Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21036-1

Опубликовано: 22 июн. 2026
Источник: suse-cvrf

Описание

Security update for cosign

This update for cosign fixes the following issues

Security issue:

  • CVE-2026-39395: Incorrect attestation verification due to malformed payloads or mismatched predicate types (bsc#1261859).

Non security issue:

  • Update to version 3.0.5 (jsc#SLE-23879).

Список пакетов

openSUSE Leap 16.0
cosign-3.0.6-160000.1.1
cosign-bash-completion-3.0.6-160000.1.1
cosign-fish-completion-3.0.6-160000.1.1
cosign-zsh-completion-3.0.6-160000.1.1

Описание

Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3.


Затронутые продукты
openSUSE Leap 16.0:cosign-3.0.6-160000.1.1
openSUSE Leap 16.0:cosign-bash-completion-3.0.6-160000.1.1
openSUSE Leap 16.0:cosign-fish-completion-3.0.6-160000.1.1
openSUSE Leap 16.0:cosign-zsh-completion-3.0.6-160000.1.1

Ссылки