Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21816-1

Опубликовано: 09 сент. 2026
Источник: suse-cvrf

Описание

Security update for hauler

This update for hauler fixes the following issues:

Changes in hauler:

Update to 2.1.0 (bsc#1265425, CVE-2026-41888, bsc#1278584, CVE-2026-56855,CVE-2026-56854,CVE-2026-78662, ).

Список пакетов

openSUSE Leap 16.0
hauler-2.1.0-bp160.2.1

Описание

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: false configuration, allowing any API client to remove tags from repositories even when the operator has explicitly disabled deletion. This vulnerability is fixed in 3.1.1.


Затронутые продукты
openSUSE Leap 16.0:hauler-2.1.0-bp160.2.1

Ссылки

Описание

The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote address, so a source-address restriction set by those callbacks was silently ignored. The check is now applied to the Permissions returned by any authentication callback.


Затронутые продукты
openSUSE Leap 16.0:hauler-2.1.0-bp160.2.1

Ссылки

Описание

Previously, after a channel has been established, a malicious peer could send crafted messages that would deadlock the entire connection. Now, we handle all RFC 4254 channel messages; global requests are handled explicitly. Then, treat all other messages as a protocol error and tear the connection down instead of buffering and blocking.


Затронутые продукты
openSUSE Leap 16.0:hauler-2.1.0-bp160.2.1

Ссылки

Описание

Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.


Затронутые продукты
openSUSE Leap 16.0:hauler-2.1.0-bp160.2.1

Ссылки