Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Denial of Service in runc (SUSE)

Дата публикации: 11-08-2026 18:50:49



Основное содержимое страницы с новостью.

Plattformen: SUSE Linux Enterprise High Performance Computing 15 SP4, SUSE Linux Enterprise Server 15 SP4, SUSE Linux Enterprise Server for SAP Applications 15 SP4, SUSE Linux Enterprise Server for SAP Applications 15 SP5, SUSE Linux Enterprise Server 15 SP5, SUSE Linux Enterprise High Performance Computing 15 SP5, SUSE Linux Enterprise High Performance Computing LTSS 15 SP4, SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4, SUSE Linux Enterprise Server for SAP Applications 15 SP6, SUSE Linux Enterprise Server 15 SP6, SUSE Linux Enterprise Server 15 SP4 LTSS, SUSE Linux Enterprise High Performance Computing LTSS 15 SP5, SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5, SUSE Linux Enterprise Server 15 SP5 LTSS, SUSE Linux Enterprise Server 15 SP6 LTSS
--===============4136074244373254168==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit

# Security update for runc

Announcement ID: SUSE-SU-2026:3433-2
Release Date: 2026-08-10T16:55:24Z
Rating: low
References:

* bsc#1268275

Cross-References:

* CVE-2026-41579

CVSS scores:

* CVE-2026-41579 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
* CVE-2026-41579 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Affected Products:

* SUSE Linux Enterprise High Performance Computing 15 SP4
* SUSE Linux Enterprise High Performance Computing 15 SP5
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
* SUSE Linux Enterprise Server 15 SP4
* SUSE Linux Enterprise Server 15 SP4 LTSS
* SUSE Linux Enterprise Server 15 SP5
* SUSE Linux Enterprise Server 15 SP5 LTSS
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves one vulnerability can now be installed.

## Description:

This update for runc fixes the following issues:

Update to 1.3.6.

* CVE-2026-41579: malicious image with a `/dev` symlink can trigger limited
host filesystem integrity violations (bsc#1268275).

Other updates and bugfixes:

* Version 1.3.6:
* When masking directories with `maskPaths`, runc will now re- use a single
`tmpfs` instance (which is not writeable) to reduce the number `tmpfs`
superblocks that need to be reaped when containers die (in particular,
Kubernetes applies masks to per-CPU sysfs directories which get expensive
quickly).
* Version 1.3.5:
* Recursive atime-related mount flags (rrelatime et al.) are now applied
properly.
* PR #4757 caused a regression that resulted in spurious cannot start a
container that has stopped errors when running runc create and has thus
been
reverted.
* Updated builds to Go 1.25, libseccomp v2.6.0.
* Minor signing keyring updates.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3433=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3433=1

* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3433=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3433=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3433=1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3433=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3433=1

* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3433=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3433=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3433=1

## Package List:

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* runc-1.3.6-150000.101.1
* runc-debuginfo-1.3.6-150000.101.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
x86_64)
* runc-1.3.6-150000.101.1
* runc-debuginfo-1.3.6-150000.101.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
x86_64)
* runc-1.3.6-150000.101.1
* runc-debuginfo-1.3.6-150000.101.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* runc-1.3.6-150000.101.1
* runc-debuginfo-1.3.6-150000.101.1
* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
* runc-1.3.6-150000.101.1
* runc-debuginfo-1.3.6-150000.101.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* runc-1.3.6-150000.101.1
* runc-debuginfo-1.3.6-150000.101.1
* SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
* runc-1.3.6-150000.101.1
* runc-debuginfo-1.3.6-150000.101.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
* runc-1.3.6-150000.101.1
* runc-debuginfo-1.3.6-150000.101.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
* runc-1.3.6-150000.101.1
* runc-debuginfo-1.3.6-150000.101.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* runc-1.3.6-150000.101.1
* runc-debuginfo-1.3.6-150000.101.1

## References:

* https://www.suse.com/security/cve/CVE-2026-41579.html
* https://bugzilla.suse.com/show_bug.cgi?id=1268275

--===============4136074244373254168==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit

<div class="container">
<h1>Security update for runc</h1>

<table class="table table-striped table-bordered">
<tbody>
<tr>
<th>Announcement ID:</th>
<td>SUSE-SU-2026:3433-2</td>
</tr>
<tr>
<th>Release Date:</th>
<td>2026-08-10T16:55:24Z</td>
</tr>

<tr>
<th>Rating:</th>
<td>low</td>
</tr>
<tr>
<th>References:</th>
<td>
<ul>

<li style="display: inline;">
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268275">bsc#1268275</a>
</li>

</ul>
</td>
</tr>

<tr>
<th>
Cross-References:
</th>
<td>
<ul>

<li style="display: inline;">
<a href="https://www.suse.com/security/cve/CVE-2026-41579.html">CVE-2026-41579</a>
</li>

</ul>
</td>
</tr>
<tr>
<th>CVSS scores:</th>
<td>
<ul class="list-group">

<li class="list-group-item">
<span
class="cvss-reference">CVE-2026-41579</span>
<span class="cvss-source">
(

SUSE

):
</span>
<span
class="cvss-score">3.3</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</span>
</li>

<li class="list-group-item">
<span
class="cvss-reference">CVE-2026-41579</span>
<span class="cvss-source">
(

NVD

):
</span>
<span
class="cvss-score">3.3</span>
<span
class="cvss-vector">CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N</span>
</li>

</ul>
</td>
</tr>

<tr>
<th>Affected Products:</th>
<td>
<ul class="list-group">

<li class="list-group-item">SUSE Linux
Enterprise High Performance Computing 15 SP4</li>

<li class="list-group-item">SUSE Linux
Enterprise High Performance Computing 15 SP5</li>

<li class="list-group-item">SUSE Linux
Enterprise High Performance Computing ESPOS 15 SP4</li>

<li class="list-group-item">SUSE Linux
Enterprise High Performance Computing ESPOS 15 SP5</li>

<li class="list-group-item">SUSE Linux
Enterprise High Performance Computing LTSS 15 SP4</li>

<li class="list-group-item">SUSE Linux
Enterprise High Performance Computing LTSS 15 SP5</li>

<li class="list-group-item">SUSE Linux
Enterprise Server 15 SP4</li>

<li class="list-group-item">SUSE Linux
Enterprise Server 15 SP4 LTSS</li>

<li class="list-group-item">SUSE Linux
Enterprise Server 15 SP5</li>

<li class="list-group-item">SUSE Linux
Enterprise Server 15 SP5 LTSS</li>

<li class="list-group-item">SUSE Linux
Enterprise Server 15 SP6</li>

<li class="list-group-item">SUSE Linux
Enterprise Server 15 SP6 LTSS</li>

<li class="list-group-item">SUSE Linux
Enterprise Server for SAP Applications 15 SP4</li>

<li class="list-group-item">SUSE Linux
Enterprise Server for SAP Applications 15 SP5</li>

<li class="list-group-item">SUSE Linux
Enterprise Server for SAP Applications 15 SP6</li>

</ul>
</td>
</tr>
</tbody>
</table>

<p>An update that solves one vulnerability can now be
installed.</p>

<h2>Description:</h2>

<p>This update for runc fixes the following issues:</p>
<p>Update to 1.3.6.</p>
<ul>
<li>CVE-2026-41579: malicious image with a <code>/dev</code>
symlink can trigger limited host filesystem integrity violations
(bsc#1268275).</li>
</ul>
<p>Other updates and bugfixes:</p>
<ul>
<li>Version 1.3.6:</li>
<li>When masking directories with <code>maskPaths</code>,
runc will now re- use a single <code>tmpfs</code> instance (which is not writeable)
to reduce the number <code>tmpfs</code> superblocks that need
to be reaped when containers die (in particular, Kubernetes
applies masks to per-CPU sysfs directories which get expensive
quickly).</li>
<li>Version 1.3.5:</li>
<li>Recursive atime-related mount flags (rrelatime et al.) are now
applied properly.</li>
<li>PR #4757 caused a regression that resulted in spurious cannot start a
container that has stopped errors when
running runc create and has thus been reverted.</li>
<li>Updated builds to Go 1.25, libseccomp v2.6.0.</li>
<li>Minor signing keyring updates.</li>
</ul>

<h2>Patch Instructions:</h2>
<p>
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper
patch".<br/>

Alternatively you can run the command listed for your product:
</p>
<ul class="list-group">

<li class="list-group-item">
SUSE Linux Enterprise Server for SAP Applications 15 SP6

<br/>
<code>zypper in -t patch
SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3433=1</code>

</li>

<li class="list-group-item">
SUSE Linux Enterprise Server for SAP Applications 15 SP4

<br/>
<code>zypper in -t patch
SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3433=1</code>

</li>

<li class="list-group-item">
SUSE Linux Enterprise Server 15 SP4 LTSS

<br/>
<code>zypper in -t patch
SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3433=1</code>

</li>

<li class="list-group-item">
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4

<br/>
<code>zypper in -t patch
SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3433=1</code>

</li>

<li class="list-group-item">
SUSE Linux Enterprise Server 15 SP6 LTSS

<br/>
<code>zypper in -t patch
SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3433=1</code>

</li>

<li class="list-group-item">
SUSE Linux Enterprise High Performance Computing LTSS 15 SP5

<br/>
<code>zypper in -t patch
SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3433=1</code>

</li>

<li class="list-group-item">
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

<br/>
<code>zypper in -t patch
SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3433=1</code>

</li>

<li class="list-group-item">
SUSE Linux Enterprise Server 15 SP5 LTSS

<br/>
<code>zypper in -t patch
SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3433=1</code>

</li>

<li class="list-group-item">
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4

<br/>
<code>zypper in -t patch
SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3433=1</code>

</li>

<li class="list-group-item">
SUSE Linux Enterprise Server for SAP Applications 15 SP5

<br/>
<code>zypper in -t patch
SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3433=1</code>

</li>

</ul>

<h2>Package List:</h2>
<ul>

<li>
SUSE Linux Enterprise High Performance Computing LTSS 15
SP5 (aarch64 x86_64)
<ul>

<li>runc-1.3.6-150000.101.1</li>

<li>runc-debuginfo-1.3.6-150000.101.1</li>

</ul>
</li>

<li>
SUSE Linux Enterprise High Performance Computing ESPOS 15
SP4 (aarch64 x86_64)
<ul>

<li>runc-1.3.6-150000.101.1</li>

<li>runc-debuginfo-1.3.6-150000.101.1</li>

</ul>
</li>

<li>
SUSE Linux Enterprise High Performance Computing LTSS 15
SP4 (aarch64 x86_64)
<ul>

<li>runc-1.3.6-150000.101.1</li>

<li>runc-debuginfo-1.3.6-150000.101.1</li>

</ul>
</li>

<li>
SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le
s390x x86_64)
<ul>

<li>runc-1.3.6-150000.101.1</li>

<li>runc-debuginfo-1.3.6-150000.101.1</li>

</ul>
</li>

<li>
SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le
s390x x86_64)
<ul>

<li>runc-1.3.6-150000.101.1</li>

<li>runc-debuginfo-1.3.6-150000.101.1</li>

</ul>
</li>

<li>
SUSE Linux Enterprise Server for SAP Applications 15 SP6
(ppc64le x86_64)
<ul>

<li>runc-1.3.6-150000.101.1</li>

<li>runc-debuginfo-1.3.6-150000.101.1</li>

</ul>
</li>

<li>
SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le
s390x x86_64)
<ul>

<li>runc-1.3.6-150000.101.1</li>

<li>runc-debuginfo-1.3.6-150000.101.1</li>

</ul>
</li>

<li>
SUSE Linux Enterprise Server for SAP Applications 15 SP5
(ppc64le x86_64)
<ul>

<li>runc-1.3.6-150000.101.1</li>

<li>runc-debuginfo-1.3.6-150000.101.1</li>

</ul>
</li>

<li>
SUSE Linux Enterprise Server for SAP Applications 15 SP4
(ppc64le x86_64)
<ul>

<li>runc-1.3.6-150000.101.1</li>

<li>runc-debuginfo-1.3.6-150000.101.1</li>

</ul>
</li>

<li>
SUSE Linux Enterprise High Performance Computing ESPOS 15
SP5 (aarch64 x86_64)
<ul>

<li>runc-1.3.6-150000.101.1</li>

<li>runc-debuginfo-1.3.6-150000.101.1</li>

</ul>
</li>

</ul>

<h2>References:</h2>
<ul>

<li>
<a href="https://www.suse.com/security/cve/CVE-2026-41579.html">https://www.suse.com/security/cve/CVE-2026-41579.html</a>
</li>

<li>
<a href="https://bugzilla.suse.com/show_bug.cgi?id=1268275">https://bugzilla.suse.com/show_bug.cgi?id=1268275</a>
</li>

</ul>

</div>

--===============4136074244373254168==--

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Denial of Service in runc (SUSE)01011-08-2026
2Denial of Service in avahi (SUSE)01011-08-2026
3Denial of Service in wpa_supplicant (SUSE)01011-08-2026
4Denial of Service in net-tools (SUSE)026.6711-08-2026
5Denial of Service in rsyslog (SUSE)01030-07-2026
6Denial of Service in python-urllib3 (SUSE)026.6711-08-2026
7Denial of Service in openssl-3 (SUSE)01030-07-2026
8Denial of Service in openssl-3 (SUSE)01030-07-2026
9Denial of Service in python3-sqlparse (SUSE)01011-08-2026
10Ausführen beliebiger Kommandos in ruby2.5 (SUSE)026.6711-08-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 10. Источник: www.pro-linux.de.