Описание
Security update for cosign
This update for cosign fixes the following issues
Security issue:
- CVE-2026-39395: Incorrect attestation verification due to malformed payloads or mismatched predicate types (bsc#1261859).
Non security issue:
- Update to version 3.0.5 (jsc#SLE-23879).
Список пакетов
openSUSE Leap 16.0
cosign-3.0.6-160000.1.1
cosign-bash-completion-3.0.6-160000.1.1
cosign-fish-completion-3.0.6-160000.1.1
cosign-zsh-completion-3.0.6-160000.1.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1261859
- SUSE CVE CVE-2026-39395 page
Описание
Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-attestation may erroneously report a "Verified OK" result for attestations with malformed payloads or mismatched predicate types. For old-format bundles and detached signatures, this was due to a logic flaw in the error handling of the predicate type validation. For new-format bundles, the predicate type validation was bypassed completely. This vulnerability is fixed in 3.0.6 and 2.6.3.
Затронутые продукты
openSUSE Leap 16.0:cosign-3.0.6-160000.1.1
openSUSE Leap 16.0:cosign-bash-completion-3.0.6-160000.1.1
openSUSE Leap 16.0:cosign-fish-completion-3.0.6-160000.1.1
openSUSE Leap 16.0:cosign-zsh-completion-3.0.6-160000.1.1
Ссылки
- CVE-2026-39395
- SUSE Bug 1261859