Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21276-1

Опубликовано: 08 июл. 2026
Источник: suse-cvrf

Описание

Security update for apptainer

This update for apptainer fixes the following issues:

Changes in apptainer:

  • Enable building of SUID starter for SLES 15 (jsc#PED-16347).
    • Security fix for CVE-2026-2303 (bsc#1270529): Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver. The dependency on mongo-driver has been removed with this version of apptainer.

Список пакетов

openSUSE Leap 16.0
apptainer-1.5.1-bp160.2.1
apptainer-leap-1.5.1-bp160.2.1

Описание

The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer.


Затронутые продукты
openSUSE Leap 16.0:apptainer-1.5.1-bp160.2.1
openSUSE Leap 16.0:apptainer-leap-1.5.1-bp160.2.1

Ссылки