Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-RU-2026:2815-1

Опубликовано: 09 июл. 2026
Источник: suse-cvrf

Описание

Recommended update for apptainer

This update for apptainer contains the following fixes:

Security fixes included on this update:

  • CVE-2026-2303: go.mongodb.org/mongo-driver: Heap Out-of-Bounds Read in GSSAPI Error Handling (bsc#1270529).

Other fixes:

  • Enable building of SUID starter for SLES 15 (jsc#PED-16347).

Список пакетов

SUSE Linux Enterprise Module for HPC 15 SP7
apptainer-1.5.1-150600.4.29.1
apptainer-sle15_7-1.5.1-150600.4.29.1
libsquashfuse0-0.5.0-150600.3.4.1
squashfuse-0.5.0-150600.3.4.1
squashfuse-tools-0.5.0-150600.3.4.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
apptainer-1.5.1-150600.4.29.1
apptainer-suid-1.5.1-150600.4.29.1
squashfuse-0.5.0-150600.3.4.1

Описание

The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer.


Затронутые продукты
SUSE Linux Enterprise Module for HPC 15 SP7:apptainer-1.5.1-150600.4.29.1
SUSE Linux Enterprise Module for HPC 15 SP7:apptainer-sle15_7-1.5.1-150600.4.29.1
SUSE Linux Enterprise Module for HPC 15 SP7:libsquashfuse0-0.5.0-150600.3.4.1
SUSE Linux Enterprise Module for HPC 15 SP7:squashfuse-0.5.0-150600.3.4.1

Ссылки