Описание
Security update for apptainer
This update for apptainer fixes the following issues:
Changes in apptainer:
- Enable building of SUID starter for SLES 15 (jsc#PED-16347).
- Security fix for CVE-2026-2303 (bsc#1270529): Heap Out-of-Bounds Read in GSSAPI Error Handling in go.mongodb.org/mongo-driver. The dependency on mongo-driver has been removed with this version of apptainer.
Список пакетов
openSUSE Leap 16.0
apptainer-1.5.1-bp160.2.1
apptainer-leap-1.5.1-bp160.2.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1270529
- SUSE CVE CVE-2026-2303 page
Описание
The mongo-go-driver repository contains CGo bindings for GSSAPI (Kerberos) authentication on Linux and macOS. The C wrapper implementation contains a heap out-of-bounds read vulnerability due to incorrect assumptions about string termination in the GSSAPI standard. Since GSSAPI buffers are not guaranteed to be null-terminated or have extra padding, this results in reading one byte past the allocated heap buffer.
Затронутые продукты
openSUSE Leap 16.0:apptainer-1.5.1-bp160.2.1
openSUSE Leap 16.0:apptainer-leap-1.5.1-bp160.2.1
Ссылки
- CVE-2026-2303
- SUSE Bug 1268652