Описание
Security update for apptainer
This update for apptainer fixes the following issues:
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266656).
- CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272115).
Changes for apptainer:
- Update apptainer to version 1.5.3:
- If the ptrace() system call does not work while building an image as an unprivileged user, skip using PRoot to preserve file ownership and print an INFO message.
- Bind getopt from the host when using fakeroot command mode, to make the fakeroot command work with base containers which no longer contain getopt by default.
- Extended the mksquashfs segmentation fault workaround for cases where mksquashfs uses many processor cores.
Список пакетов
SUSE Linux Enterprise Module for HPC 15 SP7
SUSE Linux Enterprise Module for Package Hub 15 SP7
SUSE Linux Enterprise Server 15 SP6-LTSS
Ссылки
- Link for SUSE-SU-2026:3417-1
- E-Mail link for SUSE-SU-2026:3417-1
- SUSE Security Ratings
- SUSE Bug 1266656
- SUSE Bug 1272115
- SUSE CVE CVE-2026-39821 page
- SUSE CVE CVE-2026-56852 page
Описание
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
Затронутые продукты
Ссылки
- CVE-2026-39821
- SUSE Bug 1266474
Описание
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
Затронутые продукты
Ссылки
- CVE-2026-56852
- SUSE Bug 1271661