SUSE-CU-2026:11196-1: Security update of suse/git
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Fri Sep 25 08:09:40 UTC 2026
SUSE Container Update Advisory: suse/git
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11196-1
Container Tags : suse/git:2 , suse/git:2.51 , suse/git:2.51.0 , suse/git:2.51.0-87.7 , suse/git:latest
Container Release : 87.7
Severity : critical
Type : security
References : 1261606 1268886 1269583 1270219 1275441 1277919 1278347 1278348
1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613
CVE-2026-53614 CVE-2026-76642 CVE-2026-78408 CVE-2026-78410
-----------------------------------------------------------------
The container suse/git was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 1707
Released: Fri Sep 18 18:31:02 2026
Summary: Recommended update for gcc15, gcc16
Type: recommended
Severity: critical
References: 1277919
This update for gcc15, gcc16 fixes the following issues:
Changes in gcc15:
- Rebuild to rename library packages after the switch to gcc16
libraries.
Changes in gcc16:
- Fix build reproducability when PCH is used.
- Fix auto-detection of Zen6 [bsc#1277919]
- Remove support for s390 (32bit), make sure to configure s390x with
--disable-multilib to avoid configury error without explicit
disable of multilibs. Support for s390 is officially deprecated.
-----------------------------------------------------------------
Advisory ID: 1733
Released: Tue Sep 22 09:23:33 2026
Summary: Security update for util-linux
Type: security
Severity: important
References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410
This update for util-linux fixes the following issues:
- CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).
- CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886).
- CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886).
- CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec
Bypass in SUID mount(8) (bsc#1268886).
- CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege
escalation (bsc#1278349).
- CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or
termination of root processes (bsc#1278348).
- CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode`
redirection (bsc#1278347).
Changes for util-linux:
- lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441)
- lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value
- lib/fileutils: fix unused parameter warnings without SYS_openat2
- libmount: add missing fileutils.h include to hook_idmap.c
- libmount: add mnt_open_tree() helper for safe tree opening
- libmount: pin source path with openat2() for restricted users
(bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: restrict source path canonicalization for non-root
users (bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: skip post-mount hooks after failed mount helper
(bsc#1275441, bsc#1278349, CVE-2026-76642)
- libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook
- nsenter: close cgroup.procs fd after join to prevent authority
leak (bsc#1275441, bsc#1278348, CVE-2026-78408)
- nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441,
bsc#1278348, CVE-2026-78408)
- wall, write: sanitize hostname in banner header (bsc#1275441)
- Add missing function. (bsc#1275441)
- ipcutils: Prevent using uninitialized variable (bsc#1268886)
- BREAKING CHANGE:
Paths must always be canonicalized for unprivileged users to
ensure safe target resolution. X-mount.nocanonicalize is ignored
for them.
- INCOMAPTIBLE CHANGE (linux < 6.15):
X-mount.subdir: The safe detached subdirectory is no more
supported for unprivileged users for safety reasons.
- liblastlog2: Wait on busy SQLite connections (bsc#1268886).
- libmount: Fix subvolid buffer overflow in get_btrfs_fs_root
(bsc#1268886).
- libblkid: Fix use-after-free in nested partition probing
(bsc#1269583, bsc#1268886, CVE-2026-13595)
- libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy
mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx).
- fileutils: add ul_open_no_symlinks() needed by other patches
(bsc#1268886).
- libmount: add fd_target to context for TOCTOU race condition
prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g).
- libmount: ignore X-mount.nocanonicalize for restricted users
- libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886,
CVE-2026-53612, GHSA-g8wm-75wr-g2vh).
- libmount: restrict X-mount.subdir for non-root (bsc#1268886).
- libmount: use fd_target in hook_idmap for move_mount()
- libmount: add mount ID verification and man page TOCTOU note
- loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file
(bsc#1268886#c2, bsc#1261606).
- Ignore pam-config error that prevents update failure if common*
pam configuration is not symlink to common-*-pc (bsc#1270219).
The following package changes have been done:
- libgcc_s1-16.2.0+git9497-160000.2.1 updated
- libuuid1-2.41.1-160000.5.1 updated
More information about the sle-container-updates
mailing list