Описание
Recommended update for apptainer
This update for apptainer contains the following fixes:
Security fixes included on this update:
- CVE-2026-2303: go.mongodb.org/mongo-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling (bsc#1270529).
Other fixes:
- Enable building of SUID starter for SLES 15 (jsc#PED-16347).
Список пакетов
SUSE Linux Enterprise Module for HPC 15 SP7
apptainer-1.5.1-150600.4.29.1
apptainer-sle15_7-1.5.1-150600.4.29.1
libsquashfuse0-0.5.0-150600.3.4.1
squashfuse-0.5.0-150600.3.4.1
squashfuse-tools-0.5.0-150600.3.4.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
apptainer-1.5.1-150600.4.29.1
apptainer-suid-1.5.1-150600.4.29.1
squashfuse-0.5.0-150600.3.4.1
Ссылки
- Link for SUSE-RU-2026:2815-1
- E-Mail link for SUSE-RU-2026:2815-1
- SUSE Security Ratings
- SUSE Bug 1270529
- SUSE CVE CVE-2026-2303 page
Описание
The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer.
Затронутые продукты
SUSE Linux Enterprise Module for HPC 15 SP7:apptainer-1.5.1-150600.4.29.1
SUSE Linux Enterprise Module for HPC 15 SP7:apptainer-sle15_7-1.5.1-150600.4.29.1
SUSE Linux Enterprise Module for HPC 15 SP7:libsquashfuse0-0.5.0-150600.3.4.1
SUSE Linux Enterprise Module for HPC 15 SP7:squashfuse-0.5.0-150600.3.4.1
Ссылки
- CVE-2026-2303
- SUSE Bug 1268652