Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21562-1

Опубликовано: 11 авг. 2026
Источник: suse-cvrf

Описание

Security update for go-sendxmpp

This update for go-sendxmpp fixes the following issues:

Changes in go-sendxmpp:

  • Update to 0.17.0:
    • Add --ox-transfer-private-key to transfer the encrypted private key to PEP to transfer it to other devices (requires go-xmpp >= v0.3.7).
    • Add --ox-receive-private-key to receive the encrypted private key from PEP.
    • Add config option no_root_warning.
    • Add config option no_legacy_pgp_warning.
    • Also disable legacy PGP when running as root (Ox was already disabled).
    • Disable pinning for not using PLAIN when running as root.
    • Add config option ox_trust_mode with settings blind and tofu.
    • Due to new tofu trust mode for Ox, only one public key per contact is accepted for easier ID handling.
    • Ox: Check that fingerprint of received key equals the advertised one.
    • CVE-2026-39821: Failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266617): Bump net to 0.57.0

Список пакетов

openSUSE Leap 16.0
go-sendxmpp-0.17.0-bp160.1.1

Описание

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".


Затронутые продукты
openSUSE Leap 16.0:go-sendxmpp-0.17.0-bp160.1.1

Ссылки
Уязвимость openSUSE-SU-2026:21562-1