SUSE-CU-2026:11322-1: Security update of suse/hpc/warewulf4-x86_64/sle-hpc-node

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Sep 29 07:51:50 UTC 2026


SUSE Container Update Advisory: suse/hpc/warewulf4-x86_64/sle-hpc-node
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11322-1
Container Tags        : suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7 , suse/hpc/warewulf4-x86_64/sle-hpc-node:15.7.20.8.172 , suse/hpc/warewulf4-x86_64/sle-hpc-node:latest
Container Release     : 20.8.172
Severity              : important
Type                  : security
References            : 1215737 1218034 1218038 1238078 1248600 1262043 1262072 1265060
                        1265061 1265062 1265070 1265071 1265075 1265076 1269220 1269221
                        1269390 1272206 976992 CVE-2015-8863 CVE-2023-50246 CVE-2023-50268
                        CVE-2024-53427 CVE-2025-9403 CVE-2026-15588 CVE-2026-33948 CVE-2026-40164
                        CVE-2026-40612 CVE-2026-41256 CVE-2026-41257 CVE-2026-43894 CVE-2026-43895
                        CVE-2026-43896 CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54679
-----------------------------------------------------------------

The container suse/hpc/warewulf4-x86_64/sle-hpc-node was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4275-1
Released:    Mon Sep 21 09:32:08 2026
Summary:     Security update for jq
Type:        security
Severity:    important
References:  1215737,1218034,1218038,1238078,1248600,1262043,1262072,1265060,1265061,1265062,1265070,1265071,1265075,1265076,1269220,1269221,1269390,976992,CVE-2015-8863,CVE-2023-50246,CVE-2023-50268,CVE-2024-53427,CVE-2025-9403,CVE-2026-33948,CVE-2026-40164,CVE-2026-40612,CVE-2026-41256,CVE-2026-41257,CVE-2026-43894,CVE-2026-43895,CVE-2026-43896,CVE-2026-44777,CVE-2026-47770,CVE-2026-49839,CVE-2026-54679
This update for jq fixes the following issues:

Security issues fixed:

- CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992).
- CVE-2023-50246: improper memory handling can lead to a heap buffer overflow in `decNumberToString` (bsc#1218034).
- CVE-2023-50268: stack-based buffer overflow in builds using decNumber (bsc#1218038).
- CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in decNumber.c (bsc#1238078).
- CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600).
- CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043).
- CVE-2026-40164: predictable hash collisions can lead to a denial of service (bsc#1262072).
- CVE-2026-40612: jv_contains recurses into nested arrays/objects with no depth limit and can cause a stack overflow
  (bsc#1265060).
- CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f and can lead to execution of unintended
  programs (bsc#1265061).
- CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS (bsc#1265062).
- CVE-2026-43894: signed integer overflow in `decNumber` can lead to out-of-bounds memory write (bsc#1265070).
- CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure
  (bsc#1265071).
- CVE-2026-43896: unbounded recursion in `jv_object_merge_recursive()` can lead to C stack exhaustion and a process
  crash (bsc#1265075).
- CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead
  to stack exhaustion and process crash (bsc#1265076).
- CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221).
- CVE-2026-49839: `--rawfile` invalid-state reuse after `String too long` can lead to a heap buffer overflow
  (bsc#1269220).
- CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer overrun on 32-bit systems (bsc#1269390).

Changes for jq:

Update to version 1.7.1:

 * Make the default background color more suitable for bright
 backgrounds.
 * Allow passing the inline jq script after --.
 * Fix possible uninitialised value dereference if jq_init() fails
 * Simplify paths/0 and paths/1.
 * Reject U+001F in string literals.
 * Remove unused nref accumulator in block_bind_library.
 * Remove a bunch of unused variables, and useless assignments.
 * main.c: Remove unused EXIT_STATUS_EXACT option.
 * Actually use the number correctly casted from double to int as
 index.
 * src/builtin.c: remove unnecessary jv_copy-s in
 type_error/type_error2.
 * Remove undefined behavior caught by LLVM 10 UBSAN.
 * Convert decnum to binary64 (double) instead of decimal64.
 This makes jq behave like the JSON specification suggests and
 more similar to other languages.
 * Fix memory leaks on invalid input for ltrimstr/1 and
 rtrimstr/1.
 * Fix memory leak on failed get for setpath/2.
 * Fix nan from json parsing also for nans with payload that
 start with 'n'.
 * Allow carriage return characters in comments.
 * Generate links in the man page.
 * Add extern C for C++.
 * Make object key color configurable using JQ_COLORS environment
 variable.
 * Change the default color of null to Bright Black.
 * Respect NO_COLOR environment variable to disable color output.
 * Improved --help output. Now mentions all options and nicer
 order.
 * Fix multiple issues of exit code using --exit-code/-e option.
 * Add --raw-output0 for NUL (zero byte) separated output.
 * Fix assert crash and validate JSON for --jsonarg.
 * Remove deprecated --argfile option.
 * Use decimal number literals to preserve precision. Comparison
 operations respects precision but arithmetic operations might
 truncate.
 * Adds new builtin pick(stream) to emit a projection of the
 input object or array.
 * Adds new builtin debug(msgs) that works like debug but applies
 a filter on the input before writing to stderr.
 * Adds new builtin scan($re; $flags). Was documented but not
 implemented.
 * Adds new builtin abs to get absolute value. This potentially
 allows the literal value of numbers to be preserved as length
 and fabs convert to float.
 * Allow if without else-branch. When skipped the else-branch
 will be . (identity).
 * Allow use of $binding as key in object literals.
 * Allow dot between chained indexes when using .['index']
 * Allow dot for chained value iterator .[], .[]?
 * Fix try/catch catches more than it should.
 * Speed up and refactor some builtins, also remove
 scalars_or_empty/0.
 * Now halt and halt_error exit immediately instead of continuing
 to the next input.
 * Fix issue converting string to number after previous convert
 error.
 * Fix issue representing large numbers on some platforms causing
 invalid JSON output.
 * Fix deletion using assigning empty against arrays.
 * Allow keywords to be used as binding name in more places.
 * Allow using nan as NaN in JSON.
 * Expose a module's function names in modulemeta.
 * Fix contains/1 to handle strings with NUL.
 * Fix stderr/0 to output raw text without any decoration.
 * Fix nth/2 to emit empty on index out of range.
 * Fix implode to not assert and instead replace invalid unicode
 codepoints.
 * Fix indices/1 and rindex/1 in case of overlapping matches in
 strings.
 * Fix sub/3 to resolve issues involving global search-and-replace
 (gsub) operations.
 * Fix empty regular expression matches.
 * Fix overflow exception of the modulo operator.
 * Fix string multiplication by 0 (and less than 1) to emit empty
 string.
 * Fix segfault when using libjq and threads.
 * Fix constant folding of division and reminder with zero
 divisor.
 * Fix error/0, error/1 to throw null error.
 * Simpler and faster transpose.
 * Simple and efficient implementation of walk/1.
 * Remove deprecated filters leaf_paths, recurse_down.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4367-1
Released:    Mon Sep 28 17:01:44 2026
Summary:     Security update for glib2
Type:        security
Severity:    moderate
References:  1272206,CVE-2026-15588
This update for glib2 fixes the following issue:

- CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206).


The following package changes have been done:

- glib2-tools-2.78.6-150600.4.41.1 updated
- jq-1.7.1-150000.3.25.1 updated
- libgio-2_0-0-2.78.6-150600.4.41.1 updated
- libglib-2_0-0-2.78.6-150600.4.41.1 updated
- libgmodule-2_0-0-2.78.6-150600.4.41.1 updated
- libgobject-2_0-0-2.78.6-150600.4.41.1 updated
- libjq1-1.7.1-150000.3.25.1 updated


More information about the sle-container-updates mailing list