Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3450-1

Опубликовано: 03 авг. 2026
Источник: suse-cvrf

Описание

Security update for containerd

This update for containerd fixes the following issues:

  • CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262266).

Список пакетов

SUSE Linux Enterprise Micro 5.3
containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Micro 5.4
containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Micro 5.5
containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Module for Containers 15 SP7
containerd-ctr-1.7.29-150000.142.1
containerd-devel-1.7.29-150000.142.1

Описание

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.


Затронутые продукты
SUSE Linux Enterprise Micro 5.3:containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Micro 5.4:containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Micro 5.5:containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:containerd-1.7.29-150000.142.1

Ссылки

Описание

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field indicates a key wrapping algorithm (one ending in KW, with the exception of A128GCMKW, A192GCMKW, and A256GCMKW) and the encrypted_key field is empty. The panic happens when cipher.KeyUnwrap() in key_wrap.go attempts to allocate a slice with a zero or negative length based on the length of the encrypted_key. This code path is reachable from ParseEncrypted() / ParseEncryptedJSON() / ParseEncryptedCompact() followed by Decrypt() on the resulting object. Note that the parse functions take a list of accepted key algorithms. If the accepted key algorithms do not include any key wrapping algorithms, parsing will fail and the application will be unaffected. This panic is also reachable by calling cipher.KeyUnwrap() directly with any ciphertext parameter less than 16 bytes long, but calling this function directly is less common. Panics can lead to denial of service. This vulnerability is fixed in 4.1.4 and 3.0.5.


Затронутые продукты
SUSE Linux Enterprise Micro 5.3:containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Micro 5.4:containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Micro 5.5:containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:containerd-1.7.29-150000.142.1

Ссылки

Описание

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes - all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.


Затронутые продукты
SUSE Linux Enterprise Micro 5.3:containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Micro 5.4:containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Micro 5.5:containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:containerd-1.7.29-150000.142.1

Ссылки

Описание

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".


Затронутые продукты
SUSE Linux Enterprise Micro 5.3:containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Micro 5.4:containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Micro 5.5:containerd-1.7.29-150000.142.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:containerd-1.7.29-150000.142.1

Ссылки
Уязвимость SUSE-SU-2026:3450-1