SUSE-CU-2026:11195-1: Security update of suse/registry
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Fri Sep 25 08:09:18 UTC 2026
SUSE Container Update Advisory: suse/registry
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11195-1
Container Tags : suse/registry:3.1 , suse/registry:3.1 , suse/registry:3.1-7.11 , suse/registry:latest
Container Release : 7.11
Severity : critical
Type : security
References : 1261606 1268884 1268886 1269583 1270219 1275441 1276677 1277919
1277966 1278347 1278348 1278349 1278997 1279219 1279316 CVE-2026-13595
CVE-2026-27456 CVE-2026-37236 CVE-2026-39827 CVE-2026-41178 CVE-2026-53612
CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410
CVE-2026-84303 CVE-2026-84304 CVE-2026-84445
-----------------------------------------------------------------
The container suse/registry was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 1707
Released: Fri Sep 18 18:31:02 2026
Summary: Recommended update for gcc15, gcc16
Type: recommended
Severity: critical
References: 1277919
This update for gcc15, gcc16 fixes the following issues:
Changes in gcc15:
- Rebuild to rename library packages after the switch to gcc16
libraries.
Changes in gcc16:
- Fix build reproducability when PCH is used.
- Fix auto-detection of Zen6 [bsc#1277919]
- Remove support for s390 (32bit), make sure to configure s390x with
--disable-multilib to avoid configury error without explicit
disable of multilibs. Support for s390 is officially deprecated.
-----------------------------------------------------------------
Advisory ID: 1726
Released: Mon Sep 21 14:23:04 2026
Summary: Security update for distribution
Type: security
Severity: important
References: 1268884,1276677,1277966,1278997,1279219,1279316,CVE-2026-37236,CVE-2026-39827,CVE-2026-41178,CVE-2026-84303,CVE-2026-84304,CVE-2026-84445
This update for distribution fixes the following issues:
- CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST
request through the X-HTTP-Method-Override header and bypass established access control (bsc#1277966).
- CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS
via oversized inputs (bsc#1276677).
- CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization
policies via mixed-case or canonical-case header matches (bsc#1279316).
- CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279219).
- CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS
servers (bsc#1278997).
- CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS
via oversized inputs (bsc#1276677).
- CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization
policies via mixed-case or canonical-case header matches (bsc#1279316).
- CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279219).
- CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS
servers (bsc#1278997).
-----------------------------------------------------------------
Advisory ID: 1733
Released: Tue Sep 22 09:23:33 2026
Summary: Security update for util-linux
Type: security
Severity: important
References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410
This update for util-linux fixes the following issues:
- CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).
- CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886).
- CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886).
- CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec
Bypass in SUID mount(8) (bsc#1268886).
- CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege
escalation (bsc#1278349).
- CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or
termination of root processes (bsc#1278348).
- CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode`
redirection (bsc#1278347).
Changes for util-linux:
- lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441)
- lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value
- lib/fileutils: fix unused parameter warnings without SYS_openat2
- libmount: add missing fileutils.h include to hook_idmap.c
- libmount: add mnt_open_tree() helper for safe tree opening
- libmount: pin source path with openat2() for restricted users
(bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: restrict source path canonicalization for non-root
users (bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: skip post-mount hooks after failed mount helper
(bsc#1275441, bsc#1278349, CVE-2026-76642)
- libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook
- nsenter: close cgroup.procs fd after join to prevent authority
leak (bsc#1275441, bsc#1278348, CVE-2026-78408)
- nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441,
bsc#1278348, CVE-2026-78408)
- wall, write: sanitize hostname in banner header (bsc#1275441)
- Add missing function. (bsc#1275441)
- ipcutils: Prevent using uninitialized variable (bsc#1268886)
- BREAKING CHANGE:
Paths must always be canonicalized for unprivileged users to
ensure safe target resolution. X-mount.nocanonicalize is ignored
for them.
- INCOMAPTIBLE CHANGE (linux < 6.15):
X-mount.subdir: The safe detached subdirectory is no more
supported for unprivileged users for safety reasons.
- liblastlog2: Wait on busy SQLite connections (bsc#1268886).
- libmount: Fix subvolid buffer overflow in get_btrfs_fs_root
(bsc#1268886).
- libblkid: Fix use-after-free in nested partition probing
(bsc#1269583, bsc#1268886, CVE-2026-13595)
- libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy
mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx).
- fileutils: add ul_open_no_symlinks() needed by other patches
(bsc#1268886).
- libmount: add fd_target to context for TOCTOU race condition
prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g).
- libmount: ignore X-mount.nocanonicalize for restricted users
- libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886,
CVE-2026-53612, GHSA-g8wm-75wr-g2vh).
- libmount: restrict X-mount.subdir for non-root (bsc#1268886).
- libmount: use fd_target in hook_idmap for move_mount()
- libmount: add mount ID verification and man page TOCTOU note
- loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file
(bsc#1268886#c2, bsc#1261606).
- Ignore pam-config error that prevents update failure if common*
pam configuration is not symlink to common-*-pc (bsc#1270219).
The following package changes have been done:
- libgcc_s1-16.2.0+git9497-160000.2.1 updated
- libsmartcols1-2.41.1-160000.5.1 updated
- libuuid1-2.41.1-160000.5.1 updated
- libblkid1-2.41.1-160000.5.1 updated
- libmount1-2.41.1-160000.5.1 updated
- libfdisk1-2.41.1-160000.5.1 updated
- util-linux-2.41.1-160000.5.1 updated
- distribution-registry-3.1.1-160000.3.1 updated
More information about the sle-container-updates
mailing list