SUSE-CU-2026:11195-1: Security update of suse/registry

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Sep 25 08:09:18 UTC 2026


SUSE Container Update Advisory: suse/registry
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11195-1
Container Tags        : suse/registry:3.1 , suse/registry:3.1 , suse/registry:3.1-7.11 , suse/registry:latest
Container Release     : 7.11
Severity              : critical
Type                  : security
References            : 1261606 1268884 1268886 1269583 1270219 1275441 1276677 1277919
                        1277966 1278347 1278348 1278349 1278997 1279219 1279316 CVE-2026-13595
                        CVE-2026-27456 CVE-2026-37236 CVE-2026-39827 CVE-2026-41178 CVE-2026-53612
                        CVE-2026-53613 CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410
                        CVE-2026-84303 CVE-2026-84304 CVE-2026-84445 
-----------------------------------------------------------------

The container suse/registry was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 1707
Released:    Fri Sep 18 18:31:02 2026
Summary:     Recommended update for gcc15, gcc16
Type:        recommended
Severity:    critical
References:  1277919
This update for gcc15, gcc16 fixes the following issues:

Changes in gcc15:

- Rebuild to rename library packages after the switch to gcc16
  libraries.

Changes in gcc16:

- Fix build reproducability when PCH is used.
- Fix auto-detection of Zen6 [bsc#1277919]

- Remove support for s390 (32bit), make sure to configure s390x with
  --disable-multilib to avoid configury error without explicit
  disable of multilibs.  Support for s390 is officially deprecated.

-----------------------------------------------------------------
Advisory ID: 1726
Released:    Mon Sep 21 14:23:04 2026
Summary:     Security update for distribution
Type:        security
Severity:    important
References:  1268884,1276677,1277966,1278997,1279219,1279316,CVE-2026-37236,CVE-2026-39827,CVE-2026-41178,CVE-2026-84303,CVE-2026-84304,CVE-2026-84445
This update for distribution fixes the following issues:

- CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST
  request through the X-HTTP-Method-Override header and bypass established access control (bsc#1277966).
- CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS
  via oversized inputs (bsc#1276677).
- CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization
  policies via mixed-case or canonical-case header matches (bsc#1279316).
- CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279219).
- CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS
  servers (bsc#1278997).
- CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS
  via oversized inputs (bsc#1276677).
- CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization
  policies via mixed-case or canonical-case header matches (bsc#1279316).
- CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279219).
- CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS
  servers (bsc#1278997).

-----------------------------------------------------------------
Advisory ID: 1733
Released:    Tue Sep 22 09:23:33 2026
Summary:     Security update for util-linux
Type:        security
Severity:    important
References:  1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410
This update for util-linux fixes the following issues:

- CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).
- CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886).
- CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886).
- CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec
  Bypass in SUID mount(8) (bsc#1268886).
- CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege
  escalation (bsc#1278349).
- CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or
  termination of root processes (bsc#1278348).
- CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode`
  redirection (bsc#1278347).

Changes for util-linux:

- lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441)
- lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value
- lib/fileutils: fix unused parameter warnings without SYS_openat2
- libmount: add missing fileutils.h include to hook_idmap.c
- libmount: add mnt_open_tree() helper for safe tree opening
- libmount: pin source path with openat2() for restricted users
 (bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: restrict source path canonicalization for non-root
 users (bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: skip post-mount hooks after failed mount helper
 (bsc#1275441, bsc#1278349, CVE-2026-76642)
- libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook
- nsenter: close cgroup.procs fd after join to prevent authority
 leak (bsc#1275441, bsc#1278348, CVE-2026-78408)
- nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441,
 bsc#1278348, CVE-2026-78408)
- wall, write: sanitize hostname in banner header (bsc#1275441)
- Add missing function. (bsc#1275441)
- ipcutils: Prevent using uninitialized variable (bsc#1268886)
- BREAKING CHANGE:
 Paths must always be canonicalized for unprivileged users to
 ensure safe target resolution. X-mount.nocanonicalize is ignored
 for them.
- INCOMAPTIBLE CHANGE (linux < 6.15):
 X-mount.subdir: The safe detached subdirectory is no more
 supported for unprivileged users for safety reasons.
- liblastlog2: Wait on busy SQLite connections (bsc#1268886).
- libmount: Fix subvolid buffer overflow in get_btrfs_fs_root
 (bsc#1268886).
- libblkid: Fix use-after-free in nested partition probing
 (bsc#1269583, bsc#1268886, CVE-2026-13595)
- libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy
 mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx).
- fileutils: add ul_open_no_symlinks() needed by other patches
 (bsc#1268886).
- libmount: add fd_target to context for TOCTOU race condition
 prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g).
- libmount: ignore X-mount.nocanonicalize for restricted users
- libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886,
 CVE-2026-53612, GHSA-g8wm-75wr-g2vh).
- libmount: restrict X-mount.subdir for non-root (bsc#1268886).
- libmount: use fd_target in hook_idmap for move_mount()
- libmount: add mount ID verification and man page TOCTOU note
- loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file
 (bsc#1268886#c2, bsc#1261606).
- Ignore pam-config error that prevents update failure if common*
 pam configuration is not symlink to common-*-pc (bsc#1270219).


The following package changes have been done:

- libgcc_s1-16.2.0+git9497-160000.2.1 updated
- libsmartcols1-2.41.1-160000.5.1 updated
- libuuid1-2.41.1-160000.5.1 updated
- libblkid1-2.41.1-160000.5.1 updated
- libmount1-2.41.1-160000.5.1 updated
- libfdisk1-2.41.1-160000.5.1 updated
- util-linux-2.41.1-160000.5.1 updated
- distribution-registry-3.1.1-160000.3.1 updated


More information about the sle-container-updates mailing list