.3.4.1 added
- libzypp-17.38.15-150600.3.95.1 updated
- login_defs-4.17.2-150600.17.24.1 updated
- openssh-fips-9.6p1-150600.6.49.1 added
- openssl-3-3.1.4-150600.5.64.1 updated
- patterns-base-fips-20200124-150600.32.6.1 added
- permissions-20240826-150600.10.21.1 updated
- python3-gcemetadata-1.1.0-150000.3.12.1 added
- python311-PyYAML-6.0.2-150600.10.3.1 added
- python311-base-3.11.15-150600.3.65.1 added
- python311-setuptools-67.7.2-150400.3.22.1 added
- python311-tiertune-0.1.3-150600.13.9.1 added
- python311-3.11.15-150600.3.65.1 added
- python3-3.6.15-150300.10.118.1 added
- rsyslog-module-relp-8.2406.0-150600.12.25.1 updated
- rsyslog-8.2406.0-150600.12.25.1 updated
- scap-security-guide-0.1.80-150600.1.38 updated
- shadow-4.17.2-150600.17.24.1 updated
- suseconnect-ng-1.23.0-150600.3.24.1 updated
- tiertune-gce-0.1.3-150600.13.9.1 added
- zypper-1.14.101-150600.10.58.1 updated


More information about the sle-container-updates mailing list